Readiness assessment
Healthcare & Pharma · Hospitals

The DPDP Act for Hospitals & Clinics

A hospital is a Data Fiduciary for a patient's entire record, from registration identifiers to diagnoses, mental-health and reproductive-health data.

In short

The Act does not tag health data as a separate legal category; instead it scales the bar to the risk of harm, and hospital data sits near the top. You need informed consent, tight access control, careful retention and fast breach reporting, and a large hospital may be a Significant Data Fiduciary. Penalties reach ₹250 crore.

Core impacts

What changes for this sub-sector.

Consent across the record

Take informed consent at registration and again for creating, sharing and retaining health records, including mental-health and reproductive-health data.

SDF duties may apply

A large hospital can be designated a Significant Data Fiduciary, adding a DPO, independent audits and impact assessments.

Retention vs erasure

Medical-record retention rules coexist with the right to erase; keep records for the required period, no longer, and be able to justify it.

Access control and security

Least-privilege access, encryption and audit trails across HIS, EHR and billing systems.

Patient rights and Consent Manager

Patients can access, correct and withdraw consent, and, once the Consent Manager framework goes live (registration opens 13 Nov 2026), through a registered Consent Manager spanning hospital, lab and insurer.

Processors

Cloud EHR, labs, TPAs and billing vendors are processors under contract, with your oversight.

Check your hospital data flows.

The readiness check maps consent, retention, access and SDF gaps across your systems.

Take the readiness check