Skip to main content
INTEROPERABILITY
PRANA · 2026
I.SECURITY & CONSENT
GOVERNANCE

Security & consent infrastructure.

Healthcare data governance is not just about encryption and access control. It is about consent boundaries, auditability, revocation enforcement, and traceability, ensuring that every movement of health information is governed, traceable, and under patient control.

SEC-01
Consent-Governed Access
Every data exchange begins with explicit patient consent. No access without authorization.
SEC-02
End-to-End Encryption
Health data encrypted in transit using ECDH with Curve25519. Unique nonce per exchange.
SEC-03
Audit Trail
Every consent decision timestamped and traceable. Complete governance record maintained.
SEC-04
Patient Revocation
Patients can revoke access at any time. Consent artefacts scoped to provider and time period.
SEC-05
Data Residency Control
Choose platform-managed or self-managed storage. Full control over data governance.
SEC-06
Standards Compliance
FHIR R4 compliant data structures. ABDM gateway integration following national specifications.
II.CONSENT ARCHITECTURE
DATA GOVERNANCE

Consent-driven architecture.

When a patient approves a consent request, the system generates formal consent artefacts, one per healthcare provider involved. These artefacts authorize specific access, for a defined time period, to specific record types. Patients can revoke access at any time. Every state transition is timestamped and traceable.

Consent state machine showing five states: Requested, Granted, Denied, Revoked, and ExpiredCONSENT STATE MACHINEREQUESTEDpatient approvespatient deniesGRANTEDDENIEDpatient revokestime limitREVOKEDEXPIRED
III.INTEROPERABILITY GOVERNANCE
AUDITABILITY

Every exchange is traceable.

When health data moves between systems, every step is logged: who requested access, what consent authorized it, which records were shared, when the exchange occurred, and when consent expires or is revoked. This creates an immutable governance trail.

Consent boundaries

Data can only move within the scope defined by the patient's consent artifact: specific providers, specific record types, specific time windows.

Revocation enforcement

When a patient revokes consent, access is terminated across all systems that received data under that consent. Enforcement is architectural, not implementation-dependent.

Immutable audit trail

Every consent decision, data exchange, and access event is timestamped and logged. The audit trail is queryable, exportable, and designed for regulatory review.

DPDPA-aware design

Infrastructure designed with data minimization, purpose limitation, and storage limitation principles aligned with India's Digital Personal Data Protection Act.

IV.ENCRYPTION & DATA RESIDENCY

End-to-end encryption.

Health data is encrypted in transit using ECDH with Curve25519. Each exchange uses a unique nonce. Healthcare systems can choose between platform-managed storage or self-managed storage, maintaining full control over data residency and governance.

Get in touch ↗