Saturday, May 14, 2016

Healthcare Laws And Regulatory Compliances In India

Legal and regulatory issues of technology and technology driven projects have always vexed governments around the world. India is no exception to this fact as Indian government is still struggling to deal with the legal issues of fields like e-health, m-health, telemedicine, etc. Similarly, many healthcare services are dependent upon cloud computing these days. The legal and regulatory issues of cloud computing in India are far from satisfactory. As a result many businesses and companies are hesitant in using the same for various purposes including for healthcare purposes.

On the positive side, the Electronic Health Record (EHR) Standards of India have been prescribed and establishment of a National E-Health Authority (NeHA) of India has also been proposed by Indian government. Further, if we remove the shortcomings of Digital India project then the same can be used for e-health and healthcare purposes as well.

Technology vendors and entrepreneurs are eying upon Indian healthcare market as the same is booming and has great commercial significance for the coming decades. However, along with benefits there are liabilities and obligations as well. For instance, e-health, m-health, telemedicine, etc are subject to techno legal compliances. Presently the healthcare industry and healthcare entrepreneurs of India are acting more on the side of violation than compliances.

The legal risks for developer and owners of healthcare websites cannot be ignored. Further, mobile medical devices and handsets and their respective applications must also be in strict conformity with Indian laws. Medical device makers, software providers and medical fraternity of India must also keep in mind the encryption laws of India and cloud computing related legal risks in India.

For instance, AIIMS Bhubaneswar has recently launched electronic health card system and other hospitals and clinics may also adopt this practice. However, issues of privacy rights, data protection (pdf), cyber security, data security, cyber security breach reporting, biometric collection compliances, etc have still not been addressed and complied with by hospitals, clinics and Indian government. Even the Parliamentary Committee slammed Indian government for poor privacy laws and privacy protection in India.

Similarly, there are very complicated sets of legal requirements for establishing online pharmacies in India and for online sale of prescribed medicines in India. We have no dedicated laws for opening of online pharmacy stores in India but different laws of India govern different legal aspects of the same. There are numerous legal risks associated with online selling of medicines in India and all online pharmacies that intend to operate in India mist strictly follow various regulatory provision related to this field. As on date online pharmacies in India are violating various applicable laws of this field.

In the Indian context, regulatory compliances are frequently ignored and violated. Whether it is online pharmacies, e-health, m-health, telemedicine, mobile medical devices and applications, etc, medicine field related stakeholders are openly flouting the applicable norms and regulations.

Although we have no law on the lines of United State’s Health Insurance Portability and Accountability Act of 1996 yet there are numerous statutory provisions that must be complied with. These include privacy law compliances, data protection requirements, cloud computing compliances, encryption related compliances, cyber law due diligence (pdf), etc.

Clinical establishments operating in India are also required to comply with the requirements of the Clinical Establishments (Registration and Regulation) Act 2010 (pdf) and the Clinical Establishments (Central Government) Rules 2012 (pdf). Further, Recommendations on Electronic Medical Records Standards in India (pdf) have also been prescribed that have to be followed and complied with by Indian clinics and healthcare professionals of India. Perry4Law Organisation (P4LO) strongly recommends that both national and international healthcare stakeholders must ensure techno legal compliances of this field. Non compliance would bring not only bad publicity for them but may also result in civil and criminal prosecutions.

Friday, May 13, 2016

E-Learning For Lawyers In India Rejuvenated By PTLB

Legal education in India is getting serious attention of Indian Government, Supreme Court of India and the governing body of Indian Lawyers named Bar Council of India (BCI). However, despite best efforts of various stakeholders, legal education in India is not showing any growth sign. Further, legal education in India is also not much inspired by information and communication technology (ICT). For instance, there is a dearth of institutions that provide e-learning for lawyers in India. Similarly, lifelong learning, continuing legal education, professional online lawyers training, techno legal trainings, etc are also missing as on date. Contemporary areas like cyber law, cyber security, cyber forensics, e-discovery, e-courts, online dispute resolution (ODR), etc are also not given much priority in the contemporary legal education of India.

Realising the need to have an e-learning portal for lawyers of India and other jurisdictions, Perry4Law's Techno Legal Base (PTLB) has been proving online legal education and e-learning for lawyers since 2010. We have also opened a blog in 2010 to guide young lawyers regarding bar examinations in India and related techno legal educational issues. PTLB has also been managing the first even Virtual Legal Education Campus (VLEC) In India since 2012.

PTLB has also launched an Online Skills Development, Training, E-Learning and Virtual Campus for Lawyers and other stakeholders where lawyers can update their legal knowledge in an online environment. For instance, lawyers can enroll for online cyber law courses, education and training by PTLB. They can update their cyber law related skills at this platform.

Taking these initiatives a step further, PTLB has launched two dedicated initiatives in these fields. These are launching of dedicated websites for virtual legal education campus (VLEC) of India and virtual law campus (VLC) of India by PTLB. These websites would be fully functional very soon and virtual legal education would get a new shape and meaning in India. Further, we have also launched Twitter accounts named PTLB Virtual Campus and Virtual Law Campus that would help in better coordination and information sharing between PTLB and various stakeholders.

The aim of these two initiatives and other educational projects of PTLB is to impart online legal education ranging from traditional fields to the most contemporary topics. For instance, PTLB has been managing online cyber law education in India for long. Cyber law is a contemporary legal area that requires techno legal expertise. There are very few cyber law education institutions in India and even lesser are cyber law experts in India. Thus, the demand for cyber law professionals is very great in India and other jurisdictions.

Similarly, areas like cyber security, cyber forensics, e-courts, online dispute resolution (ODR), e-discovery, etc also require qualitative educational institutions. The traditional universities or colleges are constrained by their own rules and courses but online education platforms are free to provide qualitative and customised techno legal courses.

PTLB is in the course of adding and introducing novel, qualitative and highly efficient training, skills development and education tools and technologies. We are also introducing some very unique and highly required techno legal and other courses that are not properly represented in present times. PTLB is also exploring tie ups and collaborations with universities, colleges and other online learning platforms in India and abroad.

Our initial idea is to use PTLB Virtual Campus for various techno legal courses, trainings and skills development programs like cyber law, cyber security, cyber forensics, etc. Whereas we intend to use Virtual Law Campus for legal fields and law courses that are imparted in universities and colleges. However, both Virtual Legal Education Campus (VLES) and Virtual Law Campus (VLC) would primarily cater the requirements of legal courses, trainings and skills developments initiatives though we may add other techno legal courses as well. PTLB would share more details about PTLB Virtual Campus, VLEC and VLC very soon.

Wednesday, May 11, 2016

E-Health Laws And Regulations In India Are Needed For Digital India Project

Healthcare is a priority aspect for governments across the world. However, despite the urgency for an effective healthcare system, timely and cost effective healthcare services are not readily available. This is more so in developing nations where healthcare services are very poor and are available to selective few only.

There are many facets of technology driven healthcare industry in India. These include online pharmacies, telemedicine, e-health, m-health, etc. India is yet to start working on these aspects on the fronts of technology and legal frameworks. We have no dedicated online pharmacy, telemedicine, e-health, m-health, data protection (pdf), privacy and other related techno legal framework in India as on date.

However, some positive steps have been taken by successive governments in India. For instance, the Electronic Health Record (EHR) Standards of India have been prescribed and establishment of a National E-Health Authority (NeHA) of India has also been proposed. Further, if we remove the shortcomings of Digital India project then the same can be used for e-health purposes as well. Digital India is presently suffering from lack of cyber security and absence of civil liberties protection in India. Another limitation of Digital India that it inherited from its predecessor National e-Governance Plan (NeGP) is absence of mandatory e-delivery of services in India. As on date there is no mandatory obligation to provide e-delivery of services in India and this is sufficient to avoid the same.

It has been reported that the health ministry of India has worked out a detailed e-health project under digital India initiative of the government. The project would include hospital information system, electronic health record facilitated with health information exchange, online delivery of services, citizen portal, online monitoring systems for services and others. The health ministry is also developing a digital platform - Integrated Health Information Platform (IHIP) - to enable creation of inter-operable health record which can be made available and accessible nationwide.

Perry4Law Organisation (P4LO) welcomes this initiative of health ministry. However, we also strongly recommend that a techno legal regulatory framework must be urgently formulated by Indian government to manage the complicated issues of Indian cyberspace and Digital India. We also recommend that telemedicine and online pharmacy laws must be complied with by the businesses and entrepreneurs of India that are ignored presently. Similarly, legal issues of cloud computing in India must also be kept in mind by e-health service providers of India. We hope these issues would be considered by Indian government while formulating an e-health related law in India.

Tuesday, May 10, 2016

Telemedicine Laws In India Are Essential For Businesses Operating In The Digital India Era

Indian government has adopted the ambitious project named Digital India that is a turning point for technology driven services in India. Although the Digital India project needs to eliminate various shortcomings yet issues pertaining to cyber security, civil liberties and techno legal framework require special attention of Indian government.

Although there are no dedicated laws in India regarding telemedicine and its usage yet there are different set of laws that are applicable for different aspects of telemedicine. These include cyber law, privacy law, data protection law, data security law, etc. However, telemedicine stakeholders in India are not complying with the techno legal issues applicable in India and they can be prosecuted for violating these laws and cyber law due diligence (pdf) requirements of Indian laws.

There is no second opinion about the fact that when technology is used for medical purposes, it gives rise to medico legal and techno legal issues. Countries around the world have realised this fact and they have made suitable laws to tackle these medico legal and techno legal issues. For instance, in United States, the Health Insurance Portability and Accountability Act of 1996 (HIPAA), Health Information Technology for Economic and Clinical Health Act (HITECH Act), etc are some of the laws that take care of medico legal and techno legal issues of e-health and telemedicine. On the other hand, we have no dedicated telemedicine laws in India.

E-health laws and regulations in India are still missing and legal enablement of e-health in India is needed on an urgent basis. As on date e-health in India is facing legal roadblocks. Till now we do not have any dedicated e-health laws and regulations in India. Perry4Law Organisation (P4LO) firmly believes that dedicated telemedicine laws of India must be urgently formulated.

This is more so when there are many people and institutions in India that are using Internet in an illegal manner for selling medical products and services. Illegal and unregulated online sales of prescribed medicines in India are rampant and Indian government has still not regulated or controlled these online sales of medicines in India, especially in the NCR region.

Similarly, there are some medical professional and para medical professional who are using Internet for providing their services without following the applicable laws of India. There are also many online pharmacies in India that are violating Indian laws, especially the e-commerce laws and regulations of India.

It is high time for Indian government to regulated Internet related medical issues in India before they become a big nuisance and health hazard for Indian citizens and residents.

Saturday, March 19, 2016

Censorship And Surveillance Under Digital India

Adoption of digital India project by Indian government has always been portrayed as a social and welfare oriented initiative. Digital India is treading exactly on similar lines as Aadhaar has worked so far. As Aadhaar has increasingly been tied up by Indian government with digital India, there is no escape from the conclusion that the combination of Aadhaar and digital India is a digital panopticon.

Further, it is also obvious that surveillance and censorship under digital India and Aadhaar regimes are omnipresent. The blog title Internet, Mobile And Social Media Censorship In India By Twitter, Facebook, Google, Etc has been cataloging the censorship and surveillance activities of Indian government and technology companies like Google, Microsoft, Facebook, Twitter, etc for long. A dedicated page titled censorship and surveillance under digital India has also been opened to report about surveillance and censorship activities of Indian government. Censorship and surveillance under Aadhaar project has also been covered by us.

Anyone who is active on social media websites like Twitter, Facebook, etc is well aware that critical tweets and sharing are oftenly censored in India. Twitter is on the forefront of this exercise where Aadhaar and digital India related critical tweets are censored in real time.

As far as e-surveillance is concerned, Indian government is infamous for its blatant e-surveillance with no regard to the constitutional norms. Aadhaar is the final nail in the coffin of civil liberties that are openly violated by Indian government. Civil liberties protection in cyberspace is absent in India. There is no e-surveillance policy of India (pdf) that can govern the illegal and unconstitutional e-surveillance and phone tapping activities of Indian government and its agencies.

Worst part of this situation is that parliamentary oversight of intelligence agencies of India is still missing till date. To give overreaching and illegal e-surveillance and phone tapping powers in the hands of such intelligence agencies is a death knell of civil liberties. India “must reconcile” the civil liberties and national security requirements but the same is presently missing. Clearly India has become a police state with unaccountable Orwellian powers.

Tuesday, December 8, 2015

Proposed National Telecom Security Policy Of India 2014 Must Be Balanced And Constitutional

The Telecom Security Policy of India 2014 was originally discussed by the Congress led Government. However, the Congress Government faced a defeat in the elections and now it is for the Narendra Modi led BJP Government to come out with a Telecom Security Policy for India. The Telecom Security Policy declared by Congress was defective on numerous counts and now we have to see what BJP led Government would do in this regard.

If we consider the media reports, the Central Government has proposed a new Telecom Security Policy of India. It has made few changes to the Policy declared by Congress Government. The National Telecom Security Policy is unlikely to include measures on standards that would protect public health and safety. The Government authorities have deleted the portion that emphasised rules regarding “public health and safety” in the revised draft of the Telecom Security Policy. The issue of radiations from mobile towers in India is a controversial one and the proposed Policy seems to be ignoring that aspect.

The proposed Policy has made it sure that Law Enforcement Agencies of India would be allowed to request interceptions and e-surveillance activities. Of course, in order to exercise this power, there is a dire need to modernise the Police force of India. Similarly, a lawful and constitutional interception law in India is also needed to make such requests immune from legal attacks. With the proposal to allow satellite based mobile services in India, a “Techno Legal Framework” must be formulated by the Government as soon as possible. Such a Legal Framework must be “Constitutionally Sound” and not just a collection of “Legal Jargon” as was done during the Congress Government time.

Recently Vodafone declared that Indian Government has been using Secret Wires to indulge in e-surveillance. This approach of Indian Government is definitely violation of Fundamental Rights of Indian Citizens. Realising the gravity of the situation, the Department of Telecommunication (DOT) has been ordered to investigate the issue. However, the stand of Narendra Modi Government regarding e-surveillance projects like Central Monitoring System (CMS) Project of India and Internet Spy System Network and Traffic Analysis System (NETRA) of India is still not clear. This would create troubles for the Government as well as for the Telecom Security Policy in the near future.

For instance, the draft Telecom Security Policy prescribes that cellular operator will mandatorily have to allow Law Enforcing Agencies to intercept calls, messages, and any other communications and the access to monitor it in real time, while keeping the communications secured. However, there is no Constitutional Lawful Interception Law in India as on date and this requirement would be a violation of Fundamental Rights of Indian Citizens.

The revised draft Policy also states that telecom service providers should endure that user data is not revealed or duplicated or copied or shared with recipients other than those designated by the sender, and should ensure that user data is not being routed outside the infrastructure within India when the end points of communication are inside Indian territory. This requirement would strengthen the Privacy Rights in India of the Indian Citizens. Privacy Rights in India in the Information Era require a totally different strategy and this provision would strengthen the same. This provision is also required to comply with the provisions of the Public Records Act, 1993.

Telcos will also be required to ensure authentication of end user, authorised access to services and attribution of activities and payloads to end users. However, this is not an easy task especially when Authorship Attribution in Transborder Cyber Crimes cases is very difficult to maintain. India is not very good at use of Cyber Forensics Practices. There is an urgent need to develop Cyber Forensics Investigation Solutions in India that are missing as on date. Indian law Enforcement Agencies must also understand that an IP Address should not be the Sole Criteria for Arrest and Conviction in India. The Cyber Forensics Trends and Developments in India (PDF) do not support the type of responsibilities attributed to Law Enforcement Agencies by the propose Telecom Security Policy. Even Regulations and Guidelines for Effective Investigation of Cyber Crimes in India are missing.

The proposed policy also directs that the attribution in the form audit, forensic and tracking mechanisms should ensure tracking of inappropriate use, criminal activities and enforcement of IT and cyber security laws of the Government. Earlier, the Government had differences with Blackberry over the encrypted message and email services the firm provides to customers. Fearing that such encrypted services can be used to plan and execute terrorist strikes, India had also threatened to ban the providers of such services if they failed to accommodate the legitimate demands of Law Enforcement Agencies.

It has been claimed that Silent Circle can provide safe, secure and encrypted electronic and wireless communications to its clients and Law Enforcement agencies may find it difficult to crack its encryption. However, we cannot effectively tackle encryption related issues till we have Encryption Policy of India (PDF) in place that must be based upon a dedicated Encryption Law of India. We also need dedicated Cyber Security Laws in India to manage cyber security relate issues. The Cyber Security Trends in India (PDF) have proved that India has a Poor Cyber Security Infrastructure. Intelligence Agencies Reforms in India must also be undertaken as soon as possible.

The proposed Telecom Security Policy of India must address all these issues in order to be “Balanced and Constitutional”. However, from media reports it is not clear whether the proposed Policy covers all these issues or not.

Illegal International Racket Using Unauthorised Gateways To Divert The VOIP Calls Landing In India Busted

Telecom related issues faced many challenges in the past. However, the regulatory environment for telecom sector of India is fast changing now.  Telecom security policy of India is also in pipeline that may streamline many telecom related issues in India.  The Telecom Commission has also approved satellite based mobile services in India. Satellite phones may also be allowed to be used by adventure tourists where no telecommunication connectivity is available in India.

Few areas in the field of telecom sector are still problematic in nature. For instance, Voice over Internet Protocol (VOIP) has always been a problematic aspect in India. Intelligence agencies of India have been insisting that Internet Telephony and VOIP service providers must establish servers in India. Further, Intelligence Bureau (IB) of India is also expediting the testing of VOIP interception system in India.

Meanwhile, crackdowns on illegal VOIP activities continue in India. In one such latest crackdown, the cyber crime wing of Cyberabad police arrested six persons on the charge of running an illegal international racket by setting up unauthorised gateways to divert the VOIP calls landing in India. The accused were using illegal VOIP gateways and diverted the international calls originating from cheap network providers in Pakistan, Middle East, US and UK.

According to the Police, those who receive such calls will have to pay lesser charges as against what the actual provider charges and will also not come under the government scanner.

The international VOIP grey traffic is purchased as per the daily prevailing rates from international carriers. The modus operandi used by illegal grey operators includes arranging international traffic from various VoIP operators across the globe and terminating it on their own illegal VoIP gateways using broadband connections. This traffic is then distributed to the domestic destination numbers using GSM SIMs, CDMA RUIMs and Public Switched Telephone Network (PSTN) connections.