Cursor

mode

Language Support

Site Logo

Get in touch

shape shape
SRI LAKSHMI MULTI SPECIALITY HOSPITAL

Cyber Security Policies

Your privacy is important to us. We are committed to protecting your personal and health information with transparency, integrity and confidentiality while delivering quality healthcare services.

Privacy
01
INTRODUCTION

Cyber Security Policy

Sri Lakshmi Multi Speciality Hospital is committed to protecting the confidentiality, integrity and availability of its information systems, electronic medical records, patient information and digital infrastructure. The Hospital recognises that cyber security is essential for ensuring patient safety, uninterrupted healthcare services and compliance with applicable Indian laws.

This Policy establishes the minimum cyber security requirements applicable to all employees, consultants, contractors, students, vendors and any other authorised users who access the Hospital's information systems, networks or electronic devices.

This Policy has been developed with reference to the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (to the extent applicable), the CERT-In Directions, 2022, the National Medical Commission (Registered Medical Practitioner – Professional Conduct) Regulations, 2023, the Clinical Establishments (Registration and Regulation) Act, 2010 (where applicable), the Tamil Nadu Clinical Establishments (Regulation) Act, 1997 (where applicable), and recognised NABH Standards.

02
PURPOSE

Purpose of this Policy

The purpose of this Policy is to establish a structured cyber security framework for protecting Hospital information assets against unauthorised access, data breaches, cyber-attacks, malware, ransomware and other security threats.

This Policy also promotes responsible use of Hospital information systems, protects patient confidentiality, supports business continuity and ensures compliance with applicable legal and regulatory requirements.

Information Security

Protect confidential patient and Hospital information.

Access Protection

Restrict system access to authorised users only.

Data Protection

Secure electronic medical records and Hospital information.

Legal Compliance

Comply with Indian cyber security and data protection laws.

03
SCOPE

Scope of this Policy

This Policy applies to all Hospital employees, Registered Medical Practitioners, consultants, nurses, pharmacists, technicians, administrative personnel, contract staff, interns, students, vendors and any person authorised to access Hospital information systems or electronic data.

The Policy applies to all Hospital-owned computers, servers, laptops, mobile devices, electronic medical record systems, email services, networks, cloud applications, storage media and other digital resources used in connection with Hospital operations.

"Every authorised user shares responsibility for protecting the confidentiality, integrity and availability of Hospital information."
04
CYBER SECURITY PRINCIPLES

Fundamental Cyber Security Principles

Sri Lakshmi Multi Speciality Hospital shall implement appropriate administrative, technical and organisational safeguards to protect patient information and Hospital systems against cyber threats, unauthorised access, accidental disclosure, data loss and service disruption.

Access to Hospital information shall be granted only to authorised personnel on a need-to-know basis and only to the extent necessary for their official duties.

Protect confidentiality of patient information.
Implement role-based access to Hospital systems.
Use strong authentication and secure passwords.
Protect systems against malware, ransomware and cyber threats.
Report suspected cyber incidents immediately.
Ensure compliance with applicable Indian laws and Hospital policies.

Hospital Commitment

Sri Lakshmi Multi Speciality Hospital is committed to maintaining secure digital systems that protect patient information, support safe healthcare delivery and strengthen resilience against cyber security threats.

05
PASSWORD MANAGEMENT

Password Management & Authentication

Strong authentication is essential to protect Hospital information systems from unauthorised access. Every user shall maintain the confidentiality of login credentials and use strong passwords in accordance with Hospital security requirements.

User IDs and passwords are personal and shall not be shared with colleagues, contractors, students or any other individual. Users are responsible for all activity performed using their authorised accounts.

Password Security Requirements

  • Each user shall have a unique login ID.
  • Passwords shall be strong and difficult to guess.
  • Passwords shall not be shared with any person.
  • Default passwords shall be changed immediately.
  • Passwords shall not be written on desks, monitors or accessible locations.
  • Passwords shall be changed periodically in accordance with Hospital policy.
  • Multi-factor authentication (MFA) should be enabled wherever technically feasible.
  • Compromised passwords shall be reported and changed immediately.
06
USER ACCESS CONTROL

User Access Control

Access to Hospital information systems shall be granted only to authorised personnel based on their official job responsibilities. Access rights shall follow the principle of least privilege, ensuring users can access only the information necessary to perform their assigned duties.

User accounts shall be reviewed periodically and modified or revoked promptly whenever employment, duties or contractual arrangements change.

Access Control Measures

  • Role-based access permissions.
  • Doctors shall access only authorised clinical records.
  • Billing staff shall access billing information required for their duties.
  • HR personnel shall access employee information only.
  • Administrative privileges shall be limited to authorised system administrators.
  • User accounts shall be disabled immediately upon termination or resignation.

Least Privilege Principle

Every user shall receive only the minimum system access required to perform their authorised duties.

07
PERSONAL DEVICE (BYOD)

Personal Device (Bring Your Own Device - BYOD) Policy

Personal mobile phones, laptops, tablets and other privately owned devices shall not be used to store, process or transmit confidential Hospital or patient information unless expressly authorised by Hospital Management and protected by appropriate security controls.

Patient information shall not be shared through personal email accounts, personal cloud storage, social media platforms or consumer messaging applications unless specifically authorised under Hospital policy and applicable law.

"Patient information shall remain within approved Hospital information systems unless otherwise authorised under applicable law and Hospital policy."
No storage of patient records on personal devices.
No sharing of patient information using personal email accounts.
No unauthorised sharing through messaging or social media applications.
Lost or stolen authorised devices shall be reported immediately.
08
EMAIL & INTERNET USAGE

Email & Internet Usage Policy

Hospital email systems and internet services shall be used primarily for authorised Hospital business. Employees shall exercise caution when opening emails, downloading attachments or accessing websites that may pose cyber security risks.

Users shall not intentionally access malicious websites, install unauthorised software, download pirated content or engage in activities that may compromise Hospital systems or patient information.

Acceptable Email & Internet Practices

  • Use Hospital email only for authorised professional communication.
  • Verify suspicious emails before opening attachments or clicking links.
  • Report phishing attempts immediately to the designated IT or Hospital authority.
  • Do not install unauthorised software or browser extensions.
  • Do not access illegal, offensive or inappropriate websites using Hospital systems.
  • Do not transmit confidential patient information through unsecured communication channels.
  • Log out of Hospital systems when work is completed or the workstation is unattended.
09
DATA PROTECTION & BACKUP

Data Protection & Backup

Sri Lakshmi Multi Speciality Hospital shall implement appropriate administrative, technical and organisational safeguards to protect electronic medical records, financial information, employee records and other confidential Hospital data against unauthorised access, alteration, disclosure, destruction or loss.

Regular data backup procedures shall be maintained to support business continuity, disaster recovery and restoration of critical Hospital systems following accidental deletion, equipment failure or cyber security incidents.

Data Protection Measures

  • Regular automated backup of critical Hospital systems.
  • Secure storage of backup copies.
  • Periodic testing of backup restoration procedures.
  • Protection against accidental deletion or corruption.
  • Encryption of sensitive data where technically appropriate.
  • Restricted access to backup media and recovery systems.
  • Business continuity and disaster recovery planning.
10
MALWARE & RANSOMWARE PROTECTION

Protection Against Malware & Ransomware

The Hospital shall implement reasonable security measures to protect its information systems against malware, ransomware, viruses, spyware and other malicious software that could compromise patient information or disrupt healthcare services.

All authorised users shall exercise caution while opening email attachments, downloading files or connecting external storage devices to Hospital systems.

"Every employee plays an important role in preventing cyber attacks by following safe computing practices."
Approved antivirus and endpoint protection software shall be maintained.
Operating systems and software shall be updated with security patches where practicable.
Unknown USB devices shall not be connected to Hospital computers.
Suspicious emails, links and attachments shall not be opened.
Users shall immediately disconnect affected devices if ransomware or malware is suspected, where safe to do so.
Suspected malware incidents shall be reported immediately.
11
CYBER SECURITY INCIDENT REPORTING

Cyber Security Incident Reporting

Every suspected or confirmed cyber security incident shall be reported immediately to the designated IT Administrator, Information Security Officer or Hospital Management. Prompt reporting enables timely containment, investigation and recovery while minimising the impact on Hospital operations and patient care.

Where required by applicable law, significant cyber security incidents shall be handled in accordance with the reporting obligations prescribed by the Indian Computer Emergency Response Team (CERT-In) and other competent authorities.

Examples of Reportable Cyber Incidents

  • Suspected phishing emails.
  • Ransomware or malware infections.
  • Unauthorised system access.
  • Loss or theft of Hospital laptops or authorised mobile devices.
  • Accidental disclosure of patient information.
  • Data breaches involving confidential Hospital information.
  • Unexpected system failures caused by suspected cyber attacks.
  • Any activity that may compromise Hospital information security.
12
STAFF RESPONSIBILITIES

Responsibilities of Hospital Personnel

Every employee, consultant, Registered Medical Practitioner, nurse, pharmacist, technician, administrative employee, student, contractor and authorised system user shares responsibility for protecting Hospital information systems and confidential patient information.

Staff Responsibilities

  • Protect passwords and login credentials.
  • Use Hospital systems only for authorised purposes.
  • Protect patient confidentiality at all times.
  • Lock computers before leaving workstations unattended.
  • Report cyber security incidents immediately.
  • Complete mandatory cyber security awareness training.
  • Follow Hospital IT and information security policies.
  • Cooperate during cyber security investigations.

Shared Responsibility

Cyber security is a shared responsibility. Every authorised user contributes to protecting Hospital information, maintaining patient trust and supporting uninterrupted healthcare services.

13
HOSPITAL RESPONSIBILITIES

Responsibilities of the Hospital

Sri Lakshmi Multi Speciality Hospital shall establish, implement and maintain appropriate administrative, technical and physical safeguards to protect Hospital information systems and confidential data from unauthorised access, misuse, cyber attacks and data breaches.

Hospital Management shall ensure that cyber security controls are periodically reviewed, updated and monitored to address evolving cyber threats, technological changes and applicable legal requirements.

Hospital Commitments

  • Maintain secure Hospital information systems.
  • Provide approved cyber security software and protective controls.
  • Conduct periodic cyber security awareness programmes.
  • Perform regular system updates and security maintenance.
  • Monitor compliance with Hospital cyber security requirements.
  • Respond promptly to cyber security incidents and system vulnerabilities.

Governance Commitment

Hospital Management is committed to protecting patient information, ensuring business continuity and maintaining a secure digital healthcare environment through effective cyber security governance.

14
CONTINUOUS IMPROVEMENT

Continuous Improvement

Sri Lakshmi Multi Speciality Hospital shall periodically review cyber security risks, audit findings, emerging threats, technological developments and changes in applicable laws to strengthen information security and improve organisational resilience.

Lessons learned from cyber security incidents, internal audits, vulnerability assessments and regulatory guidance shall be incorporated into revised procedures, staff training and system improvements.

Continuous Quality Improvement

Regular evaluation and improvement of cyber security practices strengthen patient trust, operational continuity, legal compliance and protection against evolving cyber threats.

15
POLICY REVIEW

Policy Review

This Cyber Security Policy shall be reviewed periodically by Hospital Management to ensure continued compliance with applicable Indian laws, National Medical Commission Regulations, CERT-In directions, evolving cyber security risks and NABH accreditation standards.

"Effective cyber security requires continuous vigilance, responsible behaviour and ongoing improvement by every authorised user."
16
CONTACT INFORMATION

Contact Information

Questions regarding this Policy, cyber security incidents, suspected data breaches or information security concerns may be reported to the Hospital's IT Administrator, Information Security Officer (where designated), Quality Department or Hospital Administration.

Sri Lakshmi Multi Speciality Hospital

Address:
No. 5/91, Near Apollo Hospital OMR,
Church Road, Perungudi,
Chennai – 600096,
Tamil Nadu, India.

Phone: +91 98407 92932
Email: contactus@slmsh.com

17
REGULATORY & STANDARDS REFERENCE

Regulatory & Standards Reference

This Cyber Security Policy has been developed with reference to applicable Indian laws, government directions and recognised healthcare standards governing cyber security, information management and protection of digital health information.

Applicable Indian Laws & Regulations

  • Digital Personal Data Protection Act, 2023.
  • Information Technology Act, 2000.
  • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (to the extent applicable).
  • CERT-In Directions, 2022.
  • National Medical Commission (Registered Medical Practitioner – Professional Conduct) Regulations, 2023.
  • Clinical Establishments (Registration and Regulation) Act, 2010 (where applicable).
  • Tamil Nadu Clinical Establishments (Regulation) Act, 1997 and applicable Rules.

Quality & Accreditation Standards

  • NABH Standards – Information Management System (IMS).
  • NABH Standards – Governance & Leadership (GL).
  • NABH Standards – Continuous Quality Improvement (CQI).
  • NABH Standards – Facility Management & Safety (FMS).
  • NABH Standards – Patient Rights & Education (PRE).
  • Healthcare Information Security Best Practices.
18
CYBER SECURITY COMMITMENT

Hospital Cyber Security Commitment

Sri Lakshmi Multi Speciality Hospital is committed to protecting patient information, maintaining secure information systems and promoting responsible use of digital technologies. The Hospital recognises that cyber security is fundamental to patient safety, operational continuity and public trust.

All Hospital personnel are expected to comply with this Policy, protect confidential information, report cyber security concerns promptly and actively contribute to a culture of information security and continuous improvement.

"Sri Lakshmi Multi Speciality Hospital is committed to safeguarding patient information, maintaining resilient and secure digital systems, complying with applicable Indian cyber security and data protection laws, and fostering a culture of cyber awareness, accountability and continuous improvement in accordance with recognised NABH standards."