Readiness assessment
Healthcare & Pharma

The DPDP Act for Healthcare & Pharma

For hospitals, labs, pharma and telemedicine, the Act layers strict consent, security and retention duties onto medical data.

In short

Hospitals, clinics, labs and pharma companies handle health data, among the most sensitive personal data the Act covers. You need clear consent, tight access controls, careful retention and fast breach reporting, alongside existing medical-records rules. Penalties reach ₹250 crore.

What the Act asks of you

The obligations that shape compliance in this sector.

Consent for health data

Take explicit, purpose-specific consent for collecting and sharing health and treatment data.

Sensitive-data security

Health records demand your strongest access controls, encryption and audit trails.

Purpose limitation

Patient data gathered for care cannot be reused for marketing or research without fresh consent.

Retention and erasure

Reconcile medical-record retention rules with the right to erase; document why you keep what you keep.

Patient rights

Let patients access, correct and request erasure of their records within legal limits.

Processors and sharing

Labs, TPAs, insurers and cloud EHR vendors are processors; their handling is your liability.

See where you stand.

Run the free readiness check for a sector-specific gap report.

Take the readiness check