DPDP compliance for hospitals and diagnostic chains

DPDP compliance for hospitals and diagnostic chains
Healthcare

DPDP compliance for hospitals and diagnostic chains

Hospitals, labs and health-tech platforms are Data Fiduciaries handling some of the most sensitive data in the economy. Here is what the DPDP Act expects of them.

Quick Answer: Hospitals, clinics, diagnostic chains, and health-tech platforms are Data Fiduciaries under the DPDP Act 2023 and the DPDP Rules 2025, directly responsible for the patient data they hold. They must obtain clear, purpose-specific consent through itemised notices, implement reasonable security safeguards such as encryption, access controls, and at least one year of audit logging, honour patient rights to access and correct data, and notify the Data Protection Board and affected patients of a breach within 72 hours. Health data must be retained only as long as necessary — bearing in mind medical-record retention rules — and especially sensitive categories like mental health, HIV status, and genetic data warrant extra protection. Substantive obligations are enforceable from 13 May 2027, and penalties for security failures run up to ₹250 crore.

Why healthcare is squarely in scope

Few sectors process personal data as intimate or as voluminous as healthcare. A multi-location hospital group or diagnostic chain holds identity documents, contact details, clinical histories, lab results, imaging, insurance information, and payment data for hundreds of thousands of patients. Under the DPDP Act, every one of those entities — hospitals, clinics, doctors, diagnostic labs, pharmacies, and health-tech platforms — is a Data Fiduciary, formally responsible for processing that data lawfully and securely. There is no exemption for being a care provider; if anything, the sensitivity of the data raises the stakes.

Consent and notice the right way

Consent in a clinical setting has to be explicit, informed, and tied to a specific purpose. A blanket "we may use your data" line buried in an admission form does not meet the standard. Patients should receive a standalone, plain-language notice that states what data is collected, for what purpose, and how it will be used, with consent captured and recorded. Where you share data with insurers, labs, or third-party processors, that sharing needs its own basis and transparency. Designing consent into registration and digitisation workflows — rather than bolting it on later — is what keeps the front desk compliant without slowing care.

Security safeguards are non-negotiable

The Rules require reasonable security safeguards, and for healthcare that translates into concrete controls: encryption of personal and health data at rest and in transit, multi-factor authentication, role-based access so staff see only what their role requires, and audit logging retained for at least a year so access can be reviewed. Periodic vulnerability assessments and a tested incident-response capability round out the baseline. Given the frequency of attacks on hospital systems, these controls are also simply good clinical-risk management.

Patient rights and data retention

Patients, as data principals, can ask to access and correct their data and, in defined circumstances, have it erased — so your systems and front-line teams need a workable process to receive and fulfil those requests. Retention requires a careful balance: the DPDP principle is to keep data only as long as necessary for the stated purpose, but medical-record regulations require retention for several years post-treatment. The answer is a documented, purpose-based retention schedule that reconciles both, with secure deletion or anonymisation when the retention period genuinely ends.

Sensitive categories and children

Some health data carries heightened risk and deserves stricter handling — mental-health records, HIV and other stigmatised conditions, and genetic data should be access-limited to treating clinicians, separately consented where appropriate, and never shared with insurers without explicit permission. Paediatric care brings the children's-data regime into play, with its verifiable-parental-consent expectations; the Rules recognise real clinical situations where care cannot wait on administrative consent cycles, but those allowances are bounded, not blanket.

Breach notification under the clock

If patient data is breached, the Act requires notification to the Data Protection Board and to affected patients, and the timeline is tight — a detailed report within 72 hours of becoming aware, with the clock running continuously through weekends and holidays. For a hospital group, that means an incident-response plan that can detect, assess, and report a breach fast, with templates and responsibilities defined in advance rather than improvised mid-crisis.

A sensible starting sequence

Most healthcare organisations should begin with a data inventory across registration, EMR, lab, pharmacy, billing, and any patient apps, then run a gap analysis against the DPDP requirements, prioritising consent, security safeguards, retention, and breach readiness. For larger networks that may face Significant Data Fiduciary designation, a Data Protection Impact Assessment for high-risk processing should be on the near-term plan.

Frequently asked questions

Are hospitals and diagnostic labs covered by the DPDP Act?

Yes. Hospitals, clinics, diagnostic chains, pharmacies, and health-tech platforms are Data Fiduciaries under the DPDP Act 2023 and the DPDP Rules 2025. They are directly responsible for processing patient personal data lawfully and securely, honouring patient rights, and reporting breaches. There is no exemption for healthcare providers.

How long can a hospital keep patient data under DPDP?

Only as long as necessary for the stated purpose — but this must be reconciled with medical-record retention rules, which typically require several years of retention post-treatment. The practical approach is a documented, purpose-based retention schedule that satisfies both regimes, followed by secure deletion or anonymisation once the retention period ends.

What is the breach-notification deadline for healthcare organisations?

The DPDP Act requires Data Fiduciaries to notify the Data Protection Board and affected individuals of a personal-data breach, with a detailed report expected within 72 hours of becoming aware. The window runs continuously, including weekends and holidays, so hospitals need a pre-built incident-response plan with defined roles and templates.

Start your hospital's DPDP readiness

Niti Bharat helps hospital groups and diagnostic chains inventory patient data, close DPDP gaps, and build breach-ready processes. Begin with our free healthcare DPDP guide.

DPDP for Healthcare (Free Guide)
Previous Post Next Post

Get Free DPDP Checklist