InfraVeritas360DPDPiq

DPDP Insights › Healthcare and hospitals › DPO / Privacy lead

Healthcare and hospitals

DPDP for the DPO / Privacy lead in Healthcare

In a hospital, your work is mostly with people: the front desk, wards, labs and billing, all handling patient data every hour.

Open this seat in the interactive tool

What is different here

The usual problems are human: a report sent to the wrong WhatsApp group, a login shared on a ward computer, a file left at the nursing station. These cause more trouble than outside attacks. Several health laws also set their own record periods and secrecy rules.

The first four things to sort out

  1. Map every point where patient data enters: registration, OPD, labs, imaging, pharmacy, camps.
  2. Separate treatment from consent for research, marketing and insurer sharing.
  3. Set retention by record type, respecting medical record minimums and PCPNDT and MTP rules.
  4. Train front-line staff to report a wrong send at once.

A worked example: A patient asks who has seen her report

  1. Day 1The front desk logs her request in one register and passes it to the privacy lead.
  2. Day 2The privacy lead pulls the access log from the HIS: two doctors, one lab technician and the insurer's TPA.
  3. Day 3She receives copies of her records, inside the 72 hours the medical ethics regulations expect.
  4. Day 5She receives a plain summary of who saw her report and why, with the date of each access.

Evidence kept: Request register entry; Access log extract; Copy of the reply.

A right exercised, answered with proof, well inside the limits.

What others in the sector usually do. Hospitals doing this well give clinicians an approved way to share reports, instead of just banning messaging apps.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Multi-specialty hospital chainShared logins on ward computers; Reports forwarded on messaging apps; VIP or staff records viewed out of curiosity
Standalone hospital or nursing homePaper case sheets at nursing stations; Vendor remote access to the hospital software; Records room with no access log
Diagnostic labs and imagingReport links sent to the wrong number; Franchisees keeping patient lists; PCPNDT records and images
Health-tech and telemedicineAnalytics and ad SDKs in health apps; Chat transcripts kept with no period; Sharing user data with partner pharmacies for offers
Pharmacy chain and e-pharmacyPrescription images in the app and with stores; Refill reminders used for marketing; Delivery partners with addresses and order details

10 guides for the DPO / Privacy lead, in full

Do we need DPDP consent to treat a patient?

Short answer: Not for treatment; yes for extra uses

Usually not for the treatment itself. A patient who comes for care gives data voluntarily for that purpose, and a medical emergency involving a threat to life is a listed use. Clinical consent for procedures is a separate medical and legal requirement and stays. Extra uses such as research, marketing, testimonials and sharing beyond what care and billing need do require DPDP consent.

From your seat: DPO / Privacy lead. This is the core message for front-desk training.
What the law says

Section 7(a) covers data given voluntarily for a specified purpose; Section 7(f) and 7(g) cover emergencies and epidemics. Section 7 · Section 6 · Section 5 · Rule 3

Steps
  1. Keep clinical consent forms as they are.
  2. Add a short notice at registration.
  3. Add separate boxes for research, offers and stories.
  4. Record which box each patient ticked.
  5. Train front desk to explain the difference.
Evidence to keep
  • Registration notice
  • Consent records for extra uses
Common mistakes
  • One form that bundles treatment and marketing
  • Calling clinical consent 'DPDP consent'
  • No notice at registration
Related questions

Can we share patient records with insurers and TPAs?

Short answer: Yes for the patient's claim; only what it needs

Yes, for a claim the patient has asked for, because that is part of the purpose. Share only what the claim needs, through the TPA portal or a secure channel, and keep a record of what was sent. Sharing for anything else, such as an insurer's own marketing, needs consent.

From your seat: DPO / Privacy lead. Patients often ask who received their data; this log answers it.
What the law says

Section 7(a) covers the claim purpose; Section 8(1) and 8(5) apply to how data is sent. Section 7 · Section 8(5) · Rule 6 · Sections 11–14 · Rule 14

Steps
  1. Use TPA portals, not email.
  2. Send only claim documents.
  3. Log what was sent, to whom, when.
  4. Answer patient questions about sharing.
  5. Check TPA agreements.
Evidence to keep
  • Sharing log
  • TPA agreement
Common mistakes
  • Full case files by email
  • No record of what was sent
  • Insurer representatives reading records on wards
Related questions

How long should we keep patient records?

Short answer: At least the legal minimums, with a written reason for anything longer

Keep them for at least the periods health laws set: indoor records for three years from the start of treatment under the 2002 medical ethics regulations, PCPNDT records for two years, MTP registers for five years, Schedule H1 registers for three years, and ethics committee trial records for five years after a trial. Many hospitals keep records longer for continuity of care and legal claims. Write the period and reason for each record type, then erase or archive.

From your seat: DPO / Privacy lead. Use this in erasure replies.
What the law says

Section 8(7) allows retention where a law requires it; Rule 8(3) sets a one-year floor. Section 8(7) · Rule 8 · Section 7

Steps
  1. List record types: OPD, IPD, lab, imaging, billing, PCPNDT, MTP, pharmacy.
  2. Note the legal minimum.
  3. Decide any longer period and why.
  4. Archive with restricted access.
  5. Record each deletion.
Evidence to keep
  • Retention schedule
  • Archive access list
  • Deletion log
Common mistakes
  • No schedule at all
  • Deleting before the minimum
  • Keeping open access to old records
Related questions

What should our privacy notice say, and where must people see it?

Short answer: Yes, at every point where you collect data

A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.

From your seat: DPO / Privacy lead. You own the wording and the version history. Keep a folder with every live notice, its date and who approved it; that folder is usually the first thing an auditor asks for.
In Healthcare

Registration desks, appointment apps, lab forms and health-camp sign-ups need short notices in the languages patients speak.

What the law says

Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14

Steps
  1. List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
  2. Write one short notice per collection point, with the data items and purpose side by side.
  3. Add how to withdraw consent, how to make a request and the DPO or contact person's details.
  4. Offer the notice in English and in the languages your patients actually use.
  5. Keep each version with the date it went live.
Evidence to keep
  • Screenshots or copies of the notice at each collection point, with dates
  • Notice version history
  • Translations, where used
Common mistakes
  • Hiding the notice inside terms and conditions
  • One notice for everything, with no link between data items and purposes
  • Forgetting old data collected before the Act
Related questions

Someone asks what data we hold about them. What do we send?

Short answer: Yes, a clear summary, inside the published timeline

Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.

From your seat: DPO / Privacy lead. Requests land with you even when the data sits with other teams. Agree a turnaround with each system owner in advance, so you are not chasing people on day 25.
In Healthcare

Under the 2002 regulations, patients and authorised attendants should get record copies within 72 hours of a request. The DPDP summary adds who the data was shared with.

What the law says

Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14

Steps
  1. Log the request in one register the day it arrives.
  2. Verify identity using details you already hold.
  3. Search every system, including vendors' copies.
  4. Write a plain summary: what data, why it is used, who received it.
  5. Send it, and file the request, search notes and reply.
Evidence to keep
  • Request register
  • Search notes for each request
  • Copy of each reply with date
Common mistakes
  • Sending raw database dumps
  • Forgetting data held by vendors
  • No identity check before sending
Related questions

How do we handle a privacy complaint within 90 days?

Short answer: Reply within your published period, never beyond 90 days

Publish one clear way to complain, log every complaint, give it an owner and reply within the period you publish, never more than 90 days. People can go to the Data Protection Board only after using your process, so a good process keeps most matters with you.

From your seat: DPO / Privacy lead. Count the days yourself. A short monthly note to management with open complaints and their age keeps the 90-day limit visible.
In Healthcare

Patient relations already handles complaints. Tag the data ones and count the days.

What the law says

Section 8(10) requires a working grievance process. Rule 14(3) caps the reply time at 90 days. Section 13 says people must use your process before approaching the Board. Section 8(9)–(10) · Rules 9, 14 · Sections 11–14 · Rule 14 · Sections 18–26

Steps
  1. Publish one contact for privacy complaints on your website, app and notices.
  2. Log each complaint with the date, channel and a named owner.
  3. Acknowledge within a few days, and set an internal target well under 90 days.
  4. Find and fix the cause, not just the single case.
  5. Reply in writing and close the entry with the date.
Evidence to keep
  • Complaint register with dates
  • Replies sent
  • Monthly summary to management
Common mistakes
  • Mixing privacy complaints into general complaints with no tag
  • No owner, so nobody counts the days
  • Closing a complaint without fixing the cause
Related questions

How long can we keep personal data?

Short answer: For the legal or business period, then erase

Keep data for as long as its purpose needs, or as long as a law requires, and then erase it. Every organisation must keep personal data and logs for at least one year under Rule 8(3). Write a retention schedule by record type, with the law or reason against each period.

From your seat: DPO / Privacy lead. Draft the schedule, but get Legal and each department head to sign their rows. Your role is to make sure deletion actually happens.
In Healthcare

Indoor records at least 3 years (2002 regulations), PCPNDT 2 years, MTP 5 years, Schedule H1 3 years.

What the law says

Section 8(7) asks for erasure when the purpose is over, unless a law requires retention. Rule 8(3) sets a one-year minimum for personal data, traffic data and logs. Section 8(7) · Rule 8 · Section 8(5) · Rule 6

Steps
  1. List the record types you hold.
  2. Write the period for each, with the law, regulator rule or business reason.
  3. Set a trigger for the period to start: end of relationship, date of transaction, exit date.
  4. Automate deletion where you can; for paper, schedule shredding.
  5. Keep a deletion log.
Evidence to keep
  • Retention schedule approved by Legal
  • Deletion log
  • Shredding or disposal certificates
Common mistakes
  • 'Keep everything forever' because storage is cheap
  • Deleting before the legal minimum
  • Forgetting email, shared drives and backups
Related questions

Do we process children's data, and what changes if we do?

Short answer: Check every channel; children often appear where you least expect

Anyone under 18 is a child under the Act. For a child's data you need verifiable consent from a parent or lawful guardian, and you must not track, behaviourally monitor or show targeted ads to children. Some classes and purposes are exempt under Rule 12 and the Fourth Schedule, for example healthcare to the extent needed to protect the child's health, and educational institutions for their educational work.

From your seat: DPO / Privacy lead. Ask every team, not only marketing. Dependants, interns, scholarship applicants and visitors are where children's data usually hides.
In Healthcare

Paediatric care is exempt from parent-consent limits only to the extent needed to protect the child's health; marketing to parents of children is not.

What the law says

Section 9 sets the duties. Rule 10 explains how to verify the parent. Rule 12 and the Fourth Schedule list the exemptions. Section 9 · Rules 10, 12 · Section 6

Steps
  1. Find where children's data enters: customers, dependants, interns, visitors, scholarships, app sign-ups.
  2. Decide whether an exemption in the Fourth Schedule applies to that purpose.
  3. Where none applies, add an age question and a parent-consent step.
  4. Switch off tracking and targeted ads for under-18 users.
  5. Record the decision for each channel.
Evidence to keep
  • Channel-by-channel note on children's data
  • Parent-consent records
  • Ad and tracking settings
Common mistakes
  • Assuming 'we are B2B, so no children'
  • Using the age 13 or 16 from foreign laws
  • Treating a tick-box from the child as parental consent
Related questions

Something has gone wrong. What happens in the first 72 hours?

Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report

Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.

From your seat: DPO / Privacy lead. You decide whether people and the Data Protection Board must be told, so you must be on the first call, not informed the next morning.
In Healthcare

A ransomware attack on the HIS needs a CERT-In report in six hours and the DPDP messages.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6

Steps
  1. Name one incident lead and a back-up, with phone numbers that work at night.
  2. Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
  3. Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
  4. Decide in advance who signs off each message.
  5. Rehearse once a year with the people who would actually be called.
Evidence to keep
  • Incident plan with clocks
  • Rehearsal record
  • Incident log with times of each step
Common mistakes
  • Waiting to finish the investigation before telling anyone
  • Treating a wrong email or a lost laptop as 'not a breach'
  • Only IT knowing the plan
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for healthcare and hospitals.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002Regulation 1.3.1: keep indoor patients' medical records for 3 years from the start of treatment. Regulation 1.3.2: issue records to patients, authorised attendants or legal authorities within 72 hours of a request. Regulation 2.2: keep patient confidences.Set retention at or above these minimums. Use the 72-hour record copy rule as the base for patient access requests.Code of Medical Ethics, 2002
Telemedicine Practice Guidelines, 2020 (Appendix 5 to the 2002 Regulations)Consent is implied when the patient starts a teleconsultation and must be explicit when a health worker or caregiver starts it. The doctor records consent and keeps logs, records and prescriptions as for in-person care.Telemedicine apps must add DPDP notices and protect chat, video and prescription data.MoHFW
Pre-Conception and Pre-Natal Diagnostic Techniques (PCPNDT) Act, 1994Records of tests and procedures, including Form F, must be preserved for 2 years, or until a legal proceeding ends.These records cannot be erased early on request; protect them carefully.Tamil Nadu health department FAQ
Medical Termination of Pregnancy Regulations, 2003The admission register is a secret document, kept by the head of the hospital, not open to inspection except under law, and kept for five years.MTP records need the tightest access in the hospital.MTP Regulations
Mental Healthcare Act, 2017Section 23: right to confidentiality. Section 24: no photos or information to media without consent. Section 25: right to access basic medical records.Psychiatry and counselling records need separate access and a careful request process.NHSRC copy of the Act
HIV and AIDS (Prevention and Control) Act, 2017HIV status may be disclosed only with informed consent, except in narrow cases. Establishments keeping HIV-related records must adopt data protection measures.Restrict HIV results and counselling notes to the treating team.Act
New Drugs and Clinical Trials Rules, 2019Informed consent of trial participants; ethics committees keep records for five years after the trial ends (Rule 13).Trial data needs both informed consent and DPDP safeguards.NDCT Rules
Drugs Rules: Schedule H1 registerPharmacies record prescriber's name and address, patient's name, drug and quantity, kept for three years.Keep the register for three years, then dispose of it.NHSRC
ABDM Health Data Management PolicyFor entities in the Ayushman Bharat Digital Mission, health records are shared through a consent manager, with consent artefacts for each request.If you are ABDM-linked, the ABDM consent flow and your DPDP notices must agree.ABDM / NHA
Clinical Establishments Act, 2010 and Rules, 2012 (states that adopted it)Registered establishments maintain medical records, and electronic records as the government specifies.Check whether your state follows this Act or its own nursing home law.MoHFW
IRDAI health insurance master circular, 2024Insurers decide cashless requests within one hour and final discharge within three hours.Fast TPA sharing is needed, but only the records the claim needs, through secure channels.IRDAI
CERT-In Directions, 2022Report specified cyber incidents within six hours; keep ICT logs 180 days in India.A ransomware attack needs a CERT-In report and the DPDP messages.CERT-In
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.