Privacy Policy
1. Introduction & Overview
At Shalom Institute of Mental Health and Research (SIMHAR), we understand that mental healthcare, clinical treatment, and academic research involve exceptionally sensitive information. We are committed to protecting the privacy, dignity, and personal data of our patients, clinical research participants, facility visitors, online users, and staff.
This Privacy Policy governs the collection, use, processing, storage, disclosure, and protection of personal data and Sensitive Personal Data or Information (SPDI) collected through our inpatient and outpatient facilities, digital health platforms, research activities, and official website.
This policy has been framed to comply comprehensively with applicable domestic Indian statutory laws and international global data protection standards:
- Digital Personal Data Protection Act, 2023 (DPDP Act) & Rules (India)
- The Mental Healthcare Act, 2017 (MHCA) (India – specifically Section 23 on Right to Confidentiality)
- Information Technology Act, 2000 & Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (India)
- Ayushman Bharat Digital Mission (ABDM) Health Data Management Policy (India)
- General Data Protection Regulation (GDPR) / EU Regulation 2016/679 (European Union)
- Health Insurance Portability and Accountability Act (HIPAA) (United States – alignment for international research and cross-border tele-consultations)
2. Information We Collect
We categorize the data collected into non-sensitive personal data and sensitive medical/health data:
A. Patient & Clinical Information (Sensitive Health Data)
- Personal Identifiers: Full name, date of birth, age, gender, national ID (Aadhaar, ABHA ID/Address, Passport number), home address, contact number, emergency contact/Nominated Representative details.
- Clinical Records: Psychiatric assessments, psychological evaluation notes, therapy audio/video recordings (if applicable and consented), medical history, diagnoses, ongoing treatment plans, prescription records, lab test results, and admission/discharge summaries.
- Advance Directives & Care Plans: Records executed under Section 5 of the Mental Healthcare Act, 2017, detailing patient preferences for care and appointed Nominated Representatives.
B. Research Data
- Data collected during clinical trials or academic mental health research studies, including psychometric testing, demographic baseline data, and observational logs. Research data is de-identified or anonymized prior to analysis unless explicitly consented otherwise.
C. Website & Digital Platform Data
- Technical Data: IP address, browser type, device information, operating system, and geographic region.
- Usage & Cookies: Pages visited, duration of visit, referral links, and cookie tracking data.
3. Legal Grounds & Statutory Compliance for Data Processing
We collect and process data under clear, lawful bases recognized under Indian and global frameworks:
- Explicit Consent (Section 6, DPDP Act 2023 / Art. 6 & 9, GDPR): Free, specific, informed, unconditional, and unambiguous consent obtained via written or digital consent forms before treatment, research enrolment, or website data collection.
- Medical Emergency / Provision of Healthcare (Section 7, DPDP Act / Art. 9(2)(h), GDPR): Necessary for medical diagnosis, provision of emergency mental health treatment, or medical care when a patient is temporarily incapable of giving explicit consent.
- Legal Obligations & Statutory Mandates: Compliance with court orders, regulatory reporting under the Mental Healthcare Act 2017, or child protection statutes (e.g., POCSO Act in India).
4. Special Mental Health Confidentiality Clauses (Indian & Global Laws)
Due to the sensitive nature of psychiatric and psychological care, SIMHAR enforces heightened confidentiality protocols. Our core confidentiality protections rest on three pillars:
| Section 23, MHCA 2017 | DPDP Act / GDPR | Media Protection (Section 24, MHCA) |
|---|---|---|
| Statutory right to confidentiality for mental health records. | Heightened protection for Sensitive Personal Data or Information (SPDI). | Strict prohibition of patient identifiers and photos. |
Clause 4.1: Statutory Confidentiality (Section 23, Mental Healthcare Act, 2017)
All health professionals at SIMHAR have a strict legal duty to keep all information obtained during care or treatment confidential. Information will NOT be released to third parties unless one of the following legal exceptions applies:
- Nominated Representative: Release to the patient’s legally appointed Nominated Representative to enable them to fulfill their duties under the Act.
- Inter-Care Disclosure: Sharing between mental health professionals directly involved in providing treatment to the patient.
- Harm Prevention: Disclosure necessary to protect the patient or another person from immediate physical harm or violence (strictly limited to the minimal information required).
- Threat to Life: Disclosure necessary to prevent a direct, immediate threat to life.
- Court / Board Order: Release required by an order from a competent Mental Health Review Board, High Court, Supreme Court, or statutory authority.
Clause 4.2: Protection from Media and Public Exposure (Section 24, MHCA)
In compliance with Section 24 of the Mental Healthcare Act, 2017:
- No photograph, video, name, or identifiable information of any patient undergoing treatment at SIMHAR shall be published or released to the media, online channels, or public domains without explicit, written, voluntary consent from the patient (or Nominated Representative where applicable).
Clause 4.3: Right to Access Records & Medical Restrictions (Section 25, MHCA / Article 15 GDPR)
Patients have the right to access their basic medical records. However, under Section 25(2) of the MHCA, the treating mental health professional in charge may temporarily withhold specific parts of the record if disclosing it would cause serious harm to the mental health, physical health, or safety of the patient or others.
5. How We Use Your Information
SIMHAR processes personal and health data strictly for specified, lawful purposes:
- Care Delivery: Providing psychiatric evaluations, psychotherapy, nursing care, medication management, and rehabilitation.
- Research & Advancement: Conducting ethical mental health research (subject to Institutional Ethics Committee approval and anonymization).
- ABDM Interoperability: Creating and linking Ayushman Bharat Health Account (ABHA) IDs for digital health record exchange, subject to user consent.
- Administration & Billing: Processing insurance claims, generating invoices, and complying with statutory audit requirements.
6. Data Sharing, Disclosures, and International Transfers
SIMHAR does not sell, rent, or commercially exploit any patient or user data under any circumstances.
A. Third-Party Service Providers (Data Processors)
We may share minimal required data with trusted third-party providers (e.g., cloud EHR platforms, secure payment gateways, diagnostic laboratories). All such processors are bound by strict Non-Disclosure Agreements (NDAs) and Data Processing Agreements (DPAs) requiring equivalent security standards.
B. Cross-Border Data Transfers (GDPR / DPDP Act)
For international tele-consultations, foreign research collaborations, or international cloud storage:
- Data will only be transferred to countries or entities that offer an adequate level of data protection.
- For EU residents, transfers comply with standard contractual clauses (SCCs) under GDPR.
- Transfers strictly adhere to notified restrictions under Section 16 of India’s DPDP Act, 2023.
7. Data Security & Storage Standards
We employ administrative, physical, and technical safeguards to prevent unauthorized access, loss, or leakage:
| Security Domain | Implemented Controls & Protocols |
|---|---|
| Encryption | End-to-end encryption for tele-health calls; AES-256 for data at rest; TLS 1.3 for data in transit. |
| Access Control | Role-Based Access Control (RBAC); multi-factor authentication (MFA) for electronic health records (EHR). |
| Physical Security | Restricted physical access to medical records archive rooms; 24/7 CCTV monitoring of administrative premises. |
| Audits & Logging | Immutable access logs detailing who viewed, modified, or downloaded patient records, audited periodically. |
8. Data Retention and Destruction
- Clinical Records: Retained for the statutory period mandated by the National Medical Commission (NMC) and local healthcare regulations (typically a minimum of 3 to 10 years from the date of last treatment).
- Research Data: Retained per Institutional Ethics Committee protocol requirements in de-identified or pseudonymized formats.
- Website Analytics Data: Retained for up to 24 months before automated purging.
- Secure Destruction: Digital files are securely shredded/overwritten; physical files are destroyed via cross-cut shredding upon expiry of statutory retention periods.
9. Your Data Rights
Depending on your jurisdiction (under DPDP Act 2023, MHCA 2017, or GDPR), you hold the following rights regarding your personal data:
- Right to Information & Summary: Request a summary of personal data processed and processing activities.
- Right to Rectification & Erasure: Request correction of inaccurate data or deletion of personal data (subject to statutory clinical retention mandates).
- Right to Withdraw Consent: Revoke consent for processing at any time (does not affect lawful processing conducted prior to revocation).
- Right to Nominate (DPDP Act): Nominate an individual to exercise data rights in the event of death or incapacity.
- Right to Grievance Redressal: Access swift, transparent mechanisms to resolve data privacy concerns.
10. Grievance Officer & Contact Information
In compliance with the Digital Personal Data Protection Act, 2023, and the IT (Reasonable Security Practices) Rules, 2011, SIMHAR has appointed a dedicated Data Protection & Grievance Officer.
For privacy complaints, access requests, or rights enforcement, please contact:
Data Protection & Grievance OfficerShalom Institute of Mental Health and Research (SIMHAR)
Address: Vazhukkapara, Kinavallur P.O., Parali, Palakkad – 678612, Kerala, India
Email: hello@simhar.com
Phone: (+91) 811 308 7028
Working Hours: Monday to Saturday, 9:00 AM – 5:00 PM IST
We will acknowledge receipt of any privacy complaint within 24 to 48 hours and aim to resolve all grievances within 15 business days.
11. Updates to This Privacy Policy
SIMHAR reserves the right to update or modify this Privacy Policy to reflect changes in legal requirements, operational practices, or technological advancements. Material changes will be published on our official website with an updated "Effective Date." Continued use of our services or website constitutes acceptance of the revised policy.