Breathe Ease (drtarunsharma.com) is operated in connection with the clinical practice of Dr. Tarun Sharma, Senior Consultant Pulmonologist & Critical Care Specialist. This policy provides patients with a clear, accurate, and practical description of health data governance. It operates alongside clinical consent forms, medical records, statutory obligations, and patient rights that cannot lawfully be excluded.
1.Who Controls Your Data
For services delivered through Breathe Ease, the clinical practice responsible for the relevant consultation determines why and how patient personal and medical data is processed. Operational identity, physical address, and contact details are maintained current on this website and in clinic records.
All clinical records are generated and preserved under the professional and statutory responsibilities applicable to the treating registered medical practitioner and the healthcare establishment involved in patient care.
2.Information We Collect
Identity & Contact Data
- Full legal name, date of birth / age, gender, and demographic details.
- Verified mobile phone number, email address, and residential location.
- Emergency contact, parent/guardian, or authorised representative details.
Clinical & Health Data (SPDI)
- Presenting symptoms, clinical history, drug allergies, medications, and lifestyle factors.
- Consultation notes, clinical observations, diagnoses, treatment plans, and prescriptions.
- PFT / Spirometry, FeNO, CT scans, chest X-rays, laboratory, and other diagnostic reports.
Appointment & Transaction Data
- Appointment date, time slot, booking status, and consultation mode (in-person vs. remote).
- Payment transaction references, transaction IDs, and clinic receipts.
- No CVV, card PINs, or raw net banking credentials are ever stored by Breathe Ease.
Technical & Security Data
- IP address, device identifiers, and browser technical parameters where logged.
- Secure authentication tokens and session state verification data.
- Security, audit, and access logs required to safeguard the platform and health records.
We adhere to the principle of data minimisation, collecting only information reasonably necessary for clinical care, administration, security, legal compliance, and patient safety.
3.Why We Process Information
- Clinical Care: Comprehensive history-taking, physical and remote assessment, pulmonary diagnosis, diagnostic test ordering, treatment formulation, prescriptions, and continuity of care.
- Appointment Administration: Scheduling, booking confirmation, automated reminders, rescheduling notifications, and clinic workflow management.
- Teleconsultation Delivery: Secure patient identity verification, encrypted audio/video session delivery, clinical messaging, and follow-up reviews.
- Medical Records Governance: Creating, indexing, retrieving, securing, and archiving electronic health records in accordance with statutory standards.
- Patient & Staff Safety: Preventing identity fraud, prescription misuse, unauthorised account access, and security threats.
- Legal & Regulatory Compliance: Fulfilling mandatory statutory duties under the National Medical Commission Act, DPDP Act 2023, tax, accounting, and court mandates.
- Technical Operations: Platform hosting, transactional messaging, transactional email, secure authentication, and IT support through vetted service providers.
4.Notice, Consent & Legal Grounds
We provide clear privacy notices at or before collection touchpoints and obtain consent where legally required. Processing may also occur on lawful grounds established by applicable legislation, including the provision of medical care, compliance with legal obligations, protecting vital interests in medical emergencies, establishing or defending legal claims, and maintaining cybersecurity.
The Digital Personal Data Protection Act, 2023 and associated rules operate under a phased commencement framework. Breathe Ease implements compliant controls as provisions become legally enforceable, while proactively maintaining rigorous medical privacy safeguards.
Where a processing activity is optional, withholding or withdrawing consent will never be used to deny unrelated essential medical care, except where the specific service genuinely requires that data for safe delivery.
5.Medical Records & Clinical Documentation
Clinical records constitute formal medical documentation containing sensitive personal data. They are maintained with strict access boundaries and heightened confidentiality.
- Records comprise clinical histories, examination findings, diagnostic reports, clinical reasoning, prescriptions, referrals, and home-care advice.
- When errors are identified, corrections are documented; clinically material amendments are preserved as an audit trail to ensure medical record integrity rather than overwriting historical entries.
- Access is restricted strictly according to professional role and legitimate clinical or administrative need.
- Patient requests for copies of their clinical records are processed in accordance with applicable medical council regulations, verified identity protocols, and lawful procedures.
- Records subject to active legal inquiries, medical board reviews, complaints, or anticipated claims are retained under legal hold protocols.
6.AI-Assisted Documentation
Breathe Ease may deploy approved AI-assisted tools for limited documentation tasks, such as formatting voice transcriptions, drafting clinical summaries, or administrative structuring. AI outputs do not constitute an independent diagnosis, prescription, or medical decision.
- All medical evaluations, diagnoses, and therapeutic decisions remain exclusively with Dr. Tarun Sharma.
- Every AI-generated draft is reviewed, validated, and approved by the treating doctor before inclusion in the patient's official medical record.
- AI technologies are selected and configured under contractual privacy and enterprise data isolation terms.
- Patient clinical data processed via private API integrations is not used to train public foundational AI models.
- If an AI tool introduces material changes to data processing workflows, relevant privacy notices and consent flows will be updated accordingly.
8.Security Safeguards
We apply technical and organisational safeguards commensurate with the sensitive nature of medical and personal data:
- Encryption in transit using modern transport security (TLS) and encryption at rest for cloud databases and document repositories.
- Role-based access control (RBAC) ensuring only authorized medical personnel access clinical files.
- Time-sensitive One-Time Password (OTP) verification for secure patient portal access.
- Administrative access controls, secret/API-key isolation, and confidentiality agreements for all staff.
- Automated database backups and disaster recovery protocols to protect data availability.
- Audit logging for sensitive administrative actions and medical record modifications.
- Continuous software dependency updates and vulnerability patching.
Security safeguards are designed systematically across control categories. Specific cryptographic algorithms and standards are maintained in line with production cloud specifications and industry best practices.
9.Security Incidents & Breaches
If Breathe Ease detects a confirmed or suspected security incident affecting personal or health data, an incident-response protocol is initiated. This includes immediate containment, credential rotation, forensic log analysis, risk assessment, remediation, and notifications to affected individuals and regulatory bodies where mandated by applicable law.
Patients should promptly report any suspected unauthorized access, compromised OTPs, lost devices with active portal sessions, or phishing attempts directly to the clinic desk.
10.Retention, Archiving & Legal Holds
Personal and medical records are retained for periods determined by clinical necessity, continuity of care, statutory obligations, accounting standards, and legal requirements:
- Medical Records: Retained for a minimum statutory period of 3 (three) years from the consultation date, in compliance with National Medical Commission regulations and Indian healthcare standards.
- Financial & Billing Records: Retained as required under Indian tax, GST, and accounting legislation.
- Security & Audit Logs: Retained for periods proportionate to cybersecurity, auditing, and diagnostic needs.
- Disposal: Upon expiry of mandatory retention periods, inactive data is securely deleted, anonymised, or archived.
- Legal Holds: Routine deletion schedules are suspended whenever records are subject to an active dispute, complaint, investigation, or court proceeding.
11.Patient Data Rights
Subject to statutory verification and legal conditions under applicable data protection laws, patients hold rights regarding:
- Access & Summary: Requesting a summary of personal and clinical data processed.
- Correction & Updating: Requesting correction of inaccurate demographic, contact, or clinical background details.
- Erasure Limitations: Requesting deletion of non-statutory personal data. Note: Erasure cannot override mandatory medical record retention periods prescribed by medical regulations.
- Nomination: Designating an authorized representative to exercise data rights in the event of incapacity or death.
- Grievance Redressal: Registering data protection concerns with our designated Grievance Officer.
All requests must be submitted in writing with verifiable proof of identity to protect patient confidentiality against unauthorized disclosure.
12.Children & Guardian Data
For pediatric patients under 18 years of age or individuals lacking capacity to consent, clinical histories, bookings, and permissions must be provided by a parent, legal guardian, or authorized representative. Proof of guardianship may be requested where clinically or legally appropriate.
Children's data is handled with heightened care and is never used for behavioral profiling or commercial advertising.
13.Communications & Messaging
- SMS, email, instant messaging channels, and portal notifications are used for appointment scheduling, reminders, and non-urgent clinical follow-ups.
- Electronic messaging carries inherent risks (e.g. device theft, misdirected messages, interception). Patients are responsible for securing their registered phone number, email, and devices.
- Digital messaging channels are monitored during clinic hours only and are not emergency hotlines.
- Patients must never use digital messaging, SMS, or email for acute emergencies or deteriorating conditions.
15.Data Transfers & Third Countries
Certain global technology infrastructure providers (e.g., cloud hosting, email gateways) may process encrypted data across geographically distributed data centers. Such services are utilized strictly under compliant data protection agreements, technical safeguards, and in adherence to instructions issued by the Government of India or competent authorities.
16.Policy Changes
This policy may be updated periodically to reflect legislative updates, technological advancements, or changes in clinical operations. The “Last Updated” date indicates the current revision. Material changes will be highlighted appropriately.
17.Privacy Grievance & Contact
Breathe Ease — Data Privacy & Grievance Redressal Desk
Dr. Tarun Sharma / Clinical Administration
H-12, Ground Floor, Sarita Vihar,
New Delhi – 110076, India
Please include the patient's full name, registered mobile number, and specific details of your query or grievance to enable prompt verification and response.
18.Important Legal Reservations
- This policy does not exclude or limit any statutory right, remedy, or professional duty that cannot lawfully be waived under Indian law.
- Clinical confidentiality remains governed by lawful exceptions, including court orders, statutory epidemic reporting, and situations requiring emergency disclosure to protect life.
- If any provision is deemed unenforceable, remaining provisions shall continue in full legal effect.
- This Privacy Policy must be read in conjunction with our Terms & Conditions and informed consent documentation provided during clinical care.