Skip to main content

Data protection

DPDP Act compliance for hospitals and patient data

India's Digital Personal Data Protection Act applies squarely to hospitals. Health data is among the most sensitive personal data a hospital holds, and the Act's obligations — lawful consent, purpose limitation, security safeguards, and patient rights over their own records — attach to every facility processing it, regardless of size.

This page sets out what the Act asks of a hospital, which parts a hospital information system can genuinely help with, and which parts it cannot. HealUDoc supplies technical controls; policy, notices, and staff conduct remain the hospital's own responsibility, and any vendor claiming otherwise is overselling.

Consent is granular, revocable, and purpose-bound

The Act treats consent as specific rather than blanket. A patient consenting to treatment has not thereby consented to their records being used for research, shared with a corporate employer, or used for marketing follow-up. Each purpose requires its own basis, and consent given for one does not carry to another.

Consent is also revocable, which has a technical consequence many hospitals miss: withdrawal has to actually stop the processing it covered. That is only possible if consent was recorded against a purpose in the first place. HealUDoc holds consent as structured data attached to the patient record, so a withdrawal is an operation the system can act on rather than a note in a file.

Consent obligations that reach into software

  • Separate, itemised consent captured per processing purpose
  • Withdrawal recorded with a timestamp and honoured going forward
  • Notices retrievable in the language they were presented in
  • A durable record of what was agreed, when, and by whom

Security safeguards and access control

The Act requires reasonable security safeguards, and in a hospital the most common failure is not an external breach but excessive internal access. When every user can open every chart, a hospital cannot demonstrate minimisation and cannot investigate a complaint about inappropriate access.

Role-based permissions scoped by department and branch address the first problem, and access logging addresses the second. HealUDoc records who opened a chart and when, so an administrator investigating a concern has evidence rather than recollection. Retention rules matter here too — data kept past its purpose is data still exposed to breach.

Patient rights create operational work, not just policy

Data principals — patients, in this context — can seek access to their data, correction of inaccuracies, and erasure in defined circumstances, and can nominate someone to exercise those rights. Each of these is a request a hospital must be able to receive, verify, action, and evidence within a reasonable period.

Hospitals that treat this as a policy document rather than a workflow tend to fail the first real request. Someone must own it, there must be a way to locate every copy of a patient's data, and the response must be recorded. A patient portal helps by letting patients see their own records directly, which resolves a share of access requests before they become formal ones.

Key capabilities

  • Consent recorded per purpose against the patient record, with withdrawal history
  • Role-based access scoped by department, seniority, and branch
  • Access logging showing which user opened which chart and when
  • Patient portal access so patients can view their own records directly
  • Configurable retention handling instead of indefinite storage by default
  • Structured export to support access and portability requests
  • Correction workflows that preserve the prior clinical value rather than overwriting it
  • Administrative reporting to evidence access controls during a review

Who this is for

Hospital administrators

Leaders accountable for the facility's data handling who need controls they can evidence, not policies they can only assert.

Compliance & legal teams

Teams translating the Act into operational requirements who need to know what the system can enforce and what it cannot.

Healthcare IT

Technical owners implementing access control, logging, and retention across departments and branches.

Frequently asked questions

Does the DPDP Act apply to hospitals and clinics?

Yes. The Act applies to organisations processing digital personal data in India, and hospitals process some of the most sensitive categories of it. Obligations scale with the nature and volume of processing rather than exempting smaller facilities, so clinics and diagnostic labs fall within scope alongside large hospital networks.

Can software make a hospital DPDP compliant?

No, and a vendor claiming otherwise should be treated with caution. Compliance covers consent notices, retention policy, grievance handling, vendor contracts, and staff conduct — much of which sits outside any system. Software supplies the technical controls the Act expects, such as consent records, role-based access, audit logging, and retention handling. The surrounding policy and governance remain the hospital's responsibility.

What is the difference between DPDP and ABDM requirements?

They are separate obligations that overlap on consent. ABDM is the national digital health framework governing identity, standards, and health information exchange, while the DPDP Act is general data protection legislation applying to all personal data. A hospital can be ABDM-integrated and still fall short on DPDP obligations such as retention limits or data-principal rights, so both need to be worked through.

What are the penalties for non-compliance?

The Act provides for substantial financial penalties for contraventions, with the maximum reserved for serious failures such as inadequate security safeguards leading to a breach. Because penalty determination depends on the specific facts and the Board's assessment, hospitals should take advice from their own counsel rather than relying on a vendor's summary — including this one.

How long can a hospital retain patient data under the Act?

The Act works on purpose limitation rather than a single universal retention period, and healthcare records are also subject to separate medical record retention requirements. In practice a hospital defines retention per record class, justified by the purpose and by applicable medical retention rules, and stops retaining personal data by default once no purpose remains.

Do patients have a right to erasure of medical records?

The right to erasure exists but is not absolute, and it is constrained where retention is required for legal or medical-record purposes. This is precisely the kind of question that turns on facts and applicable rules, so hospitals should confirm their position with counsel. What software can do is make it possible to locate and act on a patient's data once that determination has been made.

Explore related resources

Compare plans, review common questions, and understand how we protect clinical data before you decide.

Related reading

Practical guides from our blog on workflows that connect to this solution.

See the controls, not just the claims

Book a walkthrough and we will show you the consent records, access logs, and permission model directly — so your compliance team can judge them against your own obligations.