Our Compliance Philosophy
Healthcare operates in a highly regulated environment, and for good reason — patient safety and privacy are paramount. PRISM is designed from the ground up to meet the strictest regulatory requirements across multiple jurisdictions while enabling seamless interoperability through international healthcare standards.
1. Data Protection Regulations
PRISM complies with data protection and privacy laws across all regions where we operate:
GDPR
Full compliance with the EU's comprehensive data protection framework:
- Lawful basis for processing health data
- Data subject rights (access, rectification, erasure, portability)
- Data Protection Impact Assessments
- 72-hour breach notification
- Data Processing Agreements with all partners
- Appointed Data Protection Officer
HIPAA
Comprehensive HIPAA compliance for US healthcare:
- Privacy Rule — PHI protection
- Security Rule — Administrative, physical, technical safeguards
- Breach Notification Rule
- Business Associate Agreements
- Minimum necessary standard
- Regular HIPAA training for staff
DPDP Act
Aligned with India's new data protection framework:
- Consent-based data processing
- Data Principal rights
- Data localisation requirements
- ABHA ID integration support
- Significant Data Fiduciary obligations
Other Jurisdictions
Compliance with additional regional requirements:
- UK Data Protection Act 2018
- Australia Privacy Act 1988
- Singapore PDPA
- Brazil LGPD
- Canada PIPEDA / Provincial health laws
2. Healthcare-Specific Regulations
| Regulation | Jurisdiction | Scope | Status |
|---|---|---|---|
| HIPAA | United States | Protected Health Information (PHI) | Compliant |
| HITECH Act | United States | Electronic health records, breach notification | Compliant |
| MDR | European Union | Medical Device Regulation (software as medical device) | Aligned |
| NHS DTAC | United Kingdom | Digital Technology Assessment Criteria | Aligned |
| ABDM Guidelines | India | Ayushman Bharat Digital Mission standards | Compliant |
| My Health Record | Australia | National health record system integration | Aligned |
3. Interoperability Standards
PRISM is built on internationally recognised healthcare interoperability standards to ensure seamless data exchange:
3.1 FHIR Implementation
Our FHIR R4 implementation supports:
- Resources: Patient, Observation, Condition, MedicationStatement, DiagnosticReport, Encounter, and more
- Operations: RESTful CRUD operations, search, batch/transaction bundles
- Profiles: Support for national profiles (US Core, AU Base, UK Core, etc.)
- Security: SMART on FHIR for authorisation, OAuth 2.0 authentication
- Bulk Data: FHIR Bulk Data Access for population health exports
4. Audit & Accountability
4.1 Audit Trail
PRISM maintains comprehensive audit logs for compliance purposes:
- All data access events with user identification
- Data modifications with before/after values
- Consent grants and revocations
- Authentication events and failures
- Administrative and configuration changes
- Logs retained for minimum 7 years (configurable by jurisdiction)
4.2 Regular Audits
- Annual third-party security audits
- Quarterly internal compliance reviews
- Continuous automated compliance monitoring
- Penetration testing by certified firms
5. Data Localisation
PRISM respects data residency requirements by jurisdiction:
- India: Data stored in India-based data centres (Mumbai/Hyderabad)
- European Union: Data stored within EU (Frankfurt/Dublin)
- Australia: Data stored in Australian data centres
- United States: Data stored in US data centres
Cross-border transfers, where legally permitted, use Standard Contractual Clauses and appropriate safeguards.
6. Compliance Documentation
The following compliance documentation is available upon request:
- Data Processing Agreement (DPA)
- Business Associate Agreement (BAA) for US entities
- Security whitepaper and architecture documentation
- SOC 2 Type II report (under NDA)
- Penetration test executive summary
- Incident response plan overview
- FHIR conformance statements
Compliance Enquiries
For compliance documentation, certifications, or regulatory questions:
Compliance Team: compliance@prismhealth.care
Data Protection Officer: dpo@prismhealth.care
Security Team: security@prismhealth.care