Health insurers process health and financial data across TPAs, hospitals and reinsurers, under IRDAI rules and increasingly ABDM.
In short
Health insurers handle health and financial data, high-risk under the Act harm-based approach, shared across a wide chain. IRDAI regulations and, increasingly, ABDM apply alongside the DPDP Act. Explicit consent, tight sharing controls and strong security are central. Penalties reach ₹250 crore.
What changes for this niche, and the specific rule it turns on.
Underwriting and claims use health data; collect and share only what the policy needs, with clear consent, and secure it strongly.
TPAs, hospitals, reinsurers and aggregators are processors; contracts and oversight are on the insurer.
Consent for underwriting is not consent for cross-sell; keep purposes separate.
IRDAI regulations and ABDM health-data flows apply alongside the DPDP Act, not instead of it.
Insureds can access, correct and erase their data, subject to IRDAI record-retention needs.
Short, cite-able answers, mirrored in FAQPage schema.
Fix consent scope and the sharing chain first.
The readiness check flags health-data, sharing-chain and consent gaps.
Take the readiness check →