DPDP Audits

DPDP Compliance for Hospitals and Healthcare Providers

How the DPDP Act 2023 applies to hospitals, clinics, diagnostic labs and health-tech platforms, and the patient-data gaps auditors most often find.

By Ram Krishan Dudeja, CISA CAIIB · Last reviewed 25 September 2026

Hospitals, clinics, diagnostic labs, pharmacies and health-tech apps hold some of the most personal data there is: diagnoses, prescriptions, test reports, insurance details and identity documents. Every one of these organisations that processes digital personal data is a Data Fiduciary under the Digital Personal Data Protection Act 2023.

How DPDP applies to healthcare

Gaps commonly found in healthcare

Priorities before May 2027

  1. Map patient data flows across OPD, IPD, labs, pharmacy, billing and third parties.
  2. Rewrite registration and consent forms into itemised, plain-language notices.
  3. Enforce individual logins, role-based access and one-year log retention on clinical systems.
  4. Put processor clauses into lab, TPA, cloud and software vendor contracts.
  5. Rehearse a breach of patient records against the 72-hour reporting requirement.

For the full timeline, see DPDP Rules 2025 explained, and use the DPDP audit checklist to self-assess.

Need an independent DPDP audit?

67 controls, auditor-signed findings, and a remediation roadmap you can act on.

Book a Free Consultation

Related guides

This guide is general information, not legal advice. Refer to the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 as notified for the authoritative text.