Privacy Policy

Data Protection

Back to Portal

Effective Date: January 24, 2026

1. Data Collection Scope

HMS collects and processes personal and professional information necessary for hospital operations. This includes employee records, patient information, financial transactions, and system audit logs.

2. Use of Information

Information collected within HMS is used exclusively for:

  • Healthcare delivery and patient management.
  • Human resources and payroll administration.
  • Logistics and supply chain optimization.
  • Financial reporting and auditing.
  • System security and access control monitoring.

3. Data Security Measures

We implement robust security protocols, including encryption at rest and in transit, multi-factor authentication requirements, and subsystem isolation policies (HMS Fundamentals Policy) to prevent unauthorized access.

4. Roles and Access

Access is strictly granted on a "least privilege" basis. Employee data is only accessible to authorized HR personnel, and patient records are restricted to active clinical staff.

5. Auditing

Every action taken within the system is logged. These logs are used for security auditing and ensuring compliance with healthcare data regulations.

6. Statutory Compliance

HMS operates in strict accordance with the Information Privacy & Medical Confidentiality Act (IPMCA). We maintain records for the legally required duration and cooperate with judicial authorities under valid warrant while protecting patient-doctor privilege.

Privacy FAQ

Who can see my employee profile data?

Access is restricted to HR Administrators (HR3) and your direct Department Head. All access to personal data is logged including the timestamp and the identity of the person viewing the record.

Are patient records encrypted?

Yes. All patient identifiers are encrypted at the database level. Access keys are only provided to clinical staff through the Core Transaction (CT) subsystem during active treatment windows.

How long is system audit data stored?

Under the IPMCA statutory requirements, all system logs and interaction data are retained for a minimum of 7 years before being securely archived.

For privacy concerns or data access requests, please contact the Data Protection Officer.