A hospital is a Data Fiduciary for a patient's entire record, from registration identifiers to diagnoses, mental-health and reproductive-health data.
In short
The Act does not tag health data as a separate legal category; instead it scales the bar to the risk of harm, and hospital data sits near the top. You need informed consent, tight access control, careful retention and fast breach reporting, and a large hospital may be a Significant Data Fiduciary. Penalties reach ₹250 crore.
What changes for this sub-sector.
Take informed consent at registration and again for creating, sharing and retaining health records, including mental-health and reproductive-health data.
A large hospital can be designated a Significant Data Fiduciary, adding a DPO, independent audits and impact assessments.
Medical-record retention rules coexist with the right to erase; keep records for the required period, no longer, and be able to justify it.
Least-privilege access, encryption and audit trails across HIS, EHR and billing systems.
Patients can access, correct and withdraw consent, and, once the Consent Manager framework goes live (registration opens 13 Nov 2026), through a registered Consent Manager spanning hospital, lab and insurer.
Cloud EHR, labs, TPAs and billing vendors are processors under contract, with your oversight.
Fix registration consent and access control first, then work toward SDF-grade governance.
The readiness check maps consent, retention, access and SDF gaps across your systems.
Take the readiness check →