Hospitals, clinics, diagnostic labs, pharmacies and health-tech apps hold some of the most personal data there is: diagnoses, prescriptions, test reports, insurance details and identity documents. Every one of these organisations that processes digital personal data is a Data Fiduciary under the Digital Personal Data Protection Act 2023.
How DPDP applies to healthcare
- No separate "sensitive" category: the Act protects all personal data in the same framework, but a health data breach is exactly the kind of failure that attracts the highest penalties for inadequate security safeguards.
- Medical emergencies: the Act allows processing without consent to respond to a medical emergency involving a threat to life or health. Routine treatment, billing, follow-ups and marketing still need a clear lawful basis.
- Children: paediatric records involve children's data, which normally needs verifiable parental consent. The Rules provide limited exemptions for healthcare professionals and clinical establishments, but only for the purposes those exemptions cover.
- Existing frameworks: clinical-records retention requirements and digital-health programmes continue to apply alongside DPDP.
Gaps commonly found in healthcare
- Registration forms that collect far more than treatment needs, with no itemised notice
- Test reports and prescriptions shared over personal WhatsApp or email accounts
- Shared logins on hospital information systems, making access impossible to attribute
- Patient data sent to labs, TPAs, insurers and software vendors without processor contracts
- Health-tech apps collecting location, contacts or device data unrelated to care
- Patient data used for marketing of health packages without separate consent
- No process for patients to access, correct or ask for erasure of their records
Priorities before May 2027
- Map patient data flows across OPD, IPD, labs, pharmacy, billing and third parties.
- Rewrite registration and consent forms into itemised, plain-language notices.
- Enforce individual logins, role-based access and one-year log retention on clinical systems.
- Put processor clauses into lab, TPA, cloud and software vendor contracts.
- Rehearse a breach of patient records against the 72-hour reporting requirement.
For the full timeline, see DPDP Rules 2025 explained, and use the DPDP audit checklist to self-assess.
