Patient data is the most sensitive data in the world. Here's exactly how we protect it across ClinicOS, MediCore HIS and ClinicBot.
Last updated: June 1, 2026
CareNexa handles sensitive health data for thousands of patients. We treat security not as a checkbox but as a core product value. Every feature is designed with security and privacy in mind from day one.
All data encrypted with AES-256 on MongoDB Atlas India (Mumbai region).
TLS 1.3 enforced on all API and web connections. HTTP redirects to HTTPS.
Stateless JWT tokens with short expiry. Refresh token rotation on every session.
Granular roles: Doctor, Receptionist, Nurse, Lab, Pharmacy, Admin, Patient. Each sees only what they need.
Every critical action (login, data edit, ABHA link, invoice creation) is logged with user, timestamp and IP.
Each clinic and hospital is a completely isolated tenant. No cross-tenant data access is possible.
All passwords hashed with bcrypt (12 rounds). Plain passwords are never stored.
API rate limiting on all endpoints. Brute-force protection on login and OTP flows.
Every ABHA verification and link is logged with patient consent, staff member, method and timestamp.
IT Act 2000
Data processing and storage per Indian IT laws
DPDP Act 2023
Digital Personal Data Protection Act compliance
ABDM / ABHA M1
MediCore HIS certified for ABDM Milestone 1
TLS 1.3
All data in transit encrypted
AES-256
All data at rest encrypted
bcrypt (12 rounds)
All passwords securely hashed
Database: MongoDB Atlas with data residency in Mumbai, India. Automated daily backups with 7-day retention. Point-in-time recovery available.
Application hosting: Node.js/Express backend. Next.js frontend. Deployed on cloud infrastructure with auto-scaling.
Uptime: 99.5% monthly uptime SLA. Real-time status monitoring. Incident response within 30 minutes for critical issues.
If you discover a security vulnerability in CareNexa products, please report it responsibly to security@carenexa.in. We aim to respond within 48 hours and will credit responsible disclosures.
Please do not publicly disclose vulnerabilities until we have had a chance to address them.
Our team is available for security reviews and compliance queries.
security@carenexa.in →