Hospitals processing patient personal data — including medical records, biometrics, and health history — are subject to the DPDP Act 2023 as Data Fiduciaries. Specific consent is required for each processing purpose, and patients have the right to access, correct, and in limited cases delete their records.
DPDP Act 2023 compliance for hospitals — patient consent framework, data retention policy, breach notification SOP, and staff training in one pack.
Patient consent under DPDP Act 2023 is purpose-specific, informed, and freely given. Treatment consent and data processing consent are legally distinct — a single admission form that bundles both is not DPDP-compliant. This framework provides separate consent layers for different processing purposes.
Consent Layer 1 — Core Treatment Data: Processing patient identity, contact, and clinical data for direct treatment purposes. This may be treated as a legitimate processing ground under DPDP where explicit consent is impractical at every interaction, but a clear notice is mandatory. Patients must be informed of: what data is collected, by which teams, retention period, and how to exercise their rights.
Consent Layer 2 — Third-Party Sharing (Insurance): Sharing diagnosis and treatment data with health insurers requires explicit, specific consent. This cannot be implied from the insurance policy or bundled into admission consent. A separate one-page form — or a digital consent click — must be obtained before each insurer data submission.
Consent Layer 3 — Research and Analytics: Using anonymised or de-identified patient data for clinical research, AI training, or health analytics requires explicit opt-in consent. Anonymisation must be genuine and irreversible — pseudonymised data is still personal data under DPDP and requires consent.
Medical record retention is governed by multiple frameworks in India: NMC regulations (typically 7 years for adult records, until age 25 for paediatric records), the Drugs and Cosmetics Act, and hospital accreditation standards. DPDP Act adds a data minimisation overlay — retain only what is necessary, for only as long as legally required.
Retention Schedule by Data Type: (a) Admission and treatment records: 7 years from last treatment date (NMC). (b) Surgical / procedure records: 10 years (liability considerations). (c) Pathology reports: 5 years. (d) Imaging / radiology: 3–5 years (AERB guidelines for radiation-related). (e) Billing and financial data: 7 years (Income Tax). (f) Employee health data: duration of employment + 3 years.
DPDP Minimisation Principle: Once statutory retention periods expire, personal data must be deleted or anonymised. Hospitals that retain patient records indefinitely without a legal basis are in violation of DPDP data minimisation obligations. Implement quarterly purge cycles for records past their retention date.
Deletion vs Anonymisation: Where records have research value beyond retention periods, anonymisation (irreversible removal of all identifiers) is permitted. De-identification (removal of obvious identifiers but retaining re-identification potential) is not sufficient — treated as personal data under DPDP.
Hospitals are among the most data-intensive organisations subject to the DPDP Act 2023. Patient records, biometric data, health history, insurance claims data, and employee health information all constitute personal data under the Act. The DPDP Act applies to all hospitals — public and private — processing personal data of Indian residents.
The enforcement timeline (May 2027) is close. Hospitals that begin compliance preparation now have the advantage of a structured, phased approach. Hospitals that wait until enforcement begins face rushed implementation, higher costs, and the risk of being an early enforcement example.
Patients are Data Principals with four key rights under DPDP Act 2023: (1) Right to access — a patient can request all personal data held about them. (2) Right to correction — patients can request corrections to inaccurate medical records. (3) Right to erasure — patients can request deletion of data beyond statutory retention periods. (4) Right to grievance redressal — through the hospital's Grievance Officer and ultimately the DPB.
Hospitals must implement a practical process for handling these requests — not just a policy statement. The process should include a designated point of contact, a response timeline (typically 30 days), and a simple request form or digital mechanism.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.