Legal & Security
Privacy Policy & Patient Data Security
EliteHMS is committed to protecting patient health records, pharmacy transactions, and medical enterprise data with bank-level encryption and strict privacy standards.
1. Overview & Data Ownership
This Privacy Policy governs the collection, storage, and processing of personal and medical data by EliteHMS Hospital Pharymacy and Healthcare Solutions Pakistan ("EliteHMS", "we", "us", or "our").
Your Data Belongs to You: All patient profiles, electronic medical records (EMR), billing histories, lab reports, and inventory data entered into your EliteHMS subscription remain the exclusive property of your healthcare facility. EliteHMS does not sell, rent, or monetize patient or facility data to any third party.
2. Information We Collect
We collect and process the following categories of data solely to provide healthcare management services:
- Facility & Account Information: Store/hospital name, administrator email, contact phone, NTN, and billing preferences.
- Clinical & Patient Data: Patient demographics, CNIC, medical histories, vital signs, prescriptions, lab results, and IPD admission records uploaded by authorized staff.
- Technical & Session Data: IP addresses, browser user-agent signatures, active device tokens, and 30-day httpOnly refresh session cookies for security audit logging.
3. Security & Encryption Standards
EliteHMS implements enterprise-grade technical safeguards to ensure data integrity and confidentiality:
- 256-Bit SSL/TLS Encryption: All data in transit between your browser and our servers is encrypted using modern TLS protocols.
- Authentication & Access Controls: Password hashing via bcrypt, 15-minute access tokens, 30-day httpOnly refresh cookies, optional 2FA via Google Authenticator, and active session management (max 5 devices).
- Role-Based Access Control (RBAC): Granular permissions prevent non-authorized personnel (e.g., receptionist or nurse) from accessing sensitive financial or administrative data.
- Database Isolation: Vector embeddings in Qdrant and clinical records in MongoDB are logically isolated by store ID.
4. Regulatory Alignment (DRAP & FBR)
In accordance with Drug Regulatory Authority of Pakistan (DRAP) regulations, controlled medicine purchase and sale registers (Schedule H / Form-10 equivalents) are maintained securely to satisfy legal inspection requirements.
Tax summaries exported for FBR IRIS portal submission contain only necessary transaction line items and NTN invoice identifiers required by law.
5. Data Retention & Erasure
Your facility data is retained for the duration of your active subscription. Upon account termination, you may request a complete database export in standard JSON/Excel formats. Account backup archives are permanently purged within 60 days of cancellation.
6. Contact Data Protection Officer
If you have questions regarding data security, patient privacy, or compliance audits, contact our technical team directly: