InfraVeritas360DPDPiq

DPDP Insights › Healthcare and hospitals › CEO / MD

Healthcare and hospitals

DPDP for the CEO / MD in Healthcare

Patients trust your hospital with their care and their secrets. Under DPDP, you need to be able to show that trust is kept.

Open this seat in the interactive tool

What is different here

Most of what you hold is about illness. The people handling it are busy clinicians, not data specialists. The cost is mostly training, access control and vendor contracts.

The first four things to sort out

  1. Put patient-data safety on the same review as clinical quality and accreditation.
  2. Fund role-based access in the HIS and end shared logins on wards.
  3. Ask for one list of every lab, TPA, insurer and software vendor that receives patient data.
  4. Name who speaks to patients and the media if records leak.

A worked example: Starting the plan to May 2027

  1. Month 1A privacy lead is named with authority and a budget line.
  2. Month 2Shared ward logins are replaced with named access on two pilot wards.
  3. Month 4Lab, TPA and software vendor contracts get data terms.
  4. Each quarterThe board sees incidents, requests and progress with evidence.

Evidence kept: Appointment; Pilot report; Contract list; Board notes.

One owner and a dated plan.

What others in the sector usually do. Bigger hospital groups run security programmes next to accreditation work and keep consent for treatment separate from consent for research, marketing and insurers.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Multi-specialty hospital chainShared logins on ward computers; Reports forwarded on messaging apps; VIP or staff records viewed out of curiosity
Standalone hospital or nursing homePaper case sheets at nursing stations; Vendor remote access to the hospital software; Records room with no access log
Diagnostic labs and imagingReport links sent to the wrong number; Franchisees keeping patient lists; PCPNDT records and images
Health-tech and telemedicineAnalytics and ad SDKs in health apps; Chat transcripts kept with no period; Sharing user data with partner pharmacies for offers
Pharmacy chain and e-pharmacyPrescription images in the app and with stores; Refill reminders used for marketing; Delivery partners with addresses and order details

What a good answer from management sounds like

Question to askA good answer sounds likeEffort and time
Do we need DPDP consent to treat a patient?“Treatment rests on the patient's purpose. Research, offers and stories each have a separate, recorded consent.”Light · 3 to 6 weeks
Can we share patient records with insurers and TPAs?“Claims go through portals with only the needed documents, and every transfer is logged.”Light to medium
Can we use patient data for research, audits or case studies?“Research goes through the ethics committee with consent; teaching material is de-identified.”Medium
Do we need a DPO?“We have named an accountable person with a deputy, published the contact, and that person reports to management every month.”Light · 2 to 4 weeks
How much effort and time will it take to be ready by 13 May 2027?“We have a dated plan with named owners. Each month we see evidence, not just colours, and we expect to finish before March 2027.”Programme · six to nine months
Something has gone wrong. What happens in the first 72 hours?“We have one plan that meets every clock. It was rehearsed this year, and the next rehearsal date is fixed.”Medium · 4 to 8 weeks, then a yearly drill
What must a vendor contract say about personal data?“Our top vendors have data terms with a short incident-notice time, and we review them every year.”Medium · 8 to 16 weeks for the top vendors
Could we be a Significant Data Fiduciary?“We have estimated our exposure. If we are notified, we can appoint a DPO and an auditor within weeks, because the groundwork is done.”Medium if you are a likely candidate
Can we send offers to past customers and leads?“Marketing runs only on separate consent. Lead lists are checked, and stop requests take effect within a day.”Light to medium · 4 to 8 weeks

9 guides for the CEO / MD, in full

Do we need DPDP consent to treat a patient?

Short answer: Not for treatment; yes for extra uses

Usually not for the treatment itself. A patient who comes for care gives data voluntarily for that purpose, and a medical emergency involving a threat to life is a listed use. Clinical consent for procedures is a separate medical and legal requirement and stays. Extra uses such as research, marketing, testimonials and sharing beyond what care and billing need do require DPDP consent.

From your seat: CEO / MD. Expect fewer marketing lists; that is the point.
What the law says

Section 7(a) covers data given voluntarily for a specified purpose; Section 7(f) and 7(g) cover emergencies and epidemics. Section 7 · Section 6 · Section 5 · Rule 3

What a good answer from management sounds like: “Treatment rests on the patient's purpose. Research, offers and stories each have a separate, recorded consent.”
Effort and time: Light · 3 to 6 weeks.
Steps
  1. Keep clinical consent forms as they are.
  2. Add a short notice at registration.
  3. Add separate boxes for research, offers and stories.
  4. Record which box each patient ticked.
  5. Train front desk to explain the difference.
Evidence to keep
  • Registration notice
  • Consent records for extra uses
Common mistakes
  • One form that bundles treatment and marketing
  • Calling clinical consent 'DPDP consent'
  • No notice at registration
Related questions

Can we share patient records with insurers and TPAs?

Short answer: Yes for the patient's claim; only what it needs

Yes, for a claim the patient has asked for, because that is part of the purpose. Share only what the claim needs, through the TPA portal or a secure channel, and keep a record of what was sent. Sharing for anything else, such as an insurer's own marketing, needs consent.

From your seat: CEO / MD. Fast cashless and privacy can both work through portals.
What the law says

Section 7(a) covers the claim purpose; Section 8(1) and 8(5) apply to how data is sent. Section 7 · Section 8(5) · Rule 6 · Sections 11–14 · Rule 14

What a good answer from management sounds like: “Claims go through portals with only the needed documents, and every transfer is logged.”
Effort and time: Light to medium.
Steps
  1. Use TPA portals, not email.
  2. Send only claim documents.
  3. Log what was sent, to whom, when.
  4. Answer patient questions about sharing.
  5. Check TPA agreements.
Evidence to keep
  • Sharing log
  • TPA agreement
Common mistakes
  • Full case files by email
  • No record of what was sent
  • Insurer representatives reading records on wards
Related questions

Can we use patient data for research, audits or case studies?

Short answer: Consent or de-identification first

Research with identifiable patients needs informed consent under research rules and DPDP consent for that use. Clinical audit to improve care within the hospital usually fits the treatment purpose. Case studies and teaching material should be de-identified so patients cannot be recognised. Clinical trials follow the NDCT Rules, 2019.

What the law says

Section 6 sets consent; Section 17(2)(b) covers research only where no decision is taken about the person and prescribed standards are followed. Section 6 · Section 7 · Section 8(5) · Rule 6

What a good answer from management sounds like: “Research goes through the ethics committee with consent; teaching material is de-identified.”
Effort and time: Medium.
Steps
  1. Route research through the ethics committee.
  2. Take research consent separately.
  3. De-identify teaching cases and photos.
  4. Limit researcher access.
  5. Delete or anonymise at the end.
Evidence to keep
  • Ethics approvals
  • Research consents
  • De-identification checks
Common mistakes
  • Photos with faces or tattoos in slides
  • Using records for studies without approval
  • Keeping research data with names after the study
Related questions

Do we need a DPO?

Short answer: Not required by law unless notified as an SDF, but name one person

Only a Significant Data Fiduciary must appoint a DPO, based in India. Every other organisation must publish the contact of a person who can answer questions about personal data. In practice, most organisations of any size name one accountable person anyway, because someone has to own requests, complaints and breaches.

From your seat: CEO / MD. The person you name needs your visible backing. Give the role a budget line and ask for a short report every month.
In Healthcare

Hospital chains and large labs should name a privacy lead.

What the law says

Section 8(9) and Rule 9 require a published contact person for every Data Fiduciary. Section 10 requires a DPO in India for Significant Data Fiduciaries. Section 8(9)–(10) · Rules 9, 14 · Section 10 · Rule 13

What a good answer from management sounds like: “We have named an accountable person with a deputy, published the contact, and that person reports to management every month.”
Effort and time: Light · 2 to 4 weeks.
Steps
  1. Name one accountable person, with a deputy.
  2. Publish the contact on your website, app and notices.
  3. Give the role time, a budget line and a route to management.
  4. Set a short monthly report: requests, complaints, incidents, actions.
  5. Review the role if you are notified as an SDF.
Evidence to keep
  • Appointment letter
  • Published contact
  • Monthly report
Common mistakes
  • Giving the job to IT as a side task
  • A contact email nobody reads
  • No authority to make changes
Related questions

How much effort and time will it take to be ready by 13 May 2027?

Short answer: Six to nine months of steady work for most

For most organisations it is a programme of six to nine months, not a single project. The heavy parts are the data inventory, vendor contracts, access control and the request process. Notices, the contact person and training are lighter. Starting now leaves time to fix what you find.

From your seat: CEO / MD. Treat it as a nine-month programme with one owner. The cost is mostly people's time and some system changes, not a single tool.
In Healthcare

Access control and vendor contracts take the longest.

What the law says

Most duties under the DPDP Rules start on 13 May 2027. Section 8(5) · Rule 6 · Section 8(1)–(2) · Sections 11–14 · Rule 14

What a good answer from management sounds like: “We have a dated plan with named owners. Each month we see evidence, not just colours, and we expect to finish before March 2027.”
Effort and time: Programme · six to nine months.
Steps
  1. Month 1: name the owner, set a budget line, start the inventory.
  2. Months 2 to 3: notices, consent records, contact person, request register.
  3. Months 3 to 6: vendor contracts, access control, logs, retention schedule.
  4. Months 6 to 8: breach rehearsal, training, internal review.
  5. Month 9: management review with evidence.
Evidence to keep
  • Programme plan with owners
  • Monthly status with evidence
  • Management minutes
Common mistakes
  • Leaving it to the last quarter
  • Buying a tool before knowing the gaps
  • Status colours with no evidence behind them
Related questions

Something has gone wrong. What happens in the first 72 hours?

Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report

Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.

From your seat: CEO / MD. You will be the public face if something goes wrong. Know who calls you, at what hour, and who speaks to customers and the media.
In Healthcare

A ransomware attack on the HIS needs a CERT-In report in six hours and the DPDP messages.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6

What a good answer from management sounds like: “We have one plan that meets every clock. It was rehearsed this year, and the next rehearsal date is fixed.”
Effort and time: Medium · 4 to 8 weeks, then a yearly drill.
Steps
  1. Name one incident lead and a back-up, with phone numbers that work at night.
  2. Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
  3. Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
  4. Decide in advance who signs off each message.
  5. Rehearse once a year with the people who would actually be called.
Evidence to keep
  • Incident plan with clocks
  • Rehearsal record
  • Incident log with times of each step
Common mistakes
  • Waiting to finish the investigation before telling anyone
  • Treating a wrong email or a lost laptop as 'not a breach'
  • Only IT knowing the plan
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: CEO / MD. Ask for the top ten vendors by personal data held. If the list takes weeks to produce, that is the first gap.
In Healthcare

Labs, teleradiology, HIS vendors, TPAs and ambulance services.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

What a good answer from management sounds like: “Our top vendors have data terms with a short incident-notice time, and we review them every year.”
Effort and time: Medium · 8 to 16 weeks for the top vendors.
Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Could we be a Significant Data Fiduciary?

Short answer: Only by notification; none notified yet

Only the government can notify an organisation or a class of organisations as a Significant Data Fiduciary, based on the volume and sensitivity of data and the risk to people or the State. None had been notified when this page was last reviewed. Large holders of sensitive data should plan as if it could happen.

From your seat: CEO / MD. Ask management for a short note on whether you could be notified, and what it would take to be ready.
In Healthcare

Large hospital chains and health platforms hold sensitive data at scale; plan as a possible candidate.

What the law says

Section 10 and Rule 13 set the extra duties: a DPO in India, an independent data auditor, a yearly Data Protection Impact Assessment and audit, and checks on algorithms. Rule 13(4) allows the government to restrict some data from leaving India. Section 10 · Rule 13 · Section 16 · Rule 15

What a good answer from management sounds like: “We have estimated our exposure. If we are notified, we can appoint a DPO and an auditor within weeks, because the groundwork is done.”
Effort and time: Medium if you are a likely candidate.
Steps
  1. Estimate how many people's data you hold and how sensitive it is.
  2. Note any public or security role your data plays.
  3. If you are a likely candidate, run a trial impact assessment this year.
  4. Identify an auditor you could appoint.
  5. Watch MeitY notifications.
Evidence to keep
  • Volume and sensitivity note
  • Trial impact assessment
  • Board note
Common mistakes
  • Assuming 'not notified' means 'never'
  • Waiting for notification to start
  • Thinking only tech companies will be notified
Related questions

Can we send offers to past customers and leads?

Short answer: Only with separate consent and an easy way to stop

Marketing needs consent that is separate and specific, unless the person clearly expects it from the relationship. Bought or scraped lead lists are risky because you cannot show consent. Every message should carry an easy way to stop.

From your seat: CEO / MD. Growth teams feel this first. Back the rule that marketing runs only on clear consent; it protects the brand.
In Healthcare

Health package offers to past patients need separate consent.

What the law says

Section 6 sets the consent standard. Section 5 needs a notice. Section 9 bars targeted advertising at children. Section 6 · Section 5 · Rule 3 · Section 9 · Rules 10, 12

What a good answer from management sounds like: “Marketing runs only on separate consent. Lead lists are checked, and stop requests take effect within a day.”
Effort and time: Light to medium · 4 to 8 weeks.
Steps
  1. Separate service messages from marketing messages.
  2. Ask marketing consent separately, with a clear action.
  3. Stop using bought lists unless the seller can show consent for you.
  4. Add an easy stop option to every message.
  5. Respect the telecom preference rules for calls and SMS.
Evidence to keep
  • Marketing consent records
  • Lead source records
  • Stop requests and their handling
Common mistakes
  • Treating account sign-up as marketing consent
  • Agency lists with no consent proof
  • A stop option that does not work
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for healthcare and hospitals.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002Regulation 1.3.1: keep indoor patients' medical records for 3 years from the start of treatment. Regulation 1.3.2: issue records to patients, authorised attendants or legal authorities within 72 hours of a request. Regulation 2.2: keep patient confidences.Set retention at or above these minimums. Use the 72-hour record copy rule as the base for patient access requests.Code of Medical Ethics, 2002
Telemedicine Practice Guidelines, 2020 (Appendix 5 to the 2002 Regulations)Consent is implied when the patient starts a teleconsultation and must be explicit when a health worker or caregiver starts it. The doctor records consent and keeps logs, records and prescriptions as for in-person care.Telemedicine apps must add DPDP notices and protect chat, video and prescription data.MoHFW
Pre-Conception and Pre-Natal Diagnostic Techniques (PCPNDT) Act, 1994Records of tests and procedures, including Form F, must be preserved for 2 years, or until a legal proceeding ends.These records cannot be erased early on request; protect them carefully.Tamil Nadu health department FAQ
Medical Termination of Pregnancy Regulations, 2003The admission register is a secret document, kept by the head of the hospital, not open to inspection except under law, and kept for five years.MTP records need the tightest access in the hospital.MTP Regulations
Mental Healthcare Act, 2017Section 23: right to confidentiality. Section 24: no photos or information to media without consent. Section 25: right to access basic medical records.Psychiatry and counselling records need separate access and a careful request process.NHSRC copy of the Act
HIV and AIDS (Prevention and Control) Act, 2017HIV status may be disclosed only with informed consent, except in narrow cases. Establishments keeping HIV-related records must adopt data protection measures.Restrict HIV results and counselling notes to the treating team.Act
New Drugs and Clinical Trials Rules, 2019Informed consent of trial participants; ethics committees keep records for five years after the trial ends (Rule 13).Trial data needs both informed consent and DPDP safeguards.NDCT Rules
Drugs Rules: Schedule H1 registerPharmacies record prescriber's name and address, patient's name, drug and quantity, kept for three years.Keep the register for three years, then dispose of it.NHSRC
ABDM Health Data Management PolicyFor entities in the Ayushman Bharat Digital Mission, health records are shared through a consent manager, with consent artefacts for each request.If you are ABDM-linked, the ABDM consent flow and your DPDP notices must agree.ABDM / NHA
Clinical Establishments Act, 2010 and Rules, 2012 (states that adopted it)Registered establishments maintain medical records, and electronic records as the government specifies.Check whether your state follows this Act or its own nursing home law.MoHFW
IRDAI health insurance master circular, 2024Insurers decide cashless requests within one hour and final discharge within three hours.Fast TPA sharing is needed, but only the records the claim needs, through secure channels.IRDAI
CERT-In Directions, 2022Report specified cyber incidents within six hours; keep ICT logs 180 days in India.A ransomware attack needs a CERT-In report and the DPDP messages.CERT-In
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.