Patient records in one business, trial data in another, and the same controls answering for both.
Hospitals and diagnostic chains hold patient records under the DPDP Act. Pharmaceutical and research businesses hold trial data, formulations and regulatory submissions that are the whole value of the company. Both run on staff who rotate, contractors who come and go, and partners who need in: CROs, referring practitioners, insurers, suppliers.

Registrars change rotation, nurses change ward, locums arrive for a week. Provisioning from role means access follows the posting rather than accumulating across all of them, and re-provisioning on a move adjusts rather than adds. Deprovisioning at the end of a rotation runs in one action across the hospital management system, the recordkeeping system, PACS and billing. Single sign-on across those removes the shared passwords that grow around a busy station, and self-service reset keeps a locked account from becoming a clinical delay.

Trial data, molecule and formulation records, manufacturing processes and regulatory submissions are what a competitor would pay for. Akku indexes your own records as fingerprints and detects them wherever they move: an email attachment, a browser upload, a USB stick, a cloud folder shared with a CRO. Removable media is allowed or denied by device, or left available with the file content deciding what may go onto it. Print, clipboard and screenshot are covered too.

Contract research organisations, referring practitioners, insurers and equipment suppliers all need into systems you run. They are not on your payroll and nobody offboards them. Federation lets them authenticate against their own identity provider rather than an account you create and forget, and where an account is unavoidable it comes from a role with a defined window and an expiry.

Tablets at a nursing station and phones carried on rounds enrol under policy and stay under it: passcode standards enforced, camera and screenshot governed, and installable applications restricted to a list you approve. On personal devices a work profile keeps clinical applications and data separate from everything else, and a wipe takes the work profile alone. Policies assign by organisational unit, so a ward, a site or a region gets its own treatment.

Patient records and trial data both carry the same question after the fact: who reached this, when, and what did they do. Every access decision is recorded as it happens, with the user, the application, the time, the location and the factor used, in logs that are tamper-evident. Privileged access to the databases underneath runs through a proxy that records the session and logs every query.

Finance, procurement, HR and the systems that run the business hold supplier terms, payroll and commercial data. Same treatment as the clinical estate: entitlements from role, MFA that escalates on an unusual request, and provisioning that reaches the ERP rather than stopping at the directory.

The DPDP Act governs patient and customer data, with consent as the authorisation for what you do with it and rights the data principal can exercise. Akku captures consent per purpose against a versioned notice, honours withdrawal in one action, and records correction and erasure with what changed and when it completed. Where a customer or a partner requires ISO 27001, Akku covers 56 of the 93 Annex A controls and holds the certification itself.
