Healthcare data is among the most sensitive data a person owns, and every country governs it differently. Rather than build a platform for one regulator and retrofit the rest, Zeeva separates a universal clinical core from a swappable regulatory shell. What follows is how that works, and which frameworks it maps to.
Underneath every jurisdiction sits the same clinical and security core. These are open, internationally governed standards — not our inventions — which is precisely why they travel across borders.
The structural backbone of the entire platform. Every clinical object in Zeeva — patient, encounter, observation, condition, medication, immunisation, claim — is a FHIR resource. National implementation guides are applied as profiles on top of that core, never as forks of it.
SNOMED CT for clinical findings, procedures and problems; LOINC for laboratory and diagnostic observations. Coded meaning rather than free text is what allows a record written in one country to be understood in another — and what makes safety checking possible at all.
ICD-11 for diagnosis classification, morbidity and mortality reporting — the WHO standard now being adopted by member states. DICOM for medical imaging, so studies and reports move between modality, radiologist and clinician without proprietary translation.
ISO/IEC 27001 as the information-security management baseline, with SOC 2 Type II attestation covering security, availability and confidentiality. These are the two artefacts enterprise procurement asks for first, in every market, and they are jurisdiction-independent.
Each jurisdiction brings its own privacy law, identity scheme, clinician registry, accreditation regime and claim format. Zeeva treats these as configuration — a module loaded per deployment — rather than as a reason to build a different product.
HIPAA Privacy and Security Rules with Business Associate Agreements; HITECH breach notification; ONC certification criteria and information-blocking rules; US Core FHIR profiles; TEFCA-aligned exchange via Qualified Health Information Networks; NPI and state-board licence verification.
GDPR lawful basis, data-subject rights and DPIA obligations; the European Health Data Space framework for primary and secondary use; HL7 Europe base profiles; national extensions for member states; UK GDPR and NHS interoperability standards where England, Scotland, Wales or Northern Ireland apply.
Ayushman Bharat Digital Mission — health identity, facility and professional registries, and the national consent manager; the Digital Personal Data Protection Act 2023; NRCES FHIR implementation guides; National Medical Commission licence verification; NABH and NABL accreditation status.
Gulf states, Southeast Asia, Latin America and sub-Saharan Africa each have maturing national frameworks — several with published FHIR guides and enforced adoption deadlines. New modules are built against the local guide and the governing privacy statute, and certified before any patient data is processed.
Listing a framework here means Zeeva is architected against it and the module is scoped — not that certification is complete in every market. Zeeva is pre-launch. Current certification status per jurisdiction is provided in writing to partners during procurement review, and we will not process patient data in a market before the applicable module is certified.
Residency is not a policy we promise; it is a deployment topology. Each jurisdiction runs its own isolated data domain, with identifiable health data confined to it. Two regions inside that domain for resilience. No shadow copies elsewhere, and no cross-border movement of identifiable records between domains.
Mapped to the data-localisation and transfer provisions of whichever statute governs the deployment — GDPR Chapter V in Europe, the DPDP Act in India, state and federal rules in the United States. Specific data-centre locations are disclosed under NDA to enterprise partners during procurement review.
Layered security controls covering identity, network, application, data-at-rest, data-in-transit, and operational practices. Audited annually and continuously monitored.
Most privacy regimes require a named, reachable accountable officer — a Data Protection Officer under GDPR and the DPDP Act, a privacy official under HIPAA, a grievance officer under Indian intermediary rules. We publish ours transparently rather than behind a ticketing form.
For complaints about platform conduct, access, or a partner organisation on the network. Acknowledged within 24 hours and resolved within 15 days, the tightest standard among the regimes we operate under.
For data-subject and data-principal rights — access, correction, erasure, portability, consent withdrawal — under GDPR, the DPDP Act, HIPAA and equivalent regimes. Independent reporting line to the board.
All policies are versioned. Material changes are notified to registered users by email and dashboard banner at least 30 days before they take effect.
Trust is not a slogan we put on a marketing page. It is a property of the architecture.
For enterprise procurement, we maintain a vendor security questionnaire library, evidence packs, audit reports, and a dedicated compliance contact. Reach out and we'll send the right document.