Table of contents

7 DPDP Guidelines or Compliance For Healthcare & Hospitals

By
AK
Last Updated on:
July 30, 2026

A patient gives her phone number at registration. By evening, the same number sits in the hospital information system, a diagnostic lab portal, and an insurer’s queue. A discharge summary may also travel through WhatsApp. If she withdraws consent for follow-up messages, can the hospital trace every copy and stop that use?

That is the practical test behind DPDP compliance in healthcare. The Digital Personal Data Protection Act, 2023 applies to digital personal data and to paper records once they are digitised.

Sections 3 to 17 are scheduled to take effect 18 months after the 13 November 2025 Gazette notification. Hospitals have a preparation window, but the work crosses clinical, administrative, and vendor systems.

These seven DPDP guidelines for healthcare turn the law into controls a hospital can operate and prove.

TL;DR

  • Map one patient journey before writing another policy.

  • Keep separate records for notice, consent and withdrawal.

  • Test whether access, vendor and breach controls produce evidence.

Implementation status on 28 July 2026: Section 2 and the provisions that establish the Data Protection Board are in force. Most duties covering notice, consent, Data Fiduciary obligations, children’s data and Data Principal rights are scheduled for 13 May 2027. Section 6(9), which concerns a Consent Manager’s handling of personal data, is scheduled for 13 November 2026.

Check the official DPDP commencement notification before relying on these dates for an implementation plan.

What DPDP compliance means for a hospital

A hospital normally decides why and how patient data is processed. That makes it a Data Fiduciary under Section 2(i) of the Act, while a laboratory, cloud host or hospital software provider may act as a Data Processor when it handles records on the hospital’s instructions.

The Act does not create a separate category called “sensitive personal data.” Health information still carries high operational risk because a leaked oncology report or mental-health note can harm a patient in ways that an ordinary contact list cannot. The hospital’s control design should reflect that risk.

Hospitals also need to keep other legal duties in view. A DPDP erasure request does not cancel a record-retention duty imposed by another law, so the retention schedule needs to record the legal basis, owner and deletion trigger for every record type.

1. Map patient data across the full care journey

Most hospital inventories stop at the electronic medical record. Patient data starts earlier and travels further.

Map one patient journey from appointment booking to final archival. Include the systems and people that receive data at each handoff. A useful first pass covers:

  • registration and appointment systems;

  • clinical and diagnostic records;

  • billing and insurance workflows;

  • pharmacy, telemedicine and home-care systems;

  • cloud, messaging and support vendors.

For every dataset, record the purpose, system owner and recipient. Add the retention rule and deletion trigger. Section 8(2) of the Act keeps the Data Fiduciary responsible for work done on its behalf by a Data Processor. A vendor list without the related data flow will not show that responsibility.

The evidence should be a live data map linked to a processing register, with a control that places every new radiology service or patient app in that register before the hospital launches it.

A hospital data map that follows one patient
This image shows the A hospital data map that follows one patient

2. Replace the blanket admission form with purpose-led notices

One signature at reception often tries to cover treatment, insurance, research and marketing, yet that form cannot tell the hospital which downstream use the patient understood or which notice version staff displayed.

Section 5 of the Act requires notice of the patient information and the purpose for which it is proposed to be used. Section 6(1) requires consent to be free, specific, informed, unconditional and unambiguous. Rule 3 of the Digital Personal Data Protection Rules, 2025 adds that the notice should stand on its own and provide a clear route for withdrawal, rights and complaints.

Build separate purpose records where the workflows differ. Treatment administration may sit for one purpose. Research recruitment and promotional messages need their own decisions. Each consent record should retain the notice version, purpose tag and timestamp. It should also record the channel used.

The official text of the Digital Personal Data Protection Act, 2023 is the source to use when legal and product teams check the wording of Sections 5 and 6.

3. Make withdrawal propagate beyond the consent screen

A withdrawal button solves the intake step, but the hospital still carries the risk when that decision does not reach the CRM, call centre or outsourced campaign tool that continues the unwanted use.

Section 6(4) of the Act gives the Data Principal the right to withdraw consent with ease comparable to giving it. Section 6(5) requires the Data Fiduciary and its processors to stop the related use within a reasonable time, unless another legal basis permits it.

The workflow needs four linked events:

  1. Receive and authenticate the request.

  2. Identify the affected purposes and systems.

  3. Send the stop instruction to internal teams and processors.

  4. Record completion or a lawful retention exception.

The workflow owner should record who sent the instruction, which systems acknowledged it and what data stayed because another law required retention.

4. Separate emergency care from routine secondary use

Consent is not the only route the Act recognises. Section 7(d) permits a hospital to use a patient’s records when responding to a medical emergency that threatens life or health. Section 7(e) covers medical treatment and health services during a threat to public health.

These provisions should not become a permanent “clinical use” label. Create an emergency-access path with a reason code, restricted duration and after-the-event review, then make the access log identify the patient, staff member, record opened and reason for access.

Routine uses still need their proper basis. Reusing a patient’s discharge data for a marketing campaign does not become emergency processing because the hospital originally collected it during treatment.

5. Put access, vendor and breach controls around the record

Hospital access grows informally when a shared nursing-station login survives a shift change or a former vendor account remains active after its contract ends, and those gaps make an incident much harder to reconstruct.

Section 8(5) of the Act requires reasonable security safeguards. Rule 6 names controls such as access management, logs and backups. It also covers contractual safeguards for processors. Under Rule 7, the hospital must inform affected patients without delay and give the Board detailed breach information within 72 hours, unless the Board allows more time.

A hospital control baseline should include:

  • named user accounts and role-based access;

  • rapid removal when a role or contract ends;

  • logs that join user, patient record and action;

  • tested restoration of critical clinical data;

  • processor contracts with incident and deletion duties.

The failure to take reasonable safeguards can attract a penalty of up to ₹250 crore under the Act’s Schedule. A breach-notification failure can attract up to ₹200 crore. Those are maximum statutory amounts, not an automatic charge for every incident.

The first 72 hours of a hospital data breach
This image shows the The first 72 hours of a hospital data breach

6. Build one queue for patient rights and children’s data

Requests arrive through reception, email and patient portals, but no one owns the full response when each channel tracks only its own inbox and cannot see what another team has already done.

Sections 11 to 14 of the Act cover access, correction, erasure, grievance redressal and nomination. Rule 14 requires a clear way for a Data Principal to make these requests. The hospital needs one queue that can verify identity, route work and record the response.

Paediatric workflows need another gate. Section 9(1) of the Act requires verifiable parental consent before a hospital uses a child’s information. Rule 10 sets verification expectations. The record should connect the child, parent or lawful guardian and the evidence used for verification.

Do not let the queue erase records automatically. Medical-record duties or active disputes may require retention. Legal or the DPO should decide the exception, and the system should record the reason.

7. Treat every policy as a testable evidence trail

A privacy policy cannot show that a laboratory deleted a file, that a clinician’s access was appropriate or that an insurer stopped using a withdrawn phone number, so each control needs an artifact that a reviewer can inspect.

Use a simple evidence matrix:

Obligation Workflow Owner Evidence Test
Notice and consent Registration Notice version and consent event Sample 20 records
Withdrawal Privacy operations System acknowledgements Trace one request end to end
Access control IT and clinical owner User and access logs Review privileged access
Vendor control Procurement and security Register and contract clauses Check top 20 processors
Patient rights DPO or grievance lead Request queue and response record Run a timed tabletop
Breach response Security and legal Incident timeline and notices Run a 72-hour exercise

The largest table has four columns. It links each legal duty to an owner and a test rather than repeating the article.

Where Redacto fits in the hospital workflow

A hospital can link its patient-data map to consent and rights-request records, so the DPO can trace one request across the hospital information system, CRM and outside laboratory.

Redacto’s Unified Consent Manager can send a withdrawal instruction to each connected owner and keep the acknowledgement in the case record. Redacto also gives the DPO one place to see which downstream owner has not replied.

For a patient request, Redacto’s Automated DSAR Management can assign identity checks and collect responses from the teams that hold the record. The DPO can then see which system has replied and which handoff is late.

Redacto cannot decide whether an emergency-use exception applies or whether another law requires a medical record to be retained; the DPO, legal team and clinical owner remain accountable for those judgments.

Redacto is India and DPDPA-first. A hospital group seeking deep coverage across many global privacy regimes may find a long-established multi-jurisdiction suite more suitable. Redacto also has no public price list. Its pricing is license-based; contact Redacto.

Start with one patient journey this Monday

Pick one outpatient journey this week. Trace the patient’s phone number, diagnosis and lab report from registration through billing. For every handoff, write down the purpose, owner, vendor and retention rule.

Then test one withdrawal request against that map. If the request stops at the consent screen, you have found the first workflow to fix before the main hospital-facing provisions take effect.

Your Trusted partner