Supreme Court seeks Centre's response on plea for CBI probe into breach of 1.5 lakh medical records

Vitraya Technologies moved the Court alleging that the cyber attack was traced to competitors, with data allegedly routed to a Singapore server.
Supreme Court of India
Supreme Court of India
Published on
3 min read

The Supreme Court on Thursday issued notice on a plea filed by Vitraya Technologies Private Limited alleging a large-scale breach of medical data belonging to nearly 1.5 lakh Indian citizens.

A Bench of Chief Justice of India (CJI) Surya Kant and Justices Joymalya Bagchi and V Mohana heard the matter.

Justice Joymalya Bagchi, CJI Surya Kant and Justice V Mohana
Justice Joymalya Bagchi, CJI Surya Kant and Justice V Mohana

Appearing for the petitioner, Senior Advocate K Parameshwar told the Court that the breaches spanned 6 states and that medical records of nearly 1.5 lakh Indian citizens had been compromised and transferred to a server in Singapore.

"My Lords, these breaches are across six States. I have been informing the authorities from day one. I filed my complaint in March 2025. It took them till August 2025 even to register an FIR," Parameshwar submitted.

He told the Bench that he had furnished details of the Singapore server to which the medical records had allegedly gone, but that the FIR, eventually registered on August 29, 2025, was against unknown persons and invoked only Section 66 of the Information Technology Act.

"That is not effective at all," Parameshwar said, adding that this was why he did not trust the investigation and had approached the Supreme Court seeking a Central Bureau of Investigation (CBI) inquiry.

During the hearing, Justice Bagchi observed that the Solicitor General had separately been asked to take a relook at the Information Technology Act and consider amendments to it.

K Parameshwar
K Parameshwar

The petitioner, Vitraya, is a health-tech company that operates a blockchain-based platform for real-time settlement of health insurance claims, working with insurers including Niva Bupa, Aditya Birla Health Insurance and Star Health.

According to the petition, Vitraya's IT security team had traced the cyberattack to IP addresses linked to Remedinet Technologies, IHX Private Limited, Medi Assist and their common investor Bessemer Venture Partners, all of whom the petitioner claims are competitors in the health insurance claims processing space.

The petition states that the servers were subjected to over 42,000 unauthorised login attempts within 22 hours in February 2025 and that data was later routed through Singapore-based servers in alleged violation of IRDAI norms requiring insurance data of Indian citizens to remain within Indian servers.

The petition also states that despite repeated representations between March and July 2025, the FIR was registered only after a delay of nearly 6 months and that no meaningful investigation has taken place since, with the offences invoked being bailable and no arrests made so far.

The petition, filed under Article 32 of the Constitution, seeks a direction to the CBI to take over the investigation from the Punjab State Cyber Crime Police Station, or in the alternative, constitution of a Special Investigation Team comprising the CBI, CERT-In and other cyber security agencies. The petitioner has also sought preservation of electronic evidence connected to the alleged breach.

[Live coverage of the hearing]

Bar and Bench - Indian Legal news
www.barandbench.com