← All notes

Healthcare

Patient data under the DPDP Act: what clinics need to change

India's Digital Personal Data Protection Act reshapes how healthcare providers collect, store and share patient records. A practical view of the obligations.

  • Invexa Technologies
  • 3 min read

A multi-specialty clinic in Pune keeps patient records across three systems: a practice management tool, a WhatsApp Business number where patients send reports, and a shared drive holding scanned prescriptions going back nine years. Every one of those is a repository of personal data, and under the Digital Personal Data Protection Act the clinic is the data fiduciary responsible for all of it.

The Act was passed in 2023 and its rules have been rolling out since. For healthcare, where the data is sensitive by nature and often shared across labs, insurers and referring doctors, the compliance gap at most small and mid-sized providers is wide.

The central shift is that consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and recorded. A signature on an admission form covering unspecified future uses no longer works.

In practice this means separating purposes. Consent to treat is not consent to send marketing messages about a wellness package. Consent to share a report with a referring specialist is not consent to hand records to an insurer. Each purpose needs its own record with a timestamp, and patients must be able to withdraw consent as easily as they gave it, with the system honouring that withdrawal downstream.

Notices must be available in English and in the languages listed in the Eighth Schedule of the Constitution. For a clinic serving a regional population, a consent flow that exists only in English is not just poor experience, it is a compliance weakness.

The Obligations That Change System Design

Several duties translate directly into software requirements:

  • Purpose limitation and erasure. Data must be deleted once the purpose is served and consent is withdrawn, unless another law requires retention. Medical records retention rules under clinical establishment regulations vary by state, so the system needs configurable retention policies rather than one hardcoded rule.
  • Breach notification. Personal data breaches must be reported to the Data Protection Board and to affected individuals. That requires audit logging good enough to determine scope quickly, which most legacy practice systems cannot do.
  • Children’s data. Verifiable parental consent is required for anyone under 18, and behavioural tracking or targeted advertising directed at children is prohibited outright. Paediatric practices need this in the intake flow.
  • Processor accountability. Cloud vendors, billing partners and transcription services are data processors acting on your instructions. Contracts need to say so explicitly, and access needs to be scoped.
  • Grievance redressal. A named contact and a defined response path must be published, not buried.

Penalties reach up to 250 crore for failing to take reasonable security safeguards, which makes this a board-level concern for hospital groups rather than an IT line item.

A Realistic Starting Sequence

Begin with a data map. List every place patient data lives, including the informal ones, since the WhatsApp archive and the receptionist’s spreadsheet are in scope. Then classify by purpose and assign a retention period to each category. Rebuild the intake flow so consent is captured granularly and stored as structured data. Turn on encryption at rest and in transit, enforce role-based access so a front desk login cannot open clinical notes, and switch on immutable audit logging.

Most clinics can complete a meaningful first pass in a quarter. The systems that take longest to fix are always the ones nobody documented.

At Invexa, privacy requirements are written into healthcare builds at the schema level, because consent and retention logic bolted on after launch tends to be both expensive and unconvincing.

Next step

Have a project in mind?

A 30-minute call is usually enough to know whether we are the right team for it. If we are not, we will say so.

Start a project

Replies within one working day

Start a project