Patient Data Confidentiality

Privacy Policy & Health Data Governance

This policy explains how Breathe Ease handles personal information, clinical records, teleconsultation data, and technology-assisted documentation while providing pulmonary and critical-care services under Dr. Tarun Sharma.

Effective Date: 25 August 2026Last Updated: 25 August 2026Jurisdiction: India (DPDP Act & NMC Ethics)

Breathe Ease (drtarunsharma.com) is operated in connection with the clinical practice of Dr. Tarun Sharma, Senior Consultant Pulmonologist & Critical Care Specialist. This policy provides patients with a clear, accurate, and practical description of health data governance. It operates alongside clinical consent forms, medical records, statutory obligations, and patient rights that cannot lawfully be excluded.

1.Who Controls Your Data

For services delivered through Breathe Ease, the clinical practice responsible for the relevant consultation determines why and how patient personal and medical data is processed. Operational identity, physical address, and contact details are maintained current on this website and in clinic records.

All clinical records are generated and preserved under the professional and statutory responsibilities applicable to the treating registered medical practitioner and the healthcare establishment involved in patient care.

2.Information We Collect

Identity & Contact Data

  • Full legal name, date of birth / age, gender, and demographic details.
  • Verified mobile phone number, email address, and residential location.
  • Emergency contact, parent/guardian, or authorised representative details.

Clinical & Health Data (SPDI)

  • Presenting symptoms, clinical history, drug allergies, medications, and lifestyle factors.
  • Consultation notes, clinical observations, diagnoses, treatment plans, and prescriptions.
  • PFT / Spirometry, FeNO, CT scans, chest X-rays, laboratory, and other diagnostic reports.

Appointment & Transaction Data

  • Appointment date, time slot, booking status, and consultation mode (in-person vs. remote).
  • Payment transaction references, transaction IDs, and clinic receipts.
  • No CVV, card PINs, or raw net banking credentials are ever stored by Breathe Ease.

Technical & Security Data

  • IP address, device identifiers, and browser technical parameters where logged.
  • Secure authentication tokens and session state verification data.
  • Security, audit, and access logs required to safeguard the platform and health records.

We adhere to the principle of data minimisation, collecting only information reasonably necessary for clinical care, administration, security, legal compliance, and patient safety.

3.Why We Process Information

  • Clinical Care: Comprehensive history-taking, physical and remote assessment, pulmonary diagnosis, diagnostic test ordering, treatment formulation, prescriptions, and continuity of care.
  • Appointment Administration: Scheduling, booking confirmation, automated reminders, rescheduling notifications, and clinic workflow management.
  • Teleconsultation Delivery: Secure patient identity verification, encrypted audio/video session delivery, clinical messaging, and follow-up reviews.
  • Medical Records Governance: Creating, indexing, retrieving, securing, and archiving electronic health records in accordance with statutory standards.
  • Patient & Staff Safety: Preventing identity fraud, prescription misuse, unauthorised account access, and security threats.
  • Legal & Regulatory Compliance: Fulfilling mandatory statutory duties under the National Medical Commission Act, DPDP Act 2023, tax, accounting, and court mandates.
  • Technical Operations: Platform hosting, transactional messaging, transactional email, secure authentication, and IT support through vetted service providers.
Zero Commercial Sale of Health Data: Breathe Ease does not sell, rent, trade, or monetize identifiable patient health records or contact information to advertisers, data brokers, or pharmaceutical companies under any circumstances.

5.Medical Records & Clinical Documentation

Clinical records constitute formal medical documentation containing sensitive personal data. They are maintained with strict access boundaries and heightened confidentiality.

  • Records comprise clinical histories, examination findings, diagnostic reports, clinical reasoning, prescriptions, referrals, and home-care advice.
  • When errors are identified, corrections are documented; clinically material amendments are preserved as an audit trail to ensure medical record integrity rather than overwriting historical entries.
  • Access is restricted strictly according to professional role and legitimate clinical or administrative need.
  • Patient requests for copies of their clinical records are processed in accordance with applicable medical council regulations, verified identity protocols, and lawful procedures.
  • Records subject to active legal inquiries, medical board reviews, complaints, or anticipated claims are retained under legal hold protocols.

6.AI-Assisted Documentation

AI is an assistive administrative technology, not the treating doctor.

Breathe Ease may deploy approved AI-assisted tools for limited documentation tasks, such as formatting voice transcriptions, drafting clinical summaries, or administrative structuring. AI outputs do not constitute an independent diagnosis, prescription, or medical decision.

  • All medical evaluations, diagnoses, and therapeutic decisions remain exclusively with Dr. Tarun Sharma.
  • Every AI-generated draft is reviewed, validated, and approved by the treating doctor before inclusion in the patient's official medical record.
  • AI technologies are selected and configured under contractual privacy and enterprise data isolation terms.
  • Patient clinical data processed via private API integrations is not used to train public foundational AI models.
  • If an AI tool introduces material changes to data processing workflows, relevant privacy notices and consent flows will be updated accordingly.

7.Service Providers & Disclosures

Breathe Ease engages trusted technology and infrastructure partners for secure hosting, database storage, authentication, transactional SMS, email delivery, video teleconsultation, and payment processing. Sub-processors receive only data strictly necessary to perform their designated operational function.

Infrastructure / Service CategoryPurpose & FunctionTypical Data Handled
Cloud Infrastructure & Database HostingSecure cloud database, authentication state, encrypted file storageAccount identifiers, appointment records, encrypted clinical documents
Transactional SMS & Phone Verification GatewayMobile number OTP verification and booking status alertsRegistered phone number and delivery verification metadata
Transactional Email Delivery ServiceAutomated appointment confirmations, receipts, and clinical noticesEmail address, booking summaries, and payment transaction receipts
Encrypted Patient Messaging ChannelsPatient communication and appointment reminders where enabledContact details and message content required for clinical coordination
Secure Video Teleconsultation InfrastructureEncrypted real-time audio-video clinical teleconsultationsAudio/video stream metadata (consultations are not recorded by default)

The clinic maintains an internal vendor registry and updates this policy whenever vendor or infrastructure changes materially impact patient privacy.

Health information may also be disclosed where mandated by court orders, statutory health authorities, emergency responders in life-threatening scenarios, or professional legal advisors subject to strict confidentiality.

8.Security Safeguards

We apply technical and organisational safeguards commensurate with the sensitive nature of medical and personal data:

  • Encryption in transit using modern transport security (TLS) and encryption at rest for cloud databases and document repositories.
  • Role-based access control (RBAC) ensuring only authorized medical personnel access clinical files.
  • Time-sensitive One-Time Password (OTP) verification for secure patient portal access.
  • Administrative access controls, secret/API-key isolation, and confidentiality agreements for all staff.
  • Automated database backups and disaster recovery protocols to protect data availability.
  • Audit logging for sensitive administrative actions and medical record modifications.
  • Continuous software dependency updates and vulnerability patching.

Security safeguards are designed systematically across control categories. Specific cryptographic algorithms and standards are maintained in line with production cloud specifications and industry best practices.

9.Security Incidents & Breaches

If Breathe Ease detects a confirmed or suspected security incident affecting personal or health data, an incident-response protocol is initiated. This includes immediate containment, credential rotation, forensic log analysis, risk assessment, remediation, and notifications to affected individuals and regulatory bodies where mandated by applicable law.

Patients should promptly report any suspected unauthorized access, compromised OTPs, lost devices with active portal sessions, or phishing attempts directly to the clinic desk.

10.Retention, Archiving & Legal Holds

Personal and medical records are retained for periods determined by clinical necessity, continuity of care, statutory obligations, accounting standards, and legal requirements:

  • Medical Records: Retained for a minimum statutory period of 3 (three) years from the consultation date, in compliance with National Medical Commission regulations and Indian healthcare standards.
  • Financial & Billing Records: Retained as required under Indian tax, GST, and accounting legislation.
  • Security & Audit Logs: Retained for periods proportionate to cybersecurity, auditing, and diagnostic needs.
  • Disposal: Upon expiry of mandatory retention periods, inactive data is securely deleted, anonymised, or archived.
  • Legal Holds: Routine deletion schedules are suspended whenever records are subject to an active dispute, complaint, investigation, or court proceeding.

11.Patient Data Rights

Subject to statutory verification and legal conditions under applicable data protection laws, patients hold rights regarding:

  • Access & Summary: Requesting a summary of personal and clinical data processed.
  • Correction & Updating: Requesting correction of inaccurate demographic, contact, or clinical background details.
  • Erasure Limitations: Requesting deletion of non-statutory personal data. Note: Erasure cannot override mandatory medical record retention periods prescribed by medical regulations.
  • Nomination: Designating an authorized representative to exercise data rights in the event of incapacity or death.
  • Grievance Redressal: Registering data protection concerns with our designated Grievance Officer.

All requests must be submitted in writing with verifiable proof of identity to protect patient confidentiality against unauthorized disclosure.

12.Children & Guardian Data

For pediatric patients under 18 years of age or individuals lacking capacity to consent, clinical histories, bookings, and permissions must be provided by a parent, legal guardian, or authorized representative. Proof of guardianship may be requested where clinically or legally appropriate.

Children's data is handled with heightened care and is never used for behavioral profiling or commercial advertising.

13.Communications & Messaging

  • SMS, email, instant messaging channels, and portal notifications are used for appointment scheduling, reminders, and non-urgent clinical follow-ups.
  • Electronic messaging carries inherent risks (e.g. device theft, misdirected messages, interception). Patients are responsible for securing their registered phone number, email, and devices.
  • Digital messaging channels are monitored during clinic hours only and are not emergency hotlines.
  • Patients must never use digital messaging, SMS, or email for acute emergencies or deteriorating conditions.

14.Cookies & Analytics

Breathe Ease uses essential cookies and local storage tokens strictly necessary for patient portal session authentication, security checks, and site navigation. We do not use third-party tracking pixels, advertising cookies, or behavioral profiling networks.

15.Data Transfers & Third Countries

Certain global technology infrastructure providers (e.g., cloud hosting, email gateways) may process encrypted data across geographically distributed data centers. Such services are utilized strictly under compliant data protection agreements, technical safeguards, and in adherence to instructions issued by the Government of India or competent authorities.

16.Policy Changes

This policy may be updated periodically to reflect legislative updates, technological advancements, or changes in clinical operations. The “Last Updated” date indicates the current revision. Material changes will be highlighted appropriately.

17.Privacy Grievance & Contact

Breathe Ease — Data Privacy & Grievance Redressal Desk

Dr. Tarun Sharma / Clinical Administration

Clinic LocationAnanta Care Clinics & Rehabilitation Centre,
H-12, Ground Floor, Sarita Vihar,
New Delhi – 110076, India

Please include the patient's full name, registered mobile number, and specific details of your query or grievance to enable prompt verification and response.