DRMLAW
Knowledge Article

Patient Data in India: Why Clinics, Pharmacies, Hospitals and Diagnostic Labs Are Not Ready for the DPDP Act

By Rupak Ranjan Mukherjee, BE,CCLP,C.DPO.DA, Founder Partner · 2026-10-07 · Data Protection & Privacy

Every doctor's clinic, pharmacy, hospital and diagnostic lab in India that stores patient details digitally is a Data Fiduciary under the Digital Personal Data Protection Act, 2023, and the core obligations bite on 13 May 2027, roughly seven months from today.

Most of these providers are not ready. Many still believe that following HIPAA, or simply "keeping records confidential" as a matter of medical ethics, is enough. It is not. HIPAA is a US statute with no force in India. The Indian ethics codes were written for paper files and a trusted doctor, not for cloud billing software, WhatsApp report delivery and ransomware.

This article explains where patient data is exposed in each segment of Indian healthcare, what the DPDP Act and Rules actually demand, how the Indian medical-law stack fits around them, and what a provider can realistically do in 90 days.

Bottom line: The question for a provider is no longer "are we confidential?" It is "can we prove, on paper and in logs, that we collected consent, secured the data, and can report a breach to the Data Protection Board within 72 hours?"

Where patient data actually leaks

Health data is the one category of personal data that cannot be reissued after a breach. A stolen password can be changed; a diagnosis, a prescription history or an HIV status cannot. Seqrite's India Cyber Threat Report 2026 lists healthcare and pharma among the most attacked sectors in the country, and the large public incidents show the pattern.

Both are institutional giants. The more common exposure sits lower down the chain, where there is no security team at all. The patterns below are what we see repeatedly in the way these segments work, not the findings of a survey.

Doctor's clinics

A single-doctor or small group clinic typically runs patient registers in Excel, a cheap clinic-management app, and a reception phone on which prescriptions and reports travel over WhatsApp. Logins are shared between the doctor, assistant and receptionist, so there is no record of who opened which file. Old laptops are sold or repaired with patient folders still on the disk.

Large pharmacies and pharmacy chains

A pharmacy's billing software quietly builds a chronic-illness profile: who buys insulin, antidepressants, antiretrovirals or fertility medicines, and how often. That data feeds loyalty programmes, delivery apps, distributor integrations and sometimes marketing lists. Prescription images arrive on personal phones. Few chains have a consent record for any of it.

Hospitals

Hospitals run the most data, the most vendors and the oldest systems. A hospital information system, PACS imaging, billing, TPA and insurer portals, telemedicine, cloud backups, and outsourced IT each hold a copy or a window into patient records. Flat internal networks, shared credentials, unpatched legacy devices and generous "view all" access for staff are common, and ransomware finds exactly these weaknesses.

Diagnostic labs and collection networks

A lab's data leaves the building by design: home-collection agents, franchise collection centres, and reports delivered by email, WhatsApp or web link. Report portals that hand out guessable links, or that do not verify the person opening them, expose results to anyone. Imaging servers and lab systems left reachable from the internet are a recurring problem across the world, and Indian labs are not immune.

In every one of these segments the weakness is the same: nobody has decided who is responsible for the data, so nobody has the evidence to show the law was followed.

The HIPAA myth

HIPAA does not apply to an Indian clinic treating Indian patients, and copying a HIPAA policy pack onto a clinic's letterhead leaves it exposed under Indian law. HIPAA is a US federal statute that binds US "covered entities" and their business associates. It carries no legal weight before India's Data Protection Board or an Indian court.

HIPAA is also built around a different logic. The DPDP Act has no separate "sensitive" or "health" category, no treatment-payment-operations carve-out, and a breach clock measured in hours rather than weeks.

Question

HIPAA (United States)

DPDP Act and Rules (India)

Who is bound

US covered entities and business associates

Any entity deciding why and how digital personal data is processed, public or private

Regulator

HHS Office for Civil Rights

Data Protection Board of India

Legal basis for use

Treatment, payment and operations permitted without separate authorisation

Consent, or one of the narrow "legitimate uses" in Section 7

Notice to the patient

Notice of privacy practices

Itemised notice before or at collection, in plain language, with rights and complaint route

Breach reporting

Individuals within 60 days

Each affected patient without delay; the Board without delay, with a detailed report within 72 hours

Contractors

Business associate agreement

Written contract with the processor; the fiduciary stays fully liable

Top penalty

Tiered civil penalties in US dollars

Up to ₹250 crore for failure to maintain reasonable security safeguards

A provider that has "gone HIPAA" has often done useful things, such as access controls and staff training. But it has almost never built the Indian-specific elements: the consent record, the notice in the patient's language, the grievance officer, the Board-facing breach procedure, and the retention rules that follow Indian medical regulations.

What the DPDP Act and Rules require of a healthcare provider

A clinic, pharmacy, hospital or lab is a Data Fiduciary for the patient data it collects, and the software vendors, labs, billing firms and cloud hosts it uses are its Data Processors. The Act does not regulate processors directly; the fiduciary answers for them. The core duties, as notified in the DPDP Rules, 2025, are these:

Could a hospital group be a Significant Data Fiduciary?

Section 10 lets the Government notify Significant Data Fiduciaries based on the volume and sensitivity of data, risk to patients and other factors. Large hospital networks, insurer-linked platforms and health-tech apps are natural candidates. If notified, they must appoint an India-based DPO, an independent data auditor, and conduct periodic impact assessments under Rule 13. We are not aware of a healthcare-specific notification to date, so this should be monitored.

One thing the patient-facing notice cannot hide: The Act treats a provider's duty as a continuing one. A beautifully worded consent form does not help a hospital that cannot show who accessed a patient's record last Tuesday.

The wider Indian legal stack around patient records

The DPDP Act does not replace medical law. It sits on top of it, and a provider has to satisfy both. India has no single health-data statute, so the obligations come from several places.

Instrument

What it adds for patient data

NMC Code of Medical Ethics (2002 Regulations)

Duty of professional secrecy; record-keeping for indoor patients for three years; release of records on request within 72 hours. Violations are professional misconduct before the State Medical Council.

NMC Registered Medical Practitioner Regulations, 2023

Notified in August 2023 with a requirement to move to fully digitised records within three years while observing IT and data-protection law. Confirm current operational status before citing.

Telemedicine Practice Guidelines, 2020

Patient consent, digital record-keeping, and confidentiality for online consultations. A telemedicine platform is squarely a Data Fiduciary.

Clinical Establishments Act, 2010 & State Laws

Registration, minimum standards and record maintenance. Several states, including West Bengal, run their own clinical-establishment regimes with their own records and transparency duties.

Ayushman Bharat Digital Mission (ABDM)

Consent-managed sharing of health records within the ABDM ecosystem. Providers linking to ABDM carry its consent and security expectations alongside DPDP Rules.

IT Act, 2000 and SPDI Rules, 2011

Section 43A and the 2011 Rules treat medical records as sensitive personal data today. The DPDP framework repeals Section 43A when core provisions commence on 13 May 2027.

CERT-In Directions, April 2022

Cyber incidents must be reported to CERT-In within six hours, and logs retained for 180 days, applying to body corporates regardless of DPDP timelines.

Drugs & Cosmetics Rules, 1945

Prescription verification and record retention for scheduled drugs. The pharmacist's register is itself a patient-data record.

Specialty Statutes

Mental Healthcare Act, HIV/AIDS Act, MTP Act, and PCPNDT Act enforce specific confidentiality duties and disclosure limits.

Accreditation (NABH)

Information-management and records standards tested on the ground by auditors.

The practical point is that three clocks run at once: the IT Act and CERT-In regime applies today, the DPDP Act's core obligations arrive in May 2027, and professional regulators can act on confidentiality lapses whenever they choose. A hospital that treats these as one compliance programme spends less and fails less.

Sector gap map

Segment

Data held

Typical gap

DPDP exposure

First fix

Doctor's clinic

Visit notes, prescriptions, contact details, family history

Shared logins; WhatsApp as record system; no notice or consent record; no backups

Notice and consent (Sections 5, 6); security safeguards (Rule 6)

Individual logins, encrypted device/backup, one-page notice, written breach contact

Pharmacy / Chain

Medicine history, chronic conditions, prescriptions, addresses

Purchase data reused for marketing without consent; prescriptions on personal phones; missing processor contracts

Purpose limitation (Section 6); processor liability (Section 8(2))

Separate marketing consent, vendor security clauses, remove prescriptions from personal devices

Hospital

Full clinical record, imaging, insurance/ID details, minors' data

Flat networks; broad "view all" access; unverified vendors; legacy systems; ransomware exposure

Security safeguards/logs (Rule 6); 72-hour reporting (Rule 7); possible SDF status (Rule 13)

Role-based access, vendor register, incident-response plan, Board-facing breach template

Diagnostic lab

Test results, ID, home addresses, referring doctor data

Email/open-link report delivery; franchise/agent access; external imaging servers

Security safeguards (Rule 6); notice/consent at collection (Sections 5, 6); breach reporting (Rule 7)

Authenticated delivery, expiring links, franchise data-handling terms, external exposure scan

A 90-day alignment roadmap

A provider can reach a defensible baseline in three months if it works in this order:

  1. Days 1 to 30 (Discovery): Find out what you hold. Map every place patient data lives, including paper registers, personal phones, vendor portals and cloud backups. Name one accountable person. List every vendor that touches data and check which systems are reachable from the internet.
  2. Days 31 to 60 (Legal & Technical Remediation): Draft the patient notice and consent flow in English and the local language. Put individual logins, role-based access and activity logs in place. Encrypt devices and backups. Renegotiate vendor contracts to include security and breach-cooperation clauses. Align retention schedules with NMC, Drugs Rules and state clinical-establishment requirements.
  3. Days 61 to 90 (Validation & Drill): Write the breach playbook covering CERT-In's six-hour report, the Board's 72-hour report and patient intimation. Run a tabletop ransomware exercise. Train front-desk, nursing, pharmacy and lab staff on notices, WhatsApp restrictions, and how to handle patient access/correction requests.
  4. After Day 90 (Evidence Preservation): Compliance in this regime is an evidentiary exercise. Keep consent logs, access reviews, vendor assessments, training records and incident drills ready for production to the Board or a court.

Note: Hospital groups or digitally intensive lab chains should add a data-protection impact assessment and independent audit immediately.

Penalties and Timeline Status

What non-compliance can cost

The Schedule to the Act sets maximum penalties decided by the Data Protection Board after inquiry:

Timeline status

The Rules were notified in November 2025 and the Data Protection Board was constituted immediately. The phased commencement brings Consent Manager provisions on 13 November 2026 and core fiduciary obligations and patient rights on 13 May 2027. Providers should plan for 13 May 2027.

How DRMLAW Helps

DRMLAW LLP combines legal counsel, compliance architecture and digital forensics, ensuring healthcare clients across Kolkata and the Eastern Region receive comprehensive policies, technical controls, and evidentiary readiness from a single team:

To discuss a healthcare assessment for your organization, contact DRMLAW LLP through www.drmlaw.in.

Sources: Researched through web search on 7 October 2026. Statutory points should be verified against primary texts before legal reliance (including DPDP Rules 2025, NMC Regulations, CERT-In Directions, and state clinical establishment acts). This article is general information and not formal legal advice.