InfraVeritas360DPDPiq

DPDP Insights › Healthcare and hospitals › CIO / IT head

Healthcare and hospitals

DPDP for the CIO / IT head in Healthcare

Patient data lives in the HIS, PACS, LIS, pharmacy, billing, apps and often ABDM links.

Open this seat in the interactive tool

What is different here

Many systems are vendor-hosted and connected by interfaces that copy data. Each copy needs to be known before a patient's request can be answered.

The first four things to sort out

  1. List systems and interfaces with patient data.
  2. Check where vendors host and support from.
  3. Plan deletion and archive by record type.
  4. Align ABDM consent flows with DPDP notices.

A worked example: Finding every copy of a patient record

  1. Week 1IT lists systems: HIS, PACS, LIS, pharmacy, billing, the patient app, and the ABDM gateway.
  2. Week 2Interfaces are traced: lab results copy into the HIS and the app; images go to a teleradiology vendor.
  3. Week 3A test patient's data is searched across all copies.
  4. AfterThe map becomes the base for requests and retention.

Evidence kept: System and interface map; Test search record.

Interfaces create copies nobody remembers.

What others in the sector usually do. Hospitals are using the ABDM integration project to clean up their patient master data.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Multi-specialty hospital chainShared logins on ward computers; Reports forwarded on messaging apps; VIP or staff records viewed out of curiosity
Standalone hospital or nursing homePaper case sheets at nursing stations; Vendor remote access to the hospital software; Records room with no access log
Diagnostic labs and imagingReport links sent to the wrong number; Franchisees keeping patient lists; PCPNDT records and images
Health-tech and telemedicineAnalytics and ad SDKs in health apps; Chat transcripts kept with no period; Sharing user data with partner pharmacies for offers
Pharmacy chain and e-pharmacyPrescription images in the app and with stores; Refill reminders used for marketing; Delivery partners with addresses and order details

Control map: DPDP to NIST CSF 2.0 and ISO/IEC 27001:2022

DPDP dutyLawNIST CSF 2.0ISO/IEC 27001 Annex AEvidence
Know where personal data isSection 8(5) · Rule 6ID.AM-02, ID.AM-075.9, 5.12Inventory of systems and data types, with owner and hosting location
Only the right people get inSection 8(5) · Rule 6PR.AA-01, PR.AA-055.15, 5.16, 5.18, 8.2Role matrix, quarterly access review sign-off, leaver removal report
Strong sign-in for admins and remote usersSection 8(5) · Rule 6PR.AA-035.17, 8.5MFA enforcement report for admin, VPN and email accounts
Encrypt or mask dataSection 8(5) · Rule 6PR.DS-01, PR.DS-028.11, 8.24Encryption settings for databases, laptops, backups and transfers; masking in test copies
Keep and watch logsSection 8(5) · Rule 6PR.PS-04, DE.CM-01, DE.CM-038.15, 8.16, 8.17Log retention settings (one year; 180 days in India for CERT-In), alert rules, NTP source
Backups that restoreSection 8(5) · Rule 6PR.DS-11, RC.RP-038.13, 5.30Backup schedule, offline copy, last restore test with date and result
Separate networksSection 8(5) · Rule 6PR.IR-018.20, 8.22Network diagram showing segments, firewall rule review
Patch and fix weaknessesSection 8(5) · Rule 6ID.RA-018.8Vulnerability scan results and closure tracker
Handle incidents and tell peopleSection 8(6) · Rule 7RS.MA-01, RS.CO-02, RS.CO-035.24, 5.25, 5.26, 6.8Incident plan with the 6-hour and 72-hour steps, drill record, contact list
Learn from incidentsSection 8(6) · Rule 7DE.AE-02, ID.IM-015.27, 5.28Post-incident review and actions closed
Vendors protect data tooSection 8(1)–(2)GV.SC-05, GV.SC-075.19, 5.20, 5.22Contracts with data terms, vendor review record
Data comes back or is deleted at contract endSection 8(7) · Rule 8GV.SC-105.20, 8.10Exit clause and deletion certificate from the vendor
Cloud is set up safelySection 16 · Rule 15GV.SC-05, PR.DS-015.23Cloud region list, shared-responsibility note, configuration review
Delete when the purpose is overSection 8(7) · Rule 8PR.DS-018.10, 7.14Retention schedule, deletion log, disposal certificates for disks and paper
People know the rulesSection 8(5) · Rule 6PR.AT-016.3Training attendance and short test results by department
Legal duties are trackedSection 8(5) · Rule 6GV.OC-035.31, 5.34Register of laws and rules that apply, reviewed yearly
Roles are namedSection 8(9)–(10) · Rules 9, 14GV.RR-025.2, 5.4Named owners for each system and each duty, approved by management

Logs, backups and access checklist

10 guides for the CIO / IT head, in full

We are linked to ABDM. How does its consent fit with DPDP?

Short answer: Both apply; align the wording

ABDM uses a consent manager and consent artefacts to share health records between providers. That consent covers ABDM sharing. You still need your own DPDP notice for what you collect, and your own safeguards, retention and grievance process. The two should use the same plain language so patients are not confused.

From your seat: CIO / IT head. Map the ABDM interfaces.
What the law says

Section 5 and 6 for your own notice and consent; ABDM's policy for ABDM sharing. Section 5 · Rule 3 · Section 6 · Section 8(5) · Rule 6

Steps
  1. Map what goes through ABDM and what does not.
  2. Align notices with ABDM screens.
  3. Log ABDM consent requests.
  4. Keep safeguards on the gateway.
  5. Train front desk on ABHA linking.
Evidence to keep
  • Flow map
  • Aligned notices
  • Gateway logs
Common mistakes
  • Assuming ABDM consent covers everything
  • ABHA linking without explanation
  • Gateway with weak access
Related questions

Imaging machines and lab analysers hold patient data. What do we do?

Short answer: Separate network, controlled vendor access, wipe before disposal

Imaging and lab devices store names, ages and results, often on old operating systems. Put them on a separate network, control vendor remote access, change default passwords, and wipe disks before a device is returned or scrapped.

From your seat: CIO / IT head. Plan upgrades for old device software.
What the law says

Rule 6 safeguards apply to devices that store personal data. Section 8(5) · Rule 6 · Section 8(7) · Rule 8

Steps
  1. List devices that store patient data.
  2. Segment them.
  3. Control vendor remote access.
  4. Change default passwords.
  5. Wipe before disposal.
Evidence to keep
  • Device list
  • Network diagram
  • Wipe certificates
Common mistakes
  • Devices on the general network
  • Vendor modems always on
  • Disks leaving with old machines
Related questions

How long should we keep patient records?

Short answer: At least the legal minimums, with a written reason for anything longer

Keep them for at least the periods health laws set: indoor records for three years from the start of treatment under the 2002 medical ethics regulations, PCPNDT records for two years, MTP registers for five years, Schedule H1 registers for three years, and ethics committee trial records for five years after a trial. Many hospitals keep records longer for continuity of care and legal claims. Write the period and reason for each record type, then erase or archive.

From your seat: CIO / IT head. Archive tiers for old records.
What the law says

Section 8(7) allows retention where a law requires it; Rule 8(3) sets a one-year floor. Section 8(7) · Rule 8 · Section 7

Steps
  1. List record types: OPD, IPD, lab, imaging, billing, PCPNDT, MTP, pharmacy.
  2. Note the legal minimum.
  3. Decide any longer period and why.
  4. Archive with restricted access.
  5. Record each deletion.
Evidence to keep
  • Retention schedule
  • Archive access list
  • Deletion log
Common mistakes
  • No schedule at all
  • Deleting before the minimum
  • Keeping open access to old records
Related questions

Where does personal data live in our organisation?

Short answer: Start with one row per system

Usually in more places than anyone expects: core systems, email, shared drives, laptops, vendor systems, backups, test copies, spreadsheets and paper. A simple inventory, one row per system, is the base for every other duty.

From your seat: CIO / IT head. Start from your application list and cloud bills. Each system needs an owner, a hosting location and a list of the vendors that touch it.
In Healthcare

HIS, PACS, LIS, pharmacy, billing, apps, ABDM gateway and devices.

What the law says

Every duty in Sections 5 to 12 assumes you know where the data is. Rule 6 needs safeguards for each system, and Section 11 needs you to find the data when someone asks. Section 8(5) · Rule 6 · Sections 11–14 · Rule 14 · Section 8(7) · Rule 8

Steps
  1. List systems, then shared drives, email, spreadsheets and paper stores.
  2. For each one, note whose data, which items, purpose, owner, hosting location and vendors.
  3. Add copies: backups, test, analytics.
  4. Get each owner to confirm their rows.
  5. Update it whenever a system is bought or retired.
Evidence to keep
  • Data inventory
  • Owner confirmations
  • Change log
Common mistakes
  • A 200-column spreadsheet nobody finishes
  • Leaving out SaaS tools bought by departments
  • No owner for each row
Related questions

Can personal data be stored or accessed outside India?

Short answer: Yes, unless a sector rule says otherwise

Under DPDP, yes, unless the government restricts a country, and none had been restricted when this page was last reviewed. A sector rule can be stricter, for example RBI's rule that payment system data must be stored only in India. Remote support access from abroad also counts as data going outside India.

From your seat: CIO / IT head. SaaS tools bought by departments are the usual surprise. Ask Finance for the list of software subscriptions.
In Healthcare

Teleradiology and some software vendors use teams abroad; this is a transfer.

What the law says

Section 16 allows transfers unless restricted, and keeps stricter sector laws in force. Rule 15 adds conditions on making data available to foreign states. Section 16 · Rule 15 · Section 8(1)–(2)

Steps
  1. List where each system is hosted and where support teams log in from.
  2. Check sector rules for localisation.
  3. Put location and access terms in cloud and vendor contracts.
  4. Keep the list current; new SaaS tools change it quietly.
  5. Tell people in your notice if data goes abroad.
Evidence to keep
  • Hosting and access-location list
  • Contract clauses
  • Sector rule check
Common mistakes
  • Forgetting email, CRM and helpdesk SaaS
  • Ignoring overseas support logins
  • Assuming 'Indian vendor' means 'data in India'
Related questions

Does deletion have to reach backups and test copies?

Short answer: Yes, through a written backup-expiry rule

Deletion should reach every copy you control. For backups, the usual practice is to let deleted records expire with the normal backup cycle, never restore them into live use, and write this down. Test and training copies should use masked data.

From your seat: CIO / IT head. Deletion is an engineering task. Decide how each system deletes, how backups expire, and how test copies are masked.
In Healthcare

Offline backups decide whether care continues during ransomware.

What the law says

Section 8(7) asks for erasure. Rule 6 asks for backups for continuity. The two meet in a backup retention rule that is short enough and written down. Section 8(7) · Rule 8 · Section 8(5) · Rule 6

Steps
  1. List where copies live: backups, replicas, test, analytics, laptops, vendors.
  2. Set backup retention to match the retention schedule.
  3. Write a rule: deleted records are not restored into live systems.
  4. Mask personal data in test and training copies.
  5. Get deletion confirmations from vendors.
Evidence to keep
  • Backup retention settings
  • Written backup-expiry rule
  • Masking procedure for test data
Common mistakes
  • Ten-year backups for convenience
  • Live copies in test
  • Restoring old backups and bringing deleted records back
Related questions

Who should be able to see personal data in our systems?

Short answer: Only those who need it, reviewed every quarter

Only people who need it for their job, and only the part they need. Use named accounts, give access by role, review it every quarter and remove it on the day someone leaves. Watch privileged accounts closely.

From your seat: CIO / IT head. Role-based access needs application changes as well as policy. Budget for it in the next release cycle.
In Healthcare

End shared ward logins; flag VIP and staff records.

What the law says

Rule 6 names access control as a minimum safeguard, along with logs and monitoring that can detect misuse. Section 8(5) · Rule 6

Steps
  1. Write a role matrix for each key system.
  2. Replace shared logins with named accounts.
  3. Use multi-factor sign-in for admin and remote access.
  4. Review access every quarter with each manager.
  5. Remove access on the last working day.
Evidence to keep
  • Role matrix
  • Quarterly review sign-offs
  • Leaver removal report
Common mistakes
  • Generic logins on shared machines
  • Access that only grows
  • No review of vendor accounts
Related questions

Which logs must we keep, for how long, and where?

Short answer: At least one year; 180 days of ICT logs in India

Keep logs that show who accessed personal data and what they did, for at least one year under the DPDP Rules. CERT-In separately asks for ICT system logs to be kept for 180 days within India. Logs must be protected so nobody can quietly change them.

From your seat: CIO / IT head. Make sure applications log who viewed a record, not only system errors. That is what a request or a breach review needs.
In Healthcare

HIS and PACS access logs show who opened which record; keep them a year.

What the law says

Rule 6 lists logs and monitoring as a minimum safeguard. Rule 8(3) asks for logs to be kept for at least one year. The CERT-In Directions of 2022 ask for 180 days of ICT logs kept within India. Section 8(5) · Rule 6 · Section 8(7) · Rule 8

Steps
  1. List systems holding personal data and what each logs today.
  2. Turn on access logging where it is missing.
  3. Send logs to one protected store, with at least one year of retention.
  4. Keep a copy of ICT logs in India for at least 180 days.
  5. Sync clocks and review alerts every day.
Evidence to keep
  • Log source list
  • Retention settings
  • Alert review records
Common mistakes
  • Logging only failures, not who viewed a record
  • Logs stored on the same server they describe
  • Clocks out of sync, so timelines cannot be built
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: CIO / IT head. Your architecture decisions decide which vendors see data. Prefer designs that send vendors only what they need.
In Healthcare

Labs, teleradiology, HIS vendors, TPAs and ambulance services.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Does ISO 27001 or NIST CSF cover our DPDP duties?

Short answer: They cover security, not the whole Act

They help a great deal with the security part. ISO/IEC 27001 and NIST CSF 2.0 are good evidence of reasonable security safeguards. They do not cover notice, consent, rights, complaints or children's data. ISO/IEC 27701 adds privacy controls, but no certificate replaces the Act.

From your seat: CIO / IT head. Keep the mapping current as systems change. A new system without logging or access control undoes the work.
In Healthcare

NABH information management standards and ISO 27001 support Rule 6.

What the law says

Section 8(5) and Rule 6 ask for reasonable security safeguards. A recognised standard is strong evidence of that duty, and only of that duty. Section 8(5) · Rule 6

Steps
  1. Map your current controls to Rule 6.
  2. Add the DPDP-only items: notice, consent, rights, complaints, children, retention.
  3. Use the same evidence for audits and for DPDP.
  4. Include privacy in the scope of your next internal audit.
  5. Consider ISO/IEC 27701 if clients ask for it.
Evidence to keep
  • Control map
  • Audit reports
  • Gap list for DPDP-only items
Common mistakes
  • Treating a certificate as DPDP compliance
  • Scope that leaves out the systems with the most personal data
  • No owner for the non-security duties
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for healthcare and hospitals.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002Regulation 1.3.1: keep indoor patients' medical records for 3 years from the start of treatment. Regulation 1.3.2: issue records to patients, authorised attendants or legal authorities within 72 hours of a request. Regulation 2.2: keep patient confidences.Set retention at or above these minimums. Use the 72-hour record copy rule as the base for patient access requests.Code of Medical Ethics, 2002
Telemedicine Practice Guidelines, 2020 (Appendix 5 to the 2002 Regulations)Consent is implied when the patient starts a teleconsultation and must be explicit when a health worker or caregiver starts it. The doctor records consent and keeps logs, records and prescriptions as for in-person care.Telemedicine apps must add DPDP notices and protect chat, video and prescription data.MoHFW
Pre-Conception and Pre-Natal Diagnostic Techniques (PCPNDT) Act, 1994Records of tests and procedures, including Form F, must be preserved for 2 years, or until a legal proceeding ends.These records cannot be erased early on request; protect them carefully.Tamil Nadu health department FAQ
Medical Termination of Pregnancy Regulations, 2003The admission register is a secret document, kept by the head of the hospital, not open to inspection except under law, and kept for five years.MTP records need the tightest access in the hospital.MTP Regulations
Mental Healthcare Act, 2017Section 23: right to confidentiality. Section 24: no photos or information to media without consent. Section 25: right to access basic medical records.Psychiatry and counselling records need separate access and a careful request process.NHSRC copy of the Act
HIV and AIDS (Prevention and Control) Act, 2017HIV status may be disclosed only with informed consent, except in narrow cases. Establishments keeping HIV-related records must adopt data protection measures.Restrict HIV results and counselling notes to the treating team.Act
New Drugs and Clinical Trials Rules, 2019Informed consent of trial participants; ethics committees keep records for five years after the trial ends (Rule 13).Trial data needs both informed consent and DPDP safeguards.NDCT Rules
Drugs Rules: Schedule H1 registerPharmacies record prescriber's name and address, patient's name, drug and quantity, kept for three years.Keep the register for three years, then dispose of it.NHSRC
ABDM Health Data Management PolicyFor entities in the Ayushman Bharat Digital Mission, health records are shared through a consent manager, with consent artefacts for each request.If you are ABDM-linked, the ABDM consent flow and your DPDP notices must agree.ABDM / NHA
Clinical Establishments Act, 2010 and Rules, 2012 (states that adopted it)Registered establishments maintain medical records, and electronic records as the government specifies.Check whether your state follows this Act or its own nursing home law.MoHFW
IRDAI health insurance master circular, 2024Insurers decide cashless requests within one hour and final discharge within three hours.Fast TPA sharing is needed, but only the records the claim needs, through secure channels.IRDAI
CERT-In Directions, 2022Report specified cyber incidents within six hours; keep ICT logs 180 days in India.A ransomware attack needs a CERT-In report and the DPDP messages.CERT-In
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.