Cyber Security Policies
Your privacy is important to us. We are committed to protecting your personal and health information with transparency, integrity and confidentiality while delivering quality healthcare services.
Cyber Security Policy
Sri Lakshmi Multi Speciality Hospital is committed to protecting the confidentiality, integrity and availability of its information systems, electronic medical records, patient information and digital infrastructure. The Hospital recognises that cyber security is essential for ensuring patient safety, uninterrupted healthcare services and compliance with applicable Indian laws.
This Policy establishes the minimum cyber security requirements applicable to all employees, consultants, contractors, students, vendors and any other authorised users who access the Hospital's information systems, networks or electronic devices.
This Policy has been developed with reference to the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (to the extent applicable), the CERT-In Directions, 2022, the National Medical Commission (Registered Medical Practitioner – Professional Conduct) Regulations, 2023, the Clinical Establishments (Registration and Regulation) Act, 2010 (where applicable), the Tamil Nadu Clinical Establishments (Regulation) Act, 1997 (where applicable), and recognised NABH Standards.
Purpose of this Policy
The purpose of this Policy is to establish a structured cyber security framework for protecting Hospital information assets against unauthorised access, data breaches, cyber-attacks, malware, ransomware and other security threats.
This Policy also promotes responsible use of Hospital information systems, protects patient confidentiality, supports business continuity and ensures compliance with applicable legal and regulatory requirements.
Information Security
Protect confidential patient and Hospital information.
Access Protection
Restrict system access to authorised users only.
Data Protection
Secure electronic medical records and Hospital information.
Legal Compliance
Comply with Indian cyber security and data protection laws.
Scope of this Policy
This Policy applies to all Hospital employees, Registered Medical Practitioners, consultants, nurses, pharmacists, technicians, administrative personnel, contract staff, interns, students, vendors and any person authorised to access Hospital information systems or electronic data.
The Policy applies to all Hospital-owned computers, servers, laptops, mobile devices, electronic medical record systems, email services, networks, cloud applications, storage media and other digital resources used in connection with Hospital operations.
"Every authorised user shares responsibility for protecting the confidentiality, integrity and availability of Hospital information."
Fundamental Cyber Security Principles
Sri Lakshmi Multi Speciality Hospital shall implement appropriate administrative, technical and organisational safeguards to protect patient information and Hospital systems against cyber threats, unauthorised access, accidental disclosure, data loss and service disruption.
Access to Hospital information shall be granted only to authorised personnel on a need-to-know basis and only to the extent necessary for their official duties.
Hospital Commitment
Sri Lakshmi Multi Speciality Hospital is committed to maintaining secure digital systems that protect patient information, support safe healthcare delivery and strengthen resilience against cyber security threats.
Password Management & Authentication
Strong authentication is essential to protect Hospital information systems from unauthorised access. Every user shall maintain the confidentiality of login credentials and use strong passwords in accordance with Hospital security requirements.
User IDs and passwords are personal and shall not be shared with colleagues, contractors, students or any other individual. Users are responsible for all activity performed using their authorised accounts.
Password Security Requirements
- Each user shall have a unique login ID.
- Passwords shall be strong and difficult to guess.
- Passwords shall not be shared with any person.
- Default passwords shall be changed immediately.
- Passwords shall not be written on desks, monitors or accessible locations.
- Passwords shall be changed periodically in accordance with Hospital policy.
- Multi-factor authentication (MFA) should be enabled wherever technically feasible.
- Compromised passwords shall be reported and changed immediately.
User Access Control
Access to Hospital information systems shall be granted only to authorised personnel based on their official job responsibilities. Access rights shall follow the principle of least privilege, ensuring users can access only the information necessary to perform their assigned duties.
User accounts shall be reviewed periodically and modified or revoked promptly whenever employment, duties or contractual arrangements change.
Access Control Measures
- Role-based access permissions.
- Doctors shall access only authorised clinical records.
- Billing staff shall access billing information required for their duties.
- HR personnel shall access employee information only.
- Administrative privileges shall be limited to authorised system administrators.
- User accounts shall be disabled immediately upon termination or resignation.
Least Privilege Principle
Every user shall receive only the minimum system access required to perform their authorised duties.
Personal Device (Bring Your Own Device - BYOD) Policy
Personal mobile phones, laptops, tablets and other privately owned devices shall not be used to store, process or transmit confidential Hospital or patient information unless expressly authorised by Hospital Management and protected by appropriate security controls.
Patient information shall not be shared through personal email accounts, personal cloud storage, social media platforms or consumer messaging applications unless specifically authorised under Hospital policy and applicable law.
"Patient information shall remain within approved Hospital information systems unless otherwise authorised under applicable law and Hospital policy."
Email & Internet Usage Policy
Hospital email systems and internet services shall be used primarily for authorised Hospital business. Employees shall exercise caution when opening emails, downloading attachments or accessing websites that may pose cyber security risks.
Users shall not intentionally access malicious websites, install unauthorised software, download pirated content or engage in activities that may compromise Hospital systems or patient information.
Acceptable Email & Internet Practices
- Use Hospital email only for authorised professional communication.
- Verify suspicious emails before opening attachments or clicking links.
- Report phishing attempts immediately to the designated IT or Hospital authority.
- Do not install unauthorised software or browser extensions.
- Do not access illegal, offensive or inappropriate websites using Hospital systems.
- Do not transmit confidential patient information through unsecured communication channels.
- Log out of Hospital systems when work is completed or the workstation is unattended.
Data Protection & Backup
Sri Lakshmi Multi Speciality Hospital shall implement appropriate administrative, technical and organisational safeguards to protect electronic medical records, financial information, employee records and other confidential Hospital data against unauthorised access, alteration, disclosure, destruction or loss.
Regular data backup procedures shall be maintained to support business continuity, disaster recovery and restoration of critical Hospital systems following accidental deletion, equipment failure or cyber security incidents.
Data Protection Measures
- Regular automated backup of critical Hospital systems.
- Secure storage of backup copies.
- Periodic testing of backup restoration procedures.
- Protection against accidental deletion or corruption.
- Encryption of sensitive data where technically appropriate.
- Restricted access to backup media and recovery systems.
- Business continuity and disaster recovery planning.
Protection Against Malware & Ransomware
The Hospital shall implement reasonable security measures to protect its information systems against malware, ransomware, viruses, spyware and other malicious software that could compromise patient information or disrupt healthcare services.
All authorised users shall exercise caution while opening email attachments, downloading files or connecting external storage devices to Hospital systems.
"Every employee plays an important role in preventing cyber attacks by following safe computing practices."
Cyber Security Incident Reporting
Every suspected or confirmed cyber security incident shall be reported immediately to the designated IT Administrator, Information Security Officer or Hospital Management. Prompt reporting enables timely containment, investigation and recovery while minimising the impact on Hospital operations and patient care.
Where required by applicable law, significant cyber security incidents shall be handled in accordance with the reporting obligations prescribed by the Indian Computer Emergency Response Team (CERT-In) and other competent authorities.
Examples of Reportable Cyber Incidents
- Suspected phishing emails.
- Ransomware or malware infections.
- Unauthorised system access.
- Loss or theft of Hospital laptops or authorised mobile devices.
- Accidental disclosure of patient information.
- Data breaches involving confidential Hospital information.
- Unexpected system failures caused by suspected cyber attacks.
- Any activity that may compromise Hospital information security.
Responsibilities of Hospital Personnel
Every employee, consultant, Registered Medical Practitioner, nurse, pharmacist, technician, administrative employee, student, contractor and authorised system user shares responsibility for protecting Hospital information systems and confidential patient information.
Staff Responsibilities
- Protect passwords and login credentials.
- Use Hospital systems only for authorised purposes.
- Protect patient confidentiality at all times.
- Lock computers before leaving workstations unattended.
- Report cyber security incidents immediately.
- Complete mandatory cyber security awareness training.
- Follow Hospital IT and information security policies.
- Cooperate during cyber security investigations.
Shared Responsibility
Cyber security is a shared responsibility. Every authorised user contributes to protecting Hospital information, maintaining patient trust and supporting uninterrupted healthcare services.
Responsibilities of the Hospital
Sri Lakshmi Multi Speciality Hospital shall establish, implement and maintain appropriate administrative, technical and physical safeguards to protect Hospital information systems and confidential data from unauthorised access, misuse, cyber attacks and data breaches.
Hospital Management shall ensure that cyber security controls are periodically reviewed, updated and monitored to address evolving cyber threats, technological changes and applicable legal requirements.
Hospital Commitments
- Maintain secure Hospital information systems.
- Provide approved cyber security software and protective controls.
- Conduct periodic cyber security awareness programmes.
- Perform regular system updates and security maintenance.
- Monitor compliance with Hospital cyber security requirements.
- Respond promptly to cyber security incidents and system vulnerabilities.
Governance Commitment
Hospital Management is committed to protecting patient information, ensuring business continuity and maintaining a secure digital healthcare environment through effective cyber security governance.
Continuous Improvement
Sri Lakshmi Multi Speciality Hospital shall periodically review cyber security risks, audit findings, emerging threats, technological developments and changes in applicable laws to strengthen information security and improve organisational resilience.
Lessons learned from cyber security incidents, internal audits, vulnerability assessments and regulatory guidance shall be incorporated into revised procedures, staff training and system improvements.
Continuous Quality Improvement
Regular evaluation and improvement of cyber security practices strengthen patient trust, operational continuity, legal compliance and protection against evolving cyber threats.
Policy Review
This Cyber Security Policy shall be reviewed periodically by Hospital Management to ensure continued compliance with applicable Indian laws, National Medical Commission Regulations, CERT-In directions, evolving cyber security risks and NABH accreditation standards.
"Effective cyber security requires continuous vigilance, responsible behaviour and ongoing improvement by every authorised user."
Contact Information
Questions regarding this Policy, cyber security incidents, suspected data breaches or information security concerns may be reported to the Hospital's IT Administrator, Information Security Officer (where designated), Quality Department or Hospital Administration.
Sri Lakshmi Multi Speciality Hospital
Address:
No. 5/91, Near Apollo Hospital OMR,
Church Road, Perungudi,
Chennai – 600096,
Tamil Nadu, India.
Phone: +91 98407 92932
Email: contactus@slmsh.com
Regulatory & Standards Reference
This Cyber Security Policy has been developed with reference to applicable Indian laws, government directions and recognised healthcare standards governing cyber security, information management and protection of digital health information.
Applicable Indian Laws & Regulations
- Digital Personal Data Protection Act, 2023.
- Information Technology Act, 2000.
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (to the extent applicable).
- CERT-In Directions, 2022.
- National Medical Commission (Registered Medical Practitioner – Professional Conduct) Regulations, 2023.
- Clinical Establishments (Registration and Regulation) Act, 2010 (where applicable).
- Tamil Nadu Clinical Establishments (Regulation) Act, 1997 and applicable Rules.
Quality & Accreditation Standards
- NABH Standards – Information Management System (IMS).
- NABH Standards – Governance & Leadership (GL).
- NABH Standards – Continuous Quality Improvement (CQI).
- NABH Standards – Facility Management & Safety (FMS).
- NABH Standards – Patient Rights & Education (PRE).
- Healthcare Information Security Best Practices.
Hospital Cyber Security Commitment
Sri Lakshmi Multi Speciality Hospital is committed to protecting patient information, maintaining secure information systems and promoting responsible use of digital technologies. The Hospital recognises that cyber security is fundamental to patient safety, operational continuity and public trust.
All Hospital personnel are expected to comply with this Policy, protect confidential information, report cyber security concerns promptly and actively contribute to a culture of information security and continuous improvement.
"Sri Lakshmi Multi Speciality Hospital is committed to safeguarding patient information, maintaining resilient and secure digital systems, complying with applicable Indian cyber security and data protection laws, and fostering a culture of cyber awareness, accountability and continuous improvement in accordance with recognised NABH standards."
