Industry · Hospitals
DPDPA Compliance for Hospitals in India
Hospitals run the largest personal-data operations in Indian healthcare: OPD registrations, IPD case sheets, EHRs, radiology archives, TPA claim files, pharmacy and billing systems, ABHA links. Under the DPDP Act 2023 you are the Data Fiduciary for every record. Emergency care has a legitimate use; almost nothing else does. The compliance date is 13 May 2027, with NMC and Clinical Establishments retention duties running alongside.
Last reviewed: 30 July 2026
What DPDPA compliance risks do hospitals face?
The biggest gap in most hospitals is internal, not external: role-based access that doesn't really exist, so a ward clerk, an unrelated department's nurse or a resident who left last year can still open any chart. Around that sit the outward flows — full case sheets emailed to TPAs when the claim needs a fraction of them, radiology and lab vendors processing on no written contract, discharge summaries parked in shared drives, and health-package SMS blasts to years-old patient lists.
What should hospitals prepare first for DPDPA compliance?
- Itemise Section 6 consent beyond emergencies — OPD, elective care, teleconsults, marketing, research are separate asks.
- Enforce role-based HIS/EHR access, kill shared logins, and deprovision residents and leavers immediately.
- Minimise TPA disclosures to claim-necessary documents, not the full case sheet.
- Put written processor contracts on HIS, imaging, labs, transcription, cloud, and billing.
- Rehearse dual-clock breach response: CERT-In 6 hours + patient intimation without delay + DPB within 72 hours.
Frequently asked questions
We provide medical treatment. Doesn't a legitimate use cover us instead of consent?
Only in narrow situations. The Section 7 legitimate uses are a closed list, and the health-related ones cover a medical emergency involving a threat to life or an immediate threat to health where the patient cannot consent, treatment during an epidemic or other public-health threat, and assistance during a disaster or breakdown of public order. Everything else — OPD registration, elective admissions, preventive health checks, teleconsults, follow-up calls, marketing, and secondary research use of identifiable records — runs on Section 6 consent: itemised by purpose, in plain language, in English or any Eighth Schedule language, and as easy to withdraw as to give. Two clarifications that catch hospitals out. DPDPA has no separate "sensitive personal data" tier, so an HIV status, a psychiatric note and a phone number sit under one legal standard — the difference is the harm, not the rule. For patients under 18, Section 9 is the default — but Rule 12 read with the Fourth Schedule (Part A) disapplies Section 9(1) and 9(3) for a clinical establishment, mental health establishment or healthcare professional where processing is restricted to providing health services to the child to the extent necessary to protect her health (and separately for allied healthcare professionals implementing a treatment or referral plan). Marketing, research reuse and tracking outside that clinical purpose still need the full Section 9 treatment.
Who inside the hospital is allowed to see a patient's record — and does this apply to our own staff data too?
Purpose limitation applies internally, not just externally. If a login can open charts unrelated to that person's role, you are processing beyond the purpose the patient consented to, and the security safeguards duty under Section 8(5) expects access control as a safeguard. The practical fixes are unglamorous: role-based access by department and episode, immediate deprovisioning when residents rotate out or staff resign, audit logs that record who viewed which record, and an end to shared "reception" or "nursing station" logins. On staff data — HR files, payroll, biometric attendance, occupational health records — you have a distinct advantage: the employment legitimate use under Section 7(i) covers processing for purposes of employment, including safeguarding the employer from loss or liability, so you do not need consent for the core employment relationship. It does not stretch to using employee health records for anything unrelated.
We share records with insurance TPAs, reference labs, imaging centres and our HIS vendor. Who carries the liability?
The hospital does, as Data Fiduciary, and it cannot be contracted away. Your HIS and EHR provider, cloud host, billing gateway, transcription service and courier are Data Processors — they may process patient data only under a valid written contract specifying purpose, security obligations, sub-processing limits and deletion on exit. Insurers and TPAs are different: they usually process for their own purposes, which makes them fiduciaries in their own right with their own lawful ground, and the disclosure to them needs the patient's itemised consent. The common failure here isn't the consent, it's the volume — sending a complete case sheet when the claim requires a specific set of documents is a purpose-limitation problem. Similarly, ABDM and ABHA consent artefacts govern health-record exchange through that framework; they are not a substitute for your own DPDPA notice and consent record. And empanelled consultants and visiting doctors are also Data Principals — their registration details, referral volumes and payout data are personal data you process, with access and correction rights attached.
If our HIS is breached or ransomwared, what do we report — and do we need annual audits and a DPO?
Two clocks start at detection and both must be met; they are cumulative, not alternatives. CERT-In requires reporting of covered cyber incidents within 6 hours. Separately under DPDPA, you must intimate every affected patient without delay (Rule 7(1)), give the Board an initial description without delay (Rule 7(2)(a)), and file detailed particulars within 72 hours (Rule 7(2)(b)). Failure to maintain reasonable security safeguards attracts up to ₹250 crore, and failure to notify is assessed separately at up to ₹200 crore — one incident can expose you under both heads. Note also that ransomware with no confirmed exfiltration is still a personal data breach if it caused loss of access to the data; "nothing was stolen" is not an exemption from notification. On audits: the heavier Rule 13 obligations — annual DPIA, independent data audit, algorithmic due diligence and an India-based Data Protection Officer — bind Significant Data Fiduciaries only, and SDF status is conferred by Central Government notification, not triggered automatically by bed count or patient volume. Every hospital still owes the baseline duties regardless: valid consent, purpose limitation, erasure once the clinical and statutory retention period ends (subject to Rule 6(e)'s one-year floor for access logs and related personal data used as a security safeguard), security safeguards, breach notification, and a published grievance channel with a named contact.
We'll trace one patient episode through your hospital
A 30-minute call: registration to discharge to claim settlement. We look at what your front desk collects and on what notice, who inside your HIS can see which records, what leaves your building for TPAs, reference labs and imaging vendors, what your processor contracts actually say, and how long records sit after the clinical and statutory purpose ends. You leave with a written gap list mapped to Section 6, the security safeguards duty and your NABH obligations — whether or not you work with us.
Book a demo call
Free Gap Analysis
Bring your registration consent form and your HIS user-access list. No deck.
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.