InfraVeritas360DPDPiq

DPDP Insights › Healthcare and hospitals › Health-tech and telemedicine

Healthcare and hospitals

DPDP for a health-tech and telemedicine

Teleconsultation records, chats and prescriptions sit on your platform. The Telemedicine Practice Guidelines ask doctors to record consent and keep consultation records; DPDP adds notices, consent for anything beyond care, and limits on tracking.

Read it from your seat in the tool

Whose data you hold

App users and patients. You work with partner doctors, pharmacies and labs.

Where it usually goes wrong

  1. Analytics and ad SDKs in health apps
  2. Chat transcripts kept with no period
  3. Sharing user data with partner pharmacies for offers

Read it from your seat

Questions that come up first

Do we need DPDP consent to treat a patient?

Short answer: Not for treatment; yes for extra uses

Usually not for the treatment itself. A patient who comes for care gives data voluntarily for that purpose, and a medical emergency involving a threat to life is a listed use. Clinical consent for procedures is a separate medical and legal requirement and stays. Extra uses such as research, marketing, testimonials and sharing beyond what care and billing need do require DPDP consent.

What the law says

Section 7(a) covers data given voluntarily for a specified purpose; Section 7(f) and 7(g) cover emergencies and epidemics. Section 7 · Section 6 · Section 5 · Rule 3

Steps
  1. Keep clinical consent forms as they are.
  2. Add a short notice at registration.
  3. Add separate boxes for research, offers and stories.
  4. Record which box each patient ticked.
  5. Train front desk to explain the difference.
Evidence to keep
  • Registration notice
  • Consent records for extra uses
Common mistakes
  • One form that bundles treatment and marketing
  • Calling clinical consent 'DPDP consent'
  • No notice at registration
Related questions

Can we share patient records with insurers and TPAs?

Short answer: Yes for the patient's claim; only what it needs

Yes, for a claim the patient has asked for, because that is part of the purpose. Share only what the claim needs, through the TPA portal or a secure channel, and keep a record of what was sent. Sharing for anything else, such as an insurer's own marketing, needs consent.

What the law says

Section 7(a) covers the claim purpose; Section 8(1) and 8(5) apply to how data is sent. Section 7 · Section 8(5) · Rule 6 · Sections 11–14 · Rule 14

Steps
  1. Use TPA portals, not email.
  2. Send only claim documents.
  3. Log what was sent, to whom, when.
  4. Answer patient questions about sharing.
  5. Check TPA agreements.
Evidence to keep
  • Sharing log
  • TPA agreement
Common mistakes
  • Full case files by email
  • No record of what was sent
  • Insurer representatives reading records on wards
Related questions

How long should we keep patient records?

Short answer: At least the legal minimums, with a written reason for anything longer

Keep them for at least the periods health laws set: indoor records for three years from the start of treatment under the 2002 medical ethics regulations, PCPNDT records for two years, MTP registers for five years, Schedule H1 registers for three years, and ethics committee trial records for five years after a trial. Many hospitals keep records longer for continuity of care and legal claims. Write the period and reason for each record type, then erase or archive.

What the law says

Section 8(7) allows retention where a law requires it; Rule 8(3) sets a one-year floor. Section 8(7) · Rule 8 · Section 7

Steps
  1. List record types: OPD, IPD, lab, imaging, billing, PCPNDT, MTP, pharmacy.
  2. Note the legal minimum.
  3. Decide any longer period and why.
  4. Archive with restricted access.
  5. Record each deletion.
Evidence to keep
  • Retention schedule
  • Archive access list
  • Deletion log
Common mistakes
  • No schedule at all
  • Deleting before the minimum
  • Keeping open access to old records
Related questions

What should our privacy notice say, and where must people see it?

Short answer: Yes, at every point where you collect data

A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.

In Healthcare

Registration desks, appointment apps, lab forms and health-camp sign-ups need short notices in the languages patients speak.

What the law says

Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14

Steps
  1. List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
  2. Write one short notice per collection point, with the data items and purpose side by side.
  3. Add how to withdraw consent, how to make a request and the DPO or contact person's details.
  4. Offer the notice in English and in the languages your app users actually use.
  5. Keep each version with the date it went live.
Evidence to keep
  • Screenshots or copies of the notice at each collection point, with dates
  • Notice version history
  • Translations, where used
Common mistakes
  • Hiding the notice inside terms and conditions
  • One notice for everything, with no link between data items and purposes
  • Forgetting old data collected before the Act
Related questions

Someone asks what data we hold about them. What do we send?

Short answer: Yes, a clear summary, inside the published timeline

Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.

In Healthcare

Under the 2002 regulations, patients and authorised attendants should get record copies within 72 hours of a request. The DPDP summary adds who the data was shared with.

What the law says

Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14

Steps
  1. Log the request in one register the day it arrives.
  2. Verify identity using details you already hold.
  3. Search every system, including vendors' copies.
  4. Write a plain summary: what data, why it is used, who received it.
  5. Send it, and file the request, search notes and reply.
Evidence to keep
  • Request register
  • Search notes for each request
  • Copy of each reply with date
Common mistakes
  • Sending raw database dumps
  • Forgetting data held by vendors
  • No identity check before sending
Related questions
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.