Hospitals and diagnostics collect Aadhaar for registration and insurance, then attach it to records that move to insurers, TPAs, referral partners and research datasets. Here the driver is not KYC compliance — it is that a medical record tied to a national identifier is about the most sensitive object in Indian data protection.
Talk to our technical team → — for integration questions, a security review or a volume estimate.
A hospital rarely needs an Aadhaar number clinically. It collects one at registration — for insurance, for a government scheme, or simply because the form has a field — and from that moment it is attached to a medical record that will travel.
Partially, and it is worth being exact about which part. We remove identity and financial identifiers reliably — Aadhaar, PAN, phone, email and the rest. We do not remove patient names, and we do not touch clinical content. If your protocol requires full anonymisation including names, this is one component of that, not the whole of it.
No document is ever written to disk. It is processed in memory for the duration of the request and released. The only record kept is metadata: which key, which endpoint, file type, size, duration, count and status code.
AWS ap-south-1, Mumbai. Nothing crosses an international border.
No, and that is the point. Patient uploads are unstructured — a photographed prescription, a PDF report, a hospital bill. Redaction matches identifiers rather than recognising layouts, so there is no per-document-type work.
As one component. It removes identity and financial identifiers reliably. It does not remove names and does not touch clinical content, so it is not full anonymisation on its own — and we would rather say so than let you find out during an ethics review.
Tell us how many documents a month you process and what your peak looks like. We will size a plan, provision a key with a test quota, and answer a security questionnaire if you need one.