Healthcare DPDP compliance
no special category, no special exemption.
Hospitals, diagnostics chains and health apps hold the most harmful data to lose and, under the DPDP Act, no special rules for it. What they do have is ABDM's consent layer, telemedicine rules, record-keeping duties and a narrow emergency carve-out that is often stretched.
Which laws apply to healthcare data in India?
The DPDP Act governs patient data held digitally by every hospital, clinic, lab and health app. Around it sit the Ayushman Bharat Digital Mission's consent and record-sharing framework, the Telemedicine Practice Guidelines, medical council record-keeping duties, state clinical establishment rules and CERT-In's incident directions.
| Law or framework | What it governs | Notes |
|---|---|---|
| DPDP Act 2023 and Rules 2025 | Notice, consent, purpose, security, breach reporting, rights | Same obligations for a diagnosis as for an email address |
| Ayushman Bharat Digital Mission | Health IDs, facility and professional registries, consented exchange of health records | Run by the National Health Authority; its own consent flow and health data management policy |
| Telemedicine Practice Guidelines | Remote consultation, patient identification, consent to teleconsultation, record-keeping | Issued 25 March 2020 as part of the medical council's professional conduct regulations |
| IMC (Professional Conduct) Regulations 2002 | Medical records, confidentiality | In-patient records kept for three years; restored after NMC's 2023 regulations were held in abeyance |
| Clinical Establishments Act 2010 and state laws | Registration, standards, record keeping | Adopted by some states; others have their own acts |
| CERT-In directions, 2022 | Six-hour incident reporting, logs in India | Applies to hospitals as body corporates. See the CERT-In guide |
The obligation healthcare gets wrong: treating health data as special
Healthcare teams often build GDPR-style special-category consent for clinical data and then share the same data freely with labs, insurers and billing vendors. The DPDP Act has no special category, so the first effort is unnecessary, and no special exemption, so the second is a breach.
The Act applies one standard to all personal data. The only category-based rule is section 9 on children. That cuts both ways. There is no need for an extra legal basis for a diagnosis. But every disclosure to a lab, a TPA, a pharmacy partner or a cloud PACS vendor is a disclosure like any other: it needs a purpose the patient was told about, a processor contract under section 8(2), and security the hospital remains responsible for under section 8(1).
Harm still matters. The Board fixes penalties with regard to the nature, gravity and duration of a breach, and failing to take reasonable security safeguards carries the Act's highest cap, ₹250 crore. Losing oncology records will be weighed differently from losing a newsletter list, even though the statute treats them alike.
How far does the medical emergency exception go?
Section 7(f) lets a provider process personal data without consent to respond to a medical emergency involving a threat to life or an immediate threat to health, and section 7(g) covers treatment during an epidemic. The exception covers the emergency itself, not the follow-up.
The line most often crossed is after discharge. The emergency justified admitting an unconscious patient, running tests and sharing records with a specialist. It does not justify enrolling the patient in a wellness programme, passing their number to a pharmacy partner, or using the case in a marketing campaign. Once the patient can be given a notice, the ordinary rules resume.
Children are the second line. The Fourth Schedule to the DPDP Rules lets clinical establishments, mental health establishments and healthcare professionals process a child's data without verifiable parental consent, but only to provide health services to the child and only to the extent necessary to protect her health. A paediatric app's analytics SDK is not a health service. The DPDP children's data guide covers the rest of section 9.
ABDM, telemedicine and the other consent layers
ABDM runs its own consent flow for exchanging health records between facilities, and telemedicine guidelines require consent to the consultation itself. Neither is a DPDP notice. A health provider still has to tell patients what it does with their data, for which purposes, and keep proof of what each patient agreed to.
ABDM calls the component that carries consent for record exchange a consent manager. That is an ABDM role, not a DPDP Consent Manager registered with the Data Protection Board under Rule 4, and the two should not be confused in a privacy notice. The DPDP Consent Manager guide explains the statutory role. The Telemedicine Practice Guidelines treat a patient who initiates a teleconsultation as having implied consent to it, and require explicit consent where the practitioner initiates. That covers the consultation, not the platform's later use of the recording or transcript.
Retention is the third thread. The Indian Medical Council's 2002 regulations require in-patient records to be kept for three years, and many hospitals keep longer for medico-legal reasons. That retention is lawful. What the Act requires is that you can name the rule for each record set, rather than keeping the patient portal's marketing preferences indefinitely because they sit in the same database.
Healthcare control checklist
For hospitals, diagnostics chains and health platforms. Each control should leave evidence behind.
| Control | Why | Evidence to hold |
|---|---|---|
| Notice at registration naming each purpose: treatment, billing, insurance, research, marketing | DPDP s.5 | Notice versions and the record of which one each patient saw |
| Emergency processing flagged, and ordinary notice given once the patient can receive it | DPDP s.7(f) | Admission records showing the flag and the later notice |
| Processor contract for every lab, TPA, PACS and billing vendor | DPDP s.8(2) | Contract register linked to purposes |
| Retention schedule per record set, citing the rule | DPDP s.8(7); IMC 2002 | Schedule and deletion logs |
| Children's data limited to the Fourth Schedule health purpose | DPDP s.9; Rules Fourth Schedule | Purpose tags on paediatric records; no analytics on child accounts |
| No trackers on appointment, symptom or results pages before consent | DPDP s.6 | Two-pass scan of patient-facing pages |
| Encryption, access logging and six-hour incident reporting | DPDP s.8(5); CERT-In | Access logs kept at least one year; incident drill records |
Where to go next
Hospitals running their own IT should also read the CERT-In directions guide, and anyone handling paediatric data the children's data guide. For the law underneath all of it, read the DPDP Act and Rules 2025 guide. To see what your own website does before a visitor answers the banner, run the free two-pass cookie scan. The consent platform holds versioned notices in 22 languages, a hash-chained consent ledger, withdrawal relayed to each processor, and rights requests and breaches on their statutory clocks. The industries overview compares all eight sectors.
The things people ask us
Is health data sensitive personal data under the DPDP Act?
No. The Act has no special category of sensitive personal data. A diagnosis gets the same protection as an email address, with one practical difference: a breach of health data is more harmful, and the Board sets penalties by the gravity of the breach. Security safeguards under section 8(5) carry the Act's highest penalty cap, ₹250 crore.
Can a hospital treat a patient without DPDP consent?
In an emergency, yes. Section 7(f) makes responding to a medical emergency involving a threat to life or an immediate threat to health a legitimate use, and section 7(g) covers treatment during an epidemic. Ordinary outpatient care, follow-up marketing and research are not emergencies and need a notice and, usually, consent.
How long must medical records be kept in India?
At least three years for in-patient records under the Indian Medical Council's 2002 professional conduct regulations, which the National Medical Commission restored when it held its 2023 replacement in abeyance. State rules and medico-legal practice often require longer. Retention required by law is an exception to DPDP erasure, but only for the records that law covers.
Is an ABDM consent the same as DPDP consent?
No. ABDM runs its own consent flow for linking and sharing health records between facilities, through its consent manager. That authorises a record exchange. Your DPDP notice, your purposes and your own consent record are still required, and ABDM's consent manager is not a DPDP Consent Manager registered with the Data Protection Board.
Can a hospital process a child's data without parental consent?
Only within the Fourth Schedule exemption. A clinical establishment, mental health establishment or healthcare professional may process a child's data without verifiable parental consent where it is restricted to providing health services to the child, to the extent necessary to protect her health. Anything beyond that, including app analytics, needs parental consent.
Check what your appointment page sends.
Symptom checkers and booking pages often carry advertising tags. Scan yours, then see how the platform records each patient's consent against the notice version they actually saw.