← Back to Clinitricks

Privacy Policy

Last updated: September 17, 2026

1. Introduction

Clinitricks ("we", "our", "the platform") is a clinic management platform that processes personal data and protected health information (PHI) on behalf of healthcare providers. This Privacy Policy explains how we collect, use, store, protect, and share your information in compliance with:

  • Digital Personal Data Protection Act, 2023 (DPDP Act) — India
  • Health Insurance Portability and Accountability Act (HIPAA) — United States
  • Applicable data protection laws of the jurisdictions in which we operate

2. Data We Collect

We process the following categories of data on behalf of healthcare providers:

Personal Identifiers

Name, phone number, email address, postal address, date of birth, gender, government health IDs (e.g., ABHA, NHS number).

Protected Health Information (PHI)

Medical diagnoses, prescriptions, allergies, chronic conditions, current medications, appointment history, treatment records, and billing information.

Technical Data

IP address, browser user-agent, session identifiers, and access timestamps (collected for security and audit purposes).

3. Purpose of Processing

Your data is processed for the following purposes:

  • Providing healthcare management services to your healthcare provider
  • Scheduling appointments and managing treatment records
  • Generating prescriptions and billing invoices
  • Maintaining legally required audit trails
  • Ensuring the security and integrity of health records
  • Compliance with applicable healthcare regulations

4. Legal Basis for Processing

  • Consent (DPDP Act §3-5): We collect explicit consent before processing personal data. Consent can be provided in-person or via digital consent forms.
  • Treatment Purpose (HIPAA): PHI is processed for treatment, payment, and healthcare operations as permitted under HIPAA.
  • Legitimate Interest: Security monitoring, audit logging, and fraud prevention.

5. Data Security Measures

We implement the following safeguards to protect your data:

  • Encryption at Rest: All PHI is encrypted using AES-256-CBC (NIST SP 800-111 compliant)
  • Encryption in Transit: All data transmission uses TLS 1.2+ / HTTPS
  • Access Controls: Role-based access control (RBAC) ensures minimum necessary access
  • Audit Logging: All access to PHI is logged with tamper-evident hash chains
  • Session Security: Automatic logoff after 15 minutes of inactivity (HIPAA §164.312(a)(2)(iii))
  • Tenant Isolation: Each healthcare provider's data is logically isolated

6. Your Rights

Under the DPDP Act

  • Right to Access (§8(3)): You may request a summary of the personal data we process about you.
  • Right to Correction (§8(4)): You may request correction of inaccurate personal data.
  • Right to Data Portability (§8(5)): You may request export of your data in a machine-readable format (JSON).
  • Right to Erasure (§10): You may request deletion/anonymization of your personal data, subject to legal retention requirements.
  • Right to Withdraw Consent (§5): You may withdraw consent at any time. This will not affect the lawfulness of processing before withdrawal.
  • Right to Grievance Redressal (§8(7)): You may raise a grievance with our Data Protection Officer.

Under HIPAA

  • Right to Access: You may request access to your PHI (§164.524).
  • Right to Amendment: You may request amendment of your PHI (§164.526).
  • Accounting of Disclosures: You may request an accounting of disclosures of your PHI (§164.528).
  • Breach Notification: You will be notified of any breach affecting your PHI (§164.400-414).

7. Data Retention

  • Audit logs are retained for a minimum of 6 years (HIPAA requirement)
  • Consent records are retained for a minimum of 7 years (DPDP Act requirement)
  • Patient records are retained as required by applicable healthcare regulations
  • Upon data erasure request, personal identifiers are anonymized but de-identified records are retained for compliance

8. Data Sharing

We do not sell, rent, or share your personal data with third parties except:

  • With your healthcare provider (the data controller)
  • When required by law or court order
  • For treatment, payment, or healthcare operations (HIPAA permitted uses)
  • With your explicit consent

9. Consent Management

We obtain consent through the following methods:

  • In-person: Verbal or written consent recorded by healthcare staff
  • Digital: Consent form sent via WhatsApp or email with secure token link

Consent can be withdrawn at any time by contacting your healthcare provider or using the consent withdrawal form. Withdrawal of consent may limit the services that can be provided to you.

10. Breach Notification

In the event of a data breach:

  • Affected individuals will be notified within 72 hours (DPDP Act)
  • The Data Protection Board of India will be notified as required (DPDP Act §8)
  • HHS Office for Civil Rights will be notified as required (HIPAA §164.408)

11. Contact Information

For questions, data access requests, or grievances related to your personal data, please contact:

Data Protection Officer

Clinitricks

Email: privacy@clinitricks.com

12. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be communicated through the platform and will take effect upon posting. Continued use of the platform after changes constitutes acceptance of the updated policy.

© 2026 Clinitricks. All rights reserved.