Security & Compliance
Health data is the most sensitive data a person has. Here is what we do to protect it, and which standards we build against.
Last updated: 4 August 2026
Encryption
AES-256-GCM for data at rest and TLS for everything in transit.
Access control
Role-based permissions so staff see only what their role requires.
Audit trails
Every record access and change is logged, attributable and reviewable.
Digital signatures
Clinical documents are signed, so authorship and integrity are provable.
ABDM & FHIR R4
ABHA linking, HFR, HPR and consent, on NRCES-published FHIR R4 profiles.
Consent-first
Sharing happens on consent. MedScribe stores no consultation audio.
Data protection
- Health and personal data is encrypted at rest using AES-256-GCM.
- All traffic between your device and our services is encrypted with TLS.
- Credentials are stored hashed, never in plain text.
- Backups are encrypted and access to them is restricted and logged.
Access and accountability
- Role-based access control across every module — a receptionist does not see what a consultant sees.
- Individual accounts, so audit trails attribute actions to a person rather than a shared login.
- Full audit logging of record access, edits and exports.
- In Medler Health, family sharing is PIN-protected and every access is recorded in a log the account holder can review.
Regulatory alignment
- ABDM / ABHA — ABHA creation and linking, Health Facility Registry, Healthcare Professional Registry, and ABDM consent flows.
- FHIR R4 — implemented against the profiles published by NRCES, so records are portable rather than locked in.
- DPDP Act 2023 — our processing, consent and grievance handling are aligned with the Act. See the privacy policy.
- NABH — Medler HMS includes an accreditation toolkit to help facilities assemble the evidence NABH assessment requires.
- Telemedicine — tele-prescription workflows follow NHA telemedicine practice guidelines.
AI and clinical safety
Our AI features are clinical decision support. They surface information and draft documentation; the clinician reviews, edits and takes responsibility for what is saved and acted upon. We do not present AI output as an independent diagnosis, and we do not automate clinical decisions.
MedScribe operates consent-first and does not retain consultation audio. The transcript becomes a draft SOAP note that the doctor must review before it enters the record.
Reporting a vulnerability
If you believe you have found a security vulnerability in any Medler product, please tell us before telling anyone else. Email contact@medler.ai with “Security” in the subject line and include enough detail to reproduce the issue.
We will acknowledge your report, keep you updated while we investigate, and we will not pursue action against researchers who report in good faith, avoid accessing or altering other people’s data, and give us reasonable time to fix the issue.
Incident response
We monitor for unusual access and maintain an incident process covering containment, investigation, remediation and notification. Where a breach is likely to cause harm, we notify affected users and the relevant authorities as required under the DPDP Act.
A note on absolute claims
No system is unhackable, and any vendor who tells you otherwise is selling something. What we commit to is defence in depth, honest disclosure, and fixing problems quickly when they are found.
Questions about this document?
Write to contact@medler.ai or call +91-9289363999. You can also write to us at 2nd Floor, 103/A-1, Sector-6, Rohini, New Delhi – 110085, India.