Digital Personal Data Protection (DPDP) Act Compliance
DocVerb separates patient identity from clinical documentation. Our server architecture is designed to exclude direct patient identifiers such as names, phone numbers, email addresses, dates of birth, government IDs, locations, and other demographic attributes from clinical processing, storage, and indexing. Clinical conversations are processed exclusively to extract relevant medical information for generating SOAP notes and prescriptions, without creating patient identity profiles.
Only SOAP notes, prescriptions, and a doctor-specific anonymous UID are securely stored. This UID maintains continuity of care exclusively within the same doctor–patient relationship without creating a universal patient identity.
1. Applicability and Scope
This document details DocVerb's compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), as applicable to our operations as a Data Processor providing AI clinical documentation services to healthcare professionals in India. DocVerb also aligns with other applicable regulations including CDSCO (India), HIPAA (US), and other applicable data protection laws.
2. Role Classification Under DPDP
| Entity | DPDP Role | Responsibilities |
|---|---|---|
| DocVerb | Data Processor (Section 2(i)) | Process digital personal data on behalf of Data Fiduciary (Doctor/Practice) per contract |
| Doctor/Practice | Data Fiduciary (Section 2(f)) | Determine purpose/means of processing; obtain consent; ensure rights |
| Patient | Data Principal (Section 2(j)) | Rights under Sections 11-14 exercisable against Data Fiduciary |
3. UID Architecture & Data Minimization (Core Technical Design)
DocVerb implements a UID-based anonymization architecture that fundamentally limits personal data exposure. This design is central to our DPDP compliance and data minimization obligations:
3.1 What Is Stored on DocVerb Servers
- Only SOAP notes and prescriptions are stored for future reference and continuity of care.
- NO patient name, phone number, email, ID, date of birth, or any identifying information is ever stored on DocVerb servers.
- Only a UID (Unique Identifier) is used to associate clinical records.
3.2 UID Properties
- The UID remains with the patient and can be stored on the doctor's personal device (offline, under doctor's control).
- The UID is not linked to any human identification inside DocVerb systems — it becomes an anonymous token once inside the server boundary.
- The UID can only be linked to a real identity if the UID is explicitly shared from the outside world (i.e., by the doctor or patient).
3.3 One-Time Display, Never Uploaded
During the consultation, patient name and details are shown on screen exactly once — attached to the prescription/SOAP note for the doctor's verification. This information is NEVER uploaded to DocVerb servers. It exists only transiently in the browser session during the encounter.
3.4 Data Access Control: Doctor ID + Patient ID Matching
Clinical data can only be accessed when Doctor ID + Patient ID (UID) match. Without this dual-key match, data cannot be seen or obtained by any party — including DocVerb staff.
3.5 Full Identification Requires Four Factors
The only way to identify/reconstruct patient data is with all four factors simultaneously:
- Doctor ID
- Patient ID (UID)
- UID token
- Timestamp (of the specific consultation)
Any single factor alone — or any subset of three — is mathematically insufficient to identify or retrieve clinical data.
4. Section-by-Section Compliance Mapping
Section 4: Grounds for Processing
DocVerb processes personal data only per Data Fiduciary's documented instructions (Section 8 contract). Lawful basis: Contract performance (Section 7) and legitimate purposes where Fiduciary has obtained consent.
Section 5: Notice
We do not directly collect from Data Principals. Data Fiduciary (you) provides notice. Our Privacy Policy and this page serve as processor transparency. Notice should inform patients that only clinical content (SOAP/prescriptions) is stored, linked to an anonymous UID — no identifying information is processed or stored.
Section 6: Consent
DocVerb does not directly obtain consent from patients. Instead, the Data Fiduciary (Doctor/Practice) obtains explicit consent from each patient before using DocVerb for their consultations. The consent process includes:
- Doctor-Patient Discussion: The treating Doctor explains how DocVerb works, what data will be processed, and the benefits for continuity of care.
- Written/Documentary Consent: Patients sign a consent form or digitally acknowledge via the clinic's EMR system, specifying the scope of AI assistance and their right to withdraw consent at any time.
- Review and Approval: Before processing begins, the Doctor reviews and approves the AI-assisted documentation workflow.
- Editable Workflow: Patients have the option to request human review of AI-generated documentation before finalization. Any edits or overrides are logged with timestamps and attributed to the reviewing Doctor.
Consent should specifically cover: (a) audio processing for clinical documentation, (b) storage of SOAP notes/prescriptions under anonymous UID, (c) no storage of identifying information, (d) UID remaining under doctor/patient control.
Every consent record is maintained with timestamps by the Data Fiduciary. DocVerb relies on the Data Fiduciary's compliant consent as the lawful basis for processing personal data under Section 6 of the DPDP Act.
Section 7: Legitimate Uses
Processing for medical diagnosis/treatment (Section 7(1)(i)) is a legitimate use. DocVerb enables this by generating documentation drafts for your review.
Section 8: Data Fiduciary Obligations (Our Support)
- Accuracy (8(1)): We provide editing tools; you ensure accuracy before finalization.
- Security (8(2)): We implement technical/organizational measures (see Security page). UID architecture ensures identifying data never reaches our infrastructure.
- Breach Notification (8(3)): We notify you within 24 hours of discovering a personal data breach.
- Erasure (8(4)): We delete/delete-on-instruction per retention policy.
- Grievance Officer (8(5)): Available at docverb.no.reply@gmail.com.
- DPIA (8(6)): We support your Data Protection Impact Assessment with technical details.
Section 9: Data Principal Rights
Rights (Access, Correction, Erasure, Grievance) are exercisable against Data Fiduciary. We provide technical means: export (JSON/PDF), deletion APIs, correction via edit-then-regenerate. Because no identifying information is stored, rights fulfillment operates on UID-linked clinical data only.
Section 10: Children's Data
We do not independently verify age. Data Fiduciary ensures Section 10 compliance (verifiable parental consent for under-18) before processing pediatric consultations.
Section 11-14: Rights and Grievance
We honor Data Fiduciary instructions for rights fulfillment within 15 days. Grievance Officer: docverb.no.reply@gmail.com
Section 15: Data Protection Impact Assessment
We provide: data flow diagrams, subprocessor list, security measures, retention schedules, cross-border transfer details for your DPIA. UID architecture and data minimization design are documented for DPIA inclusion.
Section 16: Cross-Border Transfer
All primary processing occurs in India (Mumbai/Bangalore regions). No patient data is processed outside India. Any subprocess outside India uses adequacy/SCCs per Central Government notification.
Section 17-18: Exemptions and Powers
We comply with lawful government orders. Legal process served on Data Fiduciary; we cooperate per contract.
Section 19-23: Penalties and Adjudication
We maintain compliance to avoid processor liability. Indemnification in Terms of Service addresses allocation.
5. Data Processing Agreement (DPA) Terms
By using DocVerb, you enter into a DPA incorporating:
- Processing only on documented instructions
- Confidentiality commitments for personnel
- Security measures per Section 8(2)
- Subprocessor management (prior notice, objection right)
- Data Principal rights assistance
- Breach notification within 24 hours
- Deletion/return post-termination
- Audit/inspection cooperation (reasonable notice)
- Cross-border transfer safeguards
- UID architecture compliance: no identifying data processed/stored; dual-key access (Doctor ID + Patient UID); four-factor identification requirement
6. Practical Implementation for Doctors
- Obtain patient consent for AI-assisted documentation (verbal/written per your practice policy)
- Inform patients: "I use an AI tool to help create my notes. Audio is processed securely and deleted. Only clinical notes are stored under an anonymous ID — your name and details are never uploaded."
- Review every AI-generated note before signing off
- Export/delete patient records per your retention policy
- Direct patient rights requests to your practice; we'll technically assist
- Retain UID on your device — the UID stays with you/patient; without it, even DocVerb cannot link records to identity
7. Subprocessor Disclosure
Critical: No subprocessor receives identifying patient information. All subprocessors receive only de-identified clinical content (SOAP/prescriptions) linked to anonymous UIDs. The UID-to-identity mapping never leaves the doctor's controlled environment.
| Subprocessor | Service | Location | DPA Status | Data Received |
|---|---|---|---|---|
| AWS India | Cloud hosting | Mumbai | Executed | De-identified clinical content + UID only |
| GPU Provider | AI inference | Bangalore/India | Executed | Audio for real-time transcription (ephemeral, not stored) |
| Razorpay | Payments | India | Executed | Doctor billing data only (no patient data) |
| SendGrid | Transactional email | India region | Executed | Doctor account emails only (no patient data) |
8. Contact for DPDP Matters
Grievance Officer / Data Protection Officer: docverb.no.reply@gmail.com
Subject line: "DPDP - [Your Practice Name]"