Home/Security & Compliance
Security & Compliance

Security has to feel visible, not hidden in fine print.

HealthPocket communicates account safety, data protection, access control and responsible reporting practices in plain language.

HealthPocket · Security & Compliance
User safety basics

HealthPocket support will not ask for OTP, CVV, UPI PIN, passwords or full card details over casual channels.

Never shareOTP/CVV/PIN
Reportsecurity@healthpocket.in
AccessNeed-to-know controls
Account safety
Data protection
Responsible reporting
Protection Areas

Security principles built into the program.

01

Access control

Limit access to sensitive operational information based on role and business need.

02

Sensitive data minimisation

Avoid collecting or requesting information that is not required for support or compliance.

03

Safe support communication

Never ask users for OTP, CVV, UPI PIN or passwords over email, phone or chat.

04

Partner governance

Use onboarding checks and program rules for hospitals, pharmacies, labs and wellness partners.

05

Incident response

Review suspicious activity and route credible security reports to the appropriate internal owner.

06

Compliance alignment

Design processes to align with applicable issuer, payment, privacy and Indian regulatory requirements.

Report A Concern

How security reports should be submitted.

1

Write a summary

Explain what happened, when it happened and which account or page was affected.

2

Add safe evidence

Share screenshots or logs only after removing OTP, CVV, full card number and passwords.

3

Email security desk

Send the report to security@healthpocket.in with a clear subject line.

4

Review and response

HealthPocket reviews the issue and may request additional non-sensitive details.

User Safety Checklist

What HealthPocket will and will not ask for.

InformationSafe to share?Guidance
Transaction referenceUsually yesUseful for support when shared through official channels.
Last 4 digits of cardSometimesOnly if requested through verified support for identification.
OTP / CVV / UPI PINNoNever share these with anyone.
Full card numberAvoidDo not send over email or chat unless a verified secure flow exists.