DPDP Act for hospitals and clinics: patient data in practice
- Digital patient records, and paper records that are later scanned or digitised, are covered by the Act (s.3(a)).
- Medical emergencies, epidemics and disasters are legitimate uses that do not need consent (s.7(f), (g), (h)).
- Clinical establishments and healthcare professionals are exempt from parental consent and the tracking bar for children, but only for health services (Rule 12(1), Fourth Schedule Part A items 1 and 2).
- Patients must be able to read notices and consent requests in English or a language in the Eighth Schedule to the Constitution (s.5(3), s.6(3)).
Hospitals, clinics and diagnostic centres process personal data at every step: registration, consultation, lab work, pharmacy, insurance and follow-up. This guide maps the DPDP Act, 2023 and DPDP Rules, 2025 onto that workflow. For app-first health businesses, also see DPDP for healthtech.
What is covered
The Act applies to digital personal data, including data collected on paper and digitised later (s.3(a)). Once a paper case sheet is scanned into a hospital information system or a lab report is emailed, it is in scope. The hospital, clinic or doctor deciding why and how data is processed is the Data Fiduciary (s.2(i)); the patient is the Data Principal, and for a child that includes the parent or lawful guardian (s.2(j)).
Grounds for processing patient data
Processing needs consent or a legitimate use (s.4(1)). For hospitals, the relevant clauses of section 7 are:
- Voluntary provision (s.7(a)). Data a patient gives for a stated purpose, where she has not objected. The Act's own illustration is a pharmacy sending a payment receipt to a customer's phone.
- Medical emergency (s.7(f)). Responding to a medical emergency involving a threat to life or an immediate threat to the health of the patient or any other individual.
- Epidemics (s.7(g)). Measures to provide treatment or health services during an epidemic, outbreak or other threat to public health.
- Disasters (s.7(h)). Safety, assistance or services during a disaster or breakdown of public order.
- Legal disclosures (s.7(d)). Disclosures a law obliges you to make to the State.
Outside these, rely on consent. It must be limited to the data necessary for the specified purpose (s.6(1)). The Act's illustration is a telemedicine app: consent to read the phone's contact list is invalid because contacts are not needed to provide telemedicine. Marketing health packages to past patients is a separate purpose that needs its own consent.
Notices and consent forms
A consent request must come with a notice (s.5(1)) that stands on its own and itemises the data and purposes in plain language (Rule 3(a) and 3(b)). It must explain how to withdraw consent, exercise rights and complain to the Board (Rule 3(c)). Patients must have the option to read the notice and the consent request in English or any language in the Eighth Schedule to the Constitution (s.5(3), s.6(3)). Consent requests must also give a contact for rights queries (s.6(3)).
For patients who consented before the Act applied, give a notice as soon as reasonably practicable; you may keep processing until they withdraw (s.5(2)). See how to draft a DPDP privacy notice.
Children and patients with a lawful guardian
Normally, a child's data (under eighteen, s.2(f)) needs verifiable parental consent (s.9(1)), and tracking or behavioural monitoring of children is barred (s.9(3)). Rule 12(1) and Part A of the Fourth Schedule lift both requirements for:
- clinical establishments, mental health establishments and healthcare professionals, where processing is restricted to providing health services to the child to the extent necessary to protect her health (item 1); and
- allied healthcare professionals, where processing is restricted to supporting a treatment and referral plan recommended by such a professional, to the same extent (item 2).
These terms take their meaning from the Clinical Establishments Act, 2010, the Mental Healthcare Act, 2017 and the National Commission for Allied and Healthcare Professions Act, 2021 (Fourth Schedule, Note). The exemption does not cover section 9(2), so processing likely to harm a child's well-being remains barred. Where an adult patient has a court-appointed or other lawful guardian, the guardian's consent must be verified under Rule 11; see guardian consent.
Security, labs and vendors
Rule 6(1) sets minimum safeguards: encryption, masking or tokenisation; access control; logging and monitoring; backups for continuity; one-year retention of logs; security terms in processor contracts; and organisational measures. Lab information systems, imaging archives, cloud hosting and billing vendors are typically Data Processors. You remain responsible for their processing (s.8(1)) and need a valid contract with each (s.8(2)). See reasonable security safeguards.
Breaches
If patient data is exposed, tell each affected patient without delay through her account or registered contact: what happened, likely consequences, your mitigation, steps she can take, and a contact (Rule 7(1)). Tell the Board without delay, then send a detailed report within seventy-two hours (Rule 7(2)). Failing to notify can attract a penalty of up to ₹200 crore (Schedule item 2).
Patient rights and insurers
- Where a patient gave consent (including under s.7(a)), she can ask for a summary of her data and the identities of other Data Fiduciaries and Processors it was shared with, such as insurers or labs (s.11(1)).
- Correction and erasure follow any requirement or procedure under other laws (s.12(1)); erasure can be refused where retention is needed for the purpose or by law (s.12(3)).
- Data shared with another Data Fiduciary, such as an insurer, must be complete, accurate and consistent (s.8(3)).
- Patients can nominate someone to exercise their rights on death or incapacity (s.14, Rule 14(4)). See right to nominate.
Research use
The Act does not apply to processing necessary for research, archiving or statistical purposes if the data is not used to take a decision specific to a Data Principal and the Second Schedule standards are met (s.17(2)(b), Rule 16). That is a narrow route, not a general research licence.
Most of these duties start eighteen months from 13 November 2025 (commencement note under s.1(2); Rule 1(4)).
Frequently asked questions
Does the DPDP Act apply to paper medical records?
Only once they are digitised. Section 3(a) covers personal data collected in digital form, or in non-digital form and digitised subsequently.
Do hospitals need consent to treat a patient in an emergency?
Section 7(f) allows processing of personal data without consent to respond to a medical emergency involving a threat to life or an immediate threat to the health of the patient or any other individual.
Do hospitals need parental consent to treat a child?
For DPDP purposes, Rule 12(1) and Fourth Schedule Part A item 1 exempt clinical establishments, mental health establishments and healthcare professionals from section 9(1) and 9(3), where processing is restricted to providing health services to the child to the extent necessary to protect her health.
Is health data treated as sensitive personal data under the DPDP Act?
The Act does not create a separate sensitive category; personal data is defined once in section 2(t). The type and nature of data affected is, however, a factor in fixing penalties (s.33(2)(b)).
In which languages must a hospital give its DPDP notice?
Patients must have the option to access the notice in English or any language specified in the Eighth Schedule to the Constitution (s.5(3)). The same applies to consent requests (s.6(3)).
Practical next step
Walk one patient journey (registration, OPD, lab, discharge, billing) and note every system that stores data, the ground you rely on, and the vendor involved. Then run a quick external check of your website and appointment pages.