InfraVeritas360DPDPiq

DPDP Insights › Healthcare and hospitals › Legal & compliance

Healthcare and hospitals

DPDP for the Legal & compliance in Healthcare

You read DPDP alongside medical ethics regulations, PCPNDT, MTP, mental health, HIV and clinical trial laws.

Open this seat in the interactive tool

What is different here

Each of these laws has its own consent and confidentiality rules. Your job is to make sure the hospital's forms and contracts meet all of them at once.

The first four things to sort out

  1. Separate treatment consent from DPDP consent for extra uses.
  2. Check lab, teleradiology and software contracts for data terms.
  3. Write the retention list by law.
  4. Set a process for police, court and insurer requests.

A worked example: A teleradiology contract renewal

  1. Week 1Legal checks what the vendor receives: images with names and ages.
  2. Week 2Terms added: purpose, security, India hosting or approved locations, breach notice in hours, deletion.
  3. Week 3The vendor confirms how radiologists abroad access images.
  4. AfterLogged in the vendor register.

Evidence kept: Contract schedule; Vendor confirmation.

Renewals are the chance to fix old contracts.

What others in the sector usually do. Legal teams are rewriting consent forms so treatment, research and marketing are separate boxes.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Multi-specialty hospital chainShared logins on ward computers; Reports forwarded on messaging apps; VIP or staff records viewed out of curiosity
Standalone hospital or nursing homePaper case sheets at nursing stations; Vendor remote access to the hospital software; Records room with no access log
Diagnostic labs and imagingReport links sent to the wrong number; Franchisees keeping patient lists; PCPNDT records and images
Health-tech and telemedicineAnalytics and ad SDKs in health apps; Chat transcripts kept with no period; Sharing user data with partner pharmacies for offers
Pharmacy chain and e-pharmacyPrescription images in the app and with stores; Refill reminders used for marketing; Delivery partners with addresses and order details

10 guides for the Legal & compliance, in full

Do we need DPDP consent to treat a patient?

Short answer: Not for treatment; yes for extra uses

Usually not for the treatment itself. A patient who comes for care gives data voluntarily for that purpose, and a medical emergency involving a threat to life is a listed use. Clinical consent for procedures is a separate medical and legal requirement and stays. Extra uses such as research, marketing, testimonials and sharing beyond what care and billing need do require DPDP consent.

From your seat: Legal & compliance. Rewrite forms with separate boxes.
What the law says

Section 7(a) covers data given voluntarily for a specified purpose; Section 7(f) and 7(g) cover emergencies and epidemics. Section 7 · Section 6 · Section 5 · Rule 3

Steps
  1. Keep clinical consent forms as they are.
  2. Add a short notice at registration.
  3. Add separate boxes for research, offers and stories.
  4. Record which box each patient ticked.
  5. Train front desk to explain the difference.
Evidence to keep
  • Registration notice
  • Consent records for extra uses
Common mistakes
  • One form that bundles treatment and marketing
  • Calling clinical consent 'DPDP consent'
  • No notice at registration
Related questions

Can we use patient data for research, audits or case studies?

Short answer: Consent or de-identification first

Research with identifiable patients needs informed consent under research rules and DPDP consent for that use. Clinical audit to improve care within the hospital usually fits the treatment purpose. Case studies and teaching material should be de-identified so patients cannot be recognised. Clinical trials follow the NDCT Rules, 2019.

From your seat: Legal & compliance. Align research consent with NDCT and DPDP.
What the law says

Section 6 sets consent; Section 17(2)(b) covers research only where no decision is taken about the person and prescribed standards are followed. Section 6 · Section 7 · Section 8(5) · Rule 6

Steps
  1. Route research through the ethics committee.
  2. Take research consent separately.
  3. De-identify teaching cases and photos.
  4. Limit researcher access.
  5. Delete or anonymise at the end.
Evidence to keep
  • Ethics approvals
  • Research consents
  • De-identification checks
Common mistakes
  • Photos with faces or tattoos in slides
  • Using records for studies without approval
  • Keeping research data with names after the study
Related questions

Which records need extra protection under other health laws?

Short answer: Yes, tighter access than other records

HIV results, mental health records, MTP registers and PCPNDT records each have their own law. HIV status needs informed consent before disclosure. Mental health records are confidential and cannot go to the media without consent. The MTP admission register is a secret document. PCPNDT records are kept for two years. Give these the tightest access in the hospital.

From your seat: Legal & compliance. Keep the list of special laws current.
What the law says

Section 8(5) asks for safeguards suited to the risk; the special laws set their own rules. Section 8(5) · Rule 6 · Section 8(7) · Rule 8

Steps
  1. List where these records sit.
  2. Restrict access to the treating team.
  3. Keep the MTP register with the head of the hospital.
  4. Set retention as each law says.
  5. Log every access.
Evidence to keep
  • Access settings
  • Retention entries
  • Access logs
Common mistakes
  • HIV results visible to all clinicians
  • MTP details in general billing
  • PCPNDT records deleted early
Related questions

What should our privacy notice say, and where must people see it?

Short answer: Yes, at every point where you collect data

A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.

From your seat: Legal & compliance. Approve the wording and keep it simple. A notice a regulator can read in two minutes is better than a complete one nobody reads.
In Healthcare

Registration desks, appointment apps, lab forms and health-camp sign-ups need short notices in the languages patients speak.

What the law says

Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14

Steps
  1. List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
  2. Write one short notice per collection point, with the data items and purpose side by side.
  3. Add how to withdraw consent, how to make a request and the DPO or contact person's details.
  4. Offer the notice in English and in the languages your patients actually use.
  5. Keep each version with the date it went live.
Evidence to keep
  • Screenshots or copies of the notice at each collection point, with dates
  • Notice version history
  • Translations, where used
Common mistakes
  • Hiding the notice inside terms and conditions
  • One notice for everything, with no link between data items and purposes
  • Forgetting old data collected before the Act
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: Legal & compliance. Draft one data-protection schedule and use it for every contract that involves personal data.
In Healthcare

Labs, teleradiology, HIS vendors, TPAs and ambulance services.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Are we a Data Fiduciary or a Data Processor?

Short answer: Often both, for different data

You are a Data Fiduciary when you decide why and how personal data is used, as you do for your own staff and customers. You are a Data Processor when you handle data only on another organisation's instructions. Many organisations are both, for different data sets.

From your seat: Legal & compliance. Check that contracts match the real role. Calling a vendor a processor while it uses data for its own purposes will not hold.
In Healthcare

Partner labs and teleradiology providers usually act for you.

What the law says

Section 2(i) and 2(k) define the two roles. Section 8(1) puts the duties on the Data Fiduciary, which must use processors only under a valid contract. Section 8(1)–(2) · Section 17(1)(d)

Steps
  1. List each data set you handle.
  2. For each, ask: who decides the purpose?
  3. Mark yourself as fiduciary or processor, and name the other party.
  4. Check that contracts match the role.
  5. Route requests about processor data to the fiduciary.
Evidence to keep
  • Role register by data set
  • Contracts matching the role
Common mistakes
  • Calling yourself a processor for data you use for your own purposes
  • No contract when you act as processor
  • Answering requests that belong to your client
Related questions

Do we process children's data, and what changes if we do?

Short answer: Check every channel; children often appear where you least expect

Anyone under 18 is a child under the Act. For a child's data you need verifiable consent from a parent or lawful guardian, and you must not track, behaviourally monitor or show targeted ads to children. Some classes and purposes are exempt under Rule 12 and the Fourth Schedule, for example healthcare to the extent needed to protect the child's health, and educational institutions for their educational work.

From your seat: Legal & compliance. Advise on whether a Fourth Schedule exemption applies to each purpose, and write the reasoning down.
In Healthcare

Paediatric care is exempt from parent-consent limits only to the extent needed to protect the child's health; marketing to parents of children is not.

What the law says

Section 9 sets the duties. Rule 10 explains how to verify the parent. Rule 12 and the Fourth Schedule list the exemptions. Section 9 · Rules 10, 12 · Section 6

Steps
  1. Find where children's data enters: customers, dependants, interns, visitors, scholarships, app sign-ups.
  2. Decide whether an exemption in the Fourth Schedule applies to that purpose.
  3. Where none applies, add an age question and a parent-consent step.
  4. Switch off tracking and targeted ads for under-18 users.
  5. Record the decision for each channel.
Evidence to keep
  • Channel-by-channel note on children's data
  • Parent-consent records
  • Ad and tracking settings
Common mistakes
  • Assuming 'we are B2B, so no children'
  • Using the age 13 or 16 from foreign laws
  • Treating a tick-box from the child as parental consent
Related questions

Police, a court or a regulator asks for someone's data. What do we do?

Short answer: Yes, when the request is lawful and in writing

Check that the request is in writing, comes from the right authority and cites the legal power. Share only what is asked for, record what you sent and to whom, and keep the request on file. The Act allows processing to meet a legal duty, but it does not mean sharing everything on a phone call.

From your seat: Legal & compliance. Own the authority request log. Check the legal power every time, even for familiar requesters.
In Healthcare

Police requests for MLC records and court summons are common.

What the law says

Section 7(d) and 7(e) allow processing to meet a legal duty to disclose to the State, or to comply with a judgment or order. Section 17(1)(c) exempts processing for preventing, detecting or investigating offences. Section 7 · Section 8(5) · Rule 6

Steps
  1. Route every such request to Legal.
  2. Check the authority, the legal power and the scope.
  3. Share only what is asked, by a secure method.
  4. Log the request, what was sent, by whom and when.
  5. Tell the person, unless the law or the authority says you must not.
Evidence to keep
  • Authority request log
  • Copies of requests
  • Record of what was sent
Common mistakes
  • Sharing on a phone call
  • Sending whole files when a few lines were asked
  • No log
Related questions

Someone asks us to delete their data. Must we?

Short answer: Yes, unless a law requires you to keep it

You must erase data that you no longer need for the purpose it was collected for, unless a law requires you to keep it. Where a law does require it, keep the data, stop using it for anything else, and tell the person why it is being kept and until when.

From your seat: Legal & compliance. Approve the list of laws that require retention, so front-line teams can explain refusals correctly.
In Healthcare

Medical records have legal minimums; a patient's erasure request cannot cut those short.

What the law says

Section 12 gives the right to correction and erasure. Section 8(7) allows retention only where a law requires it. Rule 8(3) asks every organisation to keep personal data and logs for at least one year first. Sections 11–14 · Rule 14 · Section 8(7) · Rule 8

Steps
  1. Log the request and verify identity.
  2. Check the retention schedule for each record type involved.
  3. Delete what has no legal reason to stay, including copies with vendors and in test systems.
  4. Mark what must stay, with the law and the end date.
  5. Reply in plain words: what was deleted, what is kept, why and until when.
Evidence to keep
  • Erasure log
  • Vendor deletion confirmations
  • Reply to the person
Common mistakes
  • Refusing every erasure request 'because of backups'
  • Deleting records a law requires
  • Not telling vendors
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for healthcare and hospitals.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002Regulation 1.3.1: keep indoor patients' medical records for 3 years from the start of treatment. Regulation 1.3.2: issue records to patients, authorised attendants or legal authorities within 72 hours of a request. Regulation 2.2: keep patient confidences.Set retention at or above these minimums. Use the 72-hour record copy rule as the base for patient access requests.Code of Medical Ethics, 2002
Telemedicine Practice Guidelines, 2020 (Appendix 5 to the 2002 Regulations)Consent is implied when the patient starts a teleconsultation and must be explicit when a health worker or caregiver starts it. The doctor records consent and keeps logs, records and prescriptions as for in-person care.Telemedicine apps must add DPDP notices and protect chat, video and prescription data.MoHFW
Pre-Conception and Pre-Natal Diagnostic Techniques (PCPNDT) Act, 1994Records of tests and procedures, including Form F, must be preserved for 2 years, or until a legal proceeding ends.These records cannot be erased early on request; protect them carefully.Tamil Nadu health department FAQ
Medical Termination of Pregnancy Regulations, 2003The admission register is a secret document, kept by the head of the hospital, not open to inspection except under law, and kept for five years.MTP records need the tightest access in the hospital.MTP Regulations
Mental Healthcare Act, 2017Section 23: right to confidentiality. Section 24: no photos or information to media without consent. Section 25: right to access basic medical records.Psychiatry and counselling records need separate access and a careful request process.NHSRC copy of the Act
HIV and AIDS (Prevention and Control) Act, 2017HIV status may be disclosed only with informed consent, except in narrow cases. Establishments keeping HIV-related records must adopt data protection measures.Restrict HIV results and counselling notes to the treating team.Act
New Drugs and Clinical Trials Rules, 2019Informed consent of trial participants; ethics committees keep records for five years after the trial ends (Rule 13).Trial data needs both informed consent and DPDP safeguards.NDCT Rules
Drugs Rules: Schedule H1 registerPharmacies record prescriber's name and address, patient's name, drug and quantity, kept for three years.Keep the register for three years, then dispose of it.NHSRC
ABDM Health Data Management PolicyFor entities in the Ayushman Bharat Digital Mission, health records are shared through a consent manager, with consent artefacts for each request.If you are ABDM-linked, the ABDM consent flow and your DPDP notices must agree.ABDM / NHA
Clinical Establishments Act, 2010 and Rules, 2012 (states that adopted it)Registered establishments maintain medical records, and electronic records as the government specifies.Check whether your state follows this Act or its own nursing home law.MoHFW
IRDAI health insurance master circular, 2024Insurers decide cashless requests within one hour and final discharge within three hours.Fast TPA sharing is needed, but only the records the claim needs, through secure channels.IRDAI
CERT-In Directions, 2022Report specified cyber incidents within six hours; keep ICT logs 180 days in India.A ransomware attack needs a CERT-In report and the DPDP messages.CERT-In
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.