Security, privacy & complianceat MediCard
This page is maintained by the MediCard team to answer common security and privacy questions about the MediCard platform. It describes the controls we operate today and the policies you can review and rely on. It is not an independent certification.
MediCard is designed to align with the safeguards of the HIPAA Security Rule and India's Digital Personal Data Protection Act, 2023. We are a patient-controlled personal health record, not a HIPAA Covered Entity or Business Associate.
Controls we operate
Enterprise-grade safeguards, built in
HIPAA-aligned safeguards
Designed to meet the administrative, physical and technical safeguards of the HIPAA Security Rule (45 CFR §164.308–312). MediCard is a patient-controlled PHR, not a Covered Entity.
DPDP Act, 2023
For users in India, MediCard operates as a Data Fiduciary under the Digital Personal Data Protection Act. Grievance Officer: Mohit A Jaitly (mohit@medicard.co.in).
Encryption
TLS 1.2+ on every request. Data at rest is encrypted with provider-managed keys on the managed database and object storage.
Row-Level Security
Every table storing user data enforces Postgres RLS. No user can read another user's records without an explicit consent grant.
Authentication
Email + password and magic-link sign-in with session rotation. Every login is written to your Login History.
Audit Logging
Security-relevant events — access requests, PIN attempts, consent changes, admin actions — are appended to an immutable log.
Role-Based Access
RBAC matrix separates roles (user, family, doctor, hospital, lab, pharmacy, admin, super admin). Roles never live on the profile record.
Break-Glass
Emergency access requires a documented reason and is logged for post-event review.
Backups
Daily managed backups of the database. Storage buckets are versioned with lifecycle rules.
Least-Privilege Infra
Server functions run in isolated edge workers. Admin secrets stay server-side; only publishable keys ship to the browser.
Verified Provider Network
Hospitals, labs and pharmacies in the verified network are manually reviewed and can be revoked at any time.
Shared responsibility
Where MediCard ends and you begin
MediCard operates
- Platform infrastructure & hosting
- Encryption in transit and at rest
- RLS, RBAC and audit logging
- Backups and disaster recovery
- Sub-processor management
We share
- Access control decisions on your data
- Consent grants and revocations
- Verified provider integrity
- Notification of material incidents
You own
- Your credentials and devices
- Who you share your card and QR with
- Which family members you manage
- Accuracy of the records you upload
Published policies
Read what we commit to
Each policy is versioned and dated. Older versions remain available on request.
Security contact
Found something? Tell us privately.
We acknowledge every valid report within 3 business days and offer safe harbor for good-faith research within the scope of our vulnerability disclosure policy.