This procedure applies to this website now, and will apply to the hospital platform from the day the first hospital goes live. It is a public summary. The internal procedure has more detail, such as names, phone numbers and reporting templates.
1. What counts
A cyber security incident is any event that puts our systems or data at risk, such as unauthorised access, ransomware, data theft, defacement, or the compromise of an account or key.
A personal data breach is any unauthorised or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability. A single event can be both.
2. Who must be told, and by when
One event can trigger several separate duties, each with its own deadline. We treat them as separate clocks and start all of them when we first notice the event, without waiting for certainty.
| Who is told | Deadline | Basis |
|---|---|---|
| CERT-InThe Indian Computer Emergency Response Team | Within 6 hours of noticing a reportable cyber incident, whether or not personal data is affected | CERT-In Directions of 28 April 2022 under the Information Technology Act, 2000 |
| Hospital customersThe data fiduciaries for their patients | Immediately, so they can meet their own duties. We support their notifications; a hospital’s duty is not discharged by ours. | Our role as data processor |
| Data Protection Board of India | On becoming aware, with a detailed report within 72 hours | DPDP Rules, 2025, as they come into force |
| Affected individuals | Without delay. For patients, through the hospital. | DPDP Rules, 2025, as they come into force |
| National Health AuthorityABDM | In a timely manner, with the actions taken, for incidents affecting ABDM-connected services | ABDM Health Data Management Policy, clause 33 |
The DPDP breach duties apply in full from May 2027. We plan to the same standard now.
3. What we do
| When | What happens |
|---|---|
| At once | Whoever notices records the incident and the exact time it was noticed. That time starts the clocks. |
| Within 30 minutes | The incident lead decides whether a reportable incident or personal data breach is plausible. If so, the clocks are treated as running. |
| Within 1 hour | Containment: isolate affected systems, rotate credentials and keys, preserve logs. Containment never waits for the notification decision, and notification never waits for containment to finish. |
| Within 4 hours | We draft the CERT-In report from a standing template with what is known. Unknown fields are marked as under investigation. |
| Within 6 hours | We file with CERT-In and record the acknowledgement. |
| Promptly | We notify hospital customers, intimate the Data Protection Board and begin informing affected individuals. |
| Within 72 hours | Detailed report to the Board: nature and extent, data and people affected, likely consequences, measures taken and planned, and remediation status. |
| Within 7 days | Post-incident review: root cause, corrective actions with owners and dates, and any change to this procedure. |
4. What we tell you
A notification to an affected person will say, in plain language:
- what happened and when;
- what personal data was affected;
- the likely consequences for you;
- what we and the hospital have done and are doing;
- what, if anything, you should do; and
- who to contact with questions.
5. How we stay ready
- We keep an incident register, and a CERT-In reporting template that is already filled in with our organisation’s details.
- We keep the system logs the law requires, including security logs held in India for at least 180 days.
- We rehearse this procedure at least once a year and keep a record of the exercise.
- We review every incident and act on what we learn.
6. Report a security problem
If you think you have found a weakness in our website or any Vitaloop system, or you suspect a breach, please email shobhit@vitaloop.in with “Security” in the subject line, or nihar@vitaloop.in. Tell us:
- what you found and where;
- the steps needed to reproduce it; and
- how to reach you.
Please do not access, change or keep data that is not yours, do not disrupt our services, and give us reasonable time to fix the problem before you tell anyone else. We will acknowledge your report within 3 working days.
Complaints about how we have handled personal data go to the Grievance Officer.