Last reviewed: 1 January 2026
CareQ is built for Indian clinics and hospitals. While the US Health Insurance Portability and Accountability Act (HIPAA) is a US federal regulation, its security and privacy framework represents the global gold standard for protecting patient health information (PHI). CareQ adopts HIPAA-aligned practices — its administrative, physical, and technical safeguards — as a baseline for how we handle all patient data regardless of geography.
Protected Health Information (PHI) is any individually identifiable information relating to a person's health, healthcare, or payment for healthcare. In CareQ, PHI includes: patient names, mobile numbers, dates of birth, visit records, diagnoses, prescriptions, and billing details.
Roles under HIPAA terminology:
As a Business Associate, CareQ commits to using PHI only as necessary to provide the Service, to safeguarding it with appropriate technical and organisational measures, and to cooperating with you in meeting your own compliance obligations.
CareQ maintains internal security policies covering: data handling, access management, incident response, vendor risk management, and employee training. These policies are reviewed at least annually.
All CareQ employees with access to production systems or PHI undergo security and privacy training as part of onboarding and annually thereafter.
Access to production systems is limited to a small number of authorised engineers. Access is granted on a least-privilege basis and reviewed quarterly. All access requires multi-factor authentication and is logged.
CareQ maintains a formal incident response plan. Any suspected data breach is investigated within 24 hours of detection. See Section 6 for our breach notification commitments.
We conduct periodic risk assessments to identify and mitigate threats to the confidentiality, integrity, and availability of patient data.
CareQ's infrastructure runs on enterprise cloud data centres that maintain:
CareQ employees do not have physical access to servers. All administrative access is remote, authenticated, and logged.
CareQ uses a limited set of sub-processors to operate the platform. All sub-processors who may handle PHI are:
Our primary sub-processors include cloud infrastructure providers (for hosting and database services) and payment processors. We do not share patient records with any marketing or analytics platforms.
In the event of a confirmed or suspected data breach involving PHI, CareQ will:
To report a suspected breach or security vulnerability: info@amdcode.com
CareQ provides the platform and safeguards, but your clinic also has responsibilities for PHI protection:
CareQ is designed with Indian law as the primary compliance framework:
CareQ supports your obligations as a Data Fiduciary under the DPDPA. Patient data entered by your clinic is processed by CareQ only as a Data Processor on your instructions. We maintain technical and organisational measures consistent with those required of a Data Processor under the Act.
We follow the security practices specified under these rules for sensitive personal data, including health information.
Patient data is stored on servers located in India or regions where Indian law permits. We will update this section if our data localisation arrangements change and will notify affected clinics in advance.
A Business Associate Agreement (BAA) is a contract between a covered entity (your clinic) and a business associate (CareQ) that establishes each party's responsibilities for PHI protection, use, and disclosure.
If you operate a clinic that is subject to HIPAA (for example, because you serve US-based patients) or if your institution's compliance programme requires a formal BAA, CareQ can provide one.
For any questions about CareQ's security or compliance practices:
We take security reports seriously. If you discover a vulnerability in CareQ, please report it responsibly and we will investigate and respond within 24 hours.