DPDP Act for Hospitals and Health Apps
How the DPDP Act and 2025 Rules apply to hospitals, clinics, labs and health apps: consent at registration, emergencies, children's records, vendors, breaches and retention.

Hospitals hold the most personal data most people will ever share: diagnoses, test results, identity documents and insurance details. The DPDP Act does not create a special category for health data, but a breach of it does the most harm, and the Act's duties on notice, security and breach reporting apply in full from 13 May 2027.
Consent and the legitimate uses
Consent is the main basis for processing, but the Act lists legitimate uses that do not need it. Two matter to healthcare: responding to a medical emergency involving a threat to life or an immediate threat to health, and providing treatment or health services during an epidemic, outbreak or other threat to public health. A patient who voluntarily gives data for a specified purpose, such as registering for a consultation, and does not object is also covered for that purpose. Marketing, research and sharing with third parties need separate consent.
What changes at the registration desk
The registration form becomes a notice. It should list the data collected and the purposes in plain language, in the patient's language where possible, and record that the patient saw it. Software should store the notice version against each patient.
Children and patients with guardians
Patients under 18 need verifiable consent from a parent. The Rules exempt clinical establishments, mental health establishments and healthcare professionals from the parental consent and no-tracking requirements where processing is limited to providing health services to the child, to the extent necessary to protect the child's health. That exemption is narrow: a paediatric app that shows targeted advertising would not fall within it. For adults who have a lawful guardian, consent comes from the guardian, who must be verified.
Security in clinical systems
The Rules require encryption or equivalent protection, access control, access logs and backups. In hospitals, the practical gaps are usually shared logins at nursing stations, reports sent on personal WhatsApp and old systems with no audit trail.
Shared logins make every access log meaningless. Fix that first.
Vendors and integrations
Lab partners, TPAs, cloud hosting, teleconsultation providers and software vendors all process patient data for the hospital. The hospital stays responsible as Data Fiduciary. Contracts should require security safeguards, breach reporting to the hospital, deletion on termination and no use of data for the vendor's own purposes.
Retention, breaches and ABDM
Medical records have their own retention requirements under professional regulations and state Clinical Establishments rules, and the DPDP Act allows retention where another law requires it. Document those periods per record type. Any breach must be reported to affected patients and to the Data Protection Board, with a detailed report within 72 hours. ABDM's consent framework for sharing health records works alongside the Act; an ABDM consent artefact covers a specific exchange, not your general processing.
- Digital Personal Data Protection Act, 2023 (MeitY)
- Digital Personal Data Protection Rules, 2025: notification summary (Press Information Bureau)
This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.





