DPDP compliance for healthcare organisations — hospitals and diagnostic labs
Healthcare organisations process the most sensitive personal data that exists. Here is what DPDP requires of hospitals, clinics, and diagnostic labs.
What health data is covered by DPDP?
All personal data about an individual's health is covered: medical history and diagnoses; prescriptions and medications; lab results and diagnostic reports; imaging (X-rays, MRIs, CT scans); surgical records; mental health history; genetic data; health insurance information and claims; emergency contact and next-of-kin data; biometric health data (from wearables or hospital monitoring); and any data collected through digital health apps or telemedicine platforms. This data is among the most sensitive categories precisely because its misuse — in insurance underwriting, employment decisions, social situations — causes direct, serious harm.
What is the lawful basis for healthcare data processing?
Emergency care — treating an unconscious patient — can rely on the vital interests basis (protecting life). Routine treatment — collecting patient data to provide booked services — relies on the contract or implied consent. Statutory obligations — PCPNDT records, blood bank records, mandatory disease reporting — rely on the legal obligation basis. Non-essential uses — sharing patient data with pharma companies, using patient data for marketing the hospital's services, sharing with health app partners — require explicit, specific consent. Consent for research uses of patient data — clinical trials, retrospective studies — requires careful ethical and legal review.
What must a hospital patient privacy notice include?
A hospital patient privacy notice must cover: all categories of data collected at registration and during care; the purposes — diagnosis, treatment, insurance billing, statutory reporting; third parties with whom data is shared — referring doctors, labs, insurance companies, government health databases; retention periods — medical records are typically retained for 7–10 years minimum; data principal rights; and grievance officer contact. The notice must be provided at admission in the patient's language. For digital health platforms, the notice must be part of the app onboarding.
What DPAs must healthcare organisations execute?
Healthcare DPAs required: diagnostic labs receiving patient samples and returning results (Data Processor); PACS/RIS imaging vendors (cloud imaging platforms storing patient scans); EHR/HIS system vendors; telemedicine platform vendors; insurance TPAs processing health claims; digital health app vendors integrated with the hospital; pharmacy system vendors; and any research institution accessing patient data for studies. The DPA must address the extreme sensitivity of health data — encryption, access controls, no secondary use, and immediate breach notification.
How must patient data be secured under DPDP?
Minimum security for healthcare patient data: role-based access controls (only treating clinicians see diagnosis; billing team sees billing data); encryption of all patient records at rest and in transit; audit logs of all access to patient records; multi-factor authentication for all clinical system access; physical access controls for server rooms; data minimisation — diagnostic labs should receive only what is necessary for the test, not the full patient record; and a formal security assessment (VAPT) of all clinical systems at least annually. Cloud EHR vendors must provide SOC 2 or ISO 27001 certification.
How do health data breaches cause harm to patients?
A health data breach can cause: insurance discrimination — insurers may use leaked health data to deny coverage or increase premiums; employment discrimination — employers may use leaked mental health or chronic illness data to make adverse employment decisions; social stigma — leaked mental health, HIV, or reproductive health data can cause serious reputational harm; identity theft — patient identity data (Aadhaar, PAN) combined with health data enables sophisticated fraud; and emotional distress — patients have a reasonable expectation that their health information is private. These harms justify treating health data breaches as among the most serious DPDP violations.
Frequently asked questions
Can a hospital share patient data with pharmaceutical companies for research?
Sharing identifiable patient data with pharma companies for research requires explicit patient consent specific to the research purpose — it is a new processing purpose not covered by the treatment relationship. Sharing anonymised and aggregated data (which cannot identify individuals) is outside DPDP scope and can be done without consent, subject to appropriate de-identification. If the pharma company wants longitudinal patient data (following patients over time), re-identification risk is higher and the anonymisation must be more rigorous.
Does a small clinic or solo doctor need to comply with DPDP?
Yes — all healthcare providers processing patient personal data are Data Fiduciaries, regardless of size. A solo general practitioner maintaining patient health records is a Fiduciary. However, the compliance programme can be proportionately lighter: a clear patient privacy notice (one page, in regional language); a secure records system (encrypted EMR or locked physical records); a basic DPA with any lab that processes samples; and a simple breach response procedure. The fundamentals apply regardless of scale — the complexity scales with the volume and risk of processing.
Can patients request their complete medical records under DPDP?
Yes. The right of access under DPDP gives patients the right to obtain a summary of their personal data being processed — which includes their medical records held by the hospital. This is supplementary to existing statutory rights: the Clinical Establishments Act provides patients the right to receive a copy of their medical records. DPDP reinforces this right and provides an enforcement mechanism through the Data Protection Board. Hospitals must have a mechanism for patients to request their records and a defined response process.
Build your hospital DPDP compliance programme
Niti Bharat's Hospital DPDP Compliance Pack covers patient privacy notice, DPA templates for labs and EHR vendors, security standards checklist, and a breach response plan for healthcare organisations.
Get the Hospital DPDP Pack