⚡ Experience The True Potential Of Healthcare with eMedHubRequest Demo →
Back to Blog
Compliance2026-08-077 min read

DPDP Act 2023: What Hospitals Must Do With Patient Data Now

SR

Sunita Rao

Quality & Compliance Manager

Share
DPDP Act 2023: What Hospitals Must Do With Patient Data Now

The Digital Personal Data Protection Act 2023 is law, and the DPDP Act affects hospitals more directly than almost any other sector. Patient records, prescription histories, lab results, insurance claims, ABHA-linked health IDs — your systems hold exactly the kind of data this law is designed to protect. The obligations are real, the penalties are significant, and the clock is running.

How does the DPDP Act affect hospitals? The DPDP Act places seven core obligations on hospitals: obtain explicit patient consent before processing personal data; appoint a Data Protection Officer; maintain a lawful purpose for every data use; store data only as long as necessary; notify breaches promptly; honour patient rights requests; and implement reasonable security safeguards.

What the DPDP Act Requires from Hospitals

The DPDP Act 2023 classifies hospitals as "Data Fiduciaries" because you decide why and how patient personal data is collected and used. That label is not ceremonial. It carries legal accountability. The Act covers any personal data processed in digital form, which means your HIS database, pharmacy records, TPA claim files, ABHA-linked patient IDs, and lab results are all in scope. Even digital consent forms and WhatsApp appointment reminders count.

Checklist of five key DPDP Act obligations for hospitals with maximum penalties from ₹50 crore to ₹250 crore.
Consent violations carry the steepest penalty — ₹250 crore — making it the highest-risk obligation.

The penalties are structured in tiers, and the numbers are not small. The Data Protection Board of India can impose penalties up to ₹250 crore for a single breach of consent obligations. Failing to notify a data breach can attract up to ₹200 crore. A 150-bed hospital with weak data governance, a ransomware incident, and a missed notification window could face a penalty that exceeds its annual operating surplus several times over.

ObligationWhat it means for your hospitalMaximum penalty
ConsentCollect explicit, purpose-specific, informed consent before processing₹250 crore
Purpose limitationUse patient data only for the declared reason₹50 crore
Data minimisationCollect only the fields you actually need₹50 crore
Storage limitationRetain records only as long as necessary₹50 crore
Breach notificationInform the Board and affected patients promptly₹200 crore
Data qualityKeep patient records accurate and up to date₹50 crore
Children's dataParental consent mandatory; no behavioural targeting₹200 crore

Consent is the foundation of the DPDP Act, and most hospitals currently collect it in a way that will not hold up. A blanket clause printed on the OPD registration slip in small font does not qualify. The Act requires consent that is "free, specific, informed, unconditional and unambiguous," and it must be obtained before processing begins, not buried in a form the patient signs without reading.

Five-step flow of what valid DPDP-compliant patient consent requires, from plain language to linked guardian records.
A blanket OPD registration clause in small font satisfies none of these five requirements.

Here is what valid consent looks like in a hospital setting:

  • Written in plain language, not legal boilerplate, and offered in the patient's preferred language where practicable.
  • Purpose-specific: consent for clinical treatment is separate from consent to share data with a TPA, an Ayushman Bharat claims processor, or a third-party diagnostic lab.
  • Granular enough that a patient can agree to one purpose and decline another without losing access to care.
  • Revocable at any time, with a clear and accessible process for the patient to withdraw.
  • Linked to the correct Data Principal: for minors and patients who lack decision-making capacity, a parent or legal guardian must give consent, and your registration system must record that relationship and flag it in the HIS.

Emergency treatment is a recognised exception. When the situation is life-threatening, you may process data without prior consent, but you must document the emergency basis clearly in the medical record. Routine admissions and elective procedures do not qualify under this provision.

Data Fiduciary Duties Your Hospital Cannot Ignore

Beyond consent, the DPDP Act imposes ongoing duties that require structural change, not just a one-time policy update. These apply whether you run a 30-bed nursing home in Nashik or a 400-bed multispeciality hospital in Hyderabad.

  1. Appoint a Data Protection Officer (DPO). Entities notified as Significant Data Fiduciaries must appoint a DPO based in India. Health data sensitivity makes hospitals likely candidates for this designation. Even if your hospital is not initially notified, assigning a responsible person for data governance now is prudent.
  2. Maintain a processing record. Document what data you collect, for what purpose, how long you retain it, and who you share it with. Your HIS vendor, TPA integrations, and outsourced lab arrangements all need to be on this map.
  3. Implement security safeguards. The Act requires "reasonable security safeguards." For health data, the baseline includes role-based access controls, full audit trails, encrypted storage and transmission, and periodic vulnerability assessments.
  4. Honour patient rights. Patients can request access to their data, correction of inaccuracies, and in some cases erasure. Your hospital needs a defined workflow to handle these requests within the regulatory timeframe once rules are formally notified.
  5. Manage third-party processors. Billing software vendors, radiology PACS providers, pharmacy management systems, and cloud storage partners are all "Data Processors" under the Act. You remain liable for how they handle patient data. Contracts must include DPDP-aligned data protection clauses.

Breach Notification: What Happens When Data Leaks

A data breach in a hospital is not just a reputational event. Under the DPDP Act, it triggers a formal notification obligation to the Data Protection Board of India and to every affected patient. While final rules are still being notified, the expectation is a short mandatory window for reporting to the Board, broadly in line with international norms for health data incidents.

Five-step breach notification flow under the DPDP Act, from incident detection through Board notification to remediation.
Missing the notification window can attract a ₹200 crore penalty on top of the breach itself.

Consider the scenarios your hospital faces. A ransomware attack locks your HIS. A staff member emails a patient list to a personal account by mistake. An Ayushman Bharat claims portal used by your TPA is compromised and your patient files are exposed. In each case, you must assess the breach, identify the scope, notify the Board, and communicate directly with affected patients. Delaying any of these steps compounds the penalty.

Your hospital needs an incident response plan before a breach occurs. The plan should name who contacts the Board, who drafts patient notifications, who coordinates with your software vendor, and who handles media enquiries if the incident becomes public. Waiting until a crisis to assign these roles will guarantee you miss the notification window and face the maximum financial consequence.

Health Data Specifics: Why Hospitals Face Higher Scrutiny

Health data sits at the sensitive end of the personal data spectrum. The DPDP Act does not create an explicit special category, but the government retains broad powers to notify certain data fiduciaries for additional obligations based on the volume and sensitivity of data they handle. Hospitals are among the most exposed entities in this respect, and health data is the most likely category to attract enhanced rules under subordinate legislation.

For your hospital's patient data privacy obligations, the practical implications cover several specific areas:

  • ABDM and ABHA integrations: Patient-linked health records shared across the national health stack must follow minimum-necessary data principles. Every API call that sends health data out of your HIS is a potential compliance point that requires logging and purpose justification.
  • Telemedicine records: These are digital by default and often stored outside the hospital's own infrastructure. Check where your telemedicine platform stores data and under what contractual terms the vendor handles it.
  • Sensitive diagnoses: Mental health records, HIV-related records, and reproductive health data carry additional sensitivity under the Mental Healthcare Act 2017 and the HIV and AIDS Prevention and Control Act 2017. DPDP obligations layer on top of these existing statutory duties.
  • Biometric identifiers: If your hospital uses fingerprint-based identification for CGHS or ESI patients, biometric data is firmly in scope and warrants extra access controls and breach monitoring.

Data localisation rules for health data are still under discussion. If your hospital uses cloud services with servers outside India, monitor MeitY notifications and confirm that your vendor can pivot to India-based storage if and when required.

Software Controls That Help You Comply

Policy documents alone will not achieve DPDP compliance. Your hospital information system needs to enforce the Act's requirements at the workflow level, because consistent human behaviour across a busy OPD, a night-shift ward, and a high-volume pharmacy counter is not a realistic expectation without system-level controls baked in.

The controls that matter most:

  • Role-based access control: A billing clerk should not be able to view a patient's psychiatric history. A ward nurse should not access pharmacy procurement records. RBAC enforces the minimum-necessary access principle across every module, every shift.
  • Consent capture at registration: The HIS should display a structured digital consent form at OPD or IP registration, record the patient's acceptance with a timestamp, and link it permanently to the patient record so it is auditable.
  • Audit trails: Every access, edit, and export of patient data should be logged with the user ID, timestamp, and action taken. This is your primary evidence of compliance if the Data Protection Board investigates.
  • Retention policy enforcement: The system should flag records that have exceeded your configured retention period and trigger a deletion or anonymisation workflow. The Medical Council of India recommends retaining medical records for a minimum of three years from the last visit; do not keep data beyond your defined and documented period.
  • Breach alerting: Unusual access patterns, bulk data exports, or logins outside normal hours should trigger real-time alerts to your DPO or IT manager, not surface quietly in a log file nobody reads until after an incident.
  • Third-party data transfer controls: Integrations with TPAs, Ayushman Bharat portals, ABHA, and outsourced labs should pass only the minimum necessary data fields and log every outbound transfer with a purpose tag.

How eMedHub Supports DPDP Compliance

eMedHub is designed around the data governance requirements Indian hospitals face in practice. Role-based access control is enforced across all modules: OP billing, IP billing, pharmacy, lab, radiology, and OT. Digital consent capture is built into the patient registration workflow. Full audit trails cover every data access and edit across the system. Retention policies are configurable by record type, and all ABDM/ABHA integrations are built on minimum-necessary data principles with full transfer logging.

For hospitals working toward NABH accreditation, eMedHub's reporting suite addresses the information management standards that overlap directly with DPDP obligations, so the compliance work serves two purposes at once. The system is built for the realities of Indian hospital operations, whether you are a 40-bed facility in a tier-3 city managing ESI and CGHS patients or a 300-bed multispeciality group running multiple TPA integrations and a patient portal.

See how the compliance controls work in your context: book a demo of eMedHub.

Frequently asked questions

Is the DPDP Act applicable to hospitals and clinics in India?

Yes. The DPDP Act applies to any entity that processes digital personal data in India, including hospitals, clinics, diagnostic labs, IVF centres, and eye-care chains. Hospitals are classified as Data Fiduciaries because they determine the purpose and means of processing. There is no size threshold, so a small nursing home with a digital OPD system is as much in scope as a large corporate hospital.

The Act requires consent that is free, specific, informed, unconditional, and unambiguous. A blanket clause on a registration form does not qualify. Consent must be purpose-specific, meaning separate consent is needed for treatment, billing, and sharing data with TPAs or insurers. Patients can withdraw consent at any time, and your hospital must have a documented process to honour that withdrawal promptly.

How long can a hospital keep patient records under the DPDP Act?

The DPDP Act requires data to be retained only as long as necessary for the stated purpose. The Medical Council of India recommends a minimum retention period of three years from the last patient visit for medical records. Once records exceed your defined retention period, the hospital must delete or anonymise them. Retaining data indefinitely without a documented purpose and legal basis is a direct compliance risk.

What is the penalty for a hospital data breach under the DPDP Act?

Failing to notify a data breach to the Data Protection Board of India can attract a penalty of up to ₹200 crore. Inadequate security safeguards can result in separate penalties up to ₹50 crore. These are per-incident figures. A single ransomware attack at a hospital that fails to notify the Board within the mandatory window could generate penalties that exceed several years of net operating profit.

Do small nursing homes and tier-3 city hospitals need to comply with the DPDP Act?

Yes. The Act applies to any entity processing digital personal data in India, regardless of size or location. For smaller hospitals in tier-2 and tier-3 cities, the practical starting point is: get patient consent right at registration, restrict database access with role-based controls, and put a basic breach response plan in place. Your obligations scale with the volume and sensitivity of the data you process, not your bed count.

Share this article
Chat on WhatsApp