Privacy Policy for VitalHMS46 (Mobile Application & HMS Software)

Effective Date: 19.08.2025
Last Updated: 19.08.2025

VitalHMS46 (“the App” and “the Software”) is developed and managed by Vitalhms46 Tech Corporation, Bangalore. This Privacy Policy explains how we collect, use, disclose, and protect personal and health information across both our mobile application and our Hospital Management System (HMS) software platform.

We comply with HIPAA (Health Insurance Portability and Accountability Act, USA), GDPR (General Data Protection Regulation, EU), and other applicable international data protection regulations in countries where our solutions are deployed.


  1. Scope

This Privacy Policy applies to:

VitalHMS46 Mobile Application (used by healthcare professionals, patients, or authorized staff on smartphones and tablets).

VitalHMS46 HMS Software (enterprise hospital information system for healthcare institutions).


  1. Information We Collect

We may collect the following categories of data:

Personal Information: User name, email, phone number, login credentials.

Protected Health Information (PHI): Patient demographics, medical history, prescriptions, diagnostic results, billing records, treatment data.

Technical Information: Device identifiers, operating system, app usage logs, IP addresses, session activity.

Institutional Information: Hospital/clinic identifiers, staff roles, and authorized access logs.


  1. Purpose of Data Collection & Use

We collect and use information for:

Delivering HIS/HMS services and mobile health functionality.

Enabling hospitals and clinics to manage patient records securely.

Providing healthcare staff with authorized access to patient information.

Improving system performance, conducting audits, and fixing technical issues.

Complying with regulatory and legal requirements under HIPAA, GDPR, and national health data protection laws.


  1. Data Sharing & Disclosure

Data is shared only with authorized users (hospital staff, clinicians, administrators).

Patient information is never disclosed without authorization, except when required by law.

Third-party hosting providers may process data under Business Associate Agreements (BAAs) to maintain HIPAA compliance.

We do not sell, trade, or rent personal or health data.


  1. Data Security & Safeguards

VitalHMS46 Tech Corp implements technical and organizational safeguards, including:

Encryption: All data is encrypted in transit (SSL/TLS) and at rest (AES-256).

Access Controls: Role-based user permissions and multi-factor authentication.

Audit Trails: Logging of all data access and modifications.

Monitoring: Regular vulnerability scans, penetration testing, and compliance audits.

Secure Hosting: HIPAA- and GDPR-compliant cloud infrastructure.


  1. Data Retention

Patient and hospital data are retained only as long as required by applicable laws or contractual obligations with healthcare institutions.

Upon termination of services, data may be exported to the client institution or permanently deleted, based on agreement.


  1. International Data Transfers

If data is transferred across borders, it will be protected under:

HIPAA (United States).

GDPR (European Union).

National Data Protection Laws in signatory countries where the software is deployed.


  1. Rights of Users and Patients

Depending on jurisdiction, users and patients may:

Access their information.

Request corrections or updates.

Request deletion, subject to medical record retention laws.

Withdraw consent where applicable under GDPR.

Healthcare providers remain responsible for honoring patient rights as data controllers under local laws.


  1. Children’s Privacy

VitalHMS46 is intended for professional healthcare use. Any data related to minors is processed only with parental/legal guardian authorization and under the supervision of licensed healthcare providers, in compliance with COPPA (USA) and applicable laws.


  1. Updates to the Policy

We may update this Privacy Policy to reflect legal, technical, or business changes. Updated policies will be posted at the designated URL with the “Last Updated” date.


  1. Contact Us

For questions or concerns about this Privacy Policy, please contact:

VitalHMS46 Tech Corp
Email: Vitalhms46@gmail.com
Phone: +919008006131
Website: https://vitalhms46.com