Compliance & Regulation

DPDP Act for Hospitals and Health Apps

How the DPDP Act and 2025 Rules apply to hospitals, clinics, labs and health apps: consent at registration, emergencies, children's records, vendors, breaches and retention.

Purushottam Kumar Suman
Purushottam Kumar Suman
Founder & CEO, Drema AI
8 min read
Clinical team working with patient records

Hospitals hold the most personal data most people will ever share: diagnoses, test results, identity documents and insurance details. The DPDP Act does not create a special category for health data, but a breach of it does the most harm, and the Act's duties on notice, security and breach reporting apply in full from 13 May 2027.

01

Consent and the legitimate uses

Consent is the main basis for processing, but the Act lists legitimate uses that do not need it. Two matter to healthcare: responding to a medical emergency involving a threat to life or an immediate threat to health, and providing treatment or health services during an epidemic, outbreak or other threat to public health. A patient who voluntarily gives data for a specified purpose, such as registering for a consultation, and does not object is also covered for that purpose. Marketing, research and sharing with third parties need separate consent.

Treatment and billingCovered by the purpose the patient registered for; state it in the notice
Emergency careLegitimate use; record the circumstances
Insurance and TPA sharingNamed in the notice as a purpose and recipient
Health camps, offers and reminders unrelated to careSeparate, optional consent
Research and teachingConsent, or data that no longer identifies the patient
02

What changes at the registration desk

The registration form becomes a notice. It should list the data collected and the purposes in plain language, in the patient's language where possible, and record that the patient saw it. Software should store the notice version against each patient.

Itemised notice on registrationRegional language optionNotice version stored per patientSeparate marketing opt-inWithdrawal recorded in the patient record
03

Children and patients with guardians

Patients under 18 need verifiable consent from a parent. The Rules exempt clinical establishments, mental health establishments and healthcare professionals from the parental consent and no-tracking requirements where processing is limited to providing health services to the child, to the extent necessary to protect the child's health. That exemption is narrow: a paediatric app that shows targeted advertising would not fall within it. For adults who have a lawful guardian, consent comes from the guardian, who must be verified.

04

Security in clinical systems

The Rules require encryption or equivalent protection, access control, access logs and backups. In hospitals, the practical gaps are usually shared logins at nursing stations, reports sent on personal WhatsApp and old systems with no audit trail.

Shared logins make every access log meaningless. Fix that first.

Individual loginsNo shared accounts; role-based access by department
Record access logsEvery view of a patient record, kept at least one year
Break-glass accessEmergency access allowed but flagged and reviewed
Secure report deliveryPatient portal or verified number, not staff personal phones
Encrypted backupsTested restores
05

Vendors and integrations

Lab partners, TPAs, cloud hosting, teleconsultation providers and software vendors all process patient data for the hospital. The hospital stays responsible as Data Fiduciary. Contracts should require security safeguards, breach reporting to the hospital, deletion on termination and no use of data for the vendor's own purposes.

06

Retention, breaches and ABDM

Medical records have their own retention requirements under professional regulations and state Clinical Establishments rules, and the DPDP Act allows retention where another law requires it. Document those periods per record type. Any breach must be reported to affected patients and to the Data Protection Board, with a detailed report within 72 hours. ABDM's consent framework for sharing health records works alongside the Act; an ABDM consent artefact covers a specific exchange, not your general processing.

72 hours
Detailed breach report to the Board
1 year
Minimum retention for access logs
Under 18
Parental consent, with a narrow healthcare exemption
Sources · last reviewed October 1, 2026

This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.

Purushottam Kumar Suman
Written by
Purushottam Kumar Suman
Founder & CEO, Drema AI

Founder and CEO of Drema AI. Builds AI systems, SaaS platforms and industry software — and writes about what actually survives production.

CTA Background

Got a problem like this one?

Bring it to a call with a founder.You will get a straight answer, including when the answer is no.

View Our Work
AI-First Engineering
Secure & Scalable
Built to Deliver Impact