Readiness assessment
Fintech & Banking · InsurTech · Health insurance

The DPDP Act for Health Insurance

Health insurers process health and financial data across TPAs, hospitals and reinsurers, under IRDAI rules and increasingly ABDM.

In short

Health insurers handle health and financial data, high-risk under the Act harm-based approach, shared across a wide chain. IRDAI regulations and, increasingly, ABDM apply alongside the DPDP Act. Explicit consent, tight sharing controls and strong security are central. Penalties reach ₹250 crore.

Core impacts

What changes for this niche, and the specific rule it turns on.

High-risk health data

Underwriting and claims use health data; collect and share only what the policy needs, with clear consent, and secure it strongly.

The sharing chain

TPAs, hospitals, reinsurers and aggregators are processors; contracts and oversight are on the insurer.

Consent and purpose

Consent for underwriting is not consent for cross-sell; keep purposes separate.

IRDAI and ABDM

IRDAI regulations and ABDM health-data flows apply alongside the DPDP Act, not instead of it.

Policyholder rights

Insureds can access, correct and erase their data, subject to IRDAI record-retention needs.

Common questions

Short, cite-able answers, mirrored in FAQPage schema.

Is health-insurance data special under the DPDP Act?
The Act does not name a sensitive-data category, but it scales duties to the risk of harm, and health data sits at the top.
Can a health insurer share data with a TPA?
Yes, as a processor under contract, for the stated purpose and with the consent obtained; the insurer stays responsible.
Do IRDAI rules still apply under DPDP?
Yes. IRDAI regulations apply alongside the DPDP Act; where they are stricter, they prevail.

Check your policy and claims data.

The readiness check flags health-data, sharing-chain and consent gaps.

Take the readiness check