At Mediorum Technologies, we are committed to protecting the privacy and security of your information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Hospital Management System (HMS) platform and associated services.
1. Information We Collect
We collect information in the following categories:
Personal Identification Information: Name, email address, phone number, job title, and organisation details when you register or contact us.
Patient Health Information (PHI): When used in a clinical setting, our platform may process patient health records, diagnostic data, treatment history, and billing information strictly on behalf of our hospital clients (data controllers).
Usage Data: Log data, IP addresses, browser type, pages visited, and interaction data to improve our service.
Technical Data: Device identifiers, cookies, and session tokens used for authentication and performance monitoring.
2. How We Use Your Information
We use collected information to:
- Provide, operate, and maintain the Mediorum platform
- Process transactions and send billing-related communications
- Respond to customer service requests and support tickets
- Send administrative information, product updates, and security notices
- Analyse usage trends to improve platform performance
- Comply with legal obligations and regulatory requirements (HIPAA, ABDM, HL7 FHIR)
3. Data Security
We implement enterprise-grade security measures including:
- AES-256 encryption for data at rest
- TLS 1.3 encryption for all data in transit
- Role-based access control (RBAC) with audit logging
- Regular third-party penetration testing
- SOC 2-aligned security practices
- Multi-factor authentication (MFA) for all administrative access
We do not sell, trade, or rent your personal information to third parties.
4. HIPAA & ABDM Compliance
Mediorum is designed to support HIPAA compliance for covered entities and business associates. We operate as a Business Associate under HIPAA and sign Business Associate Agreements (BAAs) with our hospital clients. We also comply with ABDM (Ayushman Bharat Digital Mission) guidelines for health data exchange in India.
5. Data Retention
We retain personal data for as long as necessary to provide our services and comply with legal obligations. Patient health records are retained per the requirements of the applicable healthcare regulations (typically 7–10 years depending on jurisdiction). You may request deletion of your account data by contacting us at privacy@mediorum.in.
6. Third-Party Services
We may use trusted third-party services for cloud hosting (Microsoft Azure), email delivery, analytics, and payment processing. These partners are contractually bound to protect your data and may not use it for their own purposes.
7. Your Rights
Depending on your location, you may have rights to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Request deletion of your personal data
- Object to or restrict processing of your data
- Data portability
To exercise any of these rights, contact us at privacy@mediorum.in.
8. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact:
Mediorum Technologies
Email: privacy@mediorum.in
General: contact@mediorum.in