1. Security Framework Overview
Vantis Health Private Limited is committed to maintaining the highest security and privacy standards for Protected Health Information (PHI) and Electronic Health Records (ePHI). Our data security framework incorporates principles from the US Health Insurance Portability and Accountability Act (HIPAA) Security & Privacy Rules, the European Union GDPR, and India's DPDP Act 2023.
2. Protected Health Information (PHI) Scope
We treat all patient-identifiable clinical materials as Protected Health Information, including:
- Medical charts, clinical summaries, and discharge summaries.
- Radiology DICOM images (MRI, CT scans, PET scans, X-rays, Ultrasounds).
- Pathology reports, biopsy results, and blood work analysis.
- Physician treatment recommendations, surgical plans, and fee estimates.
- Passport copies and e-Medical Visa supporting documentation.
3. Secure Medical Record Handling Pipeline
When an international patient submits medical files for case evaluation, the information moves through a strict 4-stage encrypted security pipeline:
- Secure Intake Upload: Files are transmitted from the user's browser using TLS 1.3 encryption with 256-bit SSL certificate validation.
- Encrypted Vault Storage: Files are immediately written to isolated, encrypted storage buckets using AES-256 server-side encryption.
- Restricted Doctor Review: Assigned medical advisory physicians access records via zero-footprint web viewers with Multi-Factor Authentication (MFA).
- Hospital IPD Transmission: Files are shared exclusively with International Patient Departments of chosen JCI/NABH accredited hospitals through encrypted peer-to-peer portals.
4. Technical Safeguards
Our infrastructure enforces enterprise-grade technical safeguards:
| Category | Technical Implementation |
|---|---|
| Transit Encryption | TLS 1.3, HTTPS enforcement, HSTS enabled, RSA 2048-bit security keys. |
| At-Rest Encryption | AES-256 storage keys with automated Key Management Service (KMS) rotation. |
| Identity Management | Strict RBAC (Role-Based Access Control) & MFA required for all internal staff. |
| Audit Logging | Immutable, real-time logging of file access, IP addresses, and user activity. |
5. Administrative & Physical Safeguards
In addition to technical controls, Vantis Health enforces rigorous administrative policies:
- Workforce Training: All concierge coordinators and medical assistants undergo mandatory annual HIPAA and data protection privacy training.
- Clean Desk & Screen Policy: Strict prohibition against downloading PHI onto personal hardware, removable media, or unencrypted local drives.
- Non-Disclosure Agreements (NDAs): Mandatory confidentiality covenants signed by every team member and independent contractor.
6. Hospital Partner Compliance & BAAs
Vantis Health partners exclusively with premier hospitals accredited by Joint Commission International (JCI USA) or the National Accreditation Board for Hospitals & Healthcare Providers (NABH International).
Each partner medical center executes formal contractual Business Associate Agreements (BAAs) and Data Processing Agreements (DPAs) obligating them to protect patient record confidentiality, implement equivalent technical controls, and refrain from unauthorized data disclosures.
7. Data Breach Notification Protocol
In the unlikely event of a suspected or confirmed security breach affecting patient ePHI or personal data, Vantis Health maintains a rapid-response Incident Response Protocol:
- Immediate Containment: Security operations isolate affected systems within 60 minutes of detection.
- 72-Hour Notification: Affected patients, partner hospitals, and regulatory authorities (in accordance with GDPR Art. 33 and HIPAA Breach Notification Rule) will be notified without unreasonable delay and within 72 hours of breach verification.
- Remediation: Full forensic investigation and deployment of corrective security patches.
8. Security Operations & Contact
For technical security inquiries, vulnerability reporting, or data protection audits, please reach out to our Information Security team:
Vantis Health Private Limited
Email:
security@vantishealth.org | dpo@vantishealth.org24/7 Security Hotline: +91-9820000000