Skip to content
Compliance

DPDP Act for Hospitals: Patient Data Obligations Explained

By DevOrbital Team · · Updated · 7 min read

Compliance

DPDP Act for Hospitals: Patient Data Obligations Explained

● DevOrbital HMS

The short answer

Under the Digital Personal Data Protection Act, 2023, a hospital is a Data Fiduciary responsible for the patient data it collects. The Rules notified in November 2025 phase in the core duties over eighteen months. Plan now: map your data, tighten access and logging, prepare consent notices and a breach process, and confirm dates with your legal adviser.

Key takeaways

  • A hospital that decides why and how patient data is processed is a Data Fiduciary; its software vendor or cloud host is typically a Data Processor.
  • The Rules were notified on 14 November 2025 with an eighteen-month phased period. As of 2026, always confirm the current commencement dates, as changes to the timeline have been discussed.
  • Official summaries highlight reasonable security safeguards, breach intimation, a published contact for queries, and responses to data-principal requests within ninety days.
  • Verifiable parental consent applies to children's data, with an exception for processing related to essential services such as healthcare.
  • Most of the work is operational: know where data lives, who can see it, and how you would prove it. This is not legal advice.

What is the DPDP Act, and is a hospital covered?

The Digital Personal Data Protection (DPDP) Act, 2023 is India's law on how digital personal data is collected, used and protected. Parliament enacted it on 11 August 2023, and the Ministry of Electronics and Information Technology (MeitY) notified the DPDP Rules, 2025 on 14 November 2025, according to the Press Information Bureau (PIB).

A hospital collects some of the most sensitive personal data there is: identity details, diagnoses, test results, insurance information and family contacts. Under the Act's vocabulary:

  • The hospital is the Data Fiduciary: the entity that decides why and how personal data is processed.
  • The patient is the Data Principal. For a child, this includes the parent or lawful guardian.
  • Your HMS vendor, cloud host or SMS provider that handles data for you is typically a Data Processor.

This post is a practical orientation for hospital owners and administrators. It is not legal advice. Dates, definitions and exemptions matter here, so as of 2026, confirm everything with your legal adviser and the official text on the MeitY website.

When do the obligations start?

PIB describes the Rules as introducing an eighteen-month period for phased compliance. Secondary legal commentary breaks this into stages: parts of the Rules dealing with the Data Protection Board took effect immediately, consent-manager provisions follow after about a year, and the core duties of data fiduciaries come at the eighteen-month mark in 2027.

There has also been public discussion of shortening the period for some entities. We have not verified any gazette notification changing the dates. The sensible planning stance is to assume your core work should be well advanced before the end of 2026, and to check MeitY's website for the current position before you finalise a plan.

What are the core principles hospitals must follow?

PIB's explainer lists seven principles underlying the Act: consent and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security safeguards, and accountability. In hospital terms:

PrincipleWhat it looks like in a hospital
Consent and transparencyA clear notice at registration explaining what data is collected and why
Purpose limitationUsing patient data for care, billing and legal needs, not unrelated marketing
Data minimisationNot collecting fields you do not need on the registration form
AccuracyCorrecting wrong phone numbers, names and dates of birth
Storage limitationKeeping records only as long as law and clinical need require
Security safeguardsAccess control, encryption, backups, logging
AccountabilityBeing able to show what you did and who did it

The Rules say each Data Fiduciary must issue a separate, clear consent notice that explains the specific purpose for which personal data is collected and used. The Act also contains certain "legitimate uses" in which processing can happen without consent. Ask your legal adviser how these apply to treatment, emergency care and statutory reporting, rather than assuming.

What rights do patients get, and how fast must you respond?

According to the PIB summary, individuals can:

  • Withdraw consent at any time.
  • Ask what personal data has been collected and how it is used.
  • Request access to their data, and corrections or updates.
  • Request erasure in certain situations.
  • Nominate another person to exercise these rights.

Data Fiduciaries must respond to access, correction, updating and erasure requests within ninety days. They must also publish contact information for queries, which can be a designated officer or a Data Protection Officer.

A hospital needs a simple request log: who asked, what they asked for, who handled it, what was done and when. Medical records staff are usually the right owners. Our medical records (MRD) software includes record-request handling and a retention register, which fit this need.

What must you do if there is a data breach?

PIB says that when a personal data breach occurs, the Data Fiduciary must inform all affected individuals without delay, in plain language explaining what happened, the possible impact, the steps taken, and contact details for help. Failure to notify the Board or affected individuals is among the violations with the higher penalty caps.

Prepare before it happens:

  1. Decide who declares an incident and who is on the response team.
  2. Keep a template notice ready in simple language.
  3. Make sure your logs can show what was accessed, and by whom.
  4. Rehearse once. A paper exercise reveals gaps quickly.

This is where a full audit trail pays off. If your system logs every create, edit and delete with user and time, you can scope an incident quickly instead of guessing.

What about children's data and healthcare?

PIB states that when a child's personal data is involved, verifiable consent from a parent or guardian is required, unless the processing relates to essential services such as healthcare, education or real-time safety. Paediatric departments, maternity wards and vaccination services should still treat child data carefully and take legal advice on how this exception applies to non-clinical uses, such as sending promotional messages.

The same logic applies to patients who cannot make legal decisions even with support: a verified lawful guardian gives consent.

What do the penalties look like?

PIB's explainer on the Rules gives the maximum penalty tiers for Data Fiduciaries:

  • Up to Rs. 250 crore for failing to maintain reasonable security safeguards.
  • Up to Rs. 200 crore for failing to notify a breach, or for violating obligations relating to children.
  • Up to Rs. 50 crore for other violations.

These are upper limits set by law and are decided case by case by the Data Protection Board, which is a digital-first body of four members. Appeals go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). The practical lesson is that security safeguards are the highest-stakes item, which is why access control and logging deserve early investment.

How should a hospital map its patient data?

Start with a simple inventory. For each system or register, note what personal data it holds, who can see it, where it is stored, and who processes it for you.

Data areaTypical examplesQuestions to ask
RegistrationName, age, address, mobile, ID detailsDo we need every field?
ClinicalCase sheets, reports, images, discharge summariesWho has access by role?
Billing and insuranceBills, TPA documents, claim formsWho can export or print?
Staff dataAttendance, payroll, biometric dataIs access limited to HR?
CommunicationSMS, WhatsApp, email listsIs each message purpose-appropriate?
BackupsServer and cloud copiesAre they encrypted and tested?

You will often find that printouts, WhatsApp forwards and shared spreadsheets are the weak points. Moving those flows into a single system with proper roles is part of the fix, and our guide on going paperless covers how to do it in stages.

What technical controls should your software provide?

Ask any vendor to demonstrate, not just describe:

  • Role-based access with module-level permissions, so staff see only what their job needs.
  • A complete audit trail of every create, edit and delete.
  • Data isolation between organisations in multi-tenant set-ups.
  • Encrypted, scheduled backups with a tested restore.
  • Controlled exports, so bulk downloads of patient lists are limited and logged.

Deployment also matters. Our comparison of cloud and on-premise hospital software explains how each model shifts security responsibilities between you and the vendor. In either case, the hospital stays accountable as the Data Fiduciary, and your contract with the vendor should state what the vendor processes, how it secures it and what happens to data at the end of the contract.

DevOrbital HMS is designed with role and module permissions, an audit trail, organisation-level data isolation and encrypted backups. These support your own compliance efforts, but they do not make a hospital compliant by themselves.

A practical DPDP readiness checklist for hospitals

  1. Appoint a named person to own data protection and publish a contact for queries.
  2. Build the data inventory above and review it twice a year.
  3. Rewrite registration forms to collect only needed fields, with a plain-language notice.
  4. Review user roles and remove shared logins.
  5. Turn on, and regularly review, audit logs.
  6. Check vendor contracts for processing scope, security, breach cooperation and exit terms.
  7. Write a breach response plan and rehearse it.
  8. Set up a request log and a ninety-day response routine.
  9. Document retention periods by record type, with the legal basis, and reconcile them with clinical record requirements.
  10. Train front-desk and billing staff, because they handle the most data.

If you plan to join ABDM, consent management overlaps with these steps, so read our ABDM and ABHA guide for hospitals alongside this one. For the accreditation angle, see NABH and hospital software.

Next steps

Start with the data map and the role review; both are quick to start and reveal most risks. Then look at how a connected hospital management system and the ABDM integration module handle consent, access and logging across departments.

Frequently asked questions

Yes, in general. The Act applies to digital personal data processed in India, and a hospital that collects patient details electronically decides why and how that data is used, so it acts as a Data Fiduciary. Individual clinics are also covered. Ask your legal adviser how provisions apply to your specific set-up.

According to the Press Information Bureau's explainer on the Rules, the highest penalty, up to Rs. 250 crore, applies to failure to maintain reasonable security safeguards. Failure to notify a breach, and violations of children-related obligations, can each attract up to Rs. 200 crore. Other violations may attract up to Rs. 50 crore.

Official summaries say every Data Fiduciary must publish contact information for personal-data queries, which can be a designated officer or a Data Protection Officer. Significant Data Fiduciaries face additional duties such as audits and impact assessments. Whether you are classed as significant is decided by government notification.

Patients can request erasure in certain situations, but hospitals also have clinical record retention duties under other laws and standards. Do not delete clinical records on request without legal advice. A retention register that records the legal basis for keeping each record type helps you answer such requests properly.

Keep exploring

Related reading and systems

Read this next

All articles →

See the platform for yourself

Tell us about your facility and we will walk you through the modules that fit — one department or the whole hospital.