Checklist · Hospital Administrator

DPDPA Checklist for Hospital Administrators

Every private hospital and nursing home in India processes patient data as a Data Fiduciary. DPDPA 2023 has no separate “sensitive data” tier — health records sit under the same rules as billing data, with the same duties. This checklist translates the Act into ward-level, HIS-level and vendor-level actions before 13 May 2027.

Last reviewed: 19 August 2026

What must a hospital administrator do for DPDPA compliance?

  1. Put the Section 5 notice at the registration counter, not page 9 of the admission booklet. Issue a standalone, plain-language notice (English + local language) at OPD registration, IPD admission and lab sample collection. It must itemise the personal data collected, each purpose, how the patient exercises rights, and how to complain to the Data Protection Board. A signature on a 12-page consent-cum-undertaking booklet is not a Section 5 notice.
  2. Split your consent form into four separate, independently refusable purposes. One tick box cannot cover everything. Separate: (a) treatment, diagnosis and in-hospital care; (b) sending reports and discharge summaries over WhatsApp/SMS; (c) sharing claim documents with TPAs and insurers; (d) clinical photography, case presentations and teaching use. Section 6(1) consent must be free, specific, informed and unambiguous — bundling (b), (c) and (d) into (a) makes all four contestable. A patient must be able to refuse WhatsApp reports and still get admitted.
  3. Use Section 7 legitimate uses only where they genuinely apply — there is no general health-data carve-out. Legitimate uses that actually fit a hospital: 7(f) medical emergency involving a threat to life or immediate threat to health (unconscious trauma, MLC, casualty); 7(g) measures during an epidemic, outbreak or other public-health threat; 7(d) disclosing information to the State where a law requires it (notifiable disease reporting, PCPNDT filings); 7(e) compliance with a court judgment, decree or order; 7(i) employment purposes for staff and resident data. Clinical Establishments record-keeping is a retention duty under Section 8(7), not a Section 7 ground. Elective admissions, marketing, health-check camp follow-ups, TPA sharing and teaching photos are not legitimate uses — they need consent.
  4. Get Section 8(2) contracts signed with every vendor that touches patient data. Cover, at minimum: HIS/EMR vendor, LIS, PACS/cloud radiology, pharmacy software, billing and RCM vendor, TPA/claims intermediary, teleradiology reporters, SMS/WhatsApp gateway, backup and DR provider, biomedical vendors with remote diagnostics access. Each contract needs purpose limitation, no onward sub-processing without approval, breach notification to you within a fixed window (24 hours or less, so your own clocks survive), deletion/return on exit, and audit rights.
  5. Map referring labs and collection centres — you stay the Data Fiduciary for purposes you determine. If your hospital decides why the data is processed (outsourced histopathology, referred-out molecular tests, franchise collection centres running under your brand), you remain the fiduciary and the outside lab is your processor. If they determine their own purpose, you are sharing with an independent fiduciary and need consent plus a documented basis. Write down which arrangement each referral is.
  6. Write a four-lane breach SOP with names against each lane. The four lanes run cumulatively, not alternatively. CERT-In: 6 hours from noticing a reportable cyber incident (ransomware on HIS, PACS exposure, EMR data exfiltration) — owner: IT Head, backup: CISO/IT Manager. Rule 7(1): intimate affected patients without delay. Rule 7(2)(a): initial intimation to the Data Protection Board without delay. Rule 7(2)(b): detailed report to the Board within 72 hours — owner: Medical Superintendent, backup: designated data-protection contact (Section 8(9)). Include a WhatsApp misdirection scenario: a report sent to a wrong number is a personal data breach, not an IT ticket. Rehearse it once per quarter with the on-call roster.
  7. Treat paediatric marketing and non-clinical child data as Section 9 — do not over-apply it to the ward. A child is anyone under 18. For a clinical establishment, Rule 12 read with Fourth Schedule Part A disapplies Section 9(1) and 9(3) where processing is restricted to providing health services to the child to the extent necessary to protect her health. That covers the paediatric ward, NICU and clinically indicated school-camp testing. Full Section 9 still applies outside that clinical purpose: paediatric marketing lists, vaccination-reminder campaigns sold to third parties, research reuse of identifiable child data, and any tracking or targeted advertising directed at children. Capture verifiable parental or lawful-guardian identity in the registration workflow for those non-clinical uses, not at the discharge desk.
  8. Reconcile retention with Section 8(7) — other laws win, but only for what they cover. Clinical Establishments (Registration and Regulation) Act rules, State medical council rules, MTP and PCPNDT records, drug and blood-bank registers, and NABH accreditation requirements all stack on top of DPDPA — DPDPA does not replace them. Section 8(7) erasure does not apply where retention is required by law. But it does apply to everything outside those mandates: marketing databases, feedback-app data, old camp lead lists, ex-employee HR data, CCTV beyond your stated retention. Publish a retention schedule that names the statute for each category and a delete date for everything else.
  9. Publish the Section 8(9) contact and build the Section 8(10) grievance route into the hospital's existing complaint system. Put the DPO or designated contact's name, email and phone on the website footer, the OPD registration card, the discharge summary template and the reception notice board. Rule 14(1) requires publishing how a patient makes an access, correction or erasure request and any identifier you need. Rule 14(3) requires the grievance system to respond within a period not exceeding ninety days — that 90-day figure is the grievance ceiling, not the SLA for every rights request. A 7-working-day internal turnaround is a defensible operational target. Log every request — access, correction, erasure, consent withdrawal, nomination — with a timestamp. Patients can only approach the Board after exhausting your route.
  10. Do not commission a Rule 13 audit unless you are notified as a Significant Data Fiduciary. The DPIA, annual independent audit and algorithmic-due-diligence duties apply only to entities the Central Government notifies as SDFs. Most single-city hospitals and nursing homes will not be notified. What applies to everyone regardless: Section 8(5) reasonable security safeguards — role-based HIS access, no shared “doctor01” logins, encrypted backups, MFA on remote PACS, audit trails on record access, and de-provisioning within 24 hours of a resident or nurse leaving. Failure to take reasonable security safeguards carries a penalty of up to ₹250 crore.

Frequently asked questions

Can we keep sending lab reports and discharge summaries to patients on WhatsApp?

Yes, but it needs its own consent, separate from treatment consent, and the patient must be able to decline without affecting care. Your notice should state that reports will travel over a third-party messaging platform. Operationally, the risk is misdirection: a report sent to a wrong number is a reportable personal data breach that starts four lanes — CERT-In within 6 hours, Rule 7(1) patient intimation without delay, Rule 7(2)(a) Board initial intimation without delay, and Rule 7(2)(b) the detailed Board report within 72 hours. Verify the number at registration, re-verify at discharge, and log every send.

Does DPDPA override our Clinical Establishments Act and NABH medical record retention rules?

No. They stack. DPDPA's Section 8(7) erasure duty carves out data retained to comply with other law, so statutory medical-record retention continues unchanged. What DPDPA adds is a duty to erase everything outside those mandates once the purpose is served or consent is withdrawn — marketing lists, feedback data, camp registrations, expired vendor datasets. Treat your existing NABH record policy as the floor and add a DPDPA retention schedule on top of it.

Is our hospital a Significant Data Fiduciary, and do we need an annual audit?

Only if the Central Government notifies you as one, based on volume and sensitivity of data, risk to Data Principal rights, and impact on public order and state security. Until that notification arrives, Rule 13 audits, DPIAs and algorithmic due diligence do not apply to you. Every other duty does — notice, consent, processor contracts, breach reporting, grievance redressal and security safeguards — with the substantive compliance deadline of 13 May 2027 applying to all Data Fiduciaries regardless of size.

Official sources

We'll map HIS, LIS, TPA and WhatsApp against these ten items

Book a 30-minute discovery call to map your HIS, LIS, TPA and WhatsApp flows against these ten items. You leave with a written gap list mapped to Section 6, processor contracts and your NABH obligations — whether or not you work with us.

Book a 30-minute discovery call Free Gap Analysis

Bring your registration consent form and your HIS user-access list. No deck.

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.