Standards & compliance
Chartos is built to the Ayushman Bharat Digital Mission from the ground up: ABHA at registration, consent‑based sharing as both a Health Information Provider and User, and every clinical document as an NRCES FHIR bundle — with every byte stored and processed in India.
A patient's ABHA is created or linked at registration with their explicit consent. As a Health Information Provider (HIP), Chartos publishes care records — consults, prescriptions, lab reports — so a patient can find and link them to their ABHA. As a Health Information User (HIU), it requests records from other facilities, but only against a valid ABDM consent artefact the patient has granted. Consent is the gate on every exchange: no consent, no sharing, and a patient can withdraw at any time.
Every clinical entry is stored as a code, never free text alone — SNOMED CT for complaints, diagnoses and procedures, LOINC for lab results, ICD‑10 for reporting, and CDCI for drugs. Consults and e‑prescriptions are assembled as NRCES FHIR R4 document bundles (OP Consult Record, Prescription Record) so they are valid and portable across any ABDM‑compliant system.
Chartos aligns with the Digital Personal Data Protection Act, 2023 and the EHR Standards 2016. The clinic is the Data Fiduciary; Chartos processes on its documented instruction. Records are immutable — a correction is a new version, never an in‑place edit or delete — with a full ISO 27789 audit trail on every access and change. Access is role‑based with strict per‑tenant isolation and staff MFA. All patient data — records, logs, analytics, backups and any AI inference — stays in India, and our systems are configured to refuse data flows to processors outside the country.
See the ABDM, DPDP and EHR‑standards controls in the product — and how they map to your clinic.