New: India's DPDP Act requires all healthcare providers to be compliant by May 2027. See how Prodoc helps.

Platform

Two agents, one console, one immutable ledger.

The Prodoc Compliance Platform separates the patient-facing dialogue from the system-level execution, giving your DPO oversight, your IT team control, and your regulator an audit trail.

Architecture

The two-agent architecture, explained.

Front office · Interaction

A

Consent Agent

Dialogue liaison · reports to DPO

  • Multilingual dialogue across 22 Indian languages.
  • Captures itemised consent with purpose metadata.
  • Routes rights and correction requests to fulfilment.
  • Runs identity checks via DigiLocker & govt ID.
Restricted · No clinical access

Reports to

Data Protection Officer (DPO)

Legal supervisor of the consent lifecycle.

System governance · Execution

B

Governance Agent

Execution engine · reports to IT/Security

  • Autonomous erasure across primary and backup systems.
  • Cascades erasure to labs, insurers and cloud vendors.
  • Enforces RBAC and retention policies at query time.
  • Real-time log anomaly detection & breach triage.
Full operational authority

Reports to

Hospital IT & Security Team

Technical supervisor of execution.

1 · Identity verified

DigiLocker · Govt ID · OTP

[ VERIFIED_HANDSHAKE ] → [ ERASE ] → [ AUDIT ]

Signed instruction packet · immutable log entry

2 · Action triggered

Policy-driven · logged

Restricted

Clinical Data

EMR, PACS, lab systems · Agent B only, with policy.

Immutable

Audit Logs

Append-only, chained · min. 1-year retention.

Shared

Meta Layer

Consent IDs, purposes, expiries · both agents.

Modules

Six modules. Every DPDPA obligation covered.

console.prodoc.ai/dpo

DPO command centre

Live

Total patients

48,291

Active consents

12,847

↗ 3.2%

Open grievances

14

Compliance

92%

↗ 2.1%

Consent by channel · last 7 days

WhatsApp
41%
Voice IVR
34%
Mobile app
15%
SMS
10%

Live activity

Consent captured

Treatment · Hindi · WhatsApp

2m ago

Grievance opened

Sec 13 · Ward B · SLA 28h

8m ago

Rights request

Access · Sec 11 · Assigned to DPO

14m ago

Erasure queued

Lab sync · Oncology · Agent B

22m ago

Rollout roadmap

A structured, six-phase journey to regulatory readiness.

Most hospitals reach board-defensible compliance in 10 to 14 weeks. Prodoc provides the platform, plus the playbook for each phase.

1

Governance

Establish governance

Appoint DPO & task force · define scope and budget · set orchestration goals.

Weeks 1–2

2

Mapping

Document workflows

Map EMR and billing flows · catalog retention rules · identify blind spots.

Weeks 2–4

3

Core platform · Prodoc

Deploy the Compliance Hub

Implement the platform · integrate with EMR and patient app · automate consent logic.

Weeks 4–8

4

Automation

Automate patient workflows

Self-service portal · auto identity verification · handle rights at scale.

Weeks 6–10

5

Controls

Extend controls

Enforce RBAC and MFA · automate retention and purge · monitor vendor risk.

Weeks 8–12

6

Steady state

Monitor continuously

72-hour breach response · immutable logging · AI-driven audits.

Week 12 →

Fits your stack

FHIR-native. India-hosted. Vendor-neutral.

Prodoc connects to whatever EMR, HIS or CRM you're on today. Data stays in India; audit logs stay yours.

FHIR R4HL7ABDMDigiLockerWhatsApp Business APISAML / OIDC

EMR / HIS

Read + erase primary records with source-of-truth attribution.

Cloud & backups

Cascade erasure to object stores, warm backups and snapshots.

Labs & radiology

Processor contracts monitored; erasure confirmations tracked.

Insurance & TPA

Consent scoped per claim purpose · billing separated from marketing.

Contact centre

IVR + voice agent flows for consent capture in Indian languages.

SIEM & IAM

Immutable log stream · RBAC enforcement via existing identity provider.

8 months to May 2027. Start now.

See the DPO console, walk through the two-agent architecture, and get a scoped rollout plan for your hospital in 30 minutes.

Read the DPDPA primer