DPDP Insights › Healthcare and hospitals
Patients tell doctors things they tell nobody else, and many people touch the same record: front desk, doctors, nurses, labs, billing, insurers and TPAs. Treatment itself usually rests on the purpose the patient came for, and a medical emergency allows action without consent. Almost everything around treatment still needs a notice, a reason and proper care, and several health laws add their own confidentiality rules.
Open the interactive tool for this sectorNotice, request log, retention schedule, vendor clause and breach notice.
| Rule | What it says | What it means alongside DPDP | Source |
|---|---|---|---|
| Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002 | Regulation 1.3.1: keep indoor patients' medical records for 3 years from the start of treatment. Regulation 1.3.2: issue records to patients, authorised attendants or legal authorities within 72 hours of a request. Regulation 2.2: keep patient confidences. | Set retention at or above these minimums. Use the 72-hour record copy rule as the base for patient access requests. | Code of Medical Ethics, 2002 |
| Telemedicine Practice Guidelines, 2020 (Appendix 5 to the 2002 Regulations) | Consent is implied when the patient starts a teleconsultation and must be explicit when a health worker or caregiver starts it. The doctor records consent and keeps logs, records and prescriptions as for in-person care. | Telemedicine apps must add DPDP notices and protect chat, video and prescription data. | MoHFW |
| Pre-Conception and Pre-Natal Diagnostic Techniques (PCPNDT) Act, 1994 | Records of tests and procedures, including Form F, must be preserved for 2 years, or until a legal proceeding ends. | These records cannot be erased early on request; protect them carefully. | Tamil Nadu health department FAQ |
| Medical Termination of Pregnancy Regulations, 2003 | The admission register is a secret document, kept by the head of the hospital, not open to inspection except under law, and kept for five years. | MTP records need the tightest access in the hospital. | MTP Regulations |
| Mental Healthcare Act, 2017 | Section 23: right to confidentiality. Section 24: no photos or information to media without consent. Section 25: right to access basic medical records. | Psychiatry and counselling records need separate access and a careful request process. | NHSRC copy of the Act |
| HIV and AIDS (Prevention and Control) Act, 2017 | HIV status may be disclosed only with informed consent, except in narrow cases. Establishments keeping HIV-related records must adopt data protection measures. | Restrict HIV results and counselling notes to the treating team. | Act |
| New Drugs and Clinical Trials Rules, 2019 | Informed consent of trial participants; ethics committees keep records for five years after the trial ends (Rule 13). | Trial data needs both informed consent and DPDP safeguards. | NDCT Rules |
| Drugs Rules: Schedule H1 register | Pharmacies record prescriber's name and address, patient's name, drug and quantity, kept for three years. | Keep the register for three years, then dispose of it. | NHSRC |
| ABDM Health Data Management Policy | For entities in the Ayushman Bharat Digital Mission, health records are shared through a consent manager, with consent artefacts for each request. | If you are ABDM-linked, the ABDM consent flow and your DPDP notices must agree. | ABDM / NHA |
| Clinical Establishments Act, 2010 and Rules, 2012 (states that adopted it) | Registered establishments maintain medical records, and electronic records as the government specifies. | Check whether your state follows this Act or its own nursing home law. | MoHFW |
| IRDAI health insurance master circular, 2024 | Insurers decide cashless requests within one hour and final discharge within three hours. | Fast TPA sharing is needed, but only the records the claim needs, through secure channels. | IRDAI |
| CERT-In Directions, 2022 | Report specified cyber incidents within six hours; keep ICT logs 180 days in India. | A ransomware attack needs a CERT-In report and the DPDP messages. | CERT-In |