Every doctor's clinic, pharmacy, hospital and diagnostic lab in India that stores patient details digitally is a Data Fiduciary under the Digital Personal Data Protection Act, 2023, and the core obligations bite on 13 May 2027, roughly seven months from today.
Most of these providers are not ready. Many still believe that following HIPAA, or simply "keeping records confidential" as a matter of medical ethics, is enough. It is not. HIPAA is a US statute with no force in India. The Indian ethics codes were written for paper files and a trusted doctor, not for cloud billing software, WhatsApp report delivery and ransomware.
This article explains where patient data is exposed in each segment of Indian healthcare, what the DPDP Act and Rules actually demand, how the Indian medical-law stack fits around them, and what a provider can realistically do in 90 days.
Bottom line: The question for a provider is no longer "are we confidential?" It is "can we prove, on paper and in logs, that we collected consent, secured the data, and can report a breach to the Data Protection Board within 72 hours?"
Health data is the one category of personal data that cannot be reissued after a breach. A stolen password can be changed; a diagnosis, a prescription history or an HIV status cannot. Seqrite's India Cyber Threat Report 2026 lists healthcare and pharma among the most attacked sectors in the country, and the large public incidents show the pattern.
Both are institutional giants. The more common exposure sits lower down the chain, where there is no security team at all. The patterns below are what we see repeatedly in the way these segments work, not the findings of a survey.
A single-doctor or small group clinic typically runs patient registers in Excel, a cheap clinic-management app, and a reception phone on which prescriptions and reports travel over WhatsApp. Logins are shared between the doctor, assistant and receptionist, so there is no record of who opened which file. Old laptops are sold or repaired with patient folders still on the disk.
A pharmacy's billing software quietly builds a chronic-illness profile: who buys insulin, antidepressants, antiretrovirals or fertility medicines, and how often. That data feeds loyalty programmes, delivery apps, distributor integrations and sometimes marketing lists. Prescription images arrive on personal phones. Few chains have a consent record for any of it.
Hospitals run the most data, the most vendors and the oldest systems. A hospital information system, PACS imaging, billing, TPA and insurer portals, telemedicine, cloud backups, and outsourced IT each hold a copy or a window into patient records. Flat internal networks, shared credentials, unpatched legacy devices and generous "view all" access for staff are common, and ransomware finds exactly these weaknesses.
A lab's data leaves the building by design: home-collection agents, franchise collection centres, and reports delivered by email, WhatsApp or web link. Report portals that hand out guessable links, or that do not verify the person opening them, expose results to anyone. Imaging servers and lab systems left reachable from the internet are a recurring problem across the world, and Indian labs are not immune.
In every one of these segments the weakness is the same: nobody has decided who is responsible for the data, so nobody has the evidence to show the law was followed.
HIPAA does not apply to an Indian clinic treating Indian patients, and copying a HIPAA policy pack onto a clinic's letterhead leaves it exposed under Indian law. HIPAA is a US federal statute that binds US "covered entities" and their business associates. It carries no legal weight before India's Data Protection Board or an Indian court.
HIPAA is also built around a different logic. The DPDP Act has no separate "sensitive" or "health" category, no treatment-payment-operations carve-out, and a breach clock measured in hours rather than weeks.
Question | HIPAA (United States) | DPDP Act and Rules (India) |
|---|---|---|
Who is bound | US covered entities and business associates | Any entity deciding why and how digital personal data is processed, public or private |
Regulator | HHS Office for Civil Rights | Data Protection Board of India |
Legal basis for use | Treatment, payment and operations permitted without separate authorisation | Consent, or one of the narrow "legitimate uses" in Section 7 |
Notice to the patient | Notice of privacy practices | Itemised notice before or at collection, in plain language, with rights and complaint route |
Breach reporting | Individuals within 60 days | Each affected patient without delay; the Board without delay, with a detailed report within 72 hours |
Contractors | Business associate agreement | Written contract with the processor; the fiduciary stays fully liable |
Top penalty | Tiered civil penalties in US dollars | Up to ₹250 crore for failure to maintain reasonable security safeguards |
A provider that has "gone HIPAA" has often done useful things, such as access controls and staff training. But it has almost never built the Indian-specific elements: the consent record, the notice in the patient's language, the grievance officer, the Board-facing breach procedure, and the retention rules that follow Indian medical regulations.
A clinic, pharmacy, hospital or lab is a Data Fiduciary for the patient data it collects, and the software vendors, labs, billing firms and cloud hosts it uses are its Data Processors. The Act does not regulate processors directly; the fiduciary answers for them. The core duties, as notified in the DPDP Rules, 2025, are these:
Section 10 lets the Government notify Significant Data Fiduciaries based on the volume and sensitivity of data, risk to patients and other factors. Large hospital networks, insurer-linked platforms and health-tech apps are natural candidates. If notified, they must appoint an India-based DPO, an independent data auditor, and conduct periodic impact assessments under Rule 13. We are not aware of a healthcare-specific notification to date, so this should be monitored.
One thing the patient-facing notice cannot hide: The Act treats a provider's duty as a continuing one. A beautifully worded consent form does not help a hospital that cannot show who accessed a patient's record last Tuesday.
The DPDP Act does not replace medical law. It sits on top of it, and a provider has to satisfy both. India has no single health-data statute, so the obligations come from several places.
Instrument | What it adds for patient data |
|---|---|
NMC Code of Medical Ethics (2002 Regulations) | Duty of professional secrecy; record-keeping for indoor patients for three years; release of records on request within 72 hours. Violations are professional misconduct before the State Medical Council. |
NMC Registered Medical Practitioner Regulations, 2023 | Notified in August 2023 with a requirement to move to fully digitised records within three years while observing IT and data-protection law. Confirm current operational status before citing. |
Telemedicine Practice Guidelines, 2020 | Patient consent, digital record-keeping, and confidentiality for online consultations. A telemedicine platform is squarely a Data Fiduciary. |
Clinical Establishments Act, 2010 & State Laws | Registration, minimum standards and record maintenance. Several states, including West Bengal, run their own clinical-establishment regimes with their own records and transparency duties. |
Ayushman Bharat Digital Mission (ABDM) | Consent-managed sharing of health records within the ABDM ecosystem. Providers linking to ABDM carry its consent and security expectations alongside DPDP Rules. |
IT Act, 2000 and SPDI Rules, 2011 | Section 43A and the 2011 Rules treat medical records as sensitive personal data today. The DPDP framework repeals Section 43A when core provisions commence on 13 May 2027. |
CERT-In Directions, April 2022 | Cyber incidents must be reported to CERT-In within six hours, and logs retained for 180 days, applying to body corporates regardless of DPDP timelines. |
Drugs & Cosmetics Rules, 1945 | Prescription verification and record retention for scheduled drugs. The pharmacist's register is itself a patient-data record. |
Specialty Statutes | Mental Healthcare Act, HIV/AIDS Act, MTP Act, and PCPNDT Act enforce specific confidentiality duties and disclosure limits. |
Accreditation (NABH) | Information-management and records standards tested on the ground by auditors. |
The practical point is that three clocks run at once: the IT Act and CERT-In regime applies today, the DPDP Act's core obligations arrive in May 2027, and professional regulators can act on confidentiality lapses whenever they choose. A hospital that treats these as one compliance programme spends less and fails less.
Segment | Data held | Typical gap | DPDP exposure | First fix |
|---|---|---|---|---|
Doctor's clinic | Visit notes, prescriptions, contact details, family history | Shared logins; WhatsApp as record system; no notice or consent record; no backups | Notice and consent (Sections 5, 6); security safeguards (Rule 6) | Individual logins, encrypted device/backup, one-page notice, written breach contact |
Pharmacy / Chain | Medicine history, chronic conditions, prescriptions, addresses | Purchase data reused for marketing without consent; prescriptions on personal phones; missing processor contracts | Purpose limitation (Section 6); processor liability (Section 8(2)) | Separate marketing consent, vendor security clauses, remove prescriptions from personal devices |
Hospital | Full clinical record, imaging, insurance/ID details, minors' data | Flat networks; broad "view all" access; unverified vendors; legacy systems; ransomware exposure | Security safeguards/logs (Rule 6); 72-hour reporting (Rule 7); possible SDF status (Rule 13) | Role-based access, vendor register, incident-response plan, Board-facing breach template |
Diagnostic lab | Test results, ID, home addresses, referring doctor data | Email/open-link report delivery; franchise/agent access; external imaging servers | Security safeguards (Rule 6); notice/consent at collection (Sections 5, 6); breach reporting (Rule 7) | Authenticated delivery, expiring links, franchise data-handling terms, external exposure scan |
A provider can reach a defensible baseline in three months if it works in this order:
Note: Hospital groups or digitally intensive lab chains should add a data-protection impact assessment and independent audit immediately.
The Schedule to the Act sets maximum penalties decided by the Data Protection Board after inquiry:
The Rules were notified in November 2025 and the Data Protection Board was constituted immediately. The phased commencement brings Consent Manager provisions on 13 November 2026 and core fiduciary obligations and patient rights on 13 May 2027. Providers should plan for 13 May 2027.
DRMLAW LLP combines legal counsel, compliance architecture and digital forensics, ensuring healthcare clients across Kolkata and the Eastern Region receive comprehensive policies, technical controls, and evidentiary readiness from a single team:
To discuss a healthcare assessment for your organization, contact DRMLAW LLP through www.drmlaw.in.
Sources: Researched through web search on 7 October 2026. Statutory points should be verified against primary texts before legal reliance (including DPDP Rules 2025, NMC Regulations, CERT-In Directions, and state clinical establishment acts). This article is general information and not formal legal advice.