InfraVeritas360DPDPiq

DPDP Insights › Healthcare and hospitals › Practical examples

Healthcare and hospitals

Practical examples for Healthcare

Five documents most organisations in this sector need before 13 May 2027.

Examples to adapt, not legal advice. Replace the text in square brackets with your own details.

EXAMPLE · NOT LEGAL ADVICE

Notice wording: Patient registration (OPD or admission)

We collect your name, age, contact details, ID, medical history, test results and payment or insurance details to treat you, bill you, process your insurance claim if you ask, and meet legal record-keeping rules.

We will use your details for health package offers, patient stories or research only if you tick the separate boxes below. You can withdraw any time at the front desk or by calling us.

You can ask for copies of your records, ask what we hold and who received it, ask for correction, or complain to our Privacy Officer at [contact]. You may also approach the Data Protection Board of India.

EXAMPLE

Request and complaint log

RefDateUHIDRequestSystemsOwnerDueStatus
PR-031105-11-2026verifiedRecord copiesHIS, PACSMedical records72 hoursIssued in 48 hours
PR-031205-11-2026verifiedWho saw my reportHIS logPrivacy officerwithin published periodReplied day 5
PR-031307-11-2026verifiedStop offersCRM, SMSPatient relationssame dayClosed day 1
EXAMPLE · NOT LEGAL ADVICE

Retention schedule

RecordKeep forWhy
Indoor (IPD) recordsAt least 3 years from start of treatment; many hospitals keep longerMedical ethics regulations, continuity, claims
PCPNDT records and Form F2 years, or until legal proceedings endPCPNDT Act
MTP admission register5 yearsMTP Regulations, 2003
Schedule H1 register3 yearsDrugs Rules
Clinical trial ethics committee records5 years after the trial endsNDCT Rules, 2019
Access and activity logsAt least 1 year; ICT logs 180 days in IndiaDPDP Rules; CERT-In
EXAMPLE · NOT LEGAL ADVICE

Vendor data clause

The Laboratory shall process patient personal data received from the Hospital only to perform the tests ordered and report results to the Hospital and the patient, and for no other purpose. It shall keep reasonable security safeguards, restrict access to authorised staff, keep access logs for at least one year, and not engage any sub-contractor or transfer data outside India without the Hospital's written approval. It shall inform the Hospital of any personal data breach within [6] hours of becoming aware. It shall keep records only for the periods required by law and then delete them, confirming in writing on request.

EXAMPLE · NOT LEGAL ADVICE

Breach notice to affected people

Dear [patient], on [date] a lab report link meant for you was sent by mistake to another mobile number. The report showed your name, age and test results. We disabled the link within [time] and have informed the Data Protection Board. We are sorry this happened. We have changed how we confirm mobile numbers at registration. If you have any questions, please contact our Privacy Officer at [contact].

Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.