The Supreme Court of India has directed the Centre to respond to a petition calling for a Central Bureau of Investigation (CBI) inquiry into a substantial data breach involving the medical records of approximately 1.5 lakh Indian citizens. The plea was submitted by Vitraya Technologies Private Limited, which claimed that the data breach affected six states and involved the unauthorized transfer of sensitive information to a server in Singapore.
The case was presented before a bench comprising Chief Justice of India (CJI) Surya Kant, and Justices Joymalya Bagchi and V Mohana. During the proceedings, Senior Advocate K Parameshwar, representing the petitioner, emphasized the gravity of the situation to the court. Parameshwar explained, “My Lords, these breaches are across six States. I have been informing the authorities from day one. I filed my complaint in March 2025. It took them till August 2025 even to register an FIR.”
Parameshwar further stated that although details of the Singapore server were provided, the FIR eventually registered on August 29, 2025, identified unknown individuals as suspects and only invoked Section 66 of the Information Technology Act. “That is not effective at all,” Parameshwar remarked, expressing his lack of confidence in the current investigation and justifying the need for a CBI probe.
Justice Joymalya Bagchi noted during the hearing that the Solicitor General had been separately requested to review the Information Technology Act and consider potential amendments. Vitraya Technologies, a health-tech firm utilizing blockchain for real-time health insurance claim settlements, counts Niva Bupa, Aditya Birla Health Insurance, and Star Health among its partners.
The petition filed by Vitraya reveals that their IT security team traced the cyberattack to IP addresses associated with Remedinet Technologies, IHX Private Limited, Medi Assist, and their investor Bessemer Venture Partners. These entities are identified as competitors in the health insurance claims processing sector. The petition further alleges that the servers experienced over 42,000 unauthorized login attempts over a 22-hour period in February 2025, with data subsequently routed through Singaporean servers, contrary to the Insurance Regulatory and Development Authority of India (IRDAI) requirements for local data storage.
The petition also highlights delays and inadequacies in the investigation process, noting that despite repeated representations from March to July 2025, the FIR was only filed after nearly six months. The offences cited remain bailable with no arrests made, indicating a lack of substantial investigative progress.
Filed under Article 32 of the Constitution, the petition seeks a directive for the CBI to assume control over the investigation, currently managed by the Punjab State Cyber Crime Police Station. Alternatively, it suggests forming a Special Investigation Team involving the CBI, CERT-In, and other cybersecurity bodies. The petitioner also requests the preservation of electronic evidence linked to the breach.
