For hospitals, labs, pharma and telemedicine, the Act layers strict consent, security and retention duties onto medical data.
In short
Hospitals, clinics, labs and pharma companies handle health data, among the most sensitive personal data the Act covers. You need clear consent, tight access controls, careful retention and fast breach reporting, alongside existing medical-records rules. Penalties reach ₹250 crore.
The obligations that shape compliance in this sector.
Take explicit, purpose-specific consent for collecting and sharing health and treatment data.
Health records demand your strongest access controls, encryption and audit trails.
Patient data gathered for care cannot be reused for marketing or research without fresh consent.
Reconcile medical-record retention rules with the right to erase; document why you keep what you keep.
Let patients access, correct and request erasure of their records within legal limits.
Labs, TPAs, insurers and cloud EHR vendors are processors; their handling is your liability.
Each sub-sector has its own data flows and its own version of the rules.
Wherever you are, start there and move through to a certifiable posture.
Run the free readiness check for a sector-specific gap report.
Take the readiness check →