Under the DPDP Act 2023, patient medical records are personal data — and much of it is sensitive health information that attracts a higher standard of care. Hospitals and clinics act as Data Fiduciaries and must obtain valid consent for processing, store records securely with reasonable safeguards, retain them only as long as necessary or as required by medical-records law, and honour patient rights to access and correction. A security-safeguard failure that leads to a breach of medical records can attract penalties of up to ₹250 crore. This tool checks how ready your medical records handling is for DPDP.
Patient records are among the most sensitive personal data you hold. Check how your medical records storage, retention and security stand up under the DPDP Act 2023.
Medical records combine identity, contact, diagnostic and treatment information — often the most sensitive personal data any organisation holds about an individual. Under the DPDP Act 2023, a hospital or clinic is a Data Fiduciary responsible for how that data is collected, stored, used and eventually disposed of. Because a breach of health data can cause serious harm, regulators and courts treat security failures involving medical records with particular seriousness, and the penalty ceiling for a security-safeguard failure that leads to a breach runs up to ₹250 crore.
The practical challenge for most Indian hospitals is that medical records live across many systems — HMIS, EHR, lab platforms, billing, and often paper archives — each with different access controls. DPDP readiness for medical records is therefore as much an inventory and access-control exercise as a policy one: you cannot protect records you have not mapped.
Start by mapping every place a patient record lives, then apply consistent safeguards: encryption, role-based access with logging, a written retention-and-disposal schedule, and specific consent for each way the data is shared. Blanket admission-form consent that tries to cover treatment, insurer sharing and marketing in one tick will not hold up as valid consent under the Act, so separating those purposes is a priority.
With DPDP Rules 2025 notified and full enforcement expected around May 2027, hospitals have a limited runway to put this in place. Niti Bharat runs fixed-price DPDP readiness engagements (₹75,000–₹3.2 lakh) that map your record stores, fix consent and retention gaps, and build the evidence trail an inquiry would expect to see — designed specifically for the sensitivity of health data.
A practical PDF covering how to inventory, secure, retain and dispose of patient medical records in line with the DPDP Act — with a consent and access-control template for hospitals.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.