DPDPComplianceData protection
DPDP Act 2023 compliance checklist for hospitals and clinics
What the Digital Personal Data Protection Act 2023 and the 2025 Rules ask of a hospital: consent, notice, a contact person, breach reporting, and data location.
- Author
- Kentron Technologies
- Published
- Reading time
- 6 min read

The Digital Personal Data Protection Act 2023 applies to every hospital and clinic in India that keeps patient records in digital form. The hospital is a data fiduciary, its software vendor is a data processor, and the patient is the data principal. The DPDP Rules 2025, notified on 14 November 2025, set out how notice, consent, breach reporting and grievance handling must work, with an eighteen-month period for phased compliance.
This is a checklist, not legal advice. The Act and the Rules are on the MeitY site, and the Press Information Bureau's backgrounder on the Rules is the source for the facts below.
What does the Act ask of a hospital?
| Obligation | What it means in a hospital | Where software helps |
|---|---|---|
| Notice and consent | Tell the patient what data you collect and why, in plain language, and get consent that is clear and can be withdrawn | A consent text on the registration screen and form, with the patient's response recorded |
| Purpose limitation | Use patient data for care, billing and legal duties, not for marketing without separate consent | Role-based access so that the marketing user cannot export the patient list |
| Security safeguards | Reasonable measures to prevent a breach; the highest penalty in the Act, up to ₹250 crore, attaches to this | Login logs, audit trails, encryption, data in India, a VAPT report |
| Breach notification | Inform the Data Protection Board and affected patients; failing to do so can attract a penalty of up to ₹200 crore | Logs that show what was accessed, and a patient contact list you can message |
| Rights of the patient | Access, correction, updating, erasure and nomination; respond within ninety days | Patient portal, a data request log, and an export of one patient's record |
| Contact person | Display contact details of a designated officer or Data Protection Officer for data queries | A line on the website, the registration form and the patient app |
How should consent and notice work at registration?
- Write one short notice: what you collect (identity, contact, clinical, payment), why (treatment, billing, legal records, ABDM linking if the patient chooses), and how to withdraw consent or ask questions.
- Show it on the registration screen and print it on the form. The Rules require a separate notice that is clear and easy to understand; do not bury it in the admission consent.
- Record the patient's response with the date and the user who took it. Paper signatures are fine if the record of them can be found.
- Keep ABDM consent separate. Linking records to an ABHA is the patient's choice, and the consent artefact for each share is created inside ABDM, not on your form.
- For children, the Rules require verifiable consent from a parent or guardian, with an exception for essential services such as healthcare. Take the guardian's consent anyway; it costs nothing.
Who needs to be appointed?
Every data fiduciary must display contact details for questions about personal data. For most hospitals this is a designated officer, often the administrator, with an email and phone number on the website and registration form. Only significant data fiduciaries, a category the government notifies, must appoint a Data Protection Officer and carry out audits and impact assessments. A small hospital is unlikely to be notified.
The same person handles patient requests for access, correction, erasure and nomination, which the Rules say must be answered within ninety days. Keep a log of requests, dates and outcomes.
What happens when there is a breach?
A breach is any unauthorised access, disclosure or loss of personal data: a stolen laptop, a former employee's shared password, ransomware on the server. The Rules require the hospital to inform the Data Protection Board and every affected patient without delay, in plain language, saying what happened, the likely impact, what is being done and whom to contact. Separately, the CERT-In directions of 2022 require cyber incidents to be reported to CERT-In within 6 hours of noticing them; the text is on the CERT-In site.
None of this works without logs. If your HMIS cannot show who looked at which record and when, you cannot know the scope of a breach or tell patients truthfully what happened.
Where must the data be stored?
The Act does not impose a general rule that all personal data must stay in India; the Rules allow the government to restrict transfers for certain categories and to require local storage from significant data fiduciaries. For a hospital the practical answer is simpler: store patient data in India, because ABDM, the CERT-In log rule and your ability to answer a regulator all point that way. Ask your vendor for the location in writing, including backups. Healthixio stores patient data in India.
The checklist
- List the personal data you hold and where: HMIS, lab system, WhatsApp, spreadsheets, paper.
- Write the notice and put it on the registration screen, the form and the website.
- Record consent with a date and a user, and make withdrawal a one-line request.
- Name a contact person and display their details.
- Give every user their own login, with roles. Remove access the day someone leaves.
- Switch on audit trails and login logs, and keep logs for at least 180 days in India, as the CERT-In directions require.
- Get a written statement from each vendor on data location, backups and their processor role, and put it in the contract.
- Ask for a VAPT report from a CERT-In empanelled auditor for any cloud system.
- Write a one-page breach procedure: who decides, who tells the Board, the patients and CERT-In, and by when.
- Set up a patient request log and a ninety-day clock, and review this list every year.
Much of this list is software. Healthixio is aligned with the DPDP Act: role-based access, login logs and audit trails, data stored in India, and a VAPT by a CERT-In empanelled auditor. To walk through the checklist against your own hospital, talk to us.
Frequently asked questions
Does the DPDP Act apply to a small clinic with mostly paper files?
The Act covers digital personal data, including data collected on paper and later digitised. A clinic that types patient details into any software, sends reports on WhatsApp or keeps a spreadsheet of patients is processing digital personal data and is a data fiduciary. Size does not exempt you, though the heavier duties apply only to significant data fiduciaries.
Do we need consent to treat a patient in an emergency?
No. The Act recognises certain legitimate uses where consent is not required, and responding to a medical emergency is one of them. Treat the patient first. Once the patient or a relative is able, give the notice and record consent in the normal way. The requirement is that you do not use emergency data for anything beyond the emergency and its records.
If our software vendor leaks data, who is responsible?
The hospital, as data fiduciary, remains responsible to the patient and to the Board. The vendor is a data processor acting on your instructions, and your contract should require them to keep safeguards, notify you of incidents at once and help with the breach response. Choose vendors who can show logs, a VAPT report and a data location, because their failures are yours.
