Sector Guide 8 min read 25 July 2026

DPDP for Clinics, Hospitals and Labs: Patient Data Compliance

Patient records are among the most sensitive personal data an Indian business can hold. What the DPDP Act requires of clinics, hospitals, labs and pharmacies — from reception-desk consent to report retention.

PDF ↓ Download the free one-page guide Branded PDF summary with a QR code back to this guide — print it for your desk or team. PDF →

A clinic's appointment register knows things a bank never will: who is ill, with what, and since when. Health information is exactly the kind of personal data the DPDP Act 2023 exists to protect — and every clinic, hospital, diagnostic lab and pharmacy that stores patient details digitally is covered, from single-doctor practices up.

Where Patient Data Lives in a Typical Practice

The appointment app or register, the EMR or practice-management software, WhatsApp chats with patients, lab-report portals, billing software with treatment line items, insurance pre-authorisation files, the CCTV at reception, and the pathology machine's own logs. Most practices are surprised by their own map — which is why the map comes first (Step 2 of the 14-step checklist).

The Duties, Reception Desk First

Consent at intake, in the patient's language

The reception form (paper that gets typed in counts — Section 3) needs a plain-language notice: what you collect, why, who sees it (Section 5(1), Rule 3). Patients can ask for it in their own language (Section 5(3)) — in most Indian practices that's not an edge case, it's the majority of patients. A QR code at the desk opening the notice in the patient's own language handles this cleanly.

Share only what treatment needs

Referrals, labs and insurers are part of care — but each recipient should be in your notice, and commercial sharing (a pharmacy chain buying your patient list) is a different purpose needing its own consent. Your lab and software vendors process data on your behalf: their contracts need data-protection terms (Section 8(2)).

Requests will come — route them well

Patients can ask what you hold, demand corrections, and request deletion (Sections 11–12). Corrections in medical records matter clinically as well as legally; deletion meets its limit where medical-record retention norms require keeping — tell the patient what stays and why. Publish how and how fast you respond (Rule 14), and see how a request portal keeps this out of the front desk's WhatsApp.

Breaches: the same 72 hours as everyone

A leaked patient list is a serious breach. The sequence — affected patients and the Data Protection Board informed without delay, detailed Board filing within 72 hours (Rule 7) — is unforgiving; write the breach plan before you need it.

Children's data is routine here

Paediatric patients mean verifiable parental consent (Section 9, Rule 10) is a standing requirement in healthcare, not a corner case — and it carries the ₹200 crore penalty tier. See our parental-consent guide.

Start With Your Exposure

The free DPDP checker tells you which obligations and penalties apply to your practice in two minutes, and the interactive checklist sequences the fixes.

References & Sources

  1. Ministry of Electronics & IT — The Digital Personal Data Protection Act, 2023 (Sections 3, 5, 6, 8(2), 8(7), 9, 11–12).
  2. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 3 (notice), Rule 7 (breach intimation), Rule 10 (verifiable consent for children), Rule 14 (rights of Data Principals).

General information, not legal or medical-records advice. Sectoral medical-record regulations apply alongside DPDP — verify both for your practice.

HealthcareClinicsHospitalsDPDPPatient Data

Check Your DPDP Compliance

Free 2-minute checker — get your specific obligations and penalty exposure.