Access control
Limit access to sensitive operational information based on role and business need.
HealthPocket communicates account safety, data protection, access control and responsible reporting practices in plain language.
HealthPocket support will not ask for OTP, CVV, UPI PIN, passwords or full card details over casual channels.
Limit access to sensitive operational information based on role and business need.
Avoid collecting or requesting information that is not required for support or compliance.
Never ask users for OTP, CVV, UPI PIN or passwords over email, phone or chat.
Use onboarding checks and program rules for hospitals, pharmacies, labs and wellness partners.
Review suspicious activity and route credible security reports to the appropriate internal owner.
Design processes to align with applicable issuer, payment, privacy and Indian regulatory requirements.
Explain what happened, when it happened and which account or page was affected.
Share screenshots or logs only after removing OTP, CVV, full card number and passwords.
Send the report to security@healthpocket.in with a clear subject line.
HealthPocket reviews the issue and may request additional non-sensitive details.
| Information | Safe to share? | Guidance |
|---|---|---|
| Transaction reference | Usually yes | Useful for support when shared through official channels. |
| Last 4 digits of card | Sometimes | Only if requested through verified support for identification. |
| OTP / CVV / UPI PIN | No | Never share these with anyone. |
| Full card number | Avoid | Do not send over email or chat unless a verified secure flow exists. |