DPDP Act 2023 + DPDP Rules 2025 — Premium Healthcare Compliance Guide
Patient health data is the most sensitive category of personal data that exists. A hospital's records can reveal a person's HIV status, psychiatric history, genetic conditions, reproductive decisions, and financial vulnerability — simultaneously. The Digital Personal Data Protection Act, 2023 treats health data accordingly: with the highest penalty tier, the strictest consent requirements, and the lowest tolerance for non-compliance. Every hospital, clinic, diagnostic lab, telemedicine platform, pharmacy, health-tech company, and health insurer operating in India is a Data Fiduciary under the DPDP Act — from the moment their first patient walks in or their first online appointment is booked. This guide explains, in full detail, what the law requires from India's healthcare sector, where the greatest risks lie, and what every provider must do to be fully compliant by May 2027.
⚠️ Healthcare Faces the Highest Penalty Exposure Under DPDPA
₹250 Cr
Breach of data security safeguards — highest individual penalty in the Act. Hospitals breaching patient records face this ceiling.
₹200 Cr
Failure to notify a data breach to the Board and affected patients. A hospital ransomware attack that is concealed triggers this penalty automatically.
₹50 Cr
Per instance of consent, notice, purpose, or rights violations. Each patient whose data is misused is a separate instance.
No Cap
On the number of violations. A hospital with 10,000 patients whose data is mishandled faces penalties that are individually multiplied.
Nov 2025
DPDP Rules notified — Board operational
Nov 2026
Consent Manager registration opens
May 2027
All obligations fully enforceable — DEADLINE
📋 What This Guide Covers
- Who in healthcare is a Data Fiduciary under DPDPA
- Why health data receives special treatment — the sensitivity framework
- The data healthcare providers actually hold — and its risk map
- Consent in healthcare — the most complex consent architecture in any sector
- The 9 core obligations every healthcare Data Fiduciary must meet
- DPDPA and existing healthcare regulations — DISHA, IT Act, MCI ethics
- Telemedicine and health-tech — digital-specific obligations
- Hospital ransomware and breach notification — what the Act requires
- Significant Data Fiduciary — which healthcare entities will be designated
- Staff, insurance, and pharma — additional compliance streams
- The most critical violations in Indian healthcare today
- Compliance roadmap — 90-day implementation for healthcare providers
1. Who in Healthcare Is a Data Fiduciary Under DPDPA
The DPDP Act applies to every entity that processes digital personal data of Indian residents. In the healthcare sector, this captures a far wider range of organisations than most realise:
🏥 Hospitals and Nursing Homes
Multi-specialty hospitals, single-specialty centres, nursing homes, maternity hospitals, surgical centres — all covered, regardless of size or whether they are public, private, or trust-run.
🩺 Individual Clinics and Practitioners
Solo GP clinics, specialist consulting rooms, dental practices, physiotherapy centres, and any independent practitioner who maintains digital patient records — all covered.
🧪 Diagnostic Labs and Imaging Centres
Pathology labs, radiology centres, MRI and CT scan facilities, genetic testing labs — all covered. Labs that process genetic data face the highest sensitivity tier.
💊 Pharmacies and Pharmacy Chains
Retail pharmacies, online pharmacies, pharmacy chains — any entity that collects prescription data, customer health profiles, or medical purchase history is a Data Fiduciary.
📱 Telemedicine Platforms
Online doctor consultation platforms, mental health apps, teleconsultation services — all covered. These platforms often process health data at scale, making them prime SDF candidates.
🤖 Health-Tech and Digital Health Companies
Electronic Health Record (EHR) platforms, fitness and wellness apps, wearable data aggregators, AI diagnostics companies, and hospital management software companies — all covered.
🏢 Health Insurance Companies
Health insurers collect and process extensive medical histories, claim records, pre-existing condition disclosures, and treatment records — all highly sensitive personal data under DPDPA.
🔬 Pharmaceutical and Research Companies
Clinical trial sponsors, CROs, pharma companies conducting post-market surveillance, and research institutions collecting patient data — all covered, with additional ethical and regulatory overlay.
2. Why Health Data Receives Special Treatment
While the DPDP Act does not create an explicit "special category" list the way GDPR does, health-related data falls within its highest-sensitivity processing for several interconnected reasons that place healthcare providers in the most scrutinised sector.
🧬
Inherent Sensitivity and Immutability
Unlike a compromised password that can be changed, health data cannot be altered after a breach. A person's HIV status, genetic markers, or psychiatric diagnosis, once exposed, exposes them permanently. The Data Protection Board is expected to treat health data breaches with maximum seriousness precisely because the harm is irreversible.
⚖️
Power Asymmetry Between Provider and Patient
Patients disclose health information to providers in a position of vulnerability — they need care. This creates an inherently unequal power dynamic. The Act's consent requirements are designed to ensure that providers cannot exploit this vulnerability to obtain consent for purposes beyond treatment — such as marketing pharmaceutical products or selling data to insurers.
💥
Cascading Harm Potential
Health data breaches cause multi-dimensional harm: discrimination in employment, rejection or loading in insurance, family relationship damage (e.g. genetic conditions), and psychological harm from the exposure of intimate health details. A single hospital breach can simultaneously harm thousands of patients across all these dimensions. The Board will calibrate penalties to reflect this compounding effect.
🎯
High Monetisation Incentive Creates Higher Risk
Patient data is extraordinarily valuable commercially — to pharmaceutical companies, insurance underwriters, health-tech platforms, and advertisers. This creates strong incentives for misuse that the Act must counter. Providers who sell or share patient data for commercial gain — even through anonymised aggregation — face the highest scrutiny under the Act's purpose limitation and consent requirements.
3. The Data Healthcare Providers Hold — Full Risk Map
| Data Category |
Specific Examples in Healthcare |
DPDPA Sensitivity |
Breach Penalty Ceiling |
| Genetic & Genomic Data |
DNA test results, genetic risk reports, hereditary condition markers, ancestry data, pharmacogenomics |
CRITICAL |
₹250 Cr |
| Mental Health Records |
Psychiatric diagnoses, therapy notes, medication for mental illness, hospitalisation for mental health, addiction treatment records |
CRITICAL |
₹250 Cr |
| Biometric Health Data |
Fingerprints (patient ID systems), retinal scans, facial recognition at hospital entry, voiceprint authentication |
CRITICAL |
₹250 Cr |
| Clinical Diagnosis & Treatment |
Disease diagnoses (HIV, cancer, diabetes, TB), treatment plans, surgical records, medication prescriptions, discharge summaries |
VERY HIGH |
₹250 Cr |
| Radiology & Pathology Reports |
X-ray, MRI, CT scan images and reports; blood test results; biopsy results; urine and stool analysis reports |
VERY HIGH |
₹250 Cr |
| Reproductive Health Data |
Pregnancy records, fertility treatment, abortion history, contraception use, STI testing and results, obstetric history |
VERY HIGH |
₹250 Cr |
| Financial & Insurance Data |
Health insurance policy details, TPA records, co-pay and claim data, income certificates for subsidised treatment, patient billing records |
HIGH |
₹250 Cr |
| Identity & Contact Data |
Patient name, DOB, Aadhaar, address, emergency contacts, next-of-kin details, UHID (Universal Health ID) |
HIGH |
₹50–250 Cr |
| Behavioural & Lifestyle Data |
App usage patterns (health apps), step counts, sleep data, dietary logs, wearable device data, symptom checker inputs |
MEDIUM–HIGH |
₹50–250 Cr |
4. Consent in Healthcare — The Most Complex Architecture in Any Sector
Healthcare consent under DPDPA is not a single event at registration. It is a layered, ongoing, purpose-specific architecture that must operate across every touchpoint from a patient's first appointment to their final discharge — and beyond.
The critical distinction that most providers miss: Consent for treatment and consent for data processing are two separate legal acts. A patient consenting to surgery has not consented to their data being shared with a pharmaceutical company, added to a marketing database, or stored on an overseas cloud server. Each of these requires its own, separate, informed consent.
1
Treatment Consent vs. Data Processing Consent
Treatment consent (signing before a procedure) is governed by medical ethics and the Medical Termination of Pregnancy Act, Mental Healthcare Act, and other sector-specific laws. This does not satisfy DPDPA consent requirements. Data processing consent must be separately obtained, must specify what data is processed, for what purpose, by whom, and how long it is retained. Hospitals must redesign their patient intake process to capture both — and ensure neither is bundled with the other.
2
Emergency Treatment — The Legitimate Use Exception
The DPDP Act recognises a legitimate use ground under Section 7 for situations where consent cannot be obtained before processing is necessary — including emergency medical treatment. A hospital treating an unconscious patient can process their data without prior consent to deliver emergency care. However, this exception is narrow and strictly limited to the emergency itself. Once the patient is conscious and capable of consent, all further data processing must be consent-based. And the legitimate use cannot extend to sharing data with insurers, billing systems, or third parties without subsequent consent.
3
Purpose-Specific Consent — What Requires Its Own Consent Notice
Each of the following requires a separate, specific consent notice — it cannot be bundled into a general admission consent:
Sharing with insurance / TPA
Medical research or clinical trials
Marketing of health products / services
Telemedicine / video consultation recording
AI-assisted diagnostics using patient data
Sharing with referring doctors / hospitals
Government health scheme reporting (PMJAY etc.)
Biometric identification at entry / wards
CCTV coverage in clinical areas
Sharing records with family / caregivers
4
Withdrawal of Consent — The Right to Be Forgotten by Your Hospital
Under Section 6(4) and Section 12, a patient can withdraw consent and request erasure of their data. In healthcare, this right interacts with other legal obligations — some records must be retained for statutory periods (MCI rules, state health laws). Providers must navigate this carefully: where a legal retention obligation exists, the patient's erasure right is limited by it, but this limitation must be clearly communicated and the provider must delete everything that is not legally required to be retained.
5. The 9 Core Obligations Every Healthcare Data Fiduciary Must Meet
| # |
Obligation |
Healthcare-Specific Meaning |
Legal Ref |
Priority |
| 1 |
Lawful Basis for Every Processing Activity |
Each data flow — treatment, billing, insurance, research, marketing — must have a documented basis: consent or a specific legitimate use ground. "Patient gave us their details" is not a basis. |
S.4, S.6, S.7 |
🔴 CRITICAL |
| 2 |
Patient Privacy Notice |
A comprehensive privacy notice must be given at registration or first appointment — covering all data types, all purposes, all third parties (insurers, labs, referring hospitals), retention periods, and patient rights. In plain language. Accessible in local languages where appropriate. |
S.5 |
🔴 CRITICAL |
| 3 |
Purpose-Specific Consent Architecture |
Separate consent notices for each distinct purpose — treatment data processing, insurance sharing, marketing, research. None may be bundled. All must be obtained before the relevant processing begins. |
S.6 |
🔴 CRITICAL |
| 4 |
Patient Rights Infrastructure |
A functional process to receive, verify, and respond to requests for access, correction, erasure, and nomination from patients and their legal representatives — within prescribed timelines. Must include a dedicated intake mechanism (email, form, or portal). |
S.11–14 |
🔴 CRITICAL |
| 5 |
Grievance Officer — Named and Accessible |
A named individual responsible for data-related grievances — published in the privacy notice, on the hospital website, and on any patient-facing platform. Must have a defined resolution process and timeline. |
S.13 |
🔴 CRITICAL |
| 6 |
Data Security Safeguards |
Technical measures (encryption of EHR data at rest and in transit, access control, audit logs, network security) and organisational measures (role-based access, staff training, data handling policies) appropriate to the extraordinary sensitivity of patient data. |
S.8(5) |
🔴 CRITICAL |
| 7 |
Breach Detection and Notification |
A documented breach response plan covering detection, internal escalation, Board notification (under Rule 6), and patient notification. Given the ransomware threat to Indian hospitals, this is not theoretical — it is an operational necessity. Failure to notify carries a ₹200 crore penalty. |
S.8(6), R.6 |
🔴 CRITICAL |
| 8 |
Retention Policy and Deletion Schedule |
Patient records must be retained for the legally required period — typically 7 years under MCI guidelines, longer for specialised records — and deleted or anonymised thereafter. The retention policy must be documented, and a deletion process must be operationally functional, not just on paper. |
S.8(7) |
🔴 CRITICAL |
| 9 |
Vendor and Processor Management |
Every third party that processes patient data — EHR software, HIS vendor, cloud storage, diagnostic lab, insurance TPA, telemedicine platform, billing software — must have a Data Processing Agreement in place. The hospital is liable for breaches by its processors without a compliant DPA. |
S.9 |
🔴 CRITICAL |
6. DPDPA and Existing Healthcare Regulations — How They Interact
Healthcare is already one of India's most regulated sectors. DPDPA does not replace existing obligations — it adds to them, creating a layered compliance landscape that every provider must navigate simultaneously.
| Existing Regulation |
What It Covers |
How DPDPA Adds to It |
| DISHA (Digital Information Security in Healthcare Act — Draft) |
Proposed sector-specific framework for health data — not yet enacted |
DPDPA is already law. Waiting for DISHA means operating in violation now. DISHA, when enacted, will add additional sector-specific requirements on top of DPDPA. |
| Medical Council of India / NMC Ethics Regulations |
Patient confidentiality obligations on registered medical practitioners |
DPDPA extends confidentiality obligations beyond individual practitioners to the entire institution and all digital systems. Violations are now regulatory (Board) in addition to disciplinary (NMC). |
| IT Act 2000 / SPDI Rules 2011 |
Sensitive Personal Data and Information rules — pre-DPDPA framework |
DPDPA supersedes the SPDI Rules for most purposes and introduces a significantly stricter consent standard, higher penalties, and a statutory enforcement body. Compliance with SPDI Rules alone is no longer sufficient. |
| Telemedicine Practice Guidelines 2020 |
Framework for online medical consultations — data storage and confidentiality provisions |
DPDPA adds mandatory breach notification, Grievance Officer requirements, vendor DPA obligations, and patient rights that are not present in the 2020 Guidelines. Both must be complied with simultaneously. |
| ABDM / ABHA (Ayushman Bharat Digital Mission) |
National digital health framework — ABHA ID, health record linking |
Institutions participating in ABDM are both Data Fiduciaries (for their own records) and Data Processors (for the government's health data infrastructure). Both roles require compliance — DPAs with ABDM infrastructure and own-institution DPDPA obligations separately. |
| IRDAI Health Insurance Regulations |
Data sharing between hospitals and insurers / TPAs for claim processing |
DPDPA requires explicit, specific patient consent before sharing with insurers — even for cashless claim processing. This fundamentally changes the hospital-insurer data-sharing model and requires consent language to be built into every cashless hospitalisation form. |
7. Telemedicine and Health-Tech — Digital-Specific Obligations
Telemedicine platforms and health-tech companies face the full weight of DPDPA obligations plus a set of digital-specific risks that offline providers do not encounter at the same scale.
⚡ Platform-Level Obligations
- Sign-up consent notice must be specific, layered, and not buried in T&Cs
- Separate consent for consultation recording and AI-assisted analysis
- Consultation recordings are personal data — retention and deletion policies required
- DPAs with every cloud provider, video conferencing API, AI diagnostics vendor
- Age verification for platforms accessible to users under 18
- Cross-border transfer mapping — if servers are outside India
- Cookie and tracking consent granular and purpose-specific
🤖 AI in Healthcare — Special Caution
- Using patient data to train AI diagnostic models requires specific, informed consent — "improving our services" language is not sufficient
- Algorithmic decision-making that significantly affects a patient (triage, diagnosis, treatment suggestion) must be disclosed to the patient
- If designated SDF, algorithmic transparency obligations apply
- De-identification / anonymisation for AI training must meet actual anonymisation standards — pseudonymised data is still personal data under DPDPA
- Patients have a right to human review of automated health decisions
8. Hospital Ransomware and Breach Notification — What the Act Requires
India's healthcare sector is one of the most targeted industries for ransomware attacks globally. AIIMS Delhi, Safdarjung Hospital, and multiple private hospital chains have experienced significant cyberattacks in recent years. Under DPDPA, such incidents are not just operational crises — they are legal events that trigger mandatory notification obligations within defined timelines.
🚨 When a Ransomware Attack Hits — Your DPDPA Timeline
T0
Breach discovered. Your internal breach response plan activates immediately. Incident commander identified. IT forensics initiated. Legal counsel notified.
T+
Notification to Data Protection Board under Rule 6 — in the prescribed format, within the timeline notified by the Board. Failure to notify the Board triggers a ₹200 crore penalty independently of any damage caused by the breach itself.
T++
Notification to affected patients — every patient whose data may have been compromised must be notified in plain language: what happened, what data was involved, what the hospital is doing, and what the patient should do. A pre-drafted template is essential — drafting under crisis conditions leads to legal exposure.
T+++
Board investigation and penalty assessment. The Board has investigative powers and can assess penalties against the hospital, its Data Processors (the IT vendor or cloud provider that was breached), and any individual whose negligence contributed to the breach.
The ransomware payment trap: Many hospitals that pay ransomware attackers believe they have resolved the breach if the data is returned and not publicly released. Under DPDPA, this is incorrect. The breach occurred at the moment of unauthorised access — regardless of whether data was published externally. The hospital must notify the Board and affected patients of the breach regardless of whether a ransom was paid or data was recovered.
9. Significant Data Fiduciary — Which Healthcare Entities Will Be Designated
The Data Protection Board will designate certain entities as Significant Data Fiduciaries (SDFs) based on volume of data processed, sensitivity, national security risk, and impact on rights. In healthcare, the following categories are near-certain for SDF designation:
🏥
Large Private Hospital Chains
Apollo, Fortis, Max, Manipal, Aster, and comparable chains with multi-lakh patient databases, national presence, and processing of the full spectrum of sensitive health data.
📱
Major Telemedicine Platforms
Platforms with crore-scale user bases processing health consultation data, symptoms, diagnoses, and prescription information — Practo, Tata 1mg, Apollo 24/7, and comparable scale operators.
🧬
Genetic Testing Companies
Companies processing genetic and genomic data — the most sensitive data category under DPDPA — regardless of scale, due to the irreversible, hereditary, and deeply personal nature of the data.
🏛️
National Health Infrastructure
ABDM/ABHA infrastructure operators, National Health Authority-linked entities, and government health scheme administrators handling population-level health data.
Additional SDF Obligations (If Designated)
▶Data Protection Officer (DPO) — independent, senior, with direct Board access
▶Data Protection Impact Assessment (DPIA) — for all high-risk processing activities
▶Annual independent data audit — by a Board-recognised auditor
▶Algorithmic transparency — if AI/ML is used in clinical decision support
10. Staff, Insurance, and Pharma — Three Additional Compliance Streams
👩⚕️ Staff and Clinical Personnel Data
Healthcare institutions are major employers — doctors, nurses, technicians, administrative staff, housekeeping. All HR data (salaries, performance, leave, disciplinary records) is personal data under DPDPA. Additionally, healthcare workers' own health data — vaccination status, fitness certificates, occupational health records — is particularly sensitive. Staff must receive privacy notices, have rights of access and correction, and have access to the Grievance Officer. Employee data retention policies must cover departure, resignation, and termination scenarios.
🏦 Insurance and TPA Data Flows
Every cashless hospitalisation involves sharing patient diagnosis, treatment, and billing data with an insurer or TPA. Under DPDPA, this sharing requires explicit, informed patient consent — obtained before the claim is filed, not buried in the insurance policy's general terms. Hospitals must also have DPAs with every insurer and TPA they work with. The DPA must specify: what data is shared, for what purpose (claim processing only), how long the insurer retains it, and what happens to it after the claim is settled.
🔬 Pharma, Clinical Trials, and Research
Clinical trial sponsors, CROs, and pharmaceutical research organisations processing patient data face layered obligations — DPDPA consent requirements in addition to Schedule Y, ICMR guidelines, and CDSCO regulations. Consent for research participation must be separate from consent for treatment. Data collected in a trial cannot be repurposed for product marketing without fresh consent. And trial data shared with overseas sponsors or regulatory bodies may trigger cross-border transfer restrictions once the Board notifies restricted countries.
11. The Most Critical Violations in Indian Healthcare Today
| # |
Violation |
Where It Happens |
Max Penalty |
| 1 |
Patient data shared with pharmaceutical reps for marketing without specific consent — doctors' prescription patterns sold or shared as market research |
Hospitals, clinics, pharmacy chains |
₹250 Cr |
| 2 |
No Data Processing Agreement with EHR/HIS vendor, cloud storage provider, or lab management system despite these systems holding complete patient medical records |
~99% of hospitals and clinics |
₹250 Cr |
| 3 |
General admission consent form bundling treatment consent with data processing consent for insurance, marketing, and research — without any opt-in mechanism for non-treatment purposes |
~95% of hospitals |
₹50 Cr per patient |
| 4 |
Telemedicine platforms using Google Analytics, Meta Pixel, or retargeting tools on patient-facing pages — profiling users' health concerns for advertising |
~70% of health-tech platforms |
₹250 Cr |
| 5 |
Ransomware or cyberattack on hospital network — patient data compromised — breach not reported to the Data Protection Board or affected patients |
Increasingly common across all hospital tiers |
₹200 Cr |
| 6 |
Diagnostic lab sharing patient test results with insurance companies without specific patient consent — often driven by insurer pressure for underwriting data |
Diagnostic labs, hospitals with insurance desks |
₹50–250 Cr |
| 7 |
Clinical trial data used to train AI models or shared with pharma sponsor's overseas headquarters without patient consent for these secondary purposes |
Research hospitals, CROs, pharma companies |
₹250 Cr |
| 8 |
No named Grievance Officer — patients have no accessible way to query, correct, or delete their health records held by the hospital |
~99% of hospitals and clinics |
₹50 Cr |
12. Compliance Roadmap — 90-Day Implementation for Healthcare Providers
Weeks 1–2: Data Mapping and Risk Assessment
Map every data type the institution holds — patient, staff, insurance, vendor — and every data flow (who collects it, where it goes, who accesses it, how it exits the organisation). Identify the highest-risk flows: insurance sharing, pharma data sharing, overseas cloud storage, any AI or analytics tools. This register is foundational and is itself a compliance document.
Weeks 3–4: Legal Document Drafting
Draft all required legal documents: Patient Privacy Notice (comprehensive, plain language), Consent notices for each purpose (treatment data, insurance sharing, marketing, research, biometrics), Staff privacy notice, Website and telemedicine platform privacy policy, Breach notification templates (Board and patient). All must be customised to your institution's actual data practices — not adapted from generic templates.
Weeks 5–6: Vendor DPA Execution
Prioritise and execute Data Processing Agreements with every significant vendor: EHR/HIS software provider, cloud storage, diagnostic lab management systems, insurance TPA, payment gateway, telemedicine platform, AI diagnostics vendor, CCTV analytics, pathology lab network. Each DPA must specify processing purpose, security obligations, breach notification timelines, sub-processor restrictions, and deletion requirements.
Weeks 7–8: Governance, Roles, and Security Audit
Appoint Grievance Officer formally and publish their details. Build the patient rights request intake process. Commission a basic cybersecurity audit of patient-facing systems — EHR, hospital management software, patient portal — to identify the most critical vulnerabilities. Draft the breach response plan with clear escalation paths and pre-approved communication templates.
Weeks 9–12: Training, Integration, and Certification
Train clinical, administrative, and IT staff on DPDPA obligations and data handling procedures — tailored to their specific roles. Integrate consent notices and privacy notices into the patient registration workflow, admission forms, and digital platforms. Conduct a final compliance review across all obligation areas. Obtain a compliance certificate from legal counsel. For SDF-likely entities, commission a DPIA for highest-risk processing activities.
📊 DPDPA Healthcare — At a Glance
₹250 Cr
Maximum penalty — data security breach. Healthcare faces the highest exposure of any sector.
₹200 Cr
Breach concealment penalty. Every ransomware attack that is not reported triggers this.
9
Core obligations — every one rated Critical for healthcare providers.
12 Weeks
Full compliance implementation roadmap — starting from zero.
May 2027
Enforcement deadline. The Board has signalled healthcare as a priority sector.
Healthcare DPDPA Compliance Requires Specialist Expertise
No two hospitals are alike in their data architecture, vendor ecosystem, or regulatory obligations. A consent framework designed for a corporate hospital chain cannot be adapted for a standalone clinic, a telemedicine platform, or a diagnostic lab network. DPDPA compliance in healthcare requires a practitioner who understands both the law and the operational reality of how healthcare data actually moves.
Our Healthcare DPDPA Compliance Programme covers the full scope: data mapping across clinical and administrative systems, purpose-specific consent architecture, patient privacy notice drafting, vendor DPA execution for your EHR and cloud providers, breach response planning, Grievance Officer setup, staff training, and a final compliance certification — all customised to your institution type, size, and operating model.
We work with hospitals, diagnostic chains, telemedicine platforms, health-tech companies, and pharmaceutical research organisations across India. Every engagement is led by a qualified advocate specialising in health law and data protection.