Security & privacy

Patient data, handled like it matters

Hospital records are some of the most sensitive data there is. HMS limits who can see them, records staff sign-ins, and shares them outside the hospital only with the patient’s consent.

Role-based access

Every user has a role, a department, and separate add, view, edit and delete permissions. Staff see only the modules their role needs.

Optional activity log

For deployments that need it, a request log recording the user, page, IP address and device can be switched on.

Consent-first sharing

Records leave the hospital through ABDM only after the patient consents, and only within the scope they approved.

Encrypted health-record exchange

ABDM records are encrypted end to end with X25519 key agreement and AES-256-GCM.

Token-protected APIs

The pathology report API requires an API token, and tokens can be rotated without downtime.

HTTPS only

HMS is served over HTTPS, and plain HTTP requests are redirected.

Recorded staff sessions

Every staff sign-in and sign-out is recorded with time, IP address and device.

Data where you want it

Deploy on the hospital’s own server when patient data has to stay on the premises.

Access control

Roles and what they can reach

Each user is given one role and a department. Add, view, edit and delete permissions are set separately on top of the role.

RoleTypically used byAccess
AdministratorHospital administrationAll modules, master data (departments, doctors, users) and reports
RegistrationCounter staffPatient registration, revisits and registration reports
Queue OperatorOPD floor staffThe token queue of their own department
PathologyLab technicians, pathologistsLab registration, result entry and lab reports
RadiologyRadiology staffRadiology reports and film usage
CardiologyCardiology staffThe cardiology case register
IPDWard staffAdmissions, discharges and IPD reports
CCWCasualty staffCasualty admissions and outcomes
DrugCentral drug storePurchases, batch stock and supply to departments
Emergency Med StoreEmergency store pharmacistsEmergency medicine stock and patient issues
Blood BankBlood bank staffDonations, component stock and issues
Record RoomMedical records staffScanned records with ICD coding
Hosting

Your data stays where your policy says

HMS can run on a server inside the hospital, keeping patient data on the premises, or on cloud infrastructure. Either way it is monitored around the clock by the team that built it.

Found a security issue? Please report it privately to contact@swastik.ai with the subject “Security report”, and give us a chance to fix it before sharing it publicly.

Need to review HMS against your data policy?

We can walk your IT and administration teams through access control, sign-in records and hosting.