Security & Compliance

Role-Based Access in Clinic Software: Who Should See What (India, 2026)

Anexshe RevedhaยทCofounder & COO, CuraVertoยท3 August 2026ยท6 min read

In a clinic running on CuraVerto, a role decides which screens a staff member can open, branch scoping decides which location's records they can see, and the audit log records who opened or changed what, when, and from where. CuraVerto's roles, admin, doctor, staff, receptionist and lab, are scoped to a branch on every plan, including Essential. The audit log itself is a Plus-plan feature, included at โ‚น49,999 per year.

The four moments that make clinic owners search for this

A staff member leaves and the login outlives them.
Someone resigns and nobody switches off their account the same day. If every login opens every record, that account still reads patient files after the person who held it has gone.
A billing dispute has no owner.
A patient disputes a charge and three people could have entered it. Without a record of who touched the amount and when, the clinic can only guess at what happened.
A locum needs some access, not all of it.
A visiting consultant covers for two weeks and should see their own patients, not the full financial and staff-administration screens a permanent doctor uses.
A second branch opens, and access stops being obvious.
Front-desk staff at the new location should not browse the first branch's billing or patient list just because they share one login system. Role alone does not draw that line, location has to.

What a role actually needs to see, and what it should not

RoleWhat the job needsWhat it should not reach
AdminFull clinic settings, staff accounts, billing configuration, and every branch the account is scoped toNothing within the clinic's own scoped branches is hidden from admin, which is exactly why an admin login needs the most careful handling of any role
DoctorTheir own patients' clinical notes, prescriptions and appointment scheduleOther doctors' consultation notes and clinic-wide financial reports
Receptionist / front deskAppointment booking, patient contact details and billing at their own branchClinical notes, prescriptions and any other branch's records
StaffThe appointment queue and assigned tasks at their own branchFull consultation notes, prescriptions and billing configuration
LabTest orders and result entry at their own branchConsultation notes and billing

Branch adds a dimension that role alone cannot cover

Role answers what a person can open. Branch answers at which location. A receptionist at one branch has no business browsing another branch's billing, and a system with roles but no branch scoping cannot draw that line: access becomes all or nothing, and there is no way to say which location a change belongs to. CuraVerto scopes every role to a branch, so a front-desk login at branch A stays inside branch A's patients and billing, and opening a second branch does not mean rebuilding access from scratch.

What an audit log has to record to be worth anything

A log that only says something changed does not help in a dispute. To be useful, an audit trail has to answer six questions every time: who made the change, what they changed, when, what the value was before, what it became after, and at which branch it happened. That is the standard CuraVerto's audit log is built to meet.

CuraVerto's audit log is a Plus-plan feature, included at โ‚น49,999 per year. Essential and Pro do not lose access control by not having it, every plan gets role-scoped access to begin with. The audit log is the additional layer that keeps a history of who did what, and it sits on Plus.

Where the DPDP Act touches this, and where it does not

Two ideas from India's Digital Personal Data Protection Act 2023 map onto access control directly: purpose limitation, meaning staff should only see the data their role actually needs, and a record of who accessed what, which is what an audit log provides. Neither idea is unique to the Act, both describe what a working access-control system looks like in practice.

Software supports these practices, it does not confer compliance on its own. CuraVerto does not claim to make a clinic DPDP compliant on the strength of roles and an audit log alone, the Act's obligations, notice, consent and breach reporting among them, extend well beyond access control. Our DPDPA compliance guide for Indian clinics covers the full obligation list.

What CuraVerto includes, and on which plan

  • CuraVerto role-scoped access (admin, doctor, staff, receptionist, lab) on every plan, including Essential.
  • CuraVerto's branch scoping is tied to the multi-branch tiers: Pro includes 1 branch, Plus includes 3, and each additional branch is โ‚น9,999 per year on either tier.
  • CuraVerto's audit log, recording who, what, when, before, after and branch, on the Plus plan at โ‚น49,999 per year.
  • CuraVerto charges flat annual pricing with unlimited doctors on Pro and Plus, and no per-doctor fee at any headcount.
Pricing sources
Digital Personal Data Protection Act 2023 โ†’Full Act text, Ministry of Electronics and Information Technology
Related reading

See exactly which role does what before you switch

Roles are scoped to a branch on every CuraVerto plan, and the audit log is included on Plus at โ‚น49,999 per year with no per-doctor fee at any headcount.

View CuraVerto pricing โ†’Ask about roles and audit logsChat on WhatsApp

More from the blog

IVF & Fertility
IVF EMR vs General Clinic Software: 5 Critical Differences (2026)
IVF & Fertility
IVF Clinic Software Cost in India: โ‚น9,999โ€“โ‚น3,60,000/year Compared (2026)
IVF & Fertility
Best IVF EMR Software in India 2026: Buyer's Checklist for Fertility Clinics