Ensuring Data Privacy and Security
Your privacy and data security are at the core of everything we do. Whether you're a patient, caregiver, clinician, or community partner, we are committed to protecting your personal and health information with enterprise-grade security and compliance measures.
Data Security
We use industry-standard protections to secure your data at every touchpoint:
- Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Access Management: Only authorized users can access data, with role-based controls, multifactor authentication, and comprehensive audit logs.
- Cloud Infrastructure: Hosted on ISO 27001-compliant, HIPAA-ready cloud services with continuous monitoring and backups.
Privacy by Design
Privacy is embedded in our products from the ground up:
- We only collect data necessary to deliver care and improve outcomes.
- We do not sell or share data for marketing purposes.
- Data processing is done in line with DHA - Dubai, MOH - India, and other regional regulations.
- Our practices align with globally approved privacy principles like the ISO-27001
Regulatory Compliance
Our services adhere to health data regulations across the regions we operate in:
- DHA - Dubai & MOH - India Compliance. Connect2MyDoctor is the first and only telehealth platform from Australia to be approved by DHA (License Number - 2249728)
- HIPAA alignment for international projects
- ISO 27001 complaint processes
- Local compliance across APAC, MEA, and Africa for population health and telemedicine deployments with local storage of data
Customer Controlled Data
For health institutions using our platform, all patient data remains under the full control of the institution. We act as a data processor, providing secure infrastructure and support to meet their data governance requirements.
Incident Response
In the event of a security incident or data breach, we have a clear response process:
- Our clients will be notified within 72 hours of our discovery of the breach.
- Rapid containment and root cause analysis
- Implementation of additional safeguards to prevent recurrence
Your Data Rights
Users may request to:
- Access and review their personal data
- Correct or update inaccurate information
- Request data portability
- Withdraw consent or request deletion (subject to legal retention obligations)
- Please note: In some cases, consent or approval from our partner clients (such as hospitals, healthcare providers, or community program administrators) may be required to
process your data-related request. When applicable, we will route your request through the relevant partner and support them in fulfilling it in accordance with applicable privacy regulations.