NABH Aligned StandardsOPD: Mon–Sat 8:00 AM – 8:00 PM • Sun 9:00 AM – 2:00 PM
Digital Personal Data Protection (DPDP) Act 2023 Aligned

Privacy Policy & Hospital Management Data Governance

Governing the Haryana Hospital Management System (HMS), the Official Mobile Application (Package: com.haryanahospital.patientapp), and the Haryana Hospital Web Portal (haryanahospital.com). Last updated: August 2026.

Scope of Hospital Management Digital Ecosystem

This Privacy Policy applies to all patients, authorized hospital clinical staff (Doctors, Nurses), allied health professionals (Pharmacists, Laboratory Technicians, Blood Bank Officers), and administrative personnel (Receptionists, Cashiers/Billing Clerks, System Administrators) who access the Haryana Hospital Management System across mobile and web interfaces.

1

Introduction & Purpose of the Application

Haryana Hospital (“we,” “our,” or “us”) operates a state-of-the-art super-specialty healthcare center located at Juhi Road, Badhra, Haryana – 127308, India. To deliver seamless, error-free clinical care, we provide the Haryana Hospital Management System (HMS) & Patient Companion Mobile Application.

The primary purpose of the Haryana Hospital application is to digitize and orchestrate the full spectrum of hospital operations and clinical care workflows that traditionally occur manually in a hospital. This includes:

  • Reception & Registration: Digital patient enrollment, UHID generation, and doctor schedule-aligned OPD queue booking.
  • Nursing Triage Station: Digital recording of vital parameters (BP, SpO2, blood glucose, temperature, BMI).
  • Doctor EMR & e-Prescriptions: Comprehensive clinical notes, diagnoses, and digital orders for medications and lab tests.
  • Pathology & Diagnostic Labs: Specimen accessioning, diagnostic test processing, and authenticated PDF report uploads.
  • In-Hospital Pharmacy: Real-time prescription forwarding, batch verification, drug dispensing, and inventory tracking.
  • Billing & Cashier Counter: Consolidated invoices combining OPD fees, lab investigations, medicines, and digital receipts.
  • Blood Bank Registry: Blood group inventory, component stock (PRBC, Platelets, FFP), and transfusion safety logs.
  • Inpatient (IPD) Management: Bed occupancy, daily doctor rounds, clinical progress notes, and discharge summaries.

This Privacy Policy explains how personal data and sensitive medical records (Protected Health Information / PHI) are collected, processed, protected, retained, and deleted in strict compliance with India's Digital Personal Data Protection (DPDP) Act 2023, the Information Technology Act, 2000, the Information Technology (SPDI) Rules, 2011, and the National Medical Commission (NMC) Telemedicine Practice Guidelines (2020).

2

Role-Based Access Control (RBAC) & Data Segregation

To maintain patient confidentiality and prevent unauthorized access, the Haryana Hospital Management System enforces strict Role-Based Access Control (RBAC). Hospital staff are granted access strictly on a need-to-know basis according to their clinical or administrative responsibilities:

Hospital RolePermitted Data AccessAccess Restrictions
Receptionist / Front DeskPatient demographics (Name, Age, Gender, Phone, Address, UHID), doctor rosters, appointment booking, and OPD queue management.No access to doctor clinical notes, diagnostic pathology findings, or prescription details.
Nurse / Triage StaffPatient vital readings (Blood Pressure, SpO2, Heart Rate, Glucose, Temp, Height, Weight), triage notes, and IPD nursing charts.Cannot authorize e-prescriptions or modify laboratory diagnostic values.
Doctor / Consultant PhysicianFull clinical EMR access: patient medical history, symptoms, triage vitals, issuing digital e-prescriptions, diagnostic test orders, and discharge summaries.Access restricted to assigned or consulting patients.
Lab Technician / PathologistOrdered diagnostic investigations, test specimen tracking, numerical/biochemical test values entry, and lab PDF report upload.No access to non-diagnostic doctor consultation notes or financial billing charts.
PharmacistDoctor-prescribed medications, dosage instructions, dispensing verification, and pharmacy drug inventory.No access to private clinical examination notes or unrelated laboratory reports.
Cashier / Billing ClerkItemized financial billing, consultation fee receipts, diagnostic test charges, pharmacy invoice items, and payment transaction logs.No access to detailed clinical charts, medical notes, or pathology images.
Patient (Mobile App User)Self-service view and download of own verified digital prescriptions, lab test reports, appointment history, invoices, and metabolic vitals.Strictly isolated to the authenticated patient's own registered account.
3

Categories of Information We Collect

We collect only the minimum necessary information required to deliver high-quality clinical healthcare, hospital administration, and statutory medical documentation.

A. Patient Identification & Demographic Information

Captured during patient registration at reception or via the mobile app: Unique Hospital Identification number (UHID), Full Name, Mobile Number, Email Address, Age, Date of Birth, Gender, Residential Address, Emergency Contact Name and Number, and optional Ayushman Bharat Health Account (ABHA) ID if provided by the patient.

B. Clinical & Sensitive Health Data (Protected Health Information)

Generated or submitted during clinical consultations, diagnostic investigations, and nursing assessments:

  • Vital Signs: Blood Pressure readings, Continuous Glucose Monitoring (CGM) logs, Blood Glucose (Fasting/PP), Pulse/Heart Rate, Oxygen Saturation (SpO2), Body Temperature, and Body Mass Index (BMI).
  • Doctor Clinical Records: Consultation notes authored by Dr. Hitender Sheoran or clinical specialists, chief medical complaints, past medical/surgical history, allergy alerts, ICD diagnostic codes, and digital e-prescriptions.
  • Laboratory & Diagnostic Results: Pathology test orders, biochemistry results (HbA1c, Lipid Profile, Liver Function Tests, Renal Function Tests, Complete Blood Counts), hormone assays, and uploaded PDF lab reports.
  • Blood Bank & Transfusion Data: ABO & Rh blood group, donor screening history, cross-matching compatibility, and transfusion timestamps.

C. Operational, Pharmacy & Billing Records

Appointment booking histories, doctor consultation mode (In-Clinic OPD vs. Video Tele-Consultation), medication dispensing logs, batch numbers, itemized billing invoices, GST receipts, and digital transaction confirmation identifiers.

D. Hospital Staff & System Credentials

Staff user IDs, role designations, encrypted authentication credentials, secure session tokens, and tamper-evident audit logs recording the exact timestamps of clinical record creation, viewing, and modifications.

E. Device & Technical Telemetry

Device model, operating system version, mobile network information, IP address (anonymized for security logs), crash diagnostics, and application performance metrics to maintain system stability and security.

4

Mobile App Permissions & Transparent Rationale

In compliance with Google Play Store Policies and the DPDP Act 2023, the Haryana Hospital Mobile Application requests only permissions strictly necessary for healthcare functionality:

Camera Permission (android.permission.CAMERA)Optional / On-Demand

Purpose: Allows hospital staff and patients to scan patient UHID barcodes, take photos of physical prescription slips or external lab test reports to upload directly into the Electronic Medical Record (EMR). We never access the camera in the background.

Storage / Photos & Media (READ_EXTERNAL_STORAGE / READ_MEDIA_IMAGES)Optional / On-Demand

Purpose: Enables patients to download official PDF diagnostic lab reports and digitally signed prescriptions to their device, or attach previously saved medical PDF documents and lab charts during tele-consultation.

Push Notifications (android.permission.POST_NOTIFICATIONS)User Controlled

Purpose: Transmits critical clinical updates, including real-time OPD queue notifications, doctor appointment reminders, laboratory diagnostic report readiness alerts, and medication timing reminders.

Internet & Network State (ACCESS_NETWORK_STATE, INTERNET)Required

Purpose: Required to establish an encrypted 256-bit SSL connection with the hospital's secure medical database to retrieve appointments, prescriptions, and EMR records.

Phone / SMS (For OTP Verification)Transactional

Purpose: Transmitting and auto-verifying One-Time Password (OTP) security tokens for two-factor patient and staff login. We do not read personal SMS messages.

5

How We Process & Use Information

Your health data and personal identifiers are processed strictly for legitimate clinical, diagnostic, and hospital administrative purposes:

  • Facilitating the digital patient journey: Reception Booking → Nurse Triage → Doctor Consultation → Laboratory/Pharmacy Orders → Billing Invoicing.
  • Generating digitally signed medical prescriptions valid across licensed pharmacies nationwide.
  • Conducting diagnostic pathology investigations and publishing calibrated lab reports.
  • Managing blood bank inventory and tracking blood unit cross-matching for transfusion safety.
  • Maintaining statutory medical records in accordance with the National Medical Commission (NMC) Regulations and Clinical Establishments Acts.
  • Preventing unauthorized system access, identity theft, and cyber-security breaches through system audit logging.
Zero Commercial Sale Guarantee:

Haryana Hospital does NOT sell, rent, monetize, or disclose patient medical records, phone numbers, or health parameters to third-party data brokers, pharmaceutical marketing agencies, advertising networks, or insurance aggregators.

6

Data Security, Storage & Indian Data Localization

We implement comprehensive administrative, physical, and technical safeguards to ensure that patient health data is protected against loss, unauthorized access, and alteration:

256-Bit SSL/TLS Encryption

All data transmitted between mobile devices, web browsers, and hospital servers is encrypted using TLS 1.3. Stored database records and PDF lab reports are encrypted at rest using AES-256.

Indian Data Localization

All primary patient databases, medical imaging archives, and cloud backups reside in certified secure data centers physically situated within the territory of India in compliance with the DPDP Act 2023.

Immutable Audit Trails

Every instance of clinical record creation, doctor review, prescription generation, laboratory result entry, and cashier invoicing is permanently recorded in tamper-evident audit logs.

7

Data Retention Schedules & Statutory Medical Exceptions

In strict adherence to Indian healthcare statutes, medical records and personal data are categorized and retained according to defined regulatory schedules:

App Profile & Account Credentials (Category A)

Deleted within 30 days of verified deletion request

Legal Basis: DPDP Act 2023 Section on User Consent & Erasure

Includes mobile login credentials, device tokens, notification preferences, and application session logs.

Clinical & Diagnostic Health Records (Category B)

Statutory 3 to 5 years (mandated by Clinical Establishments & NMC Regulations)

Legal Basis: National Medical Commission & State Healthcare Acts

Medical histories, official prescriptions, vital logs, and diagnostic lab findings preserved for statutory healthcare audit and clinical continuity.

Financial & Tax Invoices (Category B)

7 years (mandated by Indian Tax & Accounting Laws)

Legal Basis: GST Act 2017 & Income Tax Act 1961

Billing receipts, payment transaction records, cashier logs, and tax invoices required for statutory financial audits.

Aggregated Clinical & Quality Analytics (Category C)

Indefinite (Fully Anonymized & De-Identified)

Legal Basis: DPDP Act 2023 Anonymized Data Provision

Non-identifiable statistical aggregates utilized solely for clinical research and hospital quality benchmarking.

8

Patient Rights & Self-Service Account Deletion

Under the DPDP Act 2023, patients and registered users possess the following statutory rights:

  • Right to Access: Request a digital summary of personal profile records and diagnostic histories held by Haryana Hospital.
  • Right to Correction & Rectification: Request correction of inaccurate demographic or contact details.
  • Right to Account Deletion & Erasure: Request permanent deletion of mobile application user accounts, login credentials, and session tokens.
  • Right to Grievance Redressal: Submit inquiries or complaints to our designated Data Protection & Grievance Officer.

Self-Service Account & Data Deletion Portal

Google Play Store Compliant Account Deletion Mechanism

If you wish to delete your Haryana Hospital mobile application account, login credentials, and non-statutory profile data, you can submit a verified request anytime through our self-service deletion portal or within the mobile app settings.

9

Children's Privacy

Our hospital management system and mobile application are designed for adult patients, legal guardians, and authorized hospital staff. Medical records of pediatric patients (minors under 18 years of age) are created and managed strictly with verifiable parental or legal guardian consent during hospital registration.

10

Third-Party Service Providers & Disclosures

We do not disclose your health records to external parties except in the following limited operational circumstances:

  • Transactional SMS & Messaging Gateways: Encrypted transmission of login OTPs and appointment alert notifications.
  • Accredited Reference Laboratories: Specialized external pathology laboratories when advanced diagnostic genomic or biomarker assays are ordered with patient consent.
  • Statutory & Legal Requirements: When mandated by valid judicial orders, law enforcement warrants, or statutory public health authorities under Indian law.
11

Data Protection & Grievance Redressal Officer

In compliance with Section 10 of the Digital Personal Data Protection (DPDP) Act 2023 and the Information Technology Rules, the contact details of our designated Data Protection & Grievance Officer are:

Officer Name: [Designated Grievance Officer / DPO]

Designation: Data Protection & Patient Grievance Officer

Healthcare Facility: Haryana Hospital

Postal Address: Haryana Hospital, Juhi Road, Near Main Market, Badhra, Haryana – 127308, India

Official Email: care@haryanahospital.com

Grievance Helpline: +91 87087 77648

Working Hours: Monday to Saturday, 10:00 AM – 5:00 PM IST

Response Timeline: All privacy-related inquiries and account deletion requests are acknowledged within 48 hours and processed within 30 days in compliance with DPDP Act regulations.

Call OPDWhatsAppBook Now