Last Updated: June 9, 2026 · Author: Saurabh Gupta, CISM, CIPP/E · Founder, MYITMANAGER
Healthcare and health-tech companies in India occupy a uniquely sensitive position under the DPDP Act 2023. They process what is arguably the most sensitive category of personal data — medical diagnoses, treatment histories, mental health records, prescription data, genetic information, and intimate health behaviours — for patients who have little choice but to share it.
The DPDP Act does not create a separate category of “sensitive personal data” (unlike GDPR’s Article 9), but health data is widely expected to receive heightened scrutiny in the forthcoming Significant Data Fiduciary designations and in DPBI enforcement priorities. A breach involving patient health records will attract maximum penalty exposure and reputational damage that no hospital, diagnostic chain, or health-tech platform can afford.
This guide covers the DPDP Act obligations that matter most for healthcare providers, diagnostic labs, telemedicine platforms, health apps, and hospital management systems — and how to build a compliance framework before the enforcement deadline.
Which Healthcare Organisations Must Comply with the DPDP Act?
The DPDP Act applies to any entity that processes digital personal data of Indian residents in the course of any business activity. In healthcare, this includes:
- Hospitals and clinic chains — processing patient registration, medical records, billing data, insurance claims
- Diagnostic labs and imaging centres — processing test results, radiology reports, genetic test data
- Telemedicine platforms — Practo, Apollo 24|7, 1mg, and similar — processing consultation records, prescriptions, health history
- Health apps and wearables — fitness trackers, menstrual health apps, mental health platforms, chronic disease management apps
- Hospital Information Systems (HIS) and EMR vendors — as Data Processors handling patient data on behalf of hospitals
- Health insurance companies — processing policy data, claims histories, pre-existing condition disclosures
- Pharmaceutical companies — processing patient data for clinical trials, pharmacovigilance, and digital health programmes
If your organisation collects, stores, processes, or shares digital health data of Indian patients, the DPDP Act applies to you.
The Core DPDP Challenges for Healthcare
1. Consent — The Hardest Problem in Healthcare
Consent under the DPDP Act must be free, specific, informed, unconditional, and revocable. In healthcare, this collides with operational reality:
- Patients in emergency situations cannot meaningfully give informed consent
- Treatment often requires sharing data with specialists, labs, insurance companies, and regulatory bodies — without explicit consent for each transfer
- Legacy systems collect consent via paper forms at admission that have no digital equivalent
- Health apps collect continuous streams of behavioural health data — step counts, sleep data, heart rate — without clear purpose limitation
The DPDP Act provides for processing without consent for “certain legitimate uses” including medical emergencies and public health purposes (Section 7). However, these exceptions are narrow and must be documented. For routine data processing — appointment management, follow-up communications, billing, insurance claims — valid consent is required.
What hospitals and health platforms need to build: A layered consent management system that captures consent digitally at point of registration, separates consent for treatment from consent for data sharing with third parties, and provides patients with a mechanism to access and revoke consent.
2. Data Principal Rights — Patients Have New Rights to Their Records
Under the DPDP Act, patients (as data principals) have the right to:
- Access — obtain a summary of what personal data you hold about them
- Correction — correct inaccurate health data (a significant operational requirement for hospitals with large patient databases)
- Erasure — request deletion of personal data when the purpose is fulfilled
- Grievance redressal — raise complaints through a defined grievance mechanism and receive responses within 30 days
- Nomination — nominate another person to exercise their rights in case of death or incapacity (particularly relevant in healthcare)
The erasure right in healthcare is complex. Patient records may need to be retained for regulatory purposes (MCI guidelines, insurance requirements, medico-legal cases) even after the patient requests deletion. Healthcare organisations need a documented retention policy that explains why certain records are retained despite erasure requests — and must be able to articulate this clearly when responding to data principal requests.
3. Data Sharing — Insurers, Labs, Specialists, and Government
Healthcare involves extensive data sharing: hospitals share patient records with insurance TPA companies for claims processing; diagnostic labs send reports to ordering physicians; telemedicine platforms share prescriptions with partner pharmacies; hospitals report notifiable diseases to government authorities. Each transfer has a different legal basis under the DPDP Act:
| Data Transfer | DPDP Basis | Action Required |
|---|---|---|
| Hospital → Insurance TPA | Contractual necessity / consent | DPA + explicit consent for health data sharing |
| Lab → Ordering Physician | Treatment purpose (legitimate use) | Document in privacy policy |
| Platform → Partner Pharmacy | Consent required | Separate consent at time of prescription |
| Hospital → Government (notifiable diseases) | Legal obligation (Section 7) | Document legal basis; no consent required |
| Data → Cloud HIS Vendor | Processor relationship | Signed Data Processing Agreement mandatory |
Every organisation that receives health data from you is either a Data Processor (acting on your instructions, requires a DPA) or an independent Data Fiduciary (requires patient consent for the transfer). Mapping these flows is a prerequisite for DPDP compliance.
4. Health Apps — The Highest-Risk Category
Consumer health apps face the most acute compliance challenges under the DPDP Act:
- Continuous data collection without clear purpose limitation (step tracking, sleep monitoring, menstrual cycle data, mental health journals)
- Third-party SDK risk — many health apps embed analytics SDKs (Firebase, Mixpanel, Appsflyer) that process user data for advertising purposes without users realising it
- Children’s data — apps accessible to users under 18 (fitness apps, school health apps) must implement age verification and parental consent
- Cross-border data transfer — many health apps send data to US/EU servers for AI processing, requiring compliance with DPDP cross-border transfer rules once notified
Health app companies must conduct a full audit of every SDK, third-party integration, and backend service that touches user health data — and either remove those that cannot be justified or obtain explicit consent for their use.
5. Security Safeguards — What “Reasonable” Means for Patient Data
The DPDP Act requires “reasonable security safeguards” to prevent personal data breaches. For health data, the bar for what constitutes reasonable security is high. Based on existing regulatory guidance (CERT-In, MeitY, HIPAA best practices applicable in international contexts), reasonable security for patient data includes:
- Encryption of patient records at rest and in transit
- Role-based access controls — clinical staff access patient records relevant to their treatment role only
- Audit logs for all access to patient health records
- Secure patient portal with multi-factor authentication for digital record access
- Regular VAPT on patient-facing applications
- Third-party vendor security assessments for HIS/EMR providers
- Physical security controls for on-premises patient data stores
6. Breach Notification — Patient Data Breaches Are High-Profile Events
Healthcare organisations are among the most targeted by ransomware and data theft attacks globally, and India is not immune. A breach of patient health records — whether through a ransomware attack on a hospital’s HIS, an API vulnerability in a health app, or a misconfigured cloud storage bucket — triggers DPDP Act breach notification obligations: notify the DPBI, and potentially notify affected patients depending on severity.
Healthcare organisations with large patient databases must have a tested breach response plan before an incident occurs. The plan must identify who is notified internally, the technical response steps, the DPBI notification timeline, and patient communication protocols.
Significant Data Fiduciary Risk for Healthcare
Large hospital chains (Fortis, Apollo, Manipal, Max), major diagnostic networks (SRL, Metropolis, Thyrocare), and high-volume telemedicine platforms (Practo, 1mg) processing health data of millions of patients are highly likely to be designated as Significant Data Fiduciaries. SDF obligations include:
- Appointment of a Data Protection Officer (DPO)
- Appointment of an independent data auditor
- Conducting Data Protection Impact Assessments (DPIAs) for new products and data processing activities
- Registering with a Consent Manager by November 2026 (per DPDP Rules 2025)
- Implementing algorithmic accountability measures for AI-driven health recommendations
Even healthcare organisations that don’t meet SDF thresholds should begin DPO readiness planning now — the DPBI is likely to look favourably on organisations that have appointed a DPO as a signal of compliance commitment.
MYITMANAGER’s DPDP Compliance for Healthcare
MYITMANAGER delivers end-to-end DPDP Act compliance engagements for healthcare providers, diagnostic labs, telemedicine platforms, and health-tech companies. Our healthcare DPDP engagements are led by Saurabh Gupta (CISM, CIPP/E) — one of fewer than 50 professionals in India with both certifications — with specific experience in health data governance and compliance frameworks that satisfy DPDP, CERT-In cybersecurity directions, and ISO 27001 simultaneously.
Our MYITMANAGER GRC Portal enables your compliance and information security teams to manage DPDP obligations, track consent records, log data principal rights requests, and monitor security controls — all in one platform, with significantly lower manpower requirements than manual tracking.
DPDP Compliance Checklist for Healthcare
- ☐ Map all patient data flows — collection, storage, processing, sharing, and deletion
- ☐ Implement digital consent management — granular, revocable, purpose-specific consent at point of registration
- ☐ Build data principal rights workflows — access, correction, erasure, grievance, and nomination request handling
- ☐ Audit all third-party data sharing relationships — classify as processor or independent fiduciary
- ☐ Execute Data Processing Agreements with all processors (HIS vendor, cloud provider, insurance TPA)
- ☐ Document legitimate use bases for processing without consent (emergencies, regulatory reporting)
- ☐ Implement patient data retention schedule — covering DPDP erasure rights and regulatory retention requirements
- ☐ Conduct security assessment — encryption, access controls, audit logs, VAPT
- ☐ Develop breach detection and notification protocol
- ☐ Assess SDF designation risk — prepare for DPO appointment if applicable
- ☐ Deploy the MYITMANAGER GRC Portal for ongoing compliance monitoring
Start with a free DPDP gap assessment specific to your healthcare organisation — written RAG-scored report in 5 business days, benchmarked against DPDP Rules 2025 and healthcare sector best practices. Book your assessment →
Ready to Build Your DPDP Compliance Programme?
50+ DPDP gap assessments completed across Indian sectors. Free assessment for qualified organisations — results in 5 business days.
Start your DPDP compliance journey →