Tuesday, 22 September 2026

Why Every Hospital Should Start Preparing for DPDP Compliance

 


Your hospital may be treating patients every day — but how securely is it handling their personal data?

Hospitals collect and process a large amount of personal data across almost every department:

๐Ÿฅ Patient registration & admission
๐Ÿ“‹ Medical records & discharge summaries
๐Ÿงช Laboratory & diagnostic reports
๐Ÿฉป Radiology & imaging records
๐Ÿ’ณ Billing & insurance information
๐Ÿ‘จ‍⚕️ Doctors, consultants & employees
๐Ÿ“ฑ Mobile numbers, email IDs and communication records
๐Ÿค Data shared with TPAs, laboratories, software providers and other vendors

The Digital Personal Data Protection Act, 2023 (DPDP Act) places important responsibilities on organisations processing digital personal data. The Act also requires appropriate technical and organisational measures and reasonable security safeguards.

The DPDP Rules, 2025 have now been notified, with different provisions coming into force according to the Government's staged commencement schedule. Therefore, hospitals should use this period to assess their present data practices and build compliance readiness, rather than waiting until every operational provision becomes applicable.

What should a hospital assess?

1. Data Inventory – What personal data is being collected?
2. Data Flow – Where does the data go after collection?
3. Purpose – Why is each category of data being processed?
4. Notice & Transparency – Are patients properly informed?
5. Consent & Other Processing Grounds – Is the correct legal basis being used?
6. Vendors & Processors – Are third parties contractually and operationally controlled?
7. Security – Are appropriate safeguards in place?
8. Retention – How long is personal data being retained?
9. Rights & Grievances – Can Data Principal requests be handled effectively?
10. Breach Response – Is there a documented incident-response mechanism?

My professional focus

I am starting a professional practice in DPDP Act, 2023 compliance and data protection advisory, with an initial focus on the healthcare sector.

My approach is practical:

Assess → Identify Gaps → Prioritise Risks → Implement → Document → Monitor

I am developing a 100-Point Hospital DPDP Gap Assessment Framework to help hospitals understand their current level of readiness and establish a practical compliance roadmap.

If you are associated with a hospital, diagnostic centre or healthcare organisation, ask yourself:

“If we were asked today to show how we collect, use, share, protect and retain patient data — could we demonstrate it clearly?”

If the answer is “not completely”, it may be time to start the assessment.

Manoj Bhagat & Associates
Corporate, Legal & Data Protection Advisory
๐Ÿ“ 31/23, 1st Floor, Mahatma Gandhi Marg, Lucknow – 226001
๐Ÿ“ž 9415010364 / 9935778867
๐Ÿ“ง maxgrowprofessionalllp@gmail.com

No comments:

Post a Comment

Why Every Hospital Should Start Preparing for DPDP Compliance

  Your hospital may be treating patients every day — but how securely is it handling their personal data? Hospitals collect and process a l...