Teleconsult platforms process consult notes, prescriptions and often payment data, under two frameworks at once.
In short
Telemedicine sits under both the Telemedicine Practice Guidelines 2020, which govern the consult, and the DPDP Act, which governs the personal data around it. You need clear consent, secure records and prescriptions, and control over the platform and its vendors. Penalties reach ₹250 crore.
What changes for this sub-sector.
The Telemedicine Practice Guidelines 2020 govern the consultation; the DPDP Act governs the data it generates.
Record consent for the teleconsultation and, separately, for processing and storing the data it produces.
Store consult notes and e-prescriptions securely, with access limited to those who need them.
Know whether the platform is a Fiduciary or a Processor for a given data flow, and contract accordingly.
Collect only what the consult needs; retain records for the required period, then delete.
Patients can access, correct and erase their teleconsult data, subject to medical-record rules.
Align consent with both frameworks, then lock down records.
The readiness check flags dual-framework consent, record-security and platform-role gaps.
Take the readiness check →