DPDP Compliance for Hospitals: A Practical Guide to Protecting Patient Data in India

DPDP Compliance for Hospitals: A Practical Guide to Protecting Patient Data in India

  • Loading...

Healthcare organisations have always handled some of the most private information about individuals. A hospital may collect a patient’s name, contact details, identification documents, medical history, diagnostic reports, prescriptions, insurance information, payment details, photographs, appointment records and information relating to family members or caregivers.

Get a callback

As healthcare becomes increasingly digital, this information moves through hospital information systems, electronic medical records, diagnostic platforms, mobile applications, cloud services, insurance portals, laboratories and third-party technology providers.

This makes data protection a core governance issue for hospitals—not merely an IT-security concern.

India’s Digital Personal Data Protection Act, 2023 (DPDP Act) establishes a statutory framework for processing digital personal data. The Act was enacted on 11 August 2023, and the Digital Personal Data Protection Rules, 2025 (DPDP Rules) were notified on 13 November 2025. The Government has adopted a phased implementation timeline, with the principal operational obligations coming into force 18 months after notification.

For hospitals, this creates an important opportunity: use the transition period to build privacy, security and governance into everyday clinical and administrative processes before compliance becomes mandatory.

What Does the DPDP Act Mean for Hospitals?

The DPDP Act regulates the processing of digital personal data. A hospital that determines why and how patient data is processed will generally fall within the role of a Data Fiduciary.

The Act defines personal data broadly as data about an individual who is identifiable by or in relation to that data. It also defines processing broadly, covering activities such as collection, recording, storage, retrieval, use, sharing, disclosure, transmission and erasure.

This is particularly relevant to hospitals because patient information is processed at almost every stage of the patient journey.

For example:

  • A patient provides information while booking an appointment.
  • Registration staff enter demographic information into the hospital system.
  • Doctors access clinical records during consultation.
  • Laboratories process information to generate test reports.
  • Pharmacies process prescriptions and patient information.
  • Insurance teams share necessary information for claims.
  • Hospitals may use cloud-based systems to store or process records.
  • Patients may access records through portals or mobile applications.
  • Hospitals may send appointment reminders and other communications.
  • Data may be shared with specialist doctors, diagnostic providers or technology vendors.

Each of these activities can create data-protection obligations.

Is Health Information Automatically “Sensitive Personal Data” Under the DPDP Act?

This is an important distinction.

Unlike India’s earlier Information Technology Rules framework, the DPDP Act does not create a separate statutory category called “sensitive personal data” in the same way.

That does not mean health information should be treated casually.

Patient medical records are inherently high-risk information from a privacy, confidentiality and security perspective. A hospital should therefore apply strong safeguards to health information even where the DPDP Act does not label it as a separate category of personal data.

The practical approach should be simple:

Treat patient health information as high-risk personal data and design controls accordingly.

This is particularly important because a breach involving medical information can have consequences far beyond financial loss. It can result in embarrassment, discrimination, identity fraud, reputational damage or other harm to patients.

DPDP Compliance Timeline for Hospitals

Hospitals should understand the phased implementation structure rather than assuming that every provision became operational immediately upon notification.

The Government’s enforcement notification dated 13 November 2025 divides implementation into phases. Certain institutional and administrative provisions came into force immediately; specified consent-manager provisions are scheduled after one year; and the principal provisions dealing with processing, Data Fiduciary obligations and Data Principal rights are scheduled after 18 months.

The DPDP Rules follow a similar phased structure:

  • Rules 1, 2 and 17–21 came into force upon publication.
  • Rule 4 comes into force one year after publication.
  • Rules 3, 5–16 and 22–23 come into force 18 months after publication.

For a hospital, this should be viewed as a compliance preparation window, not a reason to delay action.

The operational requirements will affect systems, contracts, consent processes, privacy notices, security controls, retention practices and patient-rights workflows. Implementing these changes across a hospital network can take considerable time.

1. Identify What Patient Data the Hospital Collects

The first step in DPDP compliance is knowing what data the organisation actually processes.

A hospital should conduct a comprehensive data inventory and data-flow mapping exercise.

The inventory should cover information such as:

  • Patient names and contact details
  • Date of birth and demographic information
  • Government-issued identification information
  • Medical histories
  • Diagnoses
  • Prescriptions
  • Laboratory reports
  • Radiology and imaging records
  • Surgical records
  • Admission and discharge information
  • Insurance and billing information
  • Emergency-contact information
  • Photographs and videos
  • Appointment information
  • Patient portal credentials
  • Communications and correspondence
  • Information collected through mobile applications or websites

The exercise should not stop with the hospital’s central database.

Hospitals should map where information goes after collection.

For example:

Patient → Registration Desk → Hospital Information System → Doctor → Laboratory → Pharmacy → Insurance Provider → Billing System → Cloud/Technology Vendor

Every arrow represents a potential processing or sharing activity that should be understood and governed.

2. Determine the Purpose for Every Processing Activity

The DPDP framework places significant importance on lawful and purpose-oriented processing.

Hospitals should therefore ask:

Why are we collecting this information?

For example, collecting a patient’s contact number may be necessary to:

  • confirm an appointment;
  • communicate about admission;
  • send a diagnostic report;
  • provide information relating to treatment; or
  • communicate about billing.

But the same number should not automatically be used for unrelated promotional activities simply because the hospital possesses it.

A hospital should document the purpose associated with each significant category of personal data.

This creates a useful purpose-to-data matrix:

Data Purpose System Access Retention
Patient contact number Appointment communication HIS/CRM Registration, authorised staff As required
Medical record Treatment EMR/HIS Clinical personnel As legally required
Insurance information Claims processing Billing system Billing/insurance team As legally required
Email address Patient communication Patient portal Authorised staff Based on purpose

 

The objective is not to collect as much data as possible.

The objective is to collect and process the data actually needed for legitimate purposes.

3. Review Patient Notices and Consent Mechanisms

Consent is one of the most visible aspects of DPDP compliance.

The DPDP Rules require notices to be clear, understandable and presented independently of other information. The notice must provide an itemised description of the personal data and the specified purpose or purposes for processing.

For hospitals, this means that a long, generic privacy statement hidden inside a website footer may not be an adequate practical approach.

Patient-facing notices should be understandable.

A hospital’s privacy notice may need to explain, depending on the relevant processing:

  • what information is being collected;
  • why it is being collected;
  • how it is used;
  • relevant categories of recipients;
  • how patients can exercise applicable rights;
  • how consent can be withdrawn where consent is the basis;
  • how complaints can be raised; and
  • how the hospital can be contacted.

Consent mechanisms should also be reviewed across different channels.

A hospital may currently obtain information through:

  • physical registration forms;
  • website forms;
  • mobile applications;
  • patient portals;
  • telephone bookings;
  • kiosks;
  • WhatsApp or other communication channels;
  • telemedicine platforms; and
  • third-party appointment platforms.

The hospital should determine which processing activities require consent and which may rely on other lawful grounds recognised by the DPDP Act.

Importantly, consent should not become a substitute for clinical necessity analysis.

The Act itself recognises certain situations where processing may occur without consent, including specified circumstances involving medical emergencies, provision of healthcare during epidemics or public-health threats, and other legally recognised grounds.

Hospitals should therefore create documented rules for distinguishing consent-based processing from processing undertaken under another lawful basis.

4. Build a Proper Consent-Withdrawal Process

Consent is meaningful only if patients can exercise control over it.

The DPDP framework requires organisations to facilitate withdrawal of consent, subject to the applicable legal framework.

For hospitals, this creates an operational challenge.

A patient might have provided consent through an online portal, while their information is simultaneously present in the hospital information system, laboratory platform, billing platform and other systems.

A mature compliance programme should therefore answer:

What happens technically when a patient withdraws consent?

The hospital should know:

  • which processing stops;
  • which systems receive the withdrawal;
  • whether third-party processors need to be notified;
  • what information must nevertheless be retained because of another legal obligation; and
  • how the hospital records the action taken.

The answer will differ depending on the purpose and applicable legal obligations.

5. Establish Data Retention and Deletion Policies

Hospitals often retain records for long periods, and there may be legitimate legal, regulatory, clinical or operational reasons for doing so.

However, “we might need it someday” should not become the default retention policy for every category of data.

The DPDP Act requires Data Fiduciaries to erase personal data when consent is withdrawn or when the specified purpose is no longer being served, unless retention is necessary under applicable law.

Hospitals should therefore create a retention schedule covering different categories of information.

For each category, the hospital should document:

  • the purpose of processing;
  • the applicable retention requirement;
  • the event that starts the retention period;
  • who owns the retention decision;
  • when the information should be deleted or anonymised where appropriate; and
  • how deletion is implemented across systems and vendors.

The policy should also distinguish between:

Legal retention and operational convenience.

A hospital should not retain information indefinitely merely because its systems make deletion difficult.

6. Strengthen Cybersecurity and Access Controls

Healthcare environments create a particularly challenging security environment.

A hospital may have hundreds or thousands of users, including:

  • doctors;
  • nurses;
  • technicians;
  • administrative staff;
  • billing personnel;
  • pharmacists;
  • contractors;
  • IT administrators;
  • third-party service providers; and
  • temporary staff.

Not everyone needs access to every patient record.

The DPDP Act requires Data Fiduciaries to implement appropriate technical and organisational measures and reasonable security safeguards to prevent personal data breaches.

The DPDP Rules elaborate on reasonable security safeguards, including measures such as encryption, access controls, monitoring, backups, breach detection and appropriate contractual requirements for Data Processors.

A hospital’s security programme should therefore consider:

  • role-based access control;
  • strong authentication;
  • privileged-access management;
  • encryption;
  • endpoint security;
  • network segmentation;
  • secure backups;
  • audit logs;
  • monitoring for unauthorised access;
  • vulnerability management;
  • patch management;
  • secure application development;
  • incident response procedures; and
  • periodic security testing.

The goal is not simply to have cybersecurity products.

The goal is to demonstrate that patient data is protected through a combination of technology, processes and people.

7. Prepare for Patient Data Breaches

A hospital cannot assume that a security breach will never happen.

Instead, it should prepare for what happens when an incident occurs.

Examples include:

  • ransomware affecting the hospital’s systems;
  • an employee sending a medical report to the wrong recipient;
  • unauthorised access to an EMR account;
  • stolen credentials;
  • a lost device containing patient information;
  • accidental disclosure of patient information;
  • unauthorised downloading of records; or
  • compromise of a third-party healthcare platform.

The DPDP Act requires notification of a personal data breach to the Board and affected Data Principals in the prescribed manner.

The DPDP Rules provide further requirements for breach notification. According to the notified framework, affected individuals are to be notified promptly, while detailed information is to be furnished to the Board within 72 hours or such longer period as permitted.

Hospitals should therefore maintain a documented incident-response plan covering:

  1. Detection
  2. Containment
  3. Investigation
  4. Risk assessment
  5. Internal escalation
  6. Regulatory notification
  7. Patient notification
  8. Remediation
  9. Evidence preservation
  10. Post-incident review

The incident-response team should know who makes the notification decision and who communicates with patients before a crisis occurs.

8. Control Third-Party Vendors and Data Processors

Hospitals rarely process all patient information themselves.

They commonly depend on vendors for:

  • cloud hosting;
  • hospital management software;
  • electronic medical records;
  • laboratory systems;
  • payment processing;
  • appointment management;
  • telemedicine;
  • SMS and email communications;
  • cybersecurity;
  • document management;
  • analytics;
  • billing;
  • insurance processing; and
  • IT support.

Under the DPDP Act, a Data Fiduciary may engage a Data Processor for activities connected with offering goods or services only under a valid contract, while the Data Fiduciary remains responsible for compliance for processing undertaken on its behalf.

This means that a hospital cannot simply say:

“The vendor was responsible for the breach.”

Vendor governance should include:

  • data-processing clauses;
  • confidentiality obligations;
  • security requirements;
  • access restrictions;
  • breach reporting;
  • subcontractor controls;
  • audit or assurance mechanisms;
  • deletion/return requirements;
  • business continuity requirements; and
  • obligations on termination.

Hospitals should also maintain a current vendor data-processing register.

9. Control Internal Access to Patient Records

Privacy risks do not come exclusively from external hackers.

An employee accessing a celebrity’s medical record out of curiosity can create a serious privacy incident.

Similarly, a staff member may download patient records for convenience and store them on a personal device.

Hospitals should therefore adopt a need-to-know access model.

For example:

A receptionist may need appointment and registration information.

A doctor may need access to clinical information relevant to treatment.

A billing employee may need financial and insurance information.

A system administrator may require technical access but should not automatically have unrestricted access to clinical content.

Access should be:

Necessary → Authorised → Logged → Reviewed

Periodic access reviews are especially important when employees change roles or leave the organisation.

10. Pay Special Attention to Children’s Data

Hospitals regularly process information relating to children.

The DPDP Act contains additional obligations concerning children’s personal data, including restrictions relating to certain processing activities and requirements around verifiable parental consent under the applicable framework.

This means paediatric departments, children’s hospitals and healthcare applications directed toward minors should examine their consent and verification processes particularly carefully.

The hospital should establish a clear process for identifying when a Data Principal is a child and determining what additional safeguards apply.

11. Consider Whether the Hospital Could Become a Significant Data Fiduciary

The DPDP Act provides for a category called a Significant Data Fiduciary (SDF).

The Central Government may notify a Data Fiduciary or class of Data Fiduciaries as significant, taking into account factors including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on sovereignty and integrity, security of the State, risk to electoral democracy, security of the country and public order.

A large hospital chain or healthcare platform should therefore monitor whether it may fall within this category if the Government notifies relevant classes.

Significant Data Fiduciaries have additional obligations under the Act.

Healthcare organisations with extensive patient databases should not wait for a designation before establishing mature privacy governance.

12. Create a Hospital Privacy Governance Structure

DPDP compliance cannot sit exclusively with the IT department.

A hospital should establish cross-functional responsibility involving:

  • hospital management;
  • legal/compliance;
  • information security;
  • IT;
  • medical administration;
  • nursing administration;
  • HR;
  • procurement;
  • finance;
  • patient relations; and
  • relevant clinical leadership.

A privacy governance committee can oversee:

  • data inventories;
  • privacy notices;
  • consent processes;
  • vendor assessments;
  • security controls;
  • retention schedules;
  • patient requests;
  • incident management;
  • staff training; and
  • regulatory developments.

For large healthcare organisations, privacy should become a standing governance agenda rather than an annual compliance exercise.

13. Train Doctors, Nurses and Hospital Staff

Even the strongest technical controls can fail because of human behaviour.

Staff should understand practical situations such as:

Can I send a patient’s report to my personal email?

Can I photograph a medical record using my personal phone?

Can I discuss a patient’s condition in a public area?

Can I open a patient’s record because I am curious?

What should I do if I send information to the wrong person?

What should I do if I suspect ransomware?

Training should therefore be role-specific.

A doctor, receptionist and IT administrator do not face identical privacy risks.

Short, recurring training sessions are often more effective than one annual presentation.

14. Give Patients Practical Privacy Rights

The DPDP framework gives Data Principals rights in relation to their personal data.

Hospitals should build operational processes for handling applicable requests, including mechanisms relating to access to information about personal data, correction and erasure, grievance redressal and other applicable rights.

The process should specify:

  • where patients submit requests;
  • how identity is verified;
  • who evaluates the request;
  • which system owners are responsible;
  • how requests are tracked;
  • applicable response timelines;
  • when a request may be refused or limited under law; and
  • how the patient is informed of the outcome.

A shared inbox alone is not a complete rights-management system.

The hospital should have a documented Data Principal Request Procedure.

15. Build Privacy by Design into Hospital Technology

Hospitals frequently acquire new technology without conducting a privacy assessment first.

A better approach is to ask privacy questions before procurement.

For every new application, ask:

  • What personal data will it collect?
  • Is all of it necessary?
  • What is the purpose?
  • Who can access it?
  • Where is it stored?
  • Is it shared with another organisation?
  • How long is it retained?
  • Can the vendor subcontract processing?
  • What happens when the contract ends?
  • What security controls exist?
  • How will a patient exercise applicable rights?

This approach is particularly important for:

  • AI-based diagnostic tools;
  • wearable devices;
  • remote patient monitoring;
  • patient apps;
  • telemedicine platforms;
  • cloud-based EMRs;
  • analytics platforms; and
  • healthcare chatbots.

The faster healthcare technology evolves, the more important privacy-by-design becomes.

DPDP Compliance and Other Healthcare Laws

DPDP compliance should not be treated as a replacement for every other legal or regulatory requirement applicable to healthcare organisations.

Hospitals may also need to consider obligations arising under other laws, regulations, professional standards, contractual arrangements, cybersecurity requirements and healthcare-sector frameworks.

The DPDP Act itself recognises situations in which processing may be necessary to comply with other laws and includes specific provisions addressing certain healthcare-related circumstances.

Accordingly, hospitals should conduct a legal and regulatory mapping exercise rather than implementing DPDP requirements in isolation.

The correct question is not:

“What does DPDP require?”

It is:

“What is the complete legal and operational framework governing this patient data?”

DPDP Compliance Checklist for Hospitals

A hospital preparing for DPDP compliance should consider the following workstreams:

  • Identify all categories of digital personal data processed.
  • Map patient-data flows across internal departments.
  • Identify all external Data Processors and vendors.
  • Document the purpose for each major processing activity.
  • Review patient-facing privacy notices.
  • Review consent collection mechanisms.
  • Establish a consent-withdrawal process where applicable.
  • Create a data-retention and deletion framework.
  • Review access controls for patient records.
  • Implement appropriate technical and organisational security safeguards.
  • Establish logging and monitoring for sensitive systems.
  • Test backups and business continuity arrangements.
  • Develop a personal-data-breach response plan.
  • Establish patient/data-principal request workflows.
  • Review contracts with vendors and Data Processors.
  • Assess children’s-data processing.
  • Evaluate whether the organisation may fall within the Significant Data Fiduciary framework if notified.
  • Conduct employee privacy and security training.
  • Establish management-level privacy governance.
  • Periodically audit DPDP controls and update them as the regulatory framework develops.

Common DPDP Mistakes Hospitals Should Avoid

“Our patient data is already confidential, so we are compliant.”

Confidentiality and data protection overlap, but they are not identical.

A hospital can have professional confidentiality policies while lacking appropriate mechanisms for consent, notices, rights requests, retention, vendor governance or breach response.

“We have a privacy policy on our website.”

A website privacy policy is only one component of compliance.

The hospital needs operational controls behind the policy.

“Our IT vendor handles data protection.”

The hospital cannot outsource its overall responsibility simply by outsourcing technology.

Data Processor relationships need proper contracts and oversight.

“We collect everything because we may need it later.”

Data minimisation and purpose limitation should guide collection and retention.

“Cybersecurity means installing antivirus software.”

Security is a governance, technical and organisational discipline.

It includes access controls, encryption, monitoring, backups, incident response, vendor management and staff behaviour.

“We will start after the final deadline.”

For a hospital network with multiple facilities and legacy systems, implementing privacy controls can take months.

The transition period should be used for implementation, testing and remediation—not for beginning the project at the last minute.

A Practical DPDP Roadmap for Hospitals

A hospital can approach implementation in five stages.

Stage 1: Discover

Identify:

  • data;
  • systems;
  • purposes;
  • users;
  • vendors;
  • transfers; and
  • retention requirements.

Stage 2: Assess

Identify gaps in:

  • notices;
  • consent;
  • security;
  • access;
  • contracts;
  • retention;
  • patient rights; and
  • incident management.

Stage 3: Remediate

Implement:

  • revised policies;
  • privacy notices;
  • contractual clauses;
  • access controls;
  • technical safeguards;
  • retention rules;
  • rights-management workflows; and
  • breach procedures.

Stage 4: Operationalise

Train staff and embed privacy requirements into:

  • procurement;
  • onboarding;
  • clinical workflows;
  • IT change management;
  • vendor management; and
  • incident response.

Stage 5: Monitor

DPDP compliance should become an ongoing programme.

Conduct periodic:

  • privacy assessments;
  • vendor reviews;
  • access reviews;
  • security testing;
  • staff training;
  • policy reviews; and
  • regulatory updates.

The Business Case for DPDP Compliance in Healthcare

Compliance is not only about avoiding penalties.

For hospitals, privacy can become a source of trust.

Patients are more likely to use digital healthcare services when they believe their information is handled responsibly.

Strong data governance can also reduce:

  • accidental disclosures;
  • unauthorised access;
  • duplicate or unnecessary data collection;
  • uncontrolled vendor access;
  • legacy data accumulation;
  • operational confusion during incidents; and
  • reputational damage after breaches.

The financial consequences of non-compliance can also be significant. The DPDP Act’s Schedule provides for penalties that may extend to ₹250 crore for failure to take reasonable security safeguards, and up to ₹200 crore for failures relating to personal-data-breach notification, among other specified penalties.

The maximum penalty is not the only consideration. The operational and reputational consequences of a major healthcare-data incident can be equally significant.

Conclusion

The DPDP framework changes the way Indian organisations need to think about personal data.

For hospitals, the challenge is particularly important because healthcare depends on the collection and sharing of highly private information. Patient data must be available to authorised professionals when it is needed for care, while being protected against unnecessary access, misuse, loss and disclosure.

DPDP compliance should therefore not be approached as a document-generation exercise.

It should be treated as a hospital-wide data governance programme.

The strongest approach combines:

Clear purpose + appropriate consent + patient transparency + data minimisation + controlled access + strong security + responsible vendors + retention discipline + breach readiness + effective governance.

Hospitals that begin this work early can use the DPDP transition period to modernise their privacy practices, strengthen information security and build greater patient trust.

The DPDP Act and DPDP Rules are now part of India’s evolving data-protection landscape, and hospitals should track the phased commencement dates carefully while preparing their systems and processes. The Government has published the notified Rules and implementation timeline through the Ministry of Electronics and Information Technology.

Disclaimer: This article is intended for general informational purposes and does not constitute legal advice. Healthcare organisations should assess their specific processing activities, contractual arrangements and applicable sectoral laws with qualified legal and compliance professionals.

Appointment