InfraVeritas360DPDPiq

DPDP Insights › Healthcare and hospitals › Marketing department

Healthcare and hospitals

DPDP for the Marketing department in Healthcare

Marketing runs health packages, camps and patient stories.

Open this seat in the interactive tool

What is different here

Patients tell doctors things they tell nobody else, and many people touch the same record: front desk, doctors, nurses, labs, billing, insurers and TPAs. Treatment itself usually rests on the purpose the patient came for, and a medical emergency allows action without consent. Almost everything around treatment still needs a notice, a reason and proper care, and several health laws add their own confidentiality rules.

The first four things to sort out

  1. Consent for offers.
  2. Camp notices.
  3. Testimonials with consent.
  4. No targeting of children.

A worked example: A patient testimonial video

  1. Day 1Marketing asks a recovered patient.
  2. Day 2Written consent with purpose and duration.
  3. Day 5Video avoids other patients and records.
  4. AfterWithdrawal honoured if asked.

Evidence kept: Consent form.

Stories need consent.

What others in the sector usually do. Consent-based patient stories.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Multi-specialty hospital chainShared logins on ward computers; Reports forwarded on messaging apps; VIP or staff records viewed out of curiosity
Standalone hospital or nursing homePaper case sheets at nursing stations; Vendor remote access to the hospital software; Records room with no access log
Diagnostic labs and imagingReport links sent to the wrong number; Franchisees keeping patient lists; PCPNDT records and images
Health-tech and telemedicineAnalytics and ad SDKs in health apps; Chat transcripts kept with no period; Sharing user data with partner pharmacies for offers
Pharmacy chain and e-pharmacyPrescription images in the app and with stores; Refill reminders used for marketing; Delivery partners with addresses and order details

8 guides for the Marketing department, in full

Can we use patient data for research, audits or case studies?

Short answer: Consent or de-identification first

Research with identifiable patients needs informed consent under research rules and DPDP consent for that use. Clinical audit to improve care within the hospital usually fits the treatment purpose. Case studies and teaching material should be de-identified so patients cannot be recognised. Clinical trials follow the NDCT Rules, 2019.

What the law says

Section 6 sets consent; Section 17(2)(b) covers research only where no decision is taken about the person and prescribed standards are followed. Section 6 · Section 7 · Section 8(5) · Rule 6

Steps
  1. Route research through the ethics committee.
  2. Take research consent separately.
  3. De-identify teaching cases and photos.
  4. Limit researcher access.
  5. Delete or anonymise at the end.
Evidence to keep
  • Ethics approvals
  • Research consents
  • De-identification checks
Common mistakes
  • Photos with faces or tattoos in slides
  • Using records for studies without approval
  • Keeping research data with names after the study
Related questions

Do we need DPDP consent to treat a patient?

Short answer: Not for treatment; yes for extra uses

Usually not for the treatment itself. A patient who comes for care gives data voluntarily for that purpose, and a medical emergency involving a threat to life is a listed use. Clinical consent for procedures is a separate medical and legal requirement and stays. Extra uses such as research, marketing, testimonials and sharing beyond what care and billing need do require DPDP consent.

What the law says

Section 7(a) covers data given voluntarily for a specified purpose; Section 7(f) and 7(g) cover emergencies and epidemics. Section 7 · Section 6 · Section 5 · Rule 3

Steps
  1. Keep clinical consent forms as they are.
  2. Add a short notice at registration.
  3. Add separate boxes for research, offers and stories.
  4. Record which box each patient ticked.
  5. Train front desk to explain the difference.
Evidence to keep
  • Registration notice
  • Consent records for extra uses
Common mistakes
  • One form that bundles treatment and marketing
  • Calling clinical consent 'DPDP consent'
  • No notice at registration
Related questions

Can we send offers to past customers and leads?

Short answer: Only with separate consent and an easy way to stop

Marketing needs consent that is separate and specific, unless the person clearly expects it from the relationship. Bought or scraped lead lists are risky because you cannot show consent. Every message should carry an easy way to stop.

From your seat: Marketing department. Every campaign list needs a consent source. If you cannot say where the consent came from, do not use the list.
In Healthcare

Health package offers to past patients need separate consent.

What the law says

Section 6 sets the consent standard. Section 5 needs a notice. Section 9 bars targeted advertising at children. Section 6 · Section 5 · Rule 3 · Section 9 · Rules 10, 12

Steps
  1. Separate service messages from marketing messages.
  2. Ask marketing consent separately, with a clear action.
  3. Stop using bought lists unless the seller can show consent for you.
  4. Add an easy stop option to every message.
  5. Respect the telecom preference rules for calls and SMS.
Evidence to keep
  • Marketing consent records
  • Lead source records
  • Stop requests and their handling
Common mistakes
  • Treating account sign-up as marketing consent
  • Agency lists with no consent proof
  • A stop option that does not work
Related questions

Someone withdraws consent. What has to stop, and how fast?

Short answer: Stop that use quickly, across every system and vendor

Withdrawal must be as easy as giving consent. Once someone withdraws, you and every vendor working for you must stop that use within a reasonable time. What was done before withdrawal stays lawful, and data that a law requires you to keep is kept.

From your seat: Marketing department. Make the stop option work across every channel and agency within a day.
In Healthcare

A patient who withdraws consent for offers keeps receiving care.

What the law says

Section 6(4) to 6(6) give the right to withdraw at any time, with the same ease, and require processors to stop as well. Section 8(7) then asks for erasure unless a law requires retention. Section 6 · Section 8(7) · Rule 8 · Section 8(1)–(2)

Steps
  1. Give one simple way to withdraw on every channel where consent is taken.
  2. Record the withdrawal against the person and the purpose.
  3. Push the change to every system and vendor that uses that purpose.
  4. Confirm to the person, in writing, what has stopped and what is kept by law.
  5. Check a sample every month to see that the change actually reached every list.
Evidence to keep
  • Withdrawal log with time stamps
  • Proof that downstream systems and vendors updated
  • Confirmation sent to the person
Common mistakes
  • Withdrawal by email only, while consent was one tap in an app
  • Stopping in the main system but not in vendor lists
  • Deleting records a law requires you to keep
Related questions

What should our privacy notice say, and where must people see it?

Short answer: Yes, at every point where you collect data

A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.

From your seat: Marketing department. Landing pages, contest forms and event sign-ups each need a short notice.
In Healthcare

Registration desks, appointment apps, lab forms and health-camp sign-ups need short notices in the languages patients speak.

What the law says

Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14

Steps
  1. List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
  2. Write one short notice per collection point, with the data items and purpose side by side.
  3. Add how to withdraw consent, how to make a request and the DPO or contact person's details.
  4. Offer the notice in English and in the languages your patients actually use.
  5. Keep each version with the date it went live.
Evidence to keep
  • Screenshots or copies of the notice at each collection point, with dates
  • Notice version history
  • Translations, where used
Common mistakes
  • Hiding the notice inside terms and conditions
  • One notice for everything, with no link between data items and purposes
  • Forgetting old data collected before the Act
Related questions

Do we process children's data, and what changes if we do?

Short answer: Check every channel; children often appear where you least expect

Anyone under 18 is a child under the Act. For a child's data you need verifiable consent from a parent or lawful guardian, and you must not track, behaviourally monitor or show targeted ads to children. Some classes and purposes are exempt under Rule 12 and the Fourth Schedule, for example healthcare to the extent needed to protect the child's health, and educational institutions for their educational work.

From your seat: Marketing department. Switch off targeting for under-18 audiences and avoid tracking them.
In Healthcare

Paediatric care is exempt from parent-consent limits only to the extent needed to protect the child's health; marketing to parents of children is not.

What the law says

Section 9 sets the duties. Rule 10 explains how to verify the parent. Rule 12 and the Fourth Schedule list the exemptions. Section 9 · Rules 10, 12 · Section 6

Steps
  1. Find where children's data enters: customers, dependants, interns, visitors, scholarships, app sign-ups.
  2. Decide whether an exemption in the Fourth Schedule applies to that purpose.
  3. Where none applies, add an age question and a parent-consent step.
  4. Switch off tracking and targeted ads for under-18 users.
  5. Record the decision for each channel.
Evidence to keep
  • Channel-by-channel note on children's data
  • Parent-consent records
  • Ad and tracking settings
Common mistakes
  • Assuming 'we are B2B, so no children'
  • Using the age 13 or 16 from foreign laws
  • Treating a tick-box from the child as parental consent
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: Marketing department. Agencies, ad platforms and event partners receive data. Their contracts need data terms.
In Healthcare

Labs, teleradiology, HIS vendors, TPAs and ambulance services.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for healthcare and hospitals.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002Regulation 1.3.1: keep indoor patients' medical records for 3 years from the start of treatment. Regulation 1.3.2: issue records to patients, authorised attendants or legal authorities within 72 hours of a request. Regulation 2.2: keep patient confidences.Set retention at or above these minimums. Use the 72-hour record copy rule as the base for patient access requests.Code of Medical Ethics, 2002
Telemedicine Practice Guidelines, 2020 (Appendix 5 to the 2002 Regulations)Consent is implied when the patient starts a teleconsultation and must be explicit when a health worker or caregiver starts it. The doctor records consent and keeps logs, records and prescriptions as for in-person care.Telemedicine apps must add DPDP notices and protect chat, video and prescription data.MoHFW
Pre-Conception and Pre-Natal Diagnostic Techniques (PCPNDT) Act, 1994Records of tests and procedures, including Form F, must be preserved for 2 years, or until a legal proceeding ends.These records cannot be erased early on request; protect them carefully.Tamil Nadu health department FAQ
Medical Termination of Pregnancy Regulations, 2003The admission register is a secret document, kept by the head of the hospital, not open to inspection except under law, and kept for five years.MTP records need the tightest access in the hospital.MTP Regulations
Mental Healthcare Act, 2017Section 23: right to confidentiality. Section 24: no photos or information to media without consent. Section 25: right to access basic medical records.Psychiatry and counselling records need separate access and a careful request process.NHSRC copy of the Act
HIV and AIDS (Prevention and Control) Act, 2017HIV status may be disclosed only with informed consent, except in narrow cases. Establishments keeping HIV-related records must adopt data protection measures.Restrict HIV results and counselling notes to the treating team.Act
New Drugs and Clinical Trials Rules, 2019Informed consent of trial participants; ethics committees keep records for five years after the trial ends (Rule 13).Trial data needs both informed consent and DPDP safeguards.NDCT Rules
Drugs Rules: Schedule H1 registerPharmacies record prescriber's name and address, patient's name, drug and quantity, kept for three years.Keep the register for three years, then dispose of it.NHSRC
ABDM Health Data Management PolicyFor entities in the Ayushman Bharat Digital Mission, health records are shared through a consent manager, with consent artefacts for each request.If you are ABDM-linked, the ABDM consent flow and your DPDP notices must agree.ABDM / NHA
Clinical Establishments Act, 2010 and Rules, 2012 (states that adopted it)Registered establishments maintain medical records, and electronic records as the government specifies.Check whether your state follows this Act or its own nursing home law.MoHFW
IRDAI health insurance master circular, 2024Insurers decide cashless requests within one hour and final discharge within three hours.Fast TPA sharing is needed, but only the records the claim needs, through secure channels.IRDAI
CERT-In Directions, 2022Report specified cyber incidents within six hours; keep ICT logs 180 days in India.A ransomware attack needs a CERT-In report and the DPDP messages.CERT-In
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.