Data Security Policy

EpikDoc is a healthcare technology company; storing, managing and protecting sensitive health data is core to everything we do. We use a combination of established security protocols and data-protection practices to safeguard patient, clinic and lab information.

Data Security Council of India (DSCI) — a NASSCOM initiative

EpikDoc AI is a NASSCOM member (Membership ID 3306078) and is in the process of onboarding as a Corporate Member of the Data Security Council of India (DSCI), India's premier industry body for cybersecurity and data protection. We work towards aligning our practices with DSCI best practices and the principles of India's Digital Personal Data Protection (DPDP) Act, 2023.

Security Framework

EpikDoc implements reasonable security practices and procedures and maintains a documented information security programme containing managerial, technical, operational and physical control measures that are commensurate with the information processed and the nature of our business. Our practices are designed to align with the principles of the Digital Personal Data Protection Act, 2023 and evolving industry security norms as the Act's provisions come into force.

We represent only those memberships and certifications we actually hold. Items described as "planned", "in progress" or "roadmap" are targets, not completed attestations.

Infrastructure & Cloud Isolation

  • Secure Hosting: Data is hosted on AWS cloud infrastructure
  • Private Cloud Isolation: All EpikDoc AI applications, including CRM, Xray IQ and EpikLabs, run in isolated, private cloud environments — no other applications or services share access to your data
  • Network Security: Multiple network security layers between the internet and application servers, with traffic inspection to detect and stop unusual activity
  • Monitoring: Continuous infrastructure monitoring supported by cloud-provider security tooling; advanced anomaly detection and AI-driven threat detection are planned for future integration

Encryption

All data is encrypted in transit using industry-standard protocols. Encryption at rest is planned as part of ongoing infrastructure-hardening initiatives. Application data and user data reside within the same isolated Virtual Private Cloud, so data is not exposed during internal transfer.

Access Control

  • Role-Based Access: fine-grained, role-based permissions for doctors, receptionists, lab technicians and admins — staff see only what you allow
  • Authentication: password-based login with mobile OTP verification; multi-factor enforcement is being progressively strengthened across workflows
  • Access Zones: optional IP-restricted access so an EpikDoc Pro account can be reached only from devices/locations you specify
  • Audit Logs & Sessions: tracking of data access and automatic logout after inactivity

Application Security

  • Code review for every release and periodic internal security reviews
  • OWASP Top 10 awareness for all web applications
  • Enforcement of non-disclosure agreements and strict usage terms for external parties
  • Formal penetration testing and independent external security assessments are planned as part of our security-maturity roadmap

AI Data Protection

  • Patient data used for AI training is anonymised and stripped of identifiers
  • AI-generated insights never replace clinical judgement — they serve as decision support only
  • AI features operate on a clinic's own data and are not pooled across customers

Backups & Recovery

  • Multi-region, encrypted backups stored in geographically separated locations
  • Point-in-time recovery to restore data from a prior moment
  • Automated daily backups with versioning for historical record retention

Compliance & Standards

  • DPDP Act, 2023: committed to compliance and aligned with its principles as its provisions come into force; EpikDoc acts as Data Processor for clinical data (see our DPDP Compliance Statement)
  • NASSCOM / DSCI: NASSCOM member (Membership ID 3306078); DSCI Corporate Membership in process
  • ABHA Integration: secure integration with Ayushman Bharat Digital Mission where used
  • ISO 27001: information security management certification (in progress / roadmap, not claimed as currently held)

Employee Security

EpikDoc personnel are bound by confidentiality agreements and security practices, and access to customer data is limited to authorised personnel on a need-to-know basis.

Incident Response

In the event of a security incident, we have a defined response process covering containment, investigation, notification of affected users and the relevant authorities as required under applicable law (including the DPDP Act, 2023 as and when its provisions come into force), and remediation.

What You Can Do To Keep Your Data Safe

  • Use a strong, unique password (8–20 characters, mixed case, a digit and a special character) and change it regularly
  • Enable two-factor authentication and Access Zones together for the strongest protection
  • Create separate accounts for each staff member with appropriate access levels instead of sharing logins
  • Log out on shared devices and report suspicious activity immediately

Disclaimer

While EpikDoc takes reasonable precautions to protect personal information, no method of transmission or storage over the internet is fully secure. EpikDoc shall not be responsible for any breach of security or for any actions of third parties, or events that are beyond its reasonable control, including but not limited to acts of government, computer hacking, unauthorised access to computer data and storage devices, system failure, or poor quality of internet or telecommunication services. Users are responsible for safeguarding their account credentials; EpikDoc accepts no liability for loss arising from unauthorised use of an account where credentials have been compromised.

Report Security Concerns

If you discover a security vulnerability or have concerns about our security practices, please contact us at security@epikdoc.ai. We appreciate responsible disclosure and request that issues not be publicly disclosed until investigated and resolved.