For hospitals, nursing homes and healthcare groups
DPDP compliance for hospitals
Hospitals hold the most sensitive data most people will ever share, across HIS, lab, pharmacy, billing and insurance desks. ConsentKit gives every patient a clear notice at registration, tracks what you share with insurers and TPAs, and handles record requests from patients and their nominees.
- Medical emergencies
- No consent needed
- Insurer and TPA sharing
- Map every flow
- Breach report
- Within 72 hours
City Care Hospital asks for your consent
Treatment records are kept as the law requires. Choose the optional uses below.
Where the DPDP Act touches a patient’s visit
A single admission can pass data through a dozen systems and outside parties. Pick a stage to see what you hold and the basis for it.
What changes for your hospital on 13 May 2027
Health data has no separate category in the Act, but the stakes are highest. These are the gaps we see most.
Registration needs a clear noticeSections 5 and 6
Patients need to know what you collect, why and who you share it with, in English or a scheduled Indian language they can read.
Tablet and web notices at the front desk, with consent saved to the patient’s record.
Map every sharing flowSections 6 and 8
Insurers, TPAs, labs, pharmacies, corporate clients and referral doctors all receive patient data. Each flow needs a basis.
A data-flow register with processor contracts and consent checks per partner.
Patients and nominees can request recordsSections 11 to 14
Patients can ask for a summary of their data, correction and erasure where law allows, and can nominate someone to act for them.
A request portal with identity checks, nominee handling and deadline tracking.
Security safeguards are specificSection 8(5) and Rule 6
Encryption, access control, access logs kept for at least a year, and backup plans for your HIS and PACS.
Access logging and evidence exports for your audit file.
Breaches go to the Board and to patientsRule 7
Ransomware, a lost laptop or a leaked lab report must be reported, with a detailed report within 72 hours.
Breach workflow with Board report and patient notice templates.
Keep records only as long as requiredSection 8(7) and Rule 8
Medical records have legal retention periods. Marketing lists and old leads do not.
Retention rules per record type with a deletion log.
What the healthcare exemptions cover
The DPDP Act lets you process data without consent to respond to a medical emergency. The Rules also exempt clinical establishments and healthcare professionals from verifiable parental consent when treating a child, to the extent needed to protect the child’s health. Neither is a blanket exemption.
This is general guidance, not legal advice. Confirm how it applies to you with your counsel.
A plan that fits hospital operations
Hospitals can’t pause the front desk, so roll changes out department by department.
Map systems and partners
List HIS, LIS, PACS, pharmacy, billing and every insurer, TPA and vendor.
Fix registration
Go live with notices and consent capture at OPD and IPD registration.
Contracts and access control
Sign processor terms, clean up shared logins and switch on access logs.
Train and rehearse
Train front desk, MRD and IT, and run a breach drill.
For every kind of hospital
Templates for how each setup handles patient data.
Multi-specialty hospitals
Many departments, systems and partners.
Hospital chains
Central policy with per-unit consent logs.
Nursing homes
Smaller teams, paper and digital mixed.
Maternity and children’s hospitals
Minors and parent consent handled correctly.
Eye and dental hospitals
High OPD volume and follow-up reminders.
Medical college hospitals
Teaching, research and student access.
DPDP compliance for hospitals near you
Local guidance and onboarding in these cities, with support from our team in Kolkata.
Related sectors
Questions hospitals are asking
For the full picture, read our DPDP Act guide or compliance checklist.
Does the DPDP Act apply to hospitals?
Yes. Every hospital holding patient, staff or visitor data digitally is a data fiduciary. Full obligations apply from 13 May 2027.
Do we need consent to treat an unconscious patient?
No. The Act allows processing without consent to respond to a medical emergency involving a threat to life or health. Record the basis in the patient’s file.
Can we share records with insurers and TPAs?
Yes, for the claim the patient asked you to process, and only what the claim needs. Have processor terms with TPAs and record the patient’s consent.
How long do we keep medical records?
As long as medical regulations and other laws require. Data held only for marketing or old leads should be deleted when its purpose ends.
Who can request a patient’s records if they die?
Patients can nominate someone to exercise their rights on death or incapacity. Your request process should handle nominees and verify their identity.
Get your hospital ready before May 2027
The readiness check takes about ten minutes and gives you a gap report built for hospitals, whether or not you use ConsentKit.