Hospital Management

DPDP Act 2023 for Hospitals and Clinics: A Practical Guide

What India's DPDP Act 2023 and the 2025 Rules mean for clinics and hospitals: consent, patient rights, breach duties, timelines — and where software helps.

Team iHospital36528 Aug 20265 min read

For most Indian clinics and hospitals, the Digital Personal Data Protection Act, 2023 arrived as a headline and then went quiet. That quiet is ending: the Rules that operationalise the Act were notified in November 2025, and obligations are phasing in — with the core duties for organisations landing through 2026 and 2027. Facilities that treat this as an IT topic will discover it is an operations topic, discovered late.

This guide covers what the Act actually asks of a healthcare facility, in operational terms. One note before we start: this is an operational guide from a software company, not legal advice — for compliance decisions, involve counsel.

Why healthcare sits at the sharp end

The DPDP Act applies to any organisation processing digital personal data — there is no small-clinic exemption. But healthcare has three properties that make it the sharp end of the Act:

  • Everything you hold is personal data. A patient file is a name, a phone number, a diagnosis, a prescription and a payment — identity and health status bound together. There is no anonymous corner of a patient record.
  • The data is long-lived. Clinical records are kept for years, often by legal requirement. Long retention means long exposure.
  • The data moves. Between registration desk, doctor, pharmacy, billing and the patient's own phone. Every hop is a place where "who can see this?" needs an answer.

Under the Act, the facility is the Data Fiduciary — the entity that decides why and how patient data is processed — and the patient is the Data Principal. The duties below follow from that pair of roles.

The duties, in operational terms

Lawful processing and notice

Processing personal data requires consent or a recognised legitimate use, preceded by clear notice of what is collected and why. Operationally: registration is where notice and consent live. A facility whose registration flow captures consent once, legibly, in the patient's language, is most of the way there; one that plans to "add a form later" will be retrofitting its busiest counter.

Security safeguards

The Act requires reasonable security safeguards, and backs the requirement with its largest penalty — up to ₹250 crore for failing to maintain them. For a facility, the practical checklist is short:

  • Access control — staff see what their role needs. The billing desk does not browse clinical notes; a departed employee's access dies with their employment.
  • One patient identity — duplicate records are a compliance problem, not just an operational one: you cannot honour a patient's rights over data you cannot find.
  • Audit trails — who saw and changed what, answerable after the fact.
  • Encrypted, backed-up storage — the quiet infrastructure work that separates an incident from a catastrophe.

Paper registers, incidentally, fail most of this list silently: they have no access control, no audit trail and no backup. Digitising records properly is not just efficiency — it is the only realistic route to these safeguards.

Patient rights

Data Principals can ask what you hold, seek correction and erasure (within legal retention limits), raise grievances, and nominate a person to act for them. The operational question is response: when a patient asks, can your front desk actually produce their record's contents, correct an error, and log the request? If the answer involves searching three registers and a WhatsApp group, the right exists on paper only.

Children's data

Processing a minor's data requires verifiable parental consent. For paediatric practices this is daily routine, not an edge case — the guardian relationship belongs on the patient record from the first visit.

Breach response

If personal data is breached, the Data Protection Board and the affected individuals must be notified. The uncomfortable prerequisite: knowing a breach happened at all, which circles back to access control and audit trails.

Where software helps — and where it cannot

Be suspicious of any vendor who sells "DPDP compliance" as a feature. Compliance is organisational — your notices, your consent flow, your retention decisions, your staff discipline. What software legitimately provides is the operational half: records that are access-controlled instead of ambient, one identity per patient, an audit trail, and data that lives in encrypted, backed-up storage instead of a drawer.

That is the half iHospital365 takes on. The platform is DPDP-aligned by design (compliance in progress): patient records, EMR, pharmacy and billing run on one access-controlled record, and our own security posture is documented plainly on the security standards page — including what is in progress, because pretending otherwise is exactly the vendor behaviour we advise you to distrust.

A 90-day starting plan

  1. Map what you hold — every place patient data lives: software, registers, spreadsheets, phones. The register in the drawer counts.
  2. Fix registration — notice and consent at the desk, in the patient's language, captured once on the digital record.
  3. Assign access — roles in your software matched to actual jobs; remove every shared login.
  4. Write the two responses — one page for "a patient asks for their data", one for "we suspect a breach". Name a person for each.
  5. Retire the paper shadow — every parallel paper record is an unsecured copy of data you are accountable for.

The facilities that will find 2027 uneventful are the ones treating the Act as an operations upgrade now. If your patient records still live partly on paper and partly in software that predates the Act, book a walkthrough — we will map your registration-to-record flow against the duties above, honestly.

Go deeper

See how iHospital365 handles hospital management

Explore Hospital Management

Frequently asked questions

Does the DPDP Act 2023 apply to small clinics?

Yes. The Act applies to any organisation processing digital personal data in India, with no carve-out for size. A single-doctor clinic that stores patient records digitally — or digitises paper records later — is a Data Fiduciary under the Act, with the duties that come with that role.

Is patient data covered by the DPDP Act?

Patient records are personal data, and health information is among the most sensitive data a facility holds. Registration details, diagnoses, prescriptions and bills all identify a person, so the Act's duties — lawful processing, security safeguards, breach notification, honouring patient rights — apply to the lot.

What rights do patients have under the DPDP Act?

Data Principals can ask what personal data you hold and how it is processed, seek correction and erasure subject to legal retention requirements, use your grievance mechanism, and nominate someone to exercise their rights if they are incapacitated or deceased. Facilities need a practical way to answer these requests, not just a policy that mentions them.

What happens if a hospital suffers a data breach?

The Act requires notifying the Data Protection Board and the affected individuals. Penalties under the Act are steep — up to ₹250 crore for failing to maintain reasonable security safeguards — so the first practical duty is prevention: access control, audit trails and encrypted, backed-up storage.

Does using iHospital365 make my clinic DPDP compliant?

No software makes an organisation compliant by itself, and you should treat any vendor who claims otherwise with suspicion. Compliance is organisational: your notices, consent, retention and processes. iHospital365 is DPDP-aligned by design (compliance in progress) and gives you the operational half — access-controlled records, one patient identity, and data practices built for the Act's era.

See iHospital365 on your own workflows

Book a walkthrough and we'll map iHospital365 to how your facility actually runs.