Vitaloop Breach procedure ← Back to home
Incident response

Personal data breach management procedure

How Vitaloop detects, contains, reports and learns from a security incident or personal data breach. A public summary of our internal procedure, published as the ABDM Health Data Management Policy requires.

Version 1.0Last updated 21 September 2026
Status: pre-launch

This procedure applies to this website now, and will apply to the hospital platform from the day the first hospital goes live. It is a public summary. The internal procedure has more detail, such as names, phone numbers and reporting templates.

1. What counts

A cyber security incident is any event that puts our systems or data at risk, such as unauthorised access, ransomware, data theft, defacement, or the compromise of an account or key.

A personal data breach is any unauthorised or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability. A single event can be both.

2. Who must be told, and by when

One event can trigger several separate duties, each with its own deadline. We treat them as separate clocks and start all of them when we first notice the event, without waiting for certainty.

Who is toldDeadlineBasis
CERT-InThe Indian Computer Emergency Response TeamWithin 6 hours of noticing a reportable cyber incident, whether or not personal data is affectedCERT-In Directions of 28 April 2022 under the Information Technology Act, 2000
Hospital customersThe data fiduciaries for their patientsImmediately, so they can meet their own duties. We support their notifications; a hospital’s duty is not discharged by ours.Our role as data processor
Data Protection Board of IndiaOn becoming aware, with a detailed report within 72 hoursDPDP Rules, 2025, as they come into force
Affected individualsWithout delay. For patients, through the hospital.DPDP Rules, 2025, as they come into force
National Health AuthorityABDMIn a timely manner, with the actions taken, for incidents affecting ABDM-connected servicesABDM Health Data Management Policy, clause 33

The DPDP breach duties apply in full from May 2027. We plan to the same standard now.

3. What we do

WhenWhat happens
At onceWhoever notices records the incident and the exact time it was noticed. That time starts the clocks.
Within 30 minutesThe incident lead decides whether a reportable incident or personal data breach is plausible. If so, the clocks are treated as running.
Within 1 hourContainment: isolate affected systems, rotate credentials and keys, preserve logs. Containment never waits for the notification decision, and notification never waits for containment to finish.
Within 4 hoursWe draft the CERT-In report from a standing template with what is known. Unknown fields are marked as under investigation.
Within 6 hoursWe file with CERT-In and record the acknowledgement.
PromptlyWe notify hospital customers, intimate the Data Protection Board and begin informing affected individuals.
Within 72 hoursDetailed report to the Board: nature and extent, data and people affected, likely consequences, measures taken and planned, and remediation status.
Within 7 daysPost-incident review: root cause, corrective actions with owners and dates, and any change to this procedure.

4. What we tell you

A notification to an affected person will say, in plain language:

5. How we stay ready

6. Report a security problem

If you think you have found a weakness in our website or any Vitaloop system, or you suspect a breach, please email shobhit@vitaloop.in with “Security” in the subject line, or nihar@vitaloop.in. Tell us:

Please do not access, change or keep data that is not yours, do not disrupt our services, and give us reasonable time to fix the problem before you tell anyone else. We will acknowledge your report within 3 working days.

Complaints about how we have handled personal data go to the Grievance Officer.