1. About BMRAO and This Policy
BMRAO ("we", "our", "us") is an OpenEMR hosting, customization, and support provider headquartered in India, serving clinics and hospitals in India, USA, UK, UAE, Canada, and worldwide. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website at bmrao.com and our OpenEMR hosting services.
For OpenEMR hosting, BMRAO acts as a data processor — your clinic is the data controller. Patient health records stored in your OpenEMR instance belong exclusively to you. BMRAO processes this data solely to deliver the hosting service under your instructions.
This policy covers compliance with India's Digital Personal Data Protection Act 2023 (DPDPA 2023), US HIPAA (for US-based clients), UAE data protection regulations, and ABDM (Ayushman Bharat Digital Mission) data governance standards.
2. Information We Collect
We collect the following categories of information:
- Contact Information: Name, email address, phone number, and WhatsApp number provided through our contact form or direct communication.
- Business Information: Clinic or hospital name, size, specialty, country, and service requirements.
- Technical Information: IP address, browser type, operating system, pages visited, and referral source — collected automatically via Google Tag Manager and standard server logs.
- Service Data: Information necessary to provision and maintain your OpenEMR instance, including server configuration and usage metrics.
- Patient Health Data (hosted only): All patient records, clinical notes, prescriptions, and health data entered into your OpenEMR instance by your authorised staff. This data is held in strict confidence and governed by a separate Data Processing Agreement.
We do not collect sensitive personal information unless you voluntarily provide it in a message, and we never collect payment card details directly — payments are handled through secure, PCI-compliant payment providers.
3. How We Use Your Information
We use your information for the following purposes:
- Service Delivery: Provisioning, configuring, monitoring, and maintaining your OpenEMR hosting environment.
- Communication: Responding to your inquiries, providing support, sending service updates, and billing notifications.
- ABDM & Compliance: Configuring integrations with ABDM, ABHA, NHP, HL7/FHIR, and other health standards as instructed by your clinic.
- Security & Uptime: Monitoring for threats, maintaining 99.9% SLA uptime, and running automated daily backups.
- Legal Compliance: Meeting obligations under DPDPA 2023, HIPAA, GST regulations, IT Act 2000, and ABDM governance.
- Website Analytics: Understanding how visitors use our website to improve content and UX.
We do not use your data for automated decision-making that produces legal effects, nor for profiling you or your patients for advertising purposes.
4. Patient Data Protection
For OpenEMR hosting services, BMRAO implements comprehensive data protection measures aligned with HIPAA and DPDPA 2023:
- Encryption at rest and in transit: All patient data is encrypted using AES-256 at rest and TLS 1.2+ in transit.
- Access control: Role-based access control (RBAC) ensures only your authorised staff can access patient records. BMRAO support staff access infrastructure only, not clinical data, except under explicit written authorisation for troubleshooting.
- Audit logging: All access to patient data is logged and tamper-evident, supporting HIPAA audit requirements.
- Breach notification: In the event of a security incident affecting patient data, we notify you within 72 hours as required by DPDPA 2023 and HIPAA.
- Data ownership: You retain full, exclusive ownership of all patient data. BMRAO has no right to use, analyse, or share patient health records for any purpose other than delivering the contracted service.
- Sub-processors: We use vetted cloud infrastructure providers (AWS, Azure, or equivalent) as sub-processors, subject to strict data processing agreements.
- ABDM compliance: For Indian clinics enrolled in ABDM, patient data handling follows NHP data governance guidelines and ABHA standards.
5. Data Sharing
We do not sell, rent, or trade your personal information or your patients' health data. We may share information only in these limited circumstances:
- With your consent: Only when you explicitly authorise sharing, such as for ABDM health record exchange.
- Cloud infrastructure providers: Infrastructure sub-processors (e.g., AWS) receive only technical data needed to host servers, not clinical content.
- Legal obligations: If required by a valid court order, government authority, or regulatory body under applicable Indian law. We will notify you before disclosure unless prohibited by law.
- Business transfer: In the unlikely event of a merger or acquisition, data will continue to be protected under equivalent or stronger terms, with notice to affected clients.
6. Data Residency & International Transfers
BMRAO offers data hosting in multiple regions to meet local data residency requirements:
- India: Data hosted in Indian data centres for DPDPA 2023 and ABDM compliance.
- USA: Data hosted in US data centres for HIPAA-aligned healthcare providers.
- EU: Data hosted in European data centres for GDPR-compliant operations.
- UAE: Data hosted in UAE data centres for local data protection compliance.
You select your preferred region during onboarding. Data is not transferred across regions without your explicit consent. For Indian clients, all patient health data remains in India unless you request otherwise.
7. Data Retention
We retain your information for as long as necessary to provide services and meet legal obligations:
- Active service period: All data retained for the duration of your subscription.
- Post-termination: Following cancellation, you receive a full data export within 14 days. All data is permanently deleted from our servers within 30 days of termination, confirmed in writing.
- Billing & legal records: GST invoices and financial records retained for 7 years as required by Indian tax law.
- Support communications: Retained for 2 years for audit and quality assurance purposes.
- Website analytics: Aggregated, anonymised analytics data retained for 26 months.
8. Data Security
BMRAO implements industry-standard security measures across all infrastructure:
- SSL/TLS 1.2+ encryption for all data transmission
- AES-256 encrypted data storage
- Automated daily encrypted backups with 30-day retention
- DDoS protection and Web Application Firewall (WAF)
- Intrusion detection and 24/7 infrastructure monitoring
- Regular security patches and vulnerability assessments
- Multi-factor authentication for administrative access
- Principle of least privilege for all staff access
In the event of a breach, we commit to notify affected clients within 72 hours and provide full transparency about scope, impact, and remediation steps.
9. Your Rights Under DPDPA 2023 and Applicable Law
As a data principal under India's Digital Personal Data Protection Act 2023, or as a data subject under applicable laws in your country, you have the following rights:
- Right to access: Request a copy of the personal data we hold about you.
- Right to correction: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data, subject to legal retention obligations.
- Right to data portability: Export your data in a machine-readable format.
- Right to withdraw consent: Withdraw consent for processing without affecting prior processing.
- Right to grievance redressal: Lodge a complaint with our Grievance Officer or with the Data Protection Board of India.
- HIPAA rights (US clients): Access, amendment, and accounting of disclosures rights per 45 CFR §164.524.
To exercise any of these rights, contact us at bmrao.office@gmail.com. We will respond within 30 days.
10. Cookies and Tracking Technologies
Our website uses:
- Google Tag Manager: A tag management container. GTM itself collects no data — it loads analytics tags based on your browser settings.
- Functional cookies: Session-based cookies for website navigation and form state. These expire when you close your browser.
- Analytics cookies: If Google Analytics is loaded via GTM, it may collect anonymised usage data (pages visited, session duration, referral source). This data does not identify individual users.
You can control cookie settings through your browser. Disabling analytics cookies does not affect website functionality.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in law, technology, or our services. We will notify active clients by email at least 30 days before significant changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact & Grievance Officer
For privacy-related questions, data requests, or to exercise your rights under DPDPA 2023 or HIPAA, contact our Grievance Officer:
BMRAO — Grievance Officerbmrao.office@gmail.com
+91 90160 02021
India
We aim to acknowledge all privacy requests within 72 hours and resolve them within 30 days.