Access is scoped to a facility
A user can reach a record only when they hold an active membership in the facility that owns it. The same rule applies regardless of which approved workflow they use.
Facility-level authorization
Trust architecture
Most security pages are adjectives. This one explains the practical boundaries: who can reach a record, what gets logged, where AI stops, and what a patient can take back.
11:24:07report.readdr.mehta · NMD-2481 · treatment
11:24:52report.signdr.mehta · NMD-2481 · granted
11:26:14report.releasesystem · NMD-2481 · patient app
11:26:15image.accesspatient · NMD-2481 · granted
No delete path. No update path. The row that was written is the row you read back in the review.
Six guards
Each safeguard has a clear operational consequence. Your IT and compliance teams can review these controls against the workflows they care about.
A user can reach a record only when they hold an active membership in the facility that owns it. The same rule applies regardless of which approved workflow they use.
Facility-level authorization
Reads, creates, updates, downloads, and exports append an event carrying the facility, the actor, the patient, the purpose, the outcome, and a correlation reference. The application can add events but cannot rewrite them.
Append-only audit history
NexaMed's proprietary algorithms provide an active second read and have reached up to 87% on internal evaluation benchmarks. A radiologist reviews the analysis and signs the final report.
Active assistance with clinician sign-off
A patient upload that is unavailable, ambiguous, infected, or fails its checksum never becomes downloadable, never gets extracted, and never reaches automated analysis. Uncertainty resolves to refusal, not to a best guess.
Fail-closed document intake
The patient copilot uses only the context the patient is allowed to access, minimizes retained data, keeps patient health information out of application logs, and requires approved data controls before production use.
Minimum-necessary patient context
Device integrations retain consented daily aggregates only, deletion is patient-initiated with a 30-day restore window, and copilot history is encrypted and expires on a bounded purge.
Patient-controlled retention
What we don't claim
You're going to find this out in diligence anyway. You should find it out from us, on our own website, before you've spent three weeks on a procurement.
We are building NexaMed in line with ABDM documentation and integration requirements. The foundations — facility tenancy, HFR and HIP metadata, encrypted ABHA linkage, and a consent state model — are already in place, and our ABDM registration is currently in progress. Live ABHA verification and health-record exchange will be enabled once registration and the required approvals are complete.
It is an active, proprietary second read with internal evaluation scores of up to 87%. It does not replace radiologist judgment or final sign-off, and the internal score is not presented as independent clinical validation.
Not until we've run long enough at real hospital load to have one worth putting in a contract. We'd rather show you our incident posture in the review than print a nine we haven't earned.
A scoring tool stays out of clinical use until a clinician approves the rubric behind it. A health score nobody clinical signed off on is a liability with a nice gradient on it.
Your data stays yours
Every hospital that has been trapped in a system knows the tell: the data only comes out in a format the vendor invented. So here's ours, in the open.
A consultation exports as a standard bundle — patient, organization, practitioner, encounter, diagnosis, prescriptions, investigations, diagnostic reports. Artifacts carry the FHIR version, the profile version, the source version, and a deterministic payload fingerprint.
Standards-based portability
Plain ABHA numbers are never persisted, logged, or put in a URL — only an encrypted reference. When our registration completes, the exchange turns on against foundations that were built for it from the start, rather than bolted on in a panic.
Encrypted identity linkage
Authentication confirms who signed in, and that's all we let it answer. Clinical records keep their own identity boundary, so a login provider never quietly becomes the patient index.
Identity and clinical records remain separate
Next step
Bring your IT and compliance team. We'll walk through access, audit history, patient-data boundaries, and how clinical decision support is reviewed and signed off — using the workflows they want to challenge.