InfraVeritas360DPDPiq

DPDP Insights › Healthcare and hospitals › HR department

Healthcare and hospitals

DPDP for the HR department in Healthcare

HR holds staff, resident and agency records.

Open this seat in the interactive tool

What is different here

Patients tell doctors things they tell nobody else, and many people touch the same record: front desk, doctors, nurses, labs, billing, insurers and TPAs. Treatment itself usually rests on the purpose the patient came for, and a medical emergency allows action without consent. Almost everything around treatment still needs a notice, a reason and proper care, and several health laws add their own confidentiality rules.

The first four things to sort out

  1. Staff health records.
  2. Flag staff patients.
  3. Agency terms.
  4. Training.

A worked example: Staff vaccination records on a shared drive

  1. Day 1Found open to all staff.
  2. Day 1Access restricted.
  3. Week 1Moved to HR system.
  4. AfterAssessed by DPO.

Evidence kept: Change.

Health data of staff is sensitive.

What others in the sector usually do. Staff record flags.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Multi-specialty hospital chainShared logins on ward computers; Reports forwarded on messaging apps; VIP or staff records viewed out of curiosity
Standalone hospital or nursing homePaper case sheets at nursing stations; Vendor remote access to the hospital software; Records room with no access log
Diagnostic labs and imagingReport links sent to the wrong number; Franchisees keeping patient lists; PCPNDT records and images
Health-tech and telemedicineAnalytics and ad SDKs in health apps; Chat transcripts kept with no period; Sharing user data with partner pharmacies for offers
Pharmacy chain and e-pharmacyPrescription images in the app and with stores; Refill reminders used for marketing; Delivery partners with addresses and order details

7 guides for the HR department, in full

How do we stop staff looking at records they do not need?

Short answer: Role access, flags and weekly log review

Snooping on VIP, celebrity, colleague or neighbour records is a common problem. Give access by role, mark sensitive records, ask for a reason before opening them, allow break-glass access in emergencies, and review those logs every week.

What the law says

Rule 6 requires access control and monitoring. Section 8(5) · Rule 6 · Section 8(6) · Rule 7

Steps
  1. Flag VIP, staff and sensitive records.
  2. Ask for a reason to open them.
  3. Allow break-glass with review.
  4. Review logs weekly.
  5. Act on misuse consistently.
Evidence to keep
  • Flag settings
  • Review records
  • Action records
Common mistakes
  • Everyone can see everything
  • Break-glass never reviewed
  • No action on misuse
Related questions

Do we need consent for employee data?

Short answer: Not for employment purposes; yes for anything extra

Usually not for normal employment purposes. Section 7(i) lets you process employee data for employment, such as payroll, attendance, safety and preventing corporate espionage. Anything beyond that, such as wellness apps, photos for marketing or sharing with a bank for offers, needs consent.

From your seat: HR department. Prepare the employee privacy notice and give it to every joiner.
In Healthcare

Staff health and vaccination records are sensitive; keep them apart from HR files.

What the law says

Section 7(i) covers employment purposes and safeguarding the employer from loss or liability. Notice, security, retention and rights still apply to employees. Section 7 · Section 5 · Rule 3 · Section 8(7) · Rule 8 · Sections 11–14 · Rule 14

Steps
  1. List what you collect from staff and why.
  2. Mark which items are employment purposes and which are extra.
  3. Take consent for the extras, separately.
  4. Give staff a short employee privacy notice.
  5. Set retention for ex-employee records.
Evidence to keep
  • Employee data list with basis
  • Employee privacy notice
  • Consent for extras
Common mistakes
  • A blanket consent clause in the offer letter
  • Keeping candidate data forever
  • Sharing staff data with vendors without terms
Related questions

Are contract and agency workers our responsibility?

Short answer: Yes, for the data you decide about

Their data is your responsibility when you decide why and how it is used, for example gate passes, attendance, biometrics and safety records. The agency holds payroll and personal files, so your contract with the agency must cover how it protects that data.

From your seat: HR department. Agree with Admin and agencies who holds which worker records.
In Healthcare

Housekeeping, security and ambulance staff are often agency staff.

What the law says

Section 7(i) covers employment purposes. Section 8(1) and 8(2) make you responsible for processors such as manpower agencies working on your behalf. Section 7 · Section 8(1)–(2) · Section 8(5) · Rule 6

Steps
  1. List what you hold about contract workers: ID copies, photos, biometrics, attendance, medical fitness.
  2. Decide who is the Data Fiduciary for each item: you or the agency.
  3. Put data terms in every manpower contract.
  4. Give a short notice in the workers' language at the gate or induction.
  5. Delete gate and ID records on a schedule.
Evidence to keep
  • Contract-worker data list
  • Agency contracts with data terms
  • Notice at the gate
Common mistakes
  • Photocopies of Aadhaar kept in open files
  • No terms in the agency contract
  • Biometric data with no deletion date
Related questions

How long can we keep personal data?

Short answer: For the legal or business period, then erase

Keep data for as long as its purpose needs, or as long as a law requires, and then erase it. Every organisation must keep personal data and logs for at least one year under Rule 8(3). Write a retention schedule by record type, with the law or reason against each period.

From your seat: HR department. Set periods for candidate, employee and ex-employee records.
In Healthcare

Indoor records at least 3 years (2002 regulations), PCPNDT 2 years, MTP 5 years, Schedule H1 3 years.

What the law says

Section 8(7) asks for erasure when the purpose is over, unless a law requires retention. Rule 8(3) sets a one-year minimum for personal data, traffic data and logs. Section 8(7) · Rule 8 · Section 8(5) · Rule 6

Steps
  1. List the record types you hold.
  2. Write the period for each, with the law, regulator rule or business reason.
  3. Set a trigger for the period to start: end of relationship, date of transaction, exit date.
  4. Automate deletion where you can; for paper, schedule shredding.
  5. Keep a deletion log.
Evidence to keep
  • Retention schedule approved by Legal
  • Deletion log
  • Shredding or disposal certificates
Common mistakes
  • 'Keep everything forever' because storage is cheap
  • Deleting before the legal minimum
  • Forgetting email, shared drives and backups
Related questions

Who needs DPDP training, and what should it cover?

Short answer: Everyone who handles personal data, by role

Everyone who handles personal data needs short, practical training on what to do in their own job. Front-line staff need examples from their counter or desk. Managers need to know the clocks and their own duties. Management needs to know what to ask.

From your seat: HR department. Put DPDP into induction and the yearly refresher.
In Healthcare

Short sessions with real examples: wrong sends, whiteboards, printouts.

What the law says

Section 8(4) and 8(5) ask for appropriate technical and organisational measures. Training is part of showing those measures work. Section 8(5) · Rule 6

Steps
  1. Group staff by what they handle: front line, back office, IT, managers, management.
  2. Write three to five real scenarios for each group.
  3. Keep sessions short: 20 to 30 minutes.
  4. Test with a few questions, and record attendance.
  5. Repeat every year, and at joining.
Evidence to keep
  • Training plan by group
  • Attendance and test results
  • Scenario material
Common mistakes
  • One long legal lecture for all
  • Training once and never again
  • No record of attendance
Related questions

What about CCTV, visitor registers and biometric attendance?

Short answer: Yes, with notice, limits and a deletion period

All three are personal data. Put a clear notice where people are recorded, collect only what you need at reception, keep footage and registers for a set period, and protect biometric templates carefully. Do not keep copies of ID documents unless you must.

From your seat: HR department. Biometric attendance data needs limited access and a deletion date after exit.
In Healthcare

CCTV must not cover examination or changing areas; put notices at entrances.

What the law says

Section 5 needs notice. Section 8(5) needs safeguards. Section 8(7) needs erasure after the purpose. For staff, Section 7(i) can cover security and attendance. Section 5 · Rule 3 · Section 8(5) · Rule 6 · Section 8(7) · Rule 8 · Section 7

Steps
  1. Put notices at CCTV points and reception, in the local language.
  2. Ask visitors only for name, phone and whom they are meeting, unless security needs more.
  3. Set a period for footage and registers, then delete.
  4. Restrict who can view footage, and log viewing.
  5. Check the vendor contracts for CCTV, guards and attendance systems.
Evidence to keep
  • Notices in place
  • Retention settings on the recorder
  • Viewing log
Common mistakes
  • Photocopying visitor IDs as routine
  • Footage kept until the disk fills
  • Biometric systems with vendor default passwords
Related questions

Someone asks what data we hold about them. What do we send?

Short answer: Yes, a clear summary, inside the published timeline

Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.

From your seat: HR department. Staff can ask what HR holds about them. Have the summary process ready.
In Healthcare

Under the 2002 regulations, patients and authorised attendants should get record copies within 72 hours of a request. The DPDP summary adds who the data was shared with.

What the law says

Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14

Steps
  1. Log the request in one register the day it arrives.
  2. Verify identity using details you already hold.
  3. Search every system, including vendors' copies.
  4. Write a plain summary: what data, why it is used, who received it.
  5. Send it, and file the request, search notes and reply.
Evidence to keep
  • Request register
  • Search notes for each request
  • Copy of each reply with date
Common mistakes
  • Sending raw database dumps
  • Forgetting data held by vendors
  • No identity check before sending
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for healthcare and hospitals.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002Regulation 1.3.1: keep indoor patients' medical records for 3 years from the start of treatment. Regulation 1.3.2: issue records to patients, authorised attendants or legal authorities within 72 hours of a request. Regulation 2.2: keep patient confidences.Set retention at or above these minimums. Use the 72-hour record copy rule as the base for patient access requests.Code of Medical Ethics, 2002
Telemedicine Practice Guidelines, 2020 (Appendix 5 to the 2002 Regulations)Consent is implied when the patient starts a teleconsultation and must be explicit when a health worker or caregiver starts it. The doctor records consent and keeps logs, records and prescriptions as for in-person care.Telemedicine apps must add DPDP notices and protect chat, video and prescription data.MoHFW
Pre-Conception and Pre-Natal Diagnostic Techniques (PCPNDT) Act, 1994Records of tests and procedures, including Form F, must be preserved for 2 years, or until a legal proceeding ends.These records cannot be erased early on request; protect them carefully.Tamil Nadu health department FAQ
Medical Termination of Pregnancy Regulations, 2003The admission register is a secret document, kept by the head of the hospital, not open to inspection except under law, and kept for five years.MTP records need the tightest access in the hospital.MTP Regulations
Mental Healthcare Act, 2017Section 23: right to confidentiality. Section 24: no photos or information to media without consent. Section 25: right to access basic medical records.Psychiatry and counselling records need separate access and a careful request process.NHSRC copy of the Act
HIV and AIDS (Prevention and Control) Act, 2017HIV status may be disclosed only with informed consent, except in narrow cases. Establishments keeping HIV-related records must adopt data protection measures.Restrict HIV results and counselling notes to the treating team.Act
New Drugs and Clinical Trials Rules, 2019Informed consent of trial participants; ethics committees keep records for five years after the trial ends (Rule 13).Trial data needs both informed consent and DPDP safeguards.NDCT Rules
Drugs Rules: Schedule H1 registerPharmacies record prescriber's name and address, patient's name, drug and quantity, kept for three years.Keep the register for three years, then dispose of it.NHSRC
ABDM Health Data Management PolicyFor entities in the Ayushman Bharat Digital Mission, health records are shared through a consent manager, with consent artefacts for each request.If you are ABDM-linked, the ABDM consent flow and your DPDP notices must agree.ABDM / NHA
Clinical Establishments Act, 2010 and Rules, 2012 (states that adopted it)Registered establishments maintain medical records, and electronic records as the government specifies.Check whether your state follows this Act or its own nursing home law.MoHFW
IRDAI health insurance master circular, 2024Insurers decide cashless requests within one hour and final discharge within three hours.Fast TPA sharing is needed, but only the records the claim needs, through secure channels.IRDAI
CERT-In Directions, 2022Report specified cyber incidents within six hours; keep ICT logs 180 days in India.A ransomware attack needs a CERT-In report and the DPDP messages.CERT-In
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.