Healthcare Privacy & Security
How we protect health information — HIPAA-aligned practices, with Indian DPDP Act duties as our primary legal frame
Important: D4Dent is an India-focused platform. This page describes security and privacy practices that draw on HIPAA-style controls (encryption, access control, audit logging). It is not a claim that D4Dent is certified HIPAA-compliant or that Business Associate Agreements are in place with every processor. For personal data rights under Indian law, see our Privacy Policy.
Our privacy & security commitment
As a platform serving the dental healthcare ecosystem, we treat patient and clinical data as sensitive. We design technical and organisational measures to protect that data and to support compliance with applicable Indian law, including the Digital Personal Data Protection Act, 2023.
Where useful, we also map controls to widely recognised healthcare frameworks such as HIPAA (privacy, security, and audit concepts). Mapping to those frameworks helps us improve engineering practice; it does not by itself constitute a formal certification.
Privacy Protections
D4Dent implements safeguards inspired by healthcare privacy good practices (including HIPAA Privacy Rule concepts) while aligning primary obligations with applicable Indian law, including the DPDP Act, 2023.
Security Measures
Our platform uses encryption in transit, access controls, and security protocols designed to protect electronic health information processed on D4Dent.
Patient Rights
Patients can review rights materials in the dashboard and request access, correction, or erasure through the channels described in our Privacy Policy. Self-service export and account deletion are being expanded.
Compliance Auditing
We maintain PHI access audit logging and use internal gap analyses to identify and address security and privacy improvements over time.
Vendor Agreements
We work toward appropriate contractual protections with processors who handle personal or health data. Formal BAA coverage for every vendor is not claimed as complete until executed.
Controls we implement
Privacy practices
- Purpose-scoped consent artefacts for clinical and optional non-care processing
- Role-based access to clinical workflows
- Published Privacy Policy with Grievance Officer contact for Data Principal requests
- Patient rights materials in the dashboard, with expanding self-service tooling
Security practices
- TLS for data in transit; managed database encryption at rest
- Authentication and session controls for Platform accounts
- Role-based access with least-privilege intent across services
- Audit logging for PHI access where annotated in clinical services
- Ongoing hardening based on internal security gap analyses
Incident response
If we become aware of a personal data breach, we will investigate, contain impact, and notify affected individuals and authorities as required under applicable Indian law and contractual duties.
Questions about privacy or security?
For DPDP Act / Data Principal requests, use the Grievance Officer details in our Privacy Policy. For general security questions, contact us below.
