InfraVeritas360DPDPiq

DPDP Insights › Healthcare and hospitals › Finance department

Healthcare and hospitals

DPDP for the Finance department in Healthcare

Billing and finance hold bills, insurance claims and payments.

Open this seat in the interactive tool

What is different here

Patients tell doctors things they tell nobody else, and many people touch the same record: front desk, doctors, nurses, labs, billing, insurers and TPAs. Treatment itself usually rests on the purpose the patient came for, and a medical emergency allows action without consent. Almost everything around treatment still needs a notice, a reason and proper care, and several health laws add their own confidentiality rules.

The first four things to sort out

  1. Claim files to TPAs only through portals.
  2. Limit diagnosis on bills.
  3. Retention.
  4. Payment data.

A worked example: Claim files emailed to a TPA

  1. Week 1Billing emails full case files.
  2. Week 2TPA portal is used instead.
  3. Week 3Only claim-needed documents go.
  4. AfterEmail stopped.

Evidence kept: Process change.

Send only what the claim needs.

What others in the sector usually do. TPA portals over email.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Multi-specialty hospital chainShared logins on ward computers; Reports forwarded on messaging apps; VIP or staff records viewed out of curiosity
Standalone hospital or nursing homePaper case sheets at nursing stations; Vendor remote access to the hospital software; Records room with no access log
Diagnostic labs and imagingReport links sent to the wrong number; Franchisees keeping patient lists; PCPNDT records and images
Health-tech and telemedicineAnalytics and ad SDKs in health apps; Chat transcripts kept with no period; Sharing user data with partner pharmacies for offers
Pharmacy chain and e-pharmacyPrescription images in the app and with stores; Refill reminders used for marketing; Delivery partners with addresses and order details

8 guides for the Finance department, in full

Can we share patient records with insurers and TPAs?

Short answer: Yes for the patient's claim; only what it needs

Yes, for a claim the patient has asked for, because that is part of the purpose. Share only what the claim needs, through the TPA portal or a secure channel, and keep a record of what was sent. Sharing for anything else, such as an insurer's own marketing, needs consent.

From your seat: Finance department. Billing owns this flow.
What the law says

Section 7(a) covers the claim purpose; Section 8(1) and 8(5) apply to how data is sent. Section 7 · Section 8(5) · Rule 6 · Sections 11–14 · Rule 14

Steps
  1. Use TPA portals, not email.
  2. Send only claim documents.
  3. Log what was sent, to whom, when.
  4. Answer patient questions about sharing.
  5. Check TPA agreements.
Evidence to keep
  • Sharing log
  • TPA agreement
Common mistakes
  • Full case files by email
  • No record of what was sent
  • Insurer representatives reading records on wards
Related questions

How long should we keep patient records?

Short answer: At least the legal minimums, with a written reason for anything longer

Keep them for at least the periods health laws set: indoor records for three years from the start of treatment under the 2002 medical ethics regulations, PCPNDT records for two years, MTP registers for five years, Schedule H1 registers for three years, and ethics committee trial records for five years after a trial. Many hospitals keep records longer for continuity of care and legal claims. Write the period and reason for each record type, then erase or archive.

What the law says

Section 8(7) allows retention where a law requires it; Rule 8(3) sets a one-year floor. Section 8(7) · Rule 8 · Section 7

Steps
  1. List record types: OPD, IPD, lab, imaging, billing, PCPNDT, MTP, pharmacy.
  2. Note the legal minimum.
  3. Decide any longer period and why.
  4. Archive with restricted access.
  5. Record each deletion.
Evidence to keep
  • Retention schedule
  • Archive access list
  • Deletion log
Common mistakes
  • No schedule at all
  • Deleting before the minimum
  • Keeping open access to old records
Related questions

How long can we keep personal data?

Short answer: For the legal or business period, then erase

Keep data for as long as its purpose needs, or as long as a law requires, and then erase it. Every organisation must keep personal data and logs for at least one year under Rule 8(3). Write a retention schedule by record type, with the law or reason against each period.

From your seat: Finance department. Tax and audit rules require keeping some records for years. List them so they are kept, and the rest is deleted.
In Healthcare

Indoor records at least 3 years (2002 regulations), PCPNDT 2 years, MTP 5 years, Schedule H1 3 years.

What the law says

Section 8(7) asks for erasure when the purpose is over, unless a law requires retention. Rule 8(3) sets a one-year minimum for personal data, traffic data and logs. Section 8(7) · Rule 8 · Section 8(5) · Rule 6

Steps
  1. List the record types you hold.
  2. Write the period for each, with the law, regulator rule or business reason.
  3. Set a trigger for the period to start: end of relationship, date of transaction, exit date.
  4. Automate deletion where you can; for paper, schedule shredding.
  5. Keep a deletion log.
Evidence to keep
  • Retention schedule approved by Legal
  • Deletion log
  • Shredding or disposal certificates
Common mistakes
  • 'Keep everything forever' because storage is cheap
  • Deleting before the legal minimum
  • Forgetting email, shared drives and backups
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: Finance department. Payroll, payment and collection vendors hold sensitive data. Check their contracts.
In Healthcare

Labs, teleradiology, HIS vendors, TPAs and ambulance services.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Who should be able to see personal data in our systems?

Short answer: Only those who need it, reviewed every quarter

Only people who need it for their job, and only the part they need. Use named accounts, give access by role, review it every quarter and remove it on the day someone leaves. Watch privileged accounts closely.

From your seat: Finance department. Limit who can see bank details and salary data, and log access.
In Healthcare

End shared ward logins; flag VIP and staff records.

What the law says

Rule 6 names access control as a minimum safeguard, along with logs and monitoring that can detect misuse. Section 8(5) · Rule 6

Steps
  1. Write a role matrix for each key system.
  2. Replace shared logins with named accounts.
  3. Use multi-factor sign-in for admin and remote access.
  4. Review access every quarter with each manager.
  5. Remove access on the last working day.
Evidence to keep
  • Role matrix
  • Quarterly review sign-offs
  • Leaver removal report
Common mistakes
  • Generic logins on shared machines
  • Access that only grows
  • No review of vendor accounts
Related questions

Do we need consent for employee data?

Short answer: Not for employment purposes; yes for anything extra

Usually not for normal employment purposes. Section 7(i) lets you process employee data for employment, such as payroll, attendance, safety and preventing corporate espionage. Anything beyond that, such as wellness apps, photos for marketing or sharing with a bank for offers, needs consent.

From your seat: Finance department. Salary and bank details are employment data; sharing them beyond employment needs care.
In Healthcare

Staff health and vaccination records are sensitive; keep them apart from HR files.

What the law says

Section 7(i) covers employment purposes and safeguarding the employer from loss or liability. Notice, security, retention and rights still apply to employees. Section 7 · Section 5 · Rule 3 · Section 8(7) · Rule 8 · Sections 11–14 · Rule 14

Steps
  1. List what you collect from staff and why.
  2. Mark which items are employment purposes and which are extra.
  3. Take consent for the extras, separately.
  4. Give staff a short employee privacy notice.
  5. Set retention for ex-employee records.
Evidence to keep
  • Employee data list with basis
  • Employee privacy notice
  • Consent for extras
Common mistakes
  • A blanket consent clause in the offer letter
  • Keeping candidate data forever
  • Sharing staff data with vendors without terms
Related questions

Something has gone wrong. What happens in the first 72 hours?

Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report

Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.

From your seat: Finance department. A misdirected salary file or payment list is a breach. Report it to the DPO at once.
In Healthcare

A ransomware attack on the HIS needs a CERT-In report in six hours and the DPDP messages.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6

Steps
  1. Name one incident lead and a back-up, with phone numbers that work at night.
  2. Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
  3. Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
  4. Decide in advance who signs off each message.
  5. Rehearse once a year with the people who would actually be called.
Evidence to keep
  • Incident plan with clocks
  • Rehearsal record
  • Incident log with times of each step
Common mistakes
  • Waiting to finish the investigation before telling anyone
  • Treating a wrong email or a lost laptop as 'not a breach'
  • Only IT knowing the plan
Related questions

Can personal data be stored or accessed outside India?

Short answer: Yes, unless a sector rule says otherwise

Under DPDP, yes, unless the government restricts a country, and none had been restricted when this page was last reviewed. A sector rule can be stricter, for example RBI's rule that payment system data must be stored only in India. Remote support access from abroad also counts as data going outside India.

From your seat: Finance department. Check where finance and payroll SaaS is hosted.
In Healthcare

Teleradiology and some software vendors use teams abroad; this is a transfer.

What the law says

Section 16 allows transfers unless restricted, and keeps stricter sector laws in force. Rule 15 adds conditions on making data available to foreign states. Section 16 · Rule 15 · Section 8(1)–(2)

Steps
  1. List where each system is hosted and where support teams log in from.
  2. Check sector rules for localisation.
  3. Put location and access terms in cloud and vendor contracts.
  4. Keep the list current; new SaaS tools change it quietly.
  5. Tell people in your notice if data goes abroad.
Evidence to keep
  • Hosting and access-location list
  • Contract clauses
  • Sector rule check
Common mistakes
  • Forgetting email, CRM and helpdesk SaaS
  • Ignoring overseas support logins
  • Assuming 'Indian vendor' means 'data in India'
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for healthcare and hospitals.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002Regulation 1.3.1: keep indoor patients' medical records for 3 years from the start of treatment. Regulation 1.3.2: issue records to patients, authorised attendants or legal authorities within 72 hours of a request. Regulation 2.2: keep patient confidences.Set retention at or above these minimums. Use the 72-hour record copy rule as the base for patient access requests.Code of Medical Ethics, 2002
Telemedicine Practice Guidelines, 2020 (Appendix 5 to the 2002 Regulations)Consent is implied when the patient starts a teleconsultation and must be explicit when a health worker or caregiver starts it. The doctor records consent and keeps logs, records and prescriptions as for in-person care.Telemedicine apps must add DPDP notices and protect chat, video and prescription data.MoHFW
Pre-Conception and Pre-Natal Diagnostic Techniques (PCPNDT) Act, 1994Records of tests and procedures, including Form F, must be preserved for 2 years, or until a legal proceeding ends.These records cannot be erased early on request; protect them carefully.Tamil Nadu health department FAQ
Medical Termination of Pregnancy Regulations, 2003The admission register is a secret document, kept by the head of the hospital, not open to inspection except under law, and kept for five years.MTP records need the tightest access in the hospital.MTP Regulations
Mental Healthcare Act, 2017Section 23: right to confidentiality. Section 24: no photos or information to media without consent. Section 25: right to access basic medical records.Psychiatry and counselling records need separate access and a careful request process.NHSRC copy of the Act
HIV and AIDS (Prevention and Control) Act, 2017HIV status may be disclosed only with informed consent, except in narrow cases. Establishments keeping HIV-related records must adopt data protection measures.Restrict HIV results and counselling notes to the treating team.Act
New Drugs and Clinical Trials Rules, 2019Informed consent of trial participants; ethics committees keep records for five years after the trial ends (Rule 13).Trial data needs both informed consent and DPDP safeguards.NDCT Rules
Drugs Rules: Schedule H1 registerPharmacies record prescriber's name and address, patient's name, drug and quantity, kept for three years.Keep the register for three years, then dispose of it.NHSRC
ABDM Health Data Management PolicyFor entities in the Ayushman Bharat Digital Mission, health records are shared through a consent manager, with consent artefacts for each request.If you are ABDM-linked, the ABDM consent flow and your DPDP notices must agree.ABDM / NHA
Clinical Establishments Act, 2010 and Rules, 2012 (states that adopted it)Registered establishments maintain medical records, and electronic records as the government specifies.Check whether your state follows this Act or its own nursing home law.MoHFW
IRDAI health insurance master circular, 2024Insurers decide cashless requests within one hour and final discharge within three hours.Fast TPA sharing is needed, but only the records the claim needs, through secure channels.IRDAI
CERT-In Directions, 2022Report specified cyber incidents within six hours; keep ICT logs 180 days in India.A ransomware attack needs a CERT-In report and the DPDP messages.CERT-In
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.