Skip to content
CBS Health
  1. Home
  2. Security
Security & data protection

What is encrypted, where it lives, and who is allowed to look.

Written for the person who has to sign off on the deployment, not for the person choosing between vendors on a feature grid.

At rest and in transit

The mechanics.

Field-level encryption for identifiers and clinical text
Patient identifiers and clinical free text are encrypted with AES-256-GCM before they reach the database, in a Rust core rather than in application code. Full-disk encryption protects a stolen drive; this protects against a database dump, a misconfigured backup and an over-broad support query, which is where records actually leak.
Every query audit-logged
Access to patient data is logged at the point of the query, not at the point of the route. A record of who looked at which patient, when, and under what stated purpose is the only thing that makes an internal-misuse investigation possible.
Log messages carry patient identifiers by reference. No protected health information is written into a log line.
Compliance evaluated before access, not after
Patient data access passes through a compliance layer that evaluates the country's rules for the requesting user, the purpose and the data class. A rule that is only checked after the data has been returned is a report, not a control.
Transport and browser hardening
HTTPS with HSTS, a restrictive Content-Security-Policy, and no third-party script or font loaded on any page of this site. A health platform that pulls a web font from a third-party CDN has told that CDN who is reading its clinical pages.
Jurisdiction

Five regimes, implemented separately.

Consent lifetimes, retention periods, erasure rights and portability obligations genuinely differ. Averaging them into one global policy produces a policy that is wrong everywhere.

India — DPDP Act 2023

Consent must not be indefinite: it is held with a 365-day lifetime. Erasure rights under Section 12 are implemented. Aadhaar is masked wherever it appears. Clinical retention follows the NMC period rather than the shorter privacy one.

United Kingdom — UK GDPR

Lawful basis recorded per processing purpose, subject access and erasure implemented, and data portability in a structured machine-readable form.

United States — HIPAA

Treatment, payment and operations purposes handled without requiring separate explicit consent, minimum-necessary applied to disclosures, six-year retention, and no statutory erasure right — which is itself implemented as a refusal rather than silently ignored.

Singapore and Malaysia — PDPA

Both statutes implemented as their own plugin rather than approximated to the nearest neighbour, with their own consent and notification rules.

Data residency is a deployment decision

CBS is deployed per region. An Indian deployment keeps data in India. Residency is not a setting inside a single global instance, because that is not a guarantee anyone should accept.

What we do not hold

Certification, plainly stated.

CBS Health holds no third-party security certification today. There is no ISO 27001 certificate, no SOC 2 report, and no HITRUST assessment. It is not registered as a medical device with the CDSCO, the MHRA or the FDA.

The controls described on this page are implemented and testable, and a procurement team is welcome to test them. They have not been audited by an independent third party, and we would rather you learn that here than discover it in the questionnaire.

Reporting a vulnerability

If you have found a security issue, tell us before you tell anyone else and we will work the fix with you. Use the contact form and mark the subject as a security report; it is routed differently from a sales enquiry.

Send us your security questionnaire.

We would rather answer it early and lose the deal than answer it late and lose the trust.