Biju Swasthya Kalyan Yojana covers around 1.2 crore card holders and settles claims with empanelled hospitals. Two things make it a harder assessment than its size suggests: the data is health data, and the money moves on a workflow that multiple organisations touch.
Health data raises the stakes
Health records attract a different class of consequence from a leaked email address, and under the DPDP Act 2023 they attract different obligations too. Our review covered not only whether records could be reached without authorisation, but whether the platform's handling of them, retention, access logging, and what the hospital side could see, matched what the scheme had committed to.
Workflow abuse, not just vulnerabilities
On a claims platform the interesting question is often not "can an attacker read this" but "can a participant do something the process assumes they cannot". Can a hospital user amend a submitted claim. Can the same treatment be claimed twice through different routes. Does a state change that should be one way actually enforce that.
These are logic findings. Scanners never find them. They are also the findings that scheme administrators care about most, because they map directly onto money.
Integration boundaries
Every empanelled hospital is an integration, and integrations built for a hundred participants behave differently at scale. We tested the authentication and authorisation on those interfaces as an outsider would reach them, not as the documentation described them.
What was handed over
Findings by severity with reproduction, a separate note on the data protection observations for the scheme's compliance team, remediation guidance and retesting through to closure.












