Security & Compliance
Healthcare data demands the highest security standards. Our multi-layered security architecture protects patient data at every level — from application code to physical infrastructure.
Modules under the trust umbrella
Role journeys protected by RBAC
Deployment models with security controls
Compliance frameworks surfaced
Certifications & Compliance
We don't just claim compliance — we prove it with certifications, audits, and transparent security practices.
Full HIPAA compliance with BAA support, access controls, audit logging, and encryption. PHI is protected at every layer.
Built-in support for NABH accreditation documentation, quality checklists, and compliance reporting workflows.
Certified integration with Ayushman Bharat Digital Mission for ABHA ID, health records, and consent management.
Full GDPR support with data subject rights, DPA, privacy by design, and EU data residency option.
SOC 2 Type II audit — verified controls for security, availability, confidentiality, and processing integrity.
Compliant with India's Digital Personal Data Protection Act 2023 — data fiduciary obligations met.
California Consumer Privacy Act compliance — data access, deletion, and opt-out rights fully supported for US users.
Certified HL7 FHIR R4 interoperability — US Core, UK Core, AU Base, and IN Core profiles supported.
Information Security Management System aligned with ISO 27001 standards. Annual internal audits and external review.
Personal Information Protection and Electronic Documents Act compliance for Canadian healthcare organizations.
Protection of Personal Information Act compliance — data subject rights, consent management, and cross-border transfer safeguards.
Personal Data Protection Act compliance for Singapore and Southeast Asian deployments with PDPC guidelines support.
Trust at Launch Scale
The trust story now supports public launch, regulated procurement, and enterprise due diligence across 17 markets, 44+ stakeholder roles, and 12+ deployment models.
NABH, DPDP, ABDM, RGHS, PM-JAY ready
Regulatory and audit coverage is designed in from day one so hospitals and governments can evaluate faster and launch with less retrofit risk.
48+ revenue streams across 7 tiers
Commercial upside extends beyond SaaS into claims, compliance, training, AI, services, data, support, and channel-led models.
ABDM + WASA + scheme pathways
Certification-heavy pathways create stickiness for public-health, scheme-linked, and regulated enterprise deployments.
Partner / OEM launch ready
Hospitals, groups, and channel partners can launch under their own brand while keeping the same core platform intelligence.
Security Architecture
Our security architecture follows the defense-in-depth principle — multiple overlapping layers ensure no single point of failure.
All user inputs sanitized and validated server-side. Parameterized queries prevent SQL injection. Content Security Policy headers block XSS.
Bcrypt password hashing with salt. Multi-factor authentication (MFA/2FA) via TOTP apps, SMS, or email OTP. Session management with automatic timeouts.
Role-based access control (RBAC) with principle of least privilege. Granular permission system — 200+ configurable permissions across the 18-role operating model and broader 253+ module platform.
JWT-based API authentication with short-lived tokens (15 min access, 7-day refresh). Rate limiting, IP allowlisting, and webhook signature verification.
Configurable session timeouts (default: 30 min idle). Concurrent session detection. Automatic logout on inactivity. Session invalidation on password change.
Complete audit log of every data access, modification, login, and administrative action. Tamper-proof logs with timestamps, IP addresses, and user identity.
AES-256 encryption for all stored data including database records, file uploads, and backups. Encryption keys managed via AWS KMS / Azure Key Vault.
TLS 1.3 for all data in transit. HSTS enforcement. Certificate pinning for mobile apps. No fallback to insecure protocols.
Additional field-level encryption for sensitive PHI fields (diagnoses, prescriptions, lab results). Encrypted search indexes for performance.
Hardware Security Module (HSM) backed key management. Automatic key rotation every 90 days. Separation of key management and data access roles.
Deployed on Tier-1 cloud infrastructure (AWS / Azure / GCP) with SOC 2 certified data centers. 6 global regions: India (Mumbai/Chennai), US (Virginia/Oregon), EU (Frankfurt/Ireland), Middle East (Bahrain/UAE), Singapore, and Africa (Cape Town). Customers choose their data residency region.
Virtual Private Cloud (VPC) isolation. Web Application Firewall (WAF). DDoS protection via AWS Shield / Azure DDoS Protection. Network segmentation.
Docker containers with distroless base images. Kubernetes with pod security policies. Container image scanning for vulnerabilities before deployment.
24/7 infrastructure monitoring with alerting (PagerDuty). Real-time threat detection. Anomaly detection for unusual access patterns. SIEM integration.
Automated daily backups with 30-day retention. Point-in-time recovery (5-min granularity). RTO: 4 hours, RPO: 5 minutes. Multi-region replication for enterprise.
Background checks for all employees. Mandatory security awareness training (quarterly). NDA and confidentiality agreements. Principle of least privilege for internal access.
All third-party vendors assessed for security practices. BAAs with all sub-processors. Annual vendor security reviews. No data shared without contractual safeguards.
Documented incident response plan with defined roles, escalation paths, and communication templates. 72-hour breach notification per GDPR/DPDP. Post-incident review and RCA.
Data center physical security managed by AWS/Azure — biometric access, 24/7 surveillance, environmental controls. No customer data on employee devices.
Security Practices
Annual third-party penetration testing by certified security firms. Automated vulnerability scanning (weekly). All findings tracked to remediation with SLAs.
Security baked into every stage: threat modeling, code review, SAST/DAST scanning, dependency auditing, and security-focused QA before every release.
Automated scanning of all dependencies (npm, pip, composer) for known vulnerabilities. Dependabot alerts with automatic PR generation for critical updates.
Annual SOC 2 Type II audit. HIPAA risk assessments. GDPR DPIA for new features. Internal security audits quarterly. External audit reports available on request.
Dedicated security team with CISSP, CEH, and OSCP certified professionals. Security champions embedded in each engineering team. Bug bounty program.
Documented security policies: access control, data classification, acceptable use, change management, business continuity, and disaster recovery. Reviewed annually.
| Category | Details |
|---|---|
| Data Encryption | AES-256 at rest, TLS 1.3 in transit, field-level PHI encryption |
| Authentication | Bcrypt hashing, MFA/2FA, OAuth 2.0, session management with auto-timeout |
| Access Control | RBAC with 200+ granular permissions, IP allowlisting, audit logging |
| Data Residency | 6 global regions: India (Mumbai/Chennai), US (Virginia/Oregon), EU (Frankfurt/Ireland), Middle East (Bahrain/UAE), Singapore, Africa (Cape Town). Customer chooses region at setup. |
| Backup & Recovery | Daily automated backups, 30-day retention, PITR (5-min), RTO: 4h, RPO: 5min |
| Uptime SLA | 99.9% monthly uptime guarantee with service credits |
| Penetration Testing | Annual third-party pentest, weekly automated scans, bug bounty program |
| Compliance | HIPAA, NABH, ABDM, GDPR, SOC 2 Type II, DPDP Act 2023, CCPA, HL7 FHIR R4, ISO 27001, PIPEDA, POPIA, PDPA, LGPD, HITECH |
| Incident Response | 24/7 monitoring, 72-hour breach notification, documented IR plan |
| Data Retention | Medical records per legal mandate (7-10 years), account data: subscription + 90 days |
Yes. SOC 2 Type II reports are available to customers and prospects under NDA. Contact our security team at security@ideadunes.com to request a copy.
Yes. We run a responsible disclosure program. Security researchers can report vulnerabilities to security@ideadunes.com. We acknowledge valid reports within 48 hours and offer recognition and rewards.
Enterprise customers can conduct their own security assessments and penetration tests with advance coordination. Contact your account manager to schedule.
Email security@ideadunes.com with details. Please include steps to reproduce, impact assessment, and any proof-of-concept. Do not disclose publicly until we have resolved the issue.
Yes. We provide a Business Associate Agreement to all customers who handle PHI. The BAA is included with Hospital and Enterprise plans and available on request for other plans.
Critical vulnerabilities (CVSS 9.0+): patched within 24 hours. High (7.0-8.9): within 72 hours. Medium (4.0-6.9): within 7 days. All patches are deployed via zero-downtime rolling updates.
Our security team is happy to answer your questions, provide documentation, or schedule a security review call.
Get Started Today
Join hundreds of hospitals and clinics using IdeaDunes to streamline operations, improve patient care, and grow revenue. Start your free trial — no credit card required.
No credit card required • Free onboarding • Cancel anytime
Role Quick Start
Executives, hospital teams, partners, government buyers, and patient-facing users can jump directly to their correct next step from anywhere in the web experience.