9 October 2026 · DPDP Act · Hospitals & Clinics
DPDP Act for Hospitals and Clinics: Protecting Patient Data
By CA Ratan Singh Tanwar · Chartered Accountant, Bhilwara
Few organisations handle personal data as sensitive as a hospital or clinic. Diagnoses, prescriptions, lab reports, insurance claims, Aadhaar copies and contact details of relatives all pass through reception desks, nursing stations, labs and billing counters every day.
Under the DPDP Act, a hospital or clinic that processes patient data digitally is a Data Fiduciary. It must collect only what it needs, use it for stated purposes, protect it with reasonable safeguards and respond to patient rights.
High-risk areas in healthcare
- Reports on WhatsApp: Lab reports and prescriptions sent from personal phones of staff, with no record or control.
- Shared HMS logins: Doctors, nurses and front-desk staff using common user IDs, making it impossible to trace who accessed a record.
- Third parties: Diagnostic labs, TPAs, insurers, pharmacies and IT vendors receiving patient data without clear agreements.
- Children’s data: Paediatric records involve data of minors. The DPDP framework sets specific conditions for processing children’s data, with limited exemptions for healthcare that need to be checked carefully.
- CCTV and visitor logs: These are personal data too and need defined retention.
Practical steps for hospitals and clinics
- Display a short, clear privacy notice at registration, in the local language.
- Issue individual HMS user IDs with role-based access; review access every quarter.
- Use an official channel for sharing reports, such as a patient portal or official number, instead of personal phones.
- Sign data protection clauses with labs, TPAs and software providers.
- Define retention periods for medical records, billing data and CCTV, aligned with medical and legal requirements.
- Prepare a breach response plan: who decides, who informs patients, and how the Data Protection Board is notified.
Key takeaway: Patients trust hospitals with their health and their dignity. DPDP compliance turns that trust into a documented, auditable discipline that protects both patients and the institution.
Is your hospital DPDP-ready?
Data mapping, HMS access review and privacy governance for healthcare providers.