Skip to main content

Government / Healthcare

Securing the data of 1.2 crore BSKY card holders

Health-scheme platform assessment covering beneficiary data, hospital integrations and claim workflows.

Scale

1.2 crore card holders

Biju Swasthya Kalyan Yojana, Government of Odisha

  • CERT-In Audit
  • Data Privacy
  • VAPT

The brief

Assess the health scheme platform covering beneficiary records, hospital integrations and the claims workflow.

What we did

  • Application and API security testing across beneficiary and hospital portals
  • Claims workflow abuse testing, including fraud paths
  • Health data handling review against DPDP Act 2023 obligations
  • CERT-In aligned reporting with remediation support and retesting

Biju Swasthya Kalyan Yojana covers around 1.2 crore card holders and settles claims with empanelled hospitals. Two things make it a harder assessment than its size suggests: the data is health data, and the money moves on a workflow that multiple organisations touch.

Health data raises the stakes

Health records attract a different class of consequence from a leaked email address, and under the DPDP Act 2023 they attract different obligations too. Our review covered not only whether records could be reached without authorisation, but whether the platform's handling of them, retention, access logging, and what the hospital side could see, matched what the scheme had committed to.

Workflow abuse, not just vulnerabilities

On a claims platform the interesting question is often not "can an attacker read this" but "can a participant do something the process assumes they cannot". Can a hospital user amend a submitted claim. Can the same treatment be claimed twice through different routes. Does a state change that should be one way actually enforce that.

These are logic findings. Scanners never find them. They are also the findings that scheme administrators care about most, because they map directly onto money.

Integration boundaries

Every empanelled hospital is an integration, and integrations built for a hundred participants behave differently at scale. We tested the authentication and authorisation on those interfaces as an outsider would reach them, not as the documentation described them.

What was handed over

Findings by severity with reproduction, a separate note on the data protection observations for the scheme's compliance team, remediation guidance and retesting through to closure.

Card holders covered
1.2 crore
Focus
Claims workflow and health data
Framework
CERT-In, DPDP Act 2023

Engagement detail is summarised. Specific findings, payloads and architecture remain confidential under our client agreements.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.