Skip to main content
Analytics & Compliance11 min read

A DPDP Act Readiness Checklist for Hospitals

The Digital Personal Data Protection Act, 2023 reaches into every corner of a hospital where personal data sits, including the corners nobody has catalogued. This checklist covers data mapping, notice and consent, retention, access control, patient rights, and breach response.

MJ

Meenal Joseph

Hospital Data Governance Consultant

#DPDP Act#data protection#patient privacy#compliance checklist
A DPDP Act Readiness Checklist for Hospitals

You cannot protect data you have not located

The Digital Personal Data Protection Act, 2023 applies to personal data a hospital processes, and hospitals process a great deal of it in places nobody has catalogued. Readiness starts with a data map recording what personal data is held, where it sits, why it was collected, who can reach it, how long it stays, and who it is shared with. Most hospitals find the mapping exercise itself the most revealing part of the entire programme.

Look well beyond the clinical system. Personal data lives in appointment call logs, messaging groups used by ward staff, insurance claim files, marketing lists, camera recordings, biomedical devices with local storage, staff laptops, and spreadsheets maintained by individual departments. Anything absent from the map is unprotected by definition.

What follows is a practical starting point and not legal advice; hospitals should take the Act's specific requirements to their own counsel. Obligations are described qualitatively here because how they apply depends on a hospital's own circumstances and processing. The value of the checklist is the operational scaffolding that makes any legal position implementable.

Hospital team mapping where personal data is held across departments
Hospital team mapping where personal data is held across departments

Consent under the Act is expected to be free, informed, specific, and unambiguous, given for a stated purpose and capable of being withdrawn. A single signature on an admission form covering every conceivable future use of a patient's data does not meet that description. Purposes must be separated so a patient can agree to one and refuse another.

The notice accompanying a request has to be understandable, which in an Indian hospital means available in the languages patients actually speak. A notice written for a legal audience and handed over at an admission desk is a compliance artefact rather than a communication. Test comprehension with real patients before adopting the wording.

Distinguish clearly between processing needed to deliver care and processing that is genuinely optional, such as marketing contact or research participation. Bundling the optional with the essential is the most common defect we find. Care must never be made conditional on agreeing to an optional purpose.

Layered privacy notice separating essential and optional data purposes
Layered privacy notice separating essential and optional data purposes

Separate the purposes you ask about

  • Treatment and clinical record keeping
  • Billing, insurance, and claims processing
  • Appointment and clinical reminders
  • Marketing or promotional communication
  • Research or secondary analysis

Purpose limitation and retention are operational choices

Purpose limitation means data collected for one reason is not quietly repurposed for another. In a hospital the common breach is undramatic: a marketing team pulls a list from the clinical system, an administrator uses billing records to find prospects for a health package, a department shares a patient list with an external partner. None of these feels like a violation to the person doing it, which is why the control has to be technical as well as instructional.

Retention needs a schedule reconciling clinical need, statutory obligation, accreditation expectation, and the principle of not keeping data longer than its purpose requires. These pull in different directions, and the resolution belongs to the hospital and its own legal advisers rather than to a software default. Write it down, date it, and give it an owner.

Deletion must be real and must reach backups, archives, exports, and downstream copies. A record removed from the primary database while surviving in three reporting extracts has not been deleted in any meaningful sense. Document what was disposed of, when, and under whose authority.

Retention schedule reconciling clinical statutory and accreditation needs
Retention schedule reconciling clinical statutory and accreditation needs

Access control is the safeguard an assessor can actually see

The Act requires reasonable security safeguards, and in a hospital the most consequential of these is that staff reach only the records their role requires. Broad access granted for convenience is the default state in many hospitals, particularly where a system was configured quickly and permissions were never revisited. Every account holding more access than its role needs is an unnecessary exposure.

Review role definitions against the current organisation chart, remove access on the day someone changes role or leaves, and eliminate shared logins entirely because they destroy attribution. Break-glass access for emergencies should exist but should be exceptional, logged, and reviewed afterwards. HealUDoc supports role and branch-scoped access with an audit trail, though whether the roles themselves are correct remains a hospital decision.

Logging is what turns a control into evidence. Being able to show who opened a record, when, and from where is what lets a hospital answer a complaint or investigate an incident credibly. Logs nobody ever reviews provide considerably less assurance than they appear to.

Role-based access review against a current hospital organisation chart
Role-based access review against a current hospital organisation chart

Access control review points

  • Role definitions matched to current duties
  • Same-day revocation on exit or role change
  • No shared or generic logins
  • Logged and reviewed break-glass access
  • Periodic review of high-privilege accounts

Data-principal rights need a route into daily operations

Patients hold rights over their data, including access to information about processing, correction of inaccurate data, erasure in defined circumstances, grievance redress, and nomination of someone to act on their behalf. Each right needs an operational route: a place requests arrive, a person who owns them, a way to verify who is asking, and a defined turnaround. Without that, a right exists on paper and fails in practice.

Correction is the one hospitals find hardest, because a clinical record cannot simply be overwritten. The workable approach is an amendment preserving the original entry, recording who requested and who approved the change, and propagating the correction to places the data was already sent. HealUDoc's audit trail retains the original entry alongside the amendment for this reason.

A patient portal (/patient-portal) reduces the volume of routine access requests by letting patients see their own records directly, but it does not replace a formal request channel. Publish the channel, staff it, and log every request with its outcome and timing. Independent legal advice should confirm how each right applies to your hospital's circumstances.

Patient rights request queue with verification and turnaround tracking
Patient rights request queue with verification and turnaround tracking

Breach response is judged by what you did beforehand

The Act contemplates notification of personal data breaches, and the quality of a hospital's response is largely determined before anything happens. What matters on the day is whether you can establish what was accessed, whose data was involved, and over what period, which depends entirely on logging configured months earlier. A hospital unable to scope an incident cannot report it accurately.

Write and rehearse the plan: who is notified internally, who decides, who communicates with affected individuals and authorities, and what is recorded throughout. Include incidents that are not cyberattacks, such as a misdirected discharge summary, a lost device, a misused shared login, or a vendor's error. These are far more frequent than intrusions and are usually handled worse.

Run a tabletop exercise at least annually and after any material change to systems or suppliers. Contracts with vendors and processors should state their notification obligations to you and their duty to cooperate during an investigation. None of this makes a hospital compliant on its own, and no software product can; compliance is the sum of governance, contracts, configuration, and behaviour.

The breach itself took an hour. Establishing which two hundred records were involved took eleven days, and that was the part we were judged on.

Sunil Kapadia, Data Protection Lead, Vantage Healthcare Group
Share this article
Back to all articles

Keep reading

Related articles

See HealUDoc in action

From EHR to analytics, watch how one platform runs your entire hospital. Book a personalized walkthrough with our team.

Book a demo