Skip to main content

Regulatory matrix

DRAFT — requires legal review

This document is a working draft prepared by the engineering team to describe how the platform is designed to support compliance. It is not legal advice and has not yet been reviewed by counsel. Do not rely on it as a final policy until this banner is removed.

The platform provides features that support compliance. It does not make a provider compliant or certified by itself; marketing states “supported” vs “certified” explicitly.

Law / standardProduct obligationRelease
DPDP Act 2023 + DPDP Rules 2025Notices, consent/purpose records, data-principal rights workflow (access/correction/erasure with medical-retention exceptions), grievance officer, breach runbook (72 h), processor/subprocessor inventory & DPAs, guardian consent for minors, retention per entity, access-log retentionR0–R1
IT Act 2000 / SPDI Rules 2011Privacy policy, reasonable security practicesR0
NMC Rx guidance & Telemedicine Practice Guidelines 2020Generic names, capitals, registration number; teleconsult identity/consent/mode/Rx limits, logsR1
Clinical Establishments ActRegistration number on documents, rate display, record retentionR1
NABL 112A / 133 (ISO 15189)Traceability, authorised signatories, critical-value log, amendments, QC, NABL-mode reportR2
PCPNDT ActForm F, registers, audit lockR2
Drugs & Cosmetics Act (Schedule H/H1/X)Registers, batch/expiry, pharmacist detailsR4
GST / e-invoicingExempt vs taxable, HSN/SAC, credit notes, thresholdsR1
MTP ActRestricted forms, confidentialityPack (R1+)
ABDMSandbox registration (R0); M1 ABHA create/verify/scan-and-share, HFR/HPR (R2); M2/M3 HIP/HIU via consent broker + DHIS dashboard (R3); FHIR bundle validation against ABDM profilesR0 → R3
NABH digital health standardsAudit trails, consent, access control, quality indicatorsR4–R5
Biomedical waste rules, MLCLogs, flagsR4
CERT-In Directions 2022Incident reporting within 6 hours; logs retained 180 days in IndiaR0