DPDP Insights › Healthcare and hospitals › Practical examples
Five documents most organisations in this sector need before 13 May 2027.
Examples to adapt, not legal advice. Replace the text in square brackets with your own details.
We collect your name, age, contact details, ID, medical history, test results and payment or insurance details to treat you, bill you, process your insurance claim if you ask, and meet legal record-keeping rules.
We will use your details for health package offers, patient stories or research only if you tick the separate boxes below. You can withdraw any time at the front desk or by calling us.
You can ask for copies of your records, ask what we hold and who received it, ask for correction, or complain to our Privacy Officer at [contact]. You may also approach the Data Protection Board of India.
| Ref | Date | UHID | Request | Systems | Owner | Due | Status |
|---|---|---|---|---|---|---|---|
| PR-0311 | 05-11-2026 | verified | Record copies | HIS, PACS | Medical records | 72 hours | Issued in 48 hours |
| PR-0312 | 05-11-2026 | verified | Who saw my report | HIS log | Privacy officer | within published period | Replied day 5 |
| PR-0313 | 07-11-2026 | verified | Stop offers | CRM, SMS | Patient relations | same day | Closed day 1 |
| Record | Keep for | Why |
|---|---|---|
| Indoor (IPD) records | At least 3 years from start of treatment; many hospitals keep longer | Medical ethics regulations, continuity, claims |
| PCPNDT records and Form F | 2 years, or until legal proceedings end | PCPNDT Act |
| MTP admission register | 5 years | MTP Regulations, 2003 |
| Schedule H1 register | 3 years | Drugs Rules |
| Clinical trial ethics committee records | 5 years after the trial ends | NDCT Rules, 2019 |
| Access and activity logs | At least 1 year; ICT logs 180 days in India | DPDP Rules; CERT-In |
The Laboratory shall process patient personal data received from the Hospital only to perform the tests ordered and report results to the Hospital and the patient, and for no other purpose. It shall keep reasonable security safeguards, restrict access to authorised staff, keep access logs for at least one year, and not engage any sub-contractor or transfer data outside India without the Hospital's written approval. It shall inform the Hospital of any personal data breach within [6] hours of becoming aware. It shall keep records only for the periods required by law and then delete them, confirming in writing on request.
Dear [patient], on [date] a lab report link meant for you was sent by mistake to another mobile number. The report showed your name, age and test results. We disabled the link within [time] and have informed the Data Protection Board. We are sorry this happened. We have changed how we confirm mobile numbers at registration. If you have any questions, please contact our Privacy Officer at [contact].