Legal
Data Security & Data Protection Policy
Aviral Medcare handles clinical, administrative and operational information for eye hospitals. This page sets out how that information is protected, and who is answerable for which part of protecting it.
1. What this covers
This policy sets out how information processed through Aviral Medcare is protected, and who is answerable for which part of that protection — us, the customer, and the individual user. It is built around confidentiality, integrity, availability, controlled access, and accountability for what happens inside the system.
Depending on how a deployment is configured, the platform may process patient registration and clinical records, appointments, prescriptions and investigations, surgery records, billing and payments, inventory, hospital and branch information, staff and user accounts, and system audit information. The exact set depends on which features a customer has switched on.
2. Who can reach what
Access controls are designed so that a user reaches the information and functions their job actually requires, and not the rest of the system. Depending on configuration, that is governed through:
- User accounts and authentication controls
- Role-based permissions, set per module
- Branch-level access, where multi-branch functionality is in use
- Session management
- Administrative permissions
Clinical records, billing, inventory, administration and reporting can each be opened or closed to a role independently. Where branch scoping is enabled, a user sees only the organisation or branch they belong to.
Assigning those permissions, reviewing them as people change jobs, and disabling accounts that are no longer needed is the customer's job. An account left open after someone leaves is the most ordinary security failure there is.
3. Credentials
Logins are personal. Users must not:
- Share a password with anyone.
- Let another person work under their account.
- Attempt to use someone else's account.
- Circumvent authentication.
- Store credentials somewhere insecure.
Where supported, further authentication and security mechanisms can be enabled to suit a customer's requirements.
4. How information is protected
The platform is built to protect information in transit and within the application environment. Encryption and secure communication reduce the chance of information being intercepted or read by anyone who should not see it; the specific methods vary with the infrastructure and service configuration involved, including where information moves between systems or authorised third-party providers.
We take reasonable measures against unauthorised modification or destruction of records. Customers should still verify information before relying on it clinically, financially or operationally — where a value was typed in by hand, whoever typed it is responsible for it.
Where the service configuration includes it, backup and recovery mechanisms support the availability and restoration of customer information. Frequency, retention and recovery procedure differ by arrangement, and the commitments that bind us are the ones written into your agreement rather than the ones described on a web page.
5. Audit records and monitoring
The platform can keep audit records of significant actions performed inside it — typically the user, the action, the record affected and the time, with the detail varying by feature. Those records let an organisation review what a user did, investigate a security event, spot unusual access patterns, and support its own internal compliance procedures.
On our side, monitoring and logging are used to identify unusual activity, unauthorised access attempts, application errors, infrastructure issues, potential security incidents, and performance problems. Security logs are reviewed where troubleshooting, an investigation or a compliance requirement calls for it.
6. Who is responsible for what
Security here is shared. It fails at whichever end stops holding up its part.
Aviral Medcare / Ebslon Infotech
We maintain reasonable security measures across the systems and services under our control, and address identified security concerns within a reasonable time. Our own staff with authorised access are subject to confidentiality requirements, scoped to their job and reviewed when that job changes.
Customers
Hospitals and clinics using the platform decide what access each role should have, keep user information accurate, protect account credentials, remove users who no longer need access, follow the healthcare and privacy requirements that apply to them, set their own internal data-handling procedures, and report a suspected security incident promptly.
Individual users
Everyone with a login keeps their credentials confidential, opens only what they are authorised to open, follows their organisation's security policies, secures a session when they step away, reports anything that looks wrong, and does not copy or disclose information without authorisation.
7. When something goes wrong
If we become aware of a confirmed security incident affecting customer information, we take reasonable steps to:
- Assess what happened and how far it reaches.
- Contain it and limit the impact.
- Investigate the underlying cause.
- Put corrective measures in place.
- Tell affected customers where law or contract requires it.
A notification carries what we know at the time: the service affected, the nature of the incident, and what we recommend you do.
8. Third-party providers
Parts of the service depend on third-party infrastructure, hosting, communication services and integrations. Where one of them processes information on our behalf, we look for providers with appropriate security practices and hold them to contractual safeguards. Their own terms still apply to their own service.
9. Retention and deletion
Information is kept only as long as it is reasonably needed — for the purpose it was processed for, for contractual and operational requirements, for security, or because the law requires it. How long that is depends on the type of information, the customer's requirements, and the obligations binding on both of us.
Customers can request deletion, or other handling, in line with their service agreement. Some information has to be retained regardless — where law, contract, security requirements, a live dispute or legitimate record-keeping obliges us to keep it.
10. Confidentiality and compliance
We do not sell customer or patient information.
Information processed through the platform is used to provide, maintain, secure and support the service — or where an agreement or the law requires otherwise, and nowhere else.
Whether a particular use of the platform satisfies the laws, regulations, professional standards and internal policies binding on your organisation is a question only your organisation can answer. We will not answer it for you on a website. Where specific regulatory or contractual requirements apply, further safeguards can be agreed between us.
11. Reviews and updates
Security is not a state you reach. We review our technical and organisational measures periodically and change them in response to emerging threats, technology changes, vulnerabilities we find or are told about, operational requirements, customer feedback, and legal developments.
This policy changes with them. Whatever is published on this page is the current version.
Contact
For questions, concerns or requests about data security or data protection:
Ebslon Infotech — info@aviralmedcare.com
If you are reporting a security concern, give us enough to understand and investigate it — and please leave confidential or patient information out of that first message.