InfraVeritas360DPDPiq

DPDP Insights › Healthcare and hospitals › HR head

Healthcare and hospitals

DPDP for the HR head in Healthcare

You hold records of doctors, nurses, residents and many contract staff, and staff are often patients too.

Open this seat in the interactive tool

What is different here

Staff health records, vaccination and fitness records are sensitive. Staff who are patients need their records protected from colleagues.

The first four things to sort out

  1. Restrict access to staff health and vaccination records.
  2. Flag staff patient records in the HIS.
  3. Check agency contracts for housekeeping and security staff.
  4. Train staff on messaging and wrong sends.

A worked example: A nurse's own admission records are viewed by colleagues

  1. Day 1A nurse complains colleagues knew her diagnosis.
  2. Day 2Access logs show three views without a care reason.
  3. Week 1Staff records are flagged; viewing needs a reason.
  4. AfterStaff are briefed, without names.

Evidence kept: Complaint; Log extract; Flag setting.

Staff are patients too.

What others in the sector usually do. Hospitals mark staff and VIP records so viewing them needs a reason and is logged.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Multi-specialty hospital chainShared logins on ward computers; Reports forwarded on messaging apps; VIP or staff records viewed out of curiosity
Standalone hospital or nursing homePaper case sheets at nursing stations; Vendor remote access to the hospital software; Records room with no access log
Diagnostic labs and imagingReport links sent to the wrong number; Franchisees keeping patient lists; PCPNDT records and images
Health-tech and telemedicineAnalytics and ad SDKs in health apps; Chat transcripts kept with no period; Sharing user data with partner pharmacies for offers
Pharmacy chain and e-pharmacyPrescription images in the app and with stores; Refill reminders used for marketing; Delivery partners with addresses and order details

8 guides for the HR head, in full

How do we stop staff looking at records they do not need?

Short answer: Role access, flags and weekly log review

Snooping on VIP, celebrity, colleague or neighbour records is a common problem. Give access by role, mark sensitive records, ask for a reason before opening them, allow break-glass access in emergencies, and review those logs every week.

From your seat: HR head. Misuse needs a consistent HR response.
What the law says

Rule 6 requires access control and monitoring. Section 8(5) · Rule 6 · Section 8(6) · Rule 7

Steps
  1. Flag VIP, staff and sensitive records.
  2. Ask for a reason to open them.
  3. Allow break-glass with review.
  4. Review logs weekly.
  5. Act on misuse consistently.
Evidence to keep
  • Flag settings
  • Review records
  • Action records
Common mistakes
  • Everyone can see everything
  • Break-glass never reviewed
  • No action on misuse
Related questions

Do we need consent for employee data?

Short answer: Not for employment purposes; yes for anything extra

Usually not for normal employment purposes. Section 7(i) lets you process employee data for employment, such as payroll, attendance, safety and preventing corporate espionage. Anything beyond that, such as wellness apps, photos for marketing or sharing with a bank for offers, needs consent.

From your seat: HR head. Write a one-page employee privacy notice and give it at joining. Keep consent separate for extras like wellness apps or photos.
In Healthcare

Staff health and vaccination records are sensitive; keep them apart from HR files.

What the law says

Section 7(i) covers employment purposes and safeguarding the employer from loss or liability. Notice, security, retention and rights still apply to employees. Section 7 · Section 5 · Rule 3 · Section 8(7) · Rule 8 · Sections 11–14 · Rule 14

Steps
  1. List what you collect from staff and why.
  2. Mark which items are employment purposes and which are extra.
  3. Take consent for the extras, separately.
  4. Give staff a short employee privacy notice.
  5. Set retention for ex-employee records.
Evidence to keep
  • Employee data list with basis
  • Employee privacy notice
  • Consent for extras
Common mistakes
  • A blanket consent clause in the offer letter
  • Keeping candidate data forever
  • Sharing staff data with vendors without terms
Related questions

Are contract and agency workers our responsibility?

Short answer: Yes, for the data you decide about

Their data is your responsibility when you decide why and how it is used, for example gate passes, attendance, biometrics and safety records. The agency holds payroll and personal files, so your contract with the agency must cover how it protects that data.

From your seat: HR head. You decide what is collected at the gate and in induction. Make sure agency contracts cover the data agencies hold.
In Healthcare

Housekeeping, security and ambulance staff are often agency staff.

What the law says

Section 7(i) covers employment purposes. Section 8(1) and 8(2) make you responsible for processors such as manpower agencies working on your behalf. Section 7 · Section 8(1)–(2) · Section 8(5) · Rule 6

Steps
  1. List what you hold about contract workers: ID copies, photos, biometrics, attendance, medical fitness.
  2. Decide who is the Data Fiduciary for each item: you or the agency.
  3. Put data terms in every manpower contract.
  4. Give a short notice in the workers' language at the gate or induction.
  5. Delete gate and ID records on a schedule.
Evidence to keep
  • Contract-worker data list
  • Agency contracts with data terms
  • Notice at the gate
Common mistakes
  • Photocopies of Aadhaar kept in open files
  • No terms in the agency contract
  • Biometric data with no deletion date
Related questions

What about CCTV, visitor registers and biometric attendance?

Short answer: Yes, with notice, limits and a deletion period

All three are personal data. Put a clear notice where people are recorded, collect only what you need at reception, keep footage and registers for a set period, and protect biometric templates carefully. Do not keep copies of ID documents unless you must.

From your seat: HR head. Biometric attendance is the item to watch: who can see templates, how long they are kept, and what happens when someone leaves.
In Healthcare

CCTV must not cover examination or changing areas; put notices at entrances.

What the law says

Section 5 needs notice. Section 8(5) needs safeguards. Section 8(7) needs erasure after the purpose. For staff, Section 7(i) can cover security and attendance. Section 5 · Rule 3 · Section 8(5) · Rule 6 · Section 8(7) · Rule 8 · Section 7

Steps
  1. Put notices at CCTV points and reception, in the local language.
  2. Ask visitors only for name, phone and whom they are meeting, unless security needs more.
  3. Set a period for footage and registers, then delete.
  4. Restrict who can view footage, and log viewing.
  5. Check the vendor contracts for CCTV, guards and attendance systems.
Evidence to keep
  • Notices in place
  • Retention settings on the recorder
  • Viewing log
Common mistakes
  • Photocopying visitor IDs as routine
  • Footage kept until the disk fills
  • Biometric systems with vendor default passwords
Related questions

How long can we keep personal data?

Short answer: For the legal or business period, then erase

Keep data for as long as its purpose needs, or as long as a law requires, and then erase it. Every organisation must keep personal data and logs for at least one year under Rule 8(3). Write a retention schedule by record type, with the law or reason against each period.

From your seat: HR head. Ex-employee files are the usual pile-up. Set a period by record type, with labour-law minimums, and delete after it.
In Healthcare

Indoor records at least 3 years (2002 regulations), PCPNDT 2 years, MTP 5 years, Schedule H1 3 years.

What the law says

Section 8(7) asks for erasure when the purpose is over, unless a law requires retention. Rule 8(3) sets a one-year minimum for personal data, traffic data and logs. Section 8(7) · Rule 8 · Section 8(5) · Rule 6

Steps
  1. List the record types you hold.
  2. Write the period for each, with the law, regulator rule or business reason.
  3. Set a trigger for the period to start: end of relationship, date of transaction, exit date.
  4. Automate deletion where you can; for paper, schedule shredding.
  5. Keep a deletion log.
Evidence to keep
  • Retention schedule approved by Legal
  • Deletion log
  • Shredding or disposal certificates
Common mistakes
  • 'Keep everything forever' because storage is cheap
  • Deleting before the legal minimum
  • Forgetting email, shared drives and backups
Related questions

Who needs DPDP training, and what should it cover?

Short answer: Everyone who handles personal data, by role

Everyone who handles personal data needs short, practical training on what to do in their own job. Front-line staff need examples from their counter or desk. Managers need to know the clocks and their own duties. Management needs to know what to ask.

From your seat: HR head. HR runs the joining programme, so DPDP training fits naturally in the first month for every new joiner.
In Healthcare

Short sessions with real examples: wrong sends, whiteboards, printouts.

What the law says

Section 8(4) and 8(5) ask for appropriate technical and organisational measures. Training is part of showing those measures work. Section 8(5) · Rule 6

Steps
  1. Group staff by what they handle: front line, back office, IT, managers, management.
  2. Write three to five real scenarios for each group.
  3. Keep sessions short: 20 to 30 minutes.
  4. Test with a few questions, and record attendance.
  5. Repeat every year, and at joining.
Evidence to keep
  • Training plan by group
  • Attendance and test results
  • Scenario material
Common mistakes
  • One long legal lecture for all
  • Training once and never again
  • No record of attendance
Related questions

Staff share personal data on WhatsApp and personal email. What do we do?

Short answer: Yes, this is a common breach; give staff a safer option

Sending personal data to the wrong chat or a personal account is one of the most common breaches. Banning messaging rarely works. Give staff an approved tool that is easy to use, set simple rules, and make it safe to report a wrong send at once.

From your seat: HR head. Teams share CVs, salary sheets and ID copies on chat. Give recruiters and payroll an approved way to share.
In Healthcare

Reports and images on WhatsApp groups are the most common hospital breach.

What the law says

Section 8(5) asks for reasonable safeguards. A wrong send is a breach under Section 2(u), and Section 8(6) applies. Section 8(5) · Rule 6 · Section 8(6) · Rule 7

Steps
  1. Ask teams how they actually share files and photos today.
  2. Provide an approved tool for that job.
  3. Set three simple rules: approved tool, no personal accounts, report wrong sends.
  4. Teach the rules with real examples from your own work.
  5. Treat a quick report as good behaviour, not a disciplinary case.
Evidence to keep
  • Approved-tool policy
  • Training record
  • Incident reports of wrong sends
Common mistakes
  • A ban with no alternative
  • Punishing people who report
  • Ignoring group chats with vendors
Related questions

Something has gone wrong. What happens in the first 72 hours?

Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report

Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.

From your seat: HR head. A leaked salary sheet or ID folder is a breach. Make sure HR knows to call the DPO at once.
In Healthcare

A ransomware attack on the HIS needs a CERT-In report in six hours and the DPDP messages.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6

Steps
  1. Name one incident lead and a back-up, with phone numbers that work at night.
  2. Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
  3. Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
  4. Decide in advance who signs off each message.
  5. Rehearse once a year with the people who would actually be called.
Evidence to keep
  • Incident plan with clocks
  • Rehearsal record
  • Incident log with times of each step
Common mistakes
  • Waiting to finish the investigation before telling anyone
  • Treating a wrong email or a lost laptop as 'not a breach'
  • Only IT knowing the plan
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for healthcare and hospitals.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002Regulation 1.3.1: keep indoor patients' medical records for 3 years from the start of treatment. Regulation 1.3.2: issue records to patients, authorised attendants or legal authorities within 72 hours of a request. Regulation 2.2: keep patient confidences.Set retention at or above these minimums. Use the 72-hour record copy rule as the base for patient access requests.Code of Medical Ethics, 2002
Telemedicine Practice Guidelines, 2020 (Appendix 5 to the 2002 Regulations)Consent is implied when the patient starts a teleconsultation and must be explicit when a health worker or caregiver starts it. The doctor records consent and keeps logs, records and prescriptions as for in-person care.Telemedicine apps must add DPDP notices and protect chat, video and prescription data.MoHFW
Pre-Conception and Pre-Natal Diagnostic Techniques (PCPNDT) Act, 1994Records of tests and procedures, including Form F, must be preserved for 2 years, or until a legal proceeding ends.These records cannot be erased early on request; protect them carefully.Tamil Nadu health department FAQ
Medical Termination of Pregnancy Regulations, 2003The admission register is a secret document, kept by the head of the hospital, not open to inspection except under law, and kept for five years.MTP records need the tightest access in the hospital.MTP Regulations
Mental Healthcare Act, 2017Section 23: right to confidentiality. Section 24: no photos or information to media without consent. Section 25: right to access basic medical records.Psychiatry and counselling records need separate access and a careful request process.NHSRC copy of the Act
HIV and AIDS (Prevention and Control) Act, 2017HIV status may be disclosed only with informed consent, except in narrow cases. Establishments keeping HIV-related records must adopt data protection measures.Restrict HIV results and counselling notes to the treating team.Act
New Drugs and Clinical Trials Rules, 2019Informed consent of trial participants; ethics committees keep records for five years after the trial ends (Rule 13).Trial data needs both informed consent and DPDP safeguards.NDCT Rules
Drugs Rules: Schedule H1 registerPharmacies record prescriber's name and address, patient's name, drug and quantity, kept for three years.Keep the register for three years, then dispose of it.NHSRC
ABDM Health Data Management PolicyFor entities in the Ayushman Bharat Digital Mission, health records are shared through a consent manager, with consent artefacts for each request.If you are ABDM-linked, the ABDM consent flow and your DPDP notices must agree.ABDM / NHA
Clinical Establishments Act, 2010 and Rules, 2012 (states that adopted it)Registered establishments maintain medical records, and electronic records as the government specifies.Check whether your state follows this Act or its own nursing home law.MoHFW
IRDAI health insurance master circular, 2024Insurers decide cashless requests within one hour and final discharge within three hours.Fast TPA sharing is needed, but only the records the claim needs, through secure channels.IRDAI
CERT-In Directions, 2022Report specified cyber incidents within six hours; keep ICT logs 180 days in India.A ransomware attack needs a CERT-In report and the DPDP messages.CERT-In
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.