Ye IMS ka sabse grilled standard hai (4 OEs, 2 CREO). IMS.5.a: Privacy Policy reception pe + website pe display; kisi bhi third party (insurance, family member) ko data dene se pehle patient consent; har staff induction pe confidentiality undertaking sign karta hai — ye signed undertakings HR file me ready rakho. IMS.5.b: ORALZY already deta hai — per-user login + 2FA (admin/clinical roles), role-based access, immutable audit trail, AES-256 encryption at rest, TLS 1.3 in transit, daily encrypted backup, breach response plan IMS manual me. Assessor pooche 'data leak ho jaye to?' — breach response plan dikhao. IMS.5.d statutory: IT Act 2000 Section 43A (sensitive personal data) + DPDP Act 2023; director ko DPO designate karo. 'Privacy Notice' A4 poster (IMS-5-PRIVACY) reception pe laga hona mandatory-type expectation hai — Posters tab se print karo.
Patient data confidentiality aur security ke liye NABH me kya chahiye?
IMS.5 me DO CREO hain: 5.a confidentiality (need-to-know access, third-party sharing pe consent, staff undertaking) aur 5.b security (login+2FA, role-based access, audit trail, encryption, backup, breach plan).
Where in ORALZY: Sidebar → NABH → Procedure Manual (SOPs) → IMS-5; Posters tab → Privacy Notice