DPDPA for Healthcare in India
Healthcare organisations handle some of the most sensitive personal data imaginable. Under DPDPA, the stakes of mishandling it are correspondingly high.

Healthcare organisations handle some of the most sensitive personal data imaginable. Under DPDPA Healthcare rules, the stakes of mishandling it are correspondingly high.
A hospital's data is not like a retailer's data. It is someone's diagnosis, or a child's vaccination record sitting next to a parent's insurance claim. When this kind of information leaks, you cannot fix it with a refund or an apology email. That's the lens worth keeping in mind here, because DPDPA compliance in healthcare is not really about avoiding fines. It's about handling information people had no real choice but to share and it sits at the core of hospital data protection in India.
Hospitals, clinics, diagnostic centres, health-tech platforms, and insurers all process health data, widely treated as one of the most sensitive categories of personal data globally. Here's something worth noting: DPDPA 2023 doesn't carve out a separate "sensitive data" category the way GDPR does. There's no special clause for health records with extra safeguards bolted on, but that's not casual treatment under Indian law. Health data is still personal data, squarely within the Act's scope, and obligations around consent, purpose limitation, and security apply in full. The absence of a special category means healthcare providers need more rigour, not less, since the consequences of getting this wrong are worse here.
A reminder that patient data privacy under DPDPA doesn't come with a lower bar just because there's no dedicated "sensitive data" clause. For a broader look at what every organisation, healthcare included, is required to do, see key obligations every data fiduciary must know under the DPDP Rules 2025.
What Actually Counts as Personal Data in a Healthcare Setting
It helps to make this concrete. Patient names and contact details, medical history and diagnoses, prescription records, lab results, insurance policy and claims data, genetic information, mental health records, biometric data used for patient identification. All of it is personal data under DPDPA, and processing any of it requires a valid consent basis. This is the foundation of medical records compliance.
What surprises many hospital administrators is how broad this really is. It's not just the diagnosis in a doctor's notes. The booking app capturing a phone number, the billing software storing an insurance ID, the lab's barcode tagging a sample to a patient name, each one needs a legitimate basis for collection.

Consent in a Clinical Setting Is Not the Same as Medical Consent
This is probably the most misunderstood part of healthcare compliance right now. Healthcare consent under DPDPA has to sit on top of, not get confused with, existing informed medical consent. A patient signing a form before surgery has agreed to the procedure. That signature says nothing about whether the hospital can use their phone number for a marketing SMS later, or share their diagnosis with a third-party billing vendor.
Many hospitals and clinics still rely on a single signature covering both the clinical procedure and the data processing around it. That doesn't hold up under DPDPA. The data consent workflow needs to be separate from the clinical consent process, with its own language, scope, and withdrawal mechanism. Think of it as two different conversations at the same desk: "are you okay with this treatment" and "are you okay with us using your information this way." Patients deserve to answer those independently, and so does the law.
This separation matters more once you consider how healthcare data flows after it leaves the consultation room. Data captured for one purpose at origination often gets reused downstream for purposes nobody agreed to. Healthcare carries the same vulnerability, except the data is more personal and the downstream uses, like insurance underwriting, carry heavier consequences.
DSAR Rights Don't Stop at the Hospital's Front Door
Patients have the right under DPDPA to access all personal data held about them, request correction of inaccurate records, request erasure, and file grievances. Simple enough on paper. In practice, this is where most healthcare organisations will struggle hardest.
A typical mid-sized hospital doesn't have one system holding patient data. It has a Hospital Information System (HIS), a separate laboratory system, pharmacy software, and an insurance or TPA portal, each storing a slice of the same patient's journey. When a patient files a DSAR (Data Subject Access Request), the hospital can't just pull one record. It has to retrieve and consolidate data scattered across systems never designed to talk to each other. Building that process now is far less painful than constructing it under regulatory pressure later.

Sharing Patient Data With Insurance Companies Needs More Than a Blanket Clause
Sharing patient data with insurance companies for claims processing happens constantly, and for good reason. It's how cashless treatment and reimbursements work. But under DPDPA, this sharing requires either explicit patient consent or a clearly articulated legitimate use basis, and blanket consent clauses buried inside insurance policy agreements probably won't satisfy the Act's specificity requirements.
A single checkbox reading "I consent to sharing of my information as required" is exactly the vague, catch-all language DPDPA pushes back against. Per-purpose consent is the standard now, and insurance data sharing is distinct enough from general treatment to deserve its own line item. Gaps like this are exactly how businesses break DPDP law without realizing it a blanket clause that felt sufficient a year ago quietly becomes a violation once the Act's specificity requirements are applied to it.
Telemedicine and Wellness Apps Carry Their Own Risk Profile
Digital health platforms, including telemedicine apps, remote monitoring devices, and wellness applications, collect continuous streams of health data rather than the occasional snapshot a hospital visit produces. A fitness tracker pulling heart rate data every few minutes builds a far richer dataset than a single hospital visit ever could.
The consent architecture for these platforms has to account for that granularity. Users need genuine, easy-to-exercise control over what's collected and how it's used, not a one-time pop-up tapped through at signup and never seen again. If a user wants to stop sharing sleep data with a research partner but keep the core tracking feature, the platform should let them.
This is also where healthcare data and employment data start to blur, since corporate wellness programmes increasingly route employee health data through third-party apps, worth reading alongside DPDPA for HR and Employers.
Why a Health Data Breach Is the Worst-Case Scenario Under DPDPA
A breach involving health data sits at the highest-severity end of what DPDPA contemplates, and not just because of the penalty numbers. It's the human cost that makes this category different. A leaked medical history can affect someone's employability, insurance premiums, and relationships in ways a leaked email address simply doesn't. Reputational damage compounds fast once trust breaks, and trust is the currency a hospital operates on.
This is exactly why healthcare organisations need to invest disproportionately in security infrastructure and breach response capability. Encryption at rest, strict access controls tied to role and need-to-know, and an incident response plan that's actually been tested, not just filed away, are the baseline now.
Implementing structured consent management for healthcare in India requires more than policy updates it demands purpose-built systems that can track, log, and honour patient consent at scale.
Where to Start
If you're running a hospital, clinic, diagnostic chain, or health-tech platform and none of this has a clear owner yet, that's the first problem to solve. Map every system touching patient data: HIS, lab software, pharmacy systems, insurance portals, and third-party app integrations. Separate clinical consent forms from data consent forms wherever they're combined. Build a DSAR process that can pull data from those scattered systems within a reasonable timeframe, rather than figuring it out the first time a patient asks.
Healthcare organisations that treat DPDPA compliance as a legal checkbox exercise are missing something more fundamental. Patients hand over information they have no real alternative but to share, often at moments when they're most vulnerable. The law has simply caught up to an ethical obligation good healthcare providers already understood.
OneConsent helps healthcare organisations manage sensitive personal data consent with the per-purpose granularity and complete audit trails that DPDPA compliance in this sector demands. Explore OneConsent to see how a purpose-built consent management platform handles hospital, lab, and insurance data flows in one place.
Frequently Asked Questions
Have more questions?
Search our full DPDP knowledge base for more answers.