Data & IT Policies
Your privacy is important to us. We are committed to protecting your personal and health information with transparency, integrity and confidentiality while delivering quality healthcare services.
Data Protection & Information Technology (IT) Usage Policy
Sri Lakshmi Multi Speciality Hospital recognises that patient information, medical records and organisational data are valuable assets that require appropriate protection. The Hospital is committed to safeguarding personal data, maintaining confidentiality and ensuring the secure use of information technology systems in support of safe, ethical and high-quality healthcare.
This Policy has been developed with reference to the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (to the extent applicable), the National Medical Commission (Registered Medical Practitioner – Professional Conduct) Regulations, 2023, the Clinical Establishments (Registration and Regulation) Act, 2010 (where applicable), the Consumer Protection Act, 2019, applicable CERT-In Directions, and the information management principles promoted by the National Accreditation Board for Hospitals & Healthcare Providers (NABH).
The Hospital is committed to maintaining secure information systems, protecting patient privacy, preventing unauthorised access to confidential information and promoting responsible use of Hospital information technology resources by all employees and authorised users.
Purpose of this Policy
The purpose of this Policy is to establish a comprehensive framework for protecting patient information, organisational data and Hospital information technology systems. It aims to ensure confidentiality, integrity and availability of information while supporting safe, efficient and legally compliant healthcare delivery.
The Policy also establishes responsibilities for secure handling of information, appropriate use of Hospital IT systems, prevention of data breaches and continuous improvement of cybersecurity practices.
Privacy
Protecting patient and organisational information.
Security
Maintaining secure systems and controlled access.
Responsible IT Use
Promoting appropriate use of Hospital technology resources.
Cybersecurity
Reducing information security and cyber risks.
Scope of this Policy
This Policy applies to all employees, doctors, consultants, nurses, administrative staff, contract personnel, trainees, interns, authorised service providers and any other individual granted access to Hospital information or information technology systems.
It applies to all forms of information, including paper records, electronic medical records (EMR), laboratory reports, diagnostic images, emails, financial records, databases, cloud-based systems, mobile devices, Hospital computers and other digital resources owned, operated or authorised by the Hospital.
"Protecting patient information is a shared responsibility that supports trust, quality healthcare and legal compliance."
Our Commitment to Data Protection & Information Security
Sri Lakshmi Multi Speciality Hospital is committed to maintaining secure information systems and protecting the privacy of patient and organisational information through appropriate administrative, technical and organisational safeguards. Access to confidential information shall be granted only to authorised personnel with a legitimate business or clinical need.
Information Security Commitment
We are committed to preserving the confidentiality, integrity and availability of patient information and Hospital data through secure technology, responsible information management, staff awareness and continuous improvement of our cybersecurity and data protection practices.
Protection of Patient Personal Data
Sri Lakshmi Multi Speciality Hospital is committed to protecting the privacy, confidentiality and security of patient personal data throughout its lifecycle. Patient information shall be collected, used, stored and disclosed only for lawful purposes connected with healthcare delivery, Hospital operations or other purposes permitted under applicable laws.
Personal data shall be processed in accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, applicable healthcare regulations and recognised professional standards while respecting the privacy and dignity of every patient.
Data Protection Principles
- Collect only information necessary for healthcare services.
- Maintain confidentiality of patient records.
- Protect data from unauthorised access or disclosure.
- Use patient information only for authorised purposes.
- Maintain accuracy and integrity of medical records.
- Dispose of information securely when legally permitted.
Privacy Commitment
Patient privacy is fundamental to ethical healthcare. Appropriate safeguards shall be maintained to protect confidential information against unauthorised access, misuse or accidental disclosure.
Access Control & User Authorisation
Access to Hospital information systems, electronic medical records and confidential information shall be granted only to authorised individuals whose duties require such access. User access shall be based on the principle of least privilege, ensuring that personnel receive only the minimum level of access necessary to perform their assigned responsibilities.
User accounts shall be individually assigned and protected through appropriate authentication measures. Sharing of usernames, passwords or access credentials is strictly prohibited.
"Access to confidential information shall be limited to authorised personnel with a legitimate clinical, operational or legal requirement."
Information Classification & Confidentiality
Information maintained by the Hospital shall be classified according to its sensitivity and confidentiality to ensure appropriate protection. Employees shall handle information in accordance with its classification and applicable legal requirements.
Information Categories
- Patient medical records and health information.
- Personally identifiable information (PII).
- Financial and billing information.
- Employee and Human Resources records.
- Operational and administrative documents.
- Public information approved for release.
Confidential information shall not be disclosed to any unauthorised person except where required by law, authorised by the patient or otherwise permitted under applicable legal and regulatory requirements.
Secure Data Handling & Record Management
Sri Lakshmi Multi Speciality Hospital shall implement reasonable administrative, physical and technical measures to protect paper records, electronic medical records, diagnostic information and other confidential data against unauthorised access, alteration, loss or destruction.
Medical records and electronic information shall be stored securely, backed up where appropriate and retained in accordance with applicable legal requirements, recognised professional standards and the Hospital's Medical Records Policy.
Secure Information Management
Effective information management protects patient privacy, supports continuity of care, ensures legal compliance and strengthens public confidence in the Hospital's healthcare services.
Information Technology (IT) Usage Policy
Hospital computers, servers, electronic medical record systems, email accounts, mobile devices, software, internet services and other technology resources are provided solely for authorised Hospital operations and healthcare delivery. All users shall utilise these resources responsibly, ethically and in accordance with applicable laws, Hospital policies and professional standards.
Unauthorised installation of software, misuse of Hospital systems, illegal downloads, sharing confidential information through unauthorised channels or use of Hospital IT resources for unlawful activities is strictly prohibited.
Acceptable IT Usage
- Use Hospital systems only for authorised work.
- Protect confidential patient information.
- Use only approved software and applications.
- Log out of systems after use.
- Report suspicious system activity immediately.
- Follow all Hospital cybersecurity procedures.
Responsible Technology Use
Every authorised user shares responsibility for protecting Hospital systems and confidential information through safe and responsible use of technology.
Cybersecurity & Password Management
Sri Lakshmi Multi Speciality Hospital shall implement appropriate cybersecurity measures to safeguard Hospital information systems from unauthorised access, cyberattacks, malware, ransomware and other information security threats. Employees are expected to exercise caution while using electronic communications and digital resources.
Passwords shall remain confidential, be sufficiently strong and never be shared with other individuals. Wherever implemented, additional authentication measures such as multi-factor authentication shall be used to enhance information security.
Electronic Medical Records (EMR) & Audit Trails
Electronic Medical Records (EMR) shall be maintained in a secure manner to preserve the confidentiality, integrity and availability of patient information. Access to EMR systems shall be restricted to authorised personnel based on their clinical or administrative responsibilities.
Hospital information systems should maintain audit logs, wherever technically feasible, to record user access, modifications and other significant system activities. Audit information may be reviewed for patient safety, operational integrity, legal compliance and information security purposes.
EMR Security Measures
- Role-based user access.
- Secure authentication procedures.
- Electronic audit trails where feasible.
- Regular system backup.
- Protection against unauthorised modification.
- Controlled access to archived records.
Secure Digital Healthcare
Secure management of electronic medical records supports continuity of care, protects patient privacy and strengthens confidence in digital healthcare services.
Data Breach & Information Security Incident Reporting
Any suspected or confirmed unauthorised access, disclosure, alteration, destruction or loss of Hospital information or patient personal data shall be reported immediately through the Hospital's established reporting procedures. Prompt reporting enables timely containment, investigation and appropriate corrective action.
Information security incidents may include cybersecurity attacks, phishing attempts, malware infections, accidental disclosure of confidential information, unauthorised access to Hospital systems, loss of electronic devices, system failures or other events that could compromise the confidentiality, integrity or availability of Hospital information.
"Timely reporting of information security incidents helps protect patient privacy, maintain regulatory compliance and minimise operational disruption."
Incident Response Commitment
Sri Lakshmi Multi Speciality Hospital is committed to investigating information security incidents, implementing appropriate containment measures, strengthening cybersecurity controls and complying with applicable legal and regulatory requirements concerning personal data protection and information security.
Roles & Responsibilities of Hospital Staff
Every employee, consultant, healthcare professional, trainee, contractor and authorised user of Hospital information systems shares responsibility for protecting confidential information and ensuring responsible use of Hospital technology resources. Compliance with this Policy is mandatory for all authorised users.
Hospital Responsibilities
Sri Lakshmi Multi Speciality Hospital is committed to maintaining appropriate administrative, physical and technical safeguards to protect patient information, Hospital data and information technology systems. The Hospital shall regularly evaluate information security risks and implement appropriate measures to strengthen data protection.
Hospital Commitments
- Maintain secure information systems and network infrastructure.
- Implement role-based access controls.
- Protect confidential patient information.
- Conduct periodic information security risk assessments.
- Provide staff education on privacy and cybersecurity.
- Investigate information security incidents and implement corrective actions.
Information Security Governance
The Hospital is committed to fostering a culture of privacy, responsible technology use and cybersecurity through effective governance, risk management and continuous improvement of information security practices.
Continuous Improvement & Cybersecurity Awareness
Sri Lakshmi Multi Speciality Hospital shall regularly review its information security controls, privacy practices, cybersecurity risks and technology infrastructure. Lessons learned from audits, security incidents and emerging cyber threats shall be incorporated into policies, procedures and staff education programmes.
Continuous Improvement Commitment
Ongoing staff awareness, periodic system reviews, cybersecurity exercises and continuous quality improvement initiatives help protect patient information and strengthen the Hospital's information management systems in support of future NABH accreditation.
Policy Review
This Data Protection & Information Technology (IT) Usage Policy shall be reviewed periodically by Hospital Management to ensure continued compliance with applicable Indian laws, evolving cybersecurity threats, recognised healthcare information management standards and best practices in data protection.
"Protecting patient information requires continuous vigilance, responsible technology use and ongoing improvement."
Contact Information
Questions regarding this Data Protection & Information Technology (IT) Usage Policy, information security, privacy or data protection may be directed to the Hospital Administration or the designated Information Security Officer, where appointed.
Sri Lakshmi Multi Speciality Hospital
Address:
No. 5/91, Near Apollo Hospital OMR,
Church Road, Perungudi,
Chennai – 600096, Tamil Nadu, India.
Phone: +91 98407 92932
Email: contactus@slmsh.com
Regulatory & Standards Reference
This Data Protection & Information Technology (IT) Usage Policy has been developed with reference to applicable Indian laws, professional regulations and recognised healthcare information management standards governing the protection of personal data, information security and the responsible use of technology in healthcare.
Applicable Indian Laws
- Digital Personal Data Protection Act, 2023.
- Information Technology Act, 2000.
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (to the extent applicable).
- National Medical Commission (Registered Medical Practitioner – Professional Conduct) Regulations, 2023.
- Consumer Protection Act, 2019.
- CERT-In Directions (as applicable).
- Applicable Central and State Government healthcare regulations.
Quality & Professional Standards
- NABH Standards – Information Management System (IMS).
- NABH Standards – Patient Rights & Education (PRE).
- NABH Standards – Continuous Quality Improvement (CQI).
- NABH Standards – Facility Management & Safety (FMS).
- Clinical Governance & Information Security Principles.
- Recognised Healthcare Data Protection Best Practices.
"Sri Lakshmi Multi Speciality Hospital is committed to protecting patient privacy, safeguarding confidential information and maintaining secure information technology systems through responsible governance, legal compliance, cybersecurity awareness and continuous improvement, while supporting our ongoing journey towards future NABH accreditation."
