This statement details the comprehensive security measures NarraHealth Technologies Pvt. Ltd. implements to protect your health data from unauthorized access, misuse, loss, or corruption.
| Classification | Examples | Security Level | Retention |
|---|---|---|---|
| Public | Blog posts, anonymized statistics | Standard | As needed |
| Internal | Employee records | High | Per policy |
| Confidential | Business strategies | Very High | Per legal requirement |
| Restricted / PHI | Health records, diagnoses | MAXIMUM | Indefinite or per request |
All stored data is encrypted using AES-256. The following data types are encrypted:
TLS 1.3 is used for all web traffic, mobile app data, API calls, email, and file transfers.
| Role | Permissions | Data Access |
|---|---|---|
| Patient | View own records | Own health data only |
| Provider | View + add notes | Only patients in their care |
| Clinic Admin | Manage staff and billing | De-identified analytics |
| Support | Resolve tickets | No direct health data |
| Developer | Maintain infrastructure | Encrypted data only |
| Security | Monitor threats | Audit logs and encrypted data |
Google Cloud Platform, India regions (asia-south1 and asia-south2). Meets India data residency requirements under the DPDP Act.
Cloud Run, Cloud SQL, Cloud Storage, Cloud Load Balancing, VPC.
99.5% uptime SLA, multi-AZ deployment, auto-failover, and recovery time under 5 minutes.
Google data centres feature biometric access controls, 24/7 security personnel, and continuous surveillance.
Google Cloud Armor protects against SQL injection, XSS, and CSRF attacks.
The network is divided into four zones: Public (Web), Private (App/DB), Restricted (Admin), and Data (Storage).
Google Cloud Armor provides L3/L4/L7 protection with rate limiting and behavioral analysis.
VPN is required for all internal access. Only HTTPS (port 443) is accepted for incoming traffic.
| Vulnerability | Mitigation |
|---|---|
| Injection | Parameterized queries, input validation |
| Broken Authentication | MFA, secure sessions |
| Sensitive Data Exposure | AES-256, TLS 1.3 |
| XXE | Disabled external entities |
| Broken Access Control | RBAC, least privilege |
| Security Misconfiguration | Secure defaults, regular audits |
| XSS | Input validation, CSP |
| Using Known Vulnerable Components | Dependency scanning, patching |
| Insufficient Logging | Comprehensive logging, 24/7 alerts |
Hourly replication and daily snapshots. Primary location: Mumbai; secondary location: secondary India region. All backups are encrypted with AES-256. Monthly restore tests are conducted. RTO for critical systems is under 4 hours.
Continuous monitoring via Google Cloud Logging, Security Command Center, and Cloud Monitoring. Automated alerts are triggered for:
| Severity | Definition | Response Time |
|---|---|---|
| Critical | Health data compromised | < 30 minutes |
| High | Significant vulnerability identified | < 2 hours |
| Medium | Contained incident | < 4 hours |
| Low | Policy violation | < 24 hours |
To report a suspected breach, contact security@narra.health. Do not disclose suspected breaches publicly.
DPDP Act 2023 (India), GDPR-ready, HIPAA-equivalent, NABH and NABL standards.
Compliance documentation is available upon request with a signed NDA.