DPDP compliance for healthcare organisations

DPDP compliance for healthcare organisations
Healthcare

DPDP compliance for healthcare organisations

Health data is the most sensitive category under the DPDP Act. Hospitals, diagnostics chains, and health tech companies face strict obligations around consent, data sharing, and breach response.

Quick Answer: Healthcare organisations — hospitals, diagnostic chains, health tech platforms, and insurers — process health data, which is among the most sensitive personal data under the DPDP Act. Processing health data requires a high standard of consent: specific, informed, and freely given before the processing begins. There are narrow exemptions for medical emergencies and public health purposes, but commercial health data analytics, sharing with pharma companies, or using health data for insurance profiling requires explicit consent. Breach of health data attracts penalties up to ₹200 crore. The enforcement deadline is May 2027.

Why does health data carry the highest protection under the DPDP Act?

Health data — diagnoses, prescriptions, test results, medical history, disability status, mental health records — is among the most sensitive personal data because its misuse can cause severe harm: discrimination in employment or insurance, social stigma, financial loss, or psychological distress. The DPDP Act treats health data as requiring the highest consent standard and security safeguards. Healthcare organisations that underestimate this risk face the most significant penalties if they get it wrong.

What consent is required to process patient health data under DPDP?

Processing health data requires explicit, specific consent tied to each purpose. A patient consenting to treatment does not automatically consent to: their data being shared with a pharma company for research; their diagnosis being used for insurance underwriting; their health records being analysed by an AI diagnostics tool for product development; or their contact details being used for marketing wellness products. Each of these is a separate purpose requiring separate consent. Audit your consent forms for scope creep.

When can healthcare organisations process patient data without consent under DPDP?

The Act provides narrow exemptions where processing health data without consent is permitted: genuine medical emergencies where obtaining consent is not feasible; statutory public health obligations under laws like the Epidemic Diseases Act; and processing by certain approved medical researchers. These exemptions are narrowly drawn. A hospital that processes patient data without consent and claims an emergency exemption must be able to justify that claim — it is not a blanket waiver for all non-consensual health data processing.

Can hospitals and clinics share patient data with insurers and third parties under DPDP?

Health data is frequently shared between providers, insurers, and government health schemes. Each sharing relationship must be covered by a Data Processing Agreement or, where the sharing entity determines its own use of the data, by explicit patient consent. Sharing a patient's medical records with a health insurer for underwriting requires consent. Sharing records with a government health scheme may have a statutory basis. Sharing de-identified records with a research institution requires either anonymisation (genuinely robust) or research exemption compliance.

How does DPDP apply to telemedicine apps and digital health platforms?

Digital health platforms — telemedicine apps, wearables that track health metrics, mental health apps, period and fertility trackers — generate large volumes of health data and must comply with DPDP. The combination of health data sensitivity and potential for data to be processed by international cloud vendors makes digital health one of the highest-risk sectors. Telemedicine platforms must ensure their cloud providers are contractually bound as Data Processors; wearable manufacturers must have India-resident data residency options; mental health apps must implement the highest consent standards.

How must healthcare organisations respond to a health data breach under DPDP?

Health data breaches are among the most harmful — they can expose diagnoses, mental health history, reproductive health data, or addiction treatment records. Healthcare organisations must have a tested breach response plan, rapid detection capability, and pre-prepared Board notification and patient notification templates. The 72-hour working assumption for Board notification is particularly challenging in healthcare, where incidents may first be detected by clinical staff rather than IT security. Ensure your incident escalation path from clinical to IT to legal to the Board notification is clearly defined and practiced.

Frequently asked questions

Can we share a patient's records with another hospital for a referral without fresh consent?

Sharing records for direct treatment purposes — a referral to a specialist, an emergency transfer — is generally covered by the treatment consent the patient gave when they first registered. However, if the sharing goes beyond what the patient would reasonably expect from a treatment consent — for example, sharing with a hospital in another chain that the patient has no relationship with — you should obtain fresh consent or be prepared to justify it under a specific lawful basis.

We anonymise patient data before using it for research. Is that enough?

Genuine anonymisation — where re-identification is not reasonably possible — takes the data outside the DPDP Act's scope. But 'anonymisation' in healthcare is harder than it sounds. Health data with diagnosis, age, postcode, and treatment date can often be re-identified by cross-referencing with other datasets. Get expert statistical advice on your anonymisation method, and if you cannot be confident it is robust, use the research exemption framework rather than relying on anonymisation.

Are diagnostics labs in scope for DPDP?

Yes. Diagnostic labs process health data — test results, referral details, patient identity — and are Data Fiduciaries for that data. They must have a clear privacy notice, consent for processing, access controls, retention schedules, and breach response plans. Labs that share test results with hospitals or insurance companies must have DPAs in place. The Act applies regardless of the lab's size — even single-location independent labs are in scope.

Get your healthcare DPDP assessment

Niti Bharat's Healthcare DPDP Compliance Pack covers health data consent frameworks, third-party sharing agreements, digital health platform risk, and breach response — a complete compliance toolkit for healthcare organisations.

Get Healthcare DPDP Compliance Pack
Previous Post Next Post

Get Free DPDP Checklist