EpikDoc is a healthcare technology company; storing, managing and protecting sensitive health data is core to everything we do. We use a combination of established security protocols and data-protection practices to safeguard patient, clinic and lab information.
Data Security Council of India (DSCI) — a NASSCOM initiative
EpikDoc AI is a NASSCOM member (Membership ID 3306078) and is in the process of onboarding as a Corporate Member of the Data Security Council of India (DSCI), India's premier industry body for cybersecurity and data protection. We work towards aligning our practices with DSCI best practices and the principles of India's Digital Personal Data Protection (DPDP) Act, 2023.
EpikDoc implements reasonable security practices and procedures and maintains a documented information security programme containing managerial, technical, operational and physical control measures that are commensurate with the information processed and the nature of our business. Our practices are designed to align with the principles of the Digital Personal Data Protection Act, 2023 and evolving industry security norms as the Act's provisions come into force.
We represent only those memberships and certifications we actually hold. Items described as "planned", "in progress" or "roadmap" are targets, not completed attestations.
All data is encrypted in transit using industry-standard protocols. Encryption at rest is planned as part of ongoing infrastructure-hardening initiatives. Application data and user data reside within the same isolated Virtual Private Cloud, so data is not exposed during internal transfer.
EpikDoc personnel are bound by confidentiality agreements and security practices, and access to customer data is limited to authorised personnel on a need-to-know basis.
In the event of a security incident, we have a defined response process covering containment, investigation, notification of affected users and the relevant authorities as required under applicable law (including the DPDP Act, 2023 as and when its provisions come into force), and remediation.
While EpikDoc takes reasonable precautions to protect personal information, no method of transmission or storage over the internet is fully secure. EpikDoc shall not be responsible for any breach of security or for any actions of third parties, or events that are beyond its reasonable control, including but not limited to acts of government, computer hacking, unauthorised access to computer data and storage devices, system failure, or poor quality of internet or telecommunication services. Users are responsible for safeguarding their account credentials; EpikDoc accepts no liability for loss arising from unauthorised use of an account where credentials have been compromised.
If you discover a security vulnerability or have concerns about our security practices, please contact us at security@epikdoc.ai. We appreciate responsible disclosure and request that issues not be publicly disclosed until investigated and resolved.