DPDP compliance for hospitals and diagnostic chains
Hospitals, labs and health-tech platforms are Data Fiduciaries handling some of the most sensitive data in the economy. Here is what the DPDP Act expects of them.
Why healthcare is squarely in scope
Few sectors process personal data as intimate or as voluminous as healthcare. A multi-location hospital group or diagnostic chain holds identity documents, contact details, clinical histories, lab results, imaging, insurance information, and payment data for hundreds of thousands of patients. Under the DPDP Act, every one of those entities — hospitals, clinics, doctors, diagnostic labs, pharmacies, and health-tech platforms — is a Data Fiduciary, formally responsible for processing that data lawfully and securely. There is no exemption for being a care provider; if anything, the sensitivity of the data raises the stakes.
Consent and notice the right way
Consent in a clinical setting has to be explicit, informed, and tied to a specific purpose. A blanket "we may use your data" line buried in an admission form does not meet the standard. Patients should receive a standalone, plain-language notice that states what data is collected, for what purpose, and how it will be used, with consent captured and recorded. Where you share data with insurers, labs, or third-party processors, that sharing needs its own basis and transparency. Designing consent into registration and digitisation workflows — rather than bolting it on later — is what keeps the front desk compliant without slowing care.
Security safeguards are non-negotiable
The Rules require reasonable security safeguards, and for healthcare that translates into concrete controls: encryption of personal and health data at rest and in transit, multi-factor authentication, role-based access so staff see only what their role requires, and audit logging retained for at least a year so access can be reviewed. Periodic vulnerability assessments and a tested incident-response capability round out the baseline. Given the frequency of attacks on hospital systems, these controls are also simply good clinical-risk management.
Patient rights and data retention
Patients, as data principals, can ask to access and correct their data and, in defined circumstances, have it erased — so your systems and front-line teams need a workable process to receive and fulfil those requests. Retention requires a careful balance: the DPDP principle is to keep data only as long as necessary for the stated purpose, but medical-record regulations require retention for several years post-treatment. The answer is a documented, purpose-based retention schedule that reconciles both, with secure deletion or anonymisation when the retention period genuinely ends.
Sensitive categories and children
Some health data carries heightened risk and deserves stricter handling — mental-health records, HIV and other stigmatised conditions, and genetic data should be access-limited to treating clinicians, separately consented where appropriate, and never shared with insurers without explicit permission. Paediatric care brings the children's-data regime into play, with its verifiable-parental-consent expectations; the Rules recognise real clinical situations where care cannot wait on administrative consent cycles, but those allowances are bounded, not blanket.
Breach notification under the clock
If patient data is breached, the Act requires notification to the Data Protection Board and to affected patients, and the timeline is tight — a detailed report within 72 hours of becoming aware, with the clock running continuously through weekends and holidays. For a hospital group, that means an incident-response plan that can detect, assess, and report a breach fast, with templates and responsibilities defined in advance rather than improvised mid-crisis.
A sensible starting sequence
Most healthcare organisations should begin with a data inventory across registration, EMR, lab, pharmacy, billing, and any patient apps, then run a gap analysis against the DPDP requirements, prioritising consent, security safeguards, retention, and breach readiness. For larger networks that may face Significant Data Fiduciary designation, a Data Protection Impact Assessment for high-risk processing should be on the near-term plan.
Frequently asked questions
Are hospitals and diagnostic labs covered by the DPDP Act?
Yes. Hospitals, clinics, diagnostic chains, pharmacies, and health-tech platforms are Data Fiduciaries under the DPDP Act 2023 and the DPDP Rules 2025. They are directly responsible for processing patient personal data lawfully and securely, honouring patient rights, and reporting breaches. There is no exemption for healthcare providers.
How long can a hospital keep patient data under DPDP?
Only as long as necessary for the stated purpose — but this must be reconciled with medical-record retention rules, which typically require several years of retention post-treatment. The practical approach is a documented, purpose-based retention schedule that satisfies both regimes, followed by secure deletion or anonymisation once the retention period ends.
What is the breach-notification deadline for healthcare organisations?
The DPDP Act requires Data Fiduciaries to notify the Data Protection Board and affected individuals of a personal-data breach, with a detailed report expected within 72 hours of becoming aware. The window runs continuously, including weekends and holidays, so hospitals need a pre-built incident-response plan with defined roles and templates.
Start your hospital's DPDP readiness
Niti Bharat helps hospital groups and diagnostic chains inventory patient data, close DPDP gaps, and build breach-ready processes. Begin with our free healthcare DPDP guide.
DPDP for Healthcare (Free Guide)