Security & compliance
Dental software security: patient records stay in India, with one clear retention table
Dental Software India keeps dental patient records in India with role-based access, an audit log, encrypted backups and a fixed retention period for every kind of data. It is HIPAA Compliant, and it helps a clinic meet its DPDP Act 2023 duties; the clinic remains the data fiduciary.
Clinical records: account life + 30 days
Purpose: treating and billing the patient. Patients, charts, plans, e-consents, notes, images, ledgers and WhatsApp history are kept while the clinic account is active, can be exported at any time, and are erased 30 days after the account closes.
Audit log: seven years
Purpose: proving who did what. Creates, edits, deletions, plan sends and approvals, deposits and lab updates, with user, time and IP. It records actions, not full clinical notes, and is kept for seven years.
Backups: 30 days rolling
Purpose: disaster recovery only. Encrypted nightly backups stored in India, each kept for 30 days and then overwritten. Erased data leaves the backups within 30 days.
Closed accounts and erasure: within 30 days
Purpose: the right to erasure. A closed account's data is erased from live systems when its 30-day export window ends, and a patient's record within 30 days of the clinic's request. Archiving a patient in the app hides the record; erasure is done on request.
ABHA number capture
Purpose: ABDM identity. The patient's 14-digit ABHA number is stored on the record with their consent. ABHA creation, record linking and FHIR export are planned and will need your clinic's own HFR registration.
Roles and consent
Four roles today (owner, admin, staff, viewer); desk-only and consultant-only roles are planned. The WhatsApp opt-in is stored on each patient, and each plan e-consent keeps the typed name, time, IP and a fingerprint of the text agreed.
How we build and run Dental Software India
- Isolation. Every record carries your workspace ID and every query is scoped to it at the data layer, so one customer can never read another's data.
- Encryption. TLS 1.2+ in transit; encrypted disks at rest; passwords hashed with Argon2id; API keys stored only as hashes.
- Access control. Roles (owner, admin, staff, viewer) with per-module permissions, session hardening and login throttling with temporary lockout after repeated failed attempts. Two-factor authentication is on the roadmap.
- Audit trail. Every create, edit and delete is logged with who, when, from where and what changed.
- Backups. Nightly encrypted backups, kept on a 30-day rolling cycle.
- Data ownership. Your data is exported for you on request (and much of it is available through the REST API). If you leave, you get a 30-day export window and then your data is deleted.
- Read more. See our privacy policy, terms of service, the full Dental Software India feature list and pricing.
- Responsible disclosure. Found a vulnerability? Email info@radiatus.com and we will respond within 2 business days.
Security questions
How long is each kind of data kept?
Clinical records (patients, charts, plans, consents, notes, images, ledgers, WhatsApp history): for as long as the clinic account is active, then 30 days to export, then erased. Audit log: seven years. Backups: encrypted nightly, kept on a 30-day rolling cycle. Closed-account data: erased from live systems within 30 days, and from backups as they roll off. Website enquiries: 24 months. The same table is in the privacy policy.
Where is patient data stored and can I get it back?
In India, on AWS in the Mumbai region, encrypted in transit and at rest, with nightly encrypted backups. Patients, appointments, plans and lab cases can be read as JSON through the REST API at any time, and on request our team prepares a full export (CSV plus a ZIP of images) at no charge. Your data is yours, on any plan.
Do I need to register on ABDM to use Dental Software India?
No. ABDM is optional. Today Dental Software India stores the patient's ABHA number on the record. ABDM record linking is planned; when it arrives your clinic will need its own Health Facility Registry (HFR) registration and each dentist an HPR ID, which are free and which we can guide you through.
How does Dental Software India help with the DPDP Act 2023?
It records the WhatsApp opt-in on each patient, stores e-consents with the exact text agreed, limits access by role, logs creates, edits, deletions, approvals and payments in the audit log, and erases records on request within 30 days. The law places the duties on the clinic as data fiduciary; the product gives you the controls and the evidence.
Can a visiting consultant see all my patients?
Only if you give them a login. Consultants are set up as dentist profiles for scheduling and payouts and do not need an account. If a consultant does log in, today they get one of the four standard roles (owner, admin, staff, viewer), and staff and viewer roles can see all patients. A consultant-only role limited to their own patients and payout statement is planned.
More plans accepted. More chairs filled.
14-day free trial on every plan, no card needed. Assisted migration from Practo Ray, Clinicia, Dentee or Excel included on Clinic and Chain.