Healthcare's DPDP Problem Isn't a Compliance Gap
By Privy
Sep 01, 2026

Healthcare's DPDP Problem Isn't a Compliance Gap

A diagnosis, a prescription, a lab result, a mental-health note: this is the most intimate information any organisation holds, and under India's DPDP Act it is treated with the seriousness that reflects. Health data is the textbook example of sensitive personal data, the category where misuse causes the deepest harm and the hardest-to-undo damage. For hospitals, diagnostic chains, insurers, and digital-health platforms, the practical question is no longer whether health data is sensitive. It is whether the organisation can prove it collected that data with valid consent and can act on a patient's rights over it, across every system where a copy now lives.

This is a look at the operational reality: what makes health data sensitive under the Act, why consent in a hospital is harder than a signature on an admission form, and how a provider actually services a patient's access, correction, and erasure rights when their record is scattered across a dozen systems. Enforcement of the substantive obligations lands around 13 May 2027, and providers treating this as an engineering problem now will be ready for it.

Why Health Data Is the Hardest Category of Sensitive Personal Data

Sensitive personal data is the information whose exposure can cause disproportionate harm: financial data, biometrics, and, most acutely, health and medical records. A leaked shipping address is an inconvenience. A leaked HIV status, a psychiatric history, or a fertility record can cost someone a job, a marriage, or their safety.

Health data compounds the problem in three ways. It is intimate, so the harm from misuse is severe and often irreversible. It is sprawling, generated across consultations, labs, pharmacies, imaging, insurance claims, and increasingly wearables and telemedicine apps that never stop collecting. And it is intermingled, sitting in the same systems as billing, scheduling, and marketing data, so isolating it for protection or deletion is genuinely hard. Handling it well starts with knowing where it all is, which is why data discovery and classification are the first real step, not the paperwork that usually gets done first.

sensitive personal data

Consent for Health Data Is Harder Than a Signature

For decades, a single admission form carried the entire hospital journey: treatment, diagnostics, insurance, referrals, and billing. Under the DPDP Act, that one signature no longer covers everything. Consent has to be free, specific, informed, and unambiguous, tied to a defined purpose, and as easy to withdraw as it was to give.

That breaks the old model in practical ways. Data collected to treat a patient cannot silently become training data for a diagnostic model or fuel for a hospital's marketing programme; each new purpose needs its own basis. Because much of this is sensitive data, the stakes of getting consent wrong are higher, and the difference between implicit and explicit consent matters more here than almost anywhere else. A provider needs a consent record that captures what each patient agreed to, for which purpose, under which version of the notice, and that pushes a withdrawal through every connected system rather than the one screen where it was clicked.

Not every processing activity runs on consent, though, and getting this right avoids a common error. Emergency care, where the patient cannot consent, and certain legal or public-health obligations may rest on other lawful grounds rather than consent. The task is to map each flow to the correct basis and build consent journeys only where consent genuinely belongs, which is easier to see once the different types of consent under DPDP are clear.

Servicing Patient Rights Across Fragmented Systems

The Act gives patients enforceable rights over their data: to access a summary of what is held, to correct it, to erase it where the purpose is served, and to grievance redressal within defined timelines. In a hospital, exercising even one of these is deceptively hard.

Consider an access request. A single patient's data sits in the electronic health record, the lab system, the pharmacy log, the imaging archive, the billing platform, and possibly a telemedicine app run by a third party. A complete, accurate response means finding every copy, which is impossible without a live map of where patient data lives. This is why fulfilling a data principal request is an operational capability that rests on discovery and mapping, and why a rights request that returns a partial picture is itself a compliance gap.

Erasure carries a healthcare-specific wrinkle. A patient's right to deletion runs into legitimate medical-record retention: providers often must keep records for defined periods under medical councils and other rules. The correct answer is rarely blanket deletion; it is de-linking the data from active use, tagging what must be retained and why, and being able to show that reasoning. Correction rights matter clinically too, because an error in a health record is a patient-safety issue, not only a privacy one.

The Third Parties Holding Your Patients' Data

Patient data rarely stays inside the hospital. It flows to diagnostic labs, insurers and claims administrators, telemedicine providers, cloud and EHR vendors, and analytics partners. Under the Act, the provider stays accountable for what those processors do with the data, so this is not a procurement footnote.

Two controls matter most. Contracts with every processor need the required data-protection clauses, security obligations, breach-notification duties, and audit rights, which is the discipline of proper third-party risk management. And the provider needs to know, at any moment, which vendor holds which category of patient data, because an erasure or access request has to reach them too. When a data principal asks a hospital to delete their record, that request is only honoured if every downstream vendor honours it as well.

When a Health Data Breach Happens

Healthcare is among India's most-targeted sectors, and a breach of health data is among the most damaging. The DPDP Rules require a provider to notify affected data principals without delay and to report to the Data Protection Board with a detailed report within 72 hours. Where the event qualifies as a cyber incident, CERT-In's separate six-hour reporting can run in parallel.

For health data specifically, the notification content matters because the harm is acute: patients need to know what was exposed and what they can do about it. Building this response as a rehearsed workflow rather than an improvisation is the point of incident management under DPDP, and it depends on the same data map, because you cannot scope a breach you cannot trace. Separate maximum penalties reach ₹250 crore for failing to maintain reasonable security safeguards, subject to the Board's determination.

Building It Right: A Short Sequence for Providers

Privacy for health data works best built in, not bolted on. In practice that means discovering and classifying sensitive health data across the EHR, labs, pharmacy, imaging, billing, telemedicine, and vendor systems first; mapping each processing activity to the correct lawful basis and building consent journeys only where consent belongs; designing consent and rights workflows that work across the whole estate, not one screen; fix the vendor map contractually; and standing up a tested breach response. A general 90-day path to operationalising DPDP sequences the wider programme, and a privacy impact assessment is the right tool for the high-risk processing that health data almost always involves.

How Privy by IDfy Helps Healthcare Providers

Privy by IDfy gives healthcare organisations the operating layer this sequence assumes. Its Data Compass discovers and classifies sensitive health data across EHRs, lab and pharmacy systems, cloud stores, and vendor platforms, building the inventory that consent, rights, and breach response all depend on. Its consent governance platform manages purpose-linked patient consent, versioned notices, and withdrawals that propagate across systems, while incident and third-party risk workflows run on the same platform so a request or a breach produces one auditable record rather than a scramble across teams.

The result is what the Act ultimately asks for: a provider that can show, on demand, that it collected sensitive health data lawfully, used it only for agreed purposes, and can act on a patient's rights over it wherever that data lives.

Trusted by 50+ organisations | Ranked #1 in the MeitY–NeGD DPDP Innovation Challenge

sensitive personal data

IDfy won MeitY's DPDP Innovation Challenge and brings 14 years of handling India's most sensitive identity data at a scale of 60 million verifications a month.

sensitive personal data

Conclusion

Health data is where the DPDP Act's protections matter most, because the harm from getting it wrong is measured in people's lives rather than penalties alone. The obligations are demanding: valid consent for a sensitive category, patient rights serviced across fragmented systems, vendor accountability, and breach response on a 72-hour clock, but they resolve to one underlying capability: knowing where every patient's data lives and being able to prove how it is used. Providers that build that foundation before May 2027 will be able to launch digital-health services and share data with partners without rebuilding their privacy architecture each time.

To see how Privy by IDfy helps healthcare providers discover sensitive health data, manage patient consent, and service rights across every system, request a walkthrough at shivani@IDfy.com

FAQ’s

Is health data sensitive personal data under the DPDP Act? 

Health and medical data is the archetypal sensitive personal data: information whose exposure can cause severe, often irreversible harm. The Act requires it to be handled with heightened care, valid consent or another lawful basis, strong security safeguards, and the ability to act on patient rights.

Does a hospital need separate consent for each use of patient data? 

Broadly, yes. Consent must be specific to a purpose, so data collected for treatment cannot be reused for research, model training, or marketing without a fresh basis. Some processing, such as emergency care or legally mandated reporting, may rest on grounds other than consent, so each flow should be mapped to its correct basis.

Can a patient ask a hospital to delete their health records? 

A patient has an erasure right, but it is balanced against medical-record retention obligations under other laws. The usual answer is to de-link the data from active use and retain only what regulation requires, with the retention reason documented, rather than blanket deletion.

Who is responsible when a lab or telemedicine vendor leaks patient data? 

The healthcare provider that collected the data generally remains accountable as the Data Fiduciary, even when a processor causes the breach. This makes vendor contracts, security obligations, and knowing which vendor holds which data an essential part of compliance.

What are the breach-notification rules for health data? 

Affected patients must be informed without delay, and the Data Protection Board must receive an intimation followed by a detailed report within 72 hours. A qualifying cyber incident may also trigger CERT-In's six-hour reporting in parallel.

Search Here

Reach out to us

Explore More

DPDP Readiness for Banks | What Banking Institution Must Do After DPDP Rules
DPDP Rules

Dec 10, 2025

DPDP Readiness for Banks | What Banking Institution Must Do After DPDP Rules

What is ROPA? Record of processing activities under India's DPDP Act
DPDP Rules

Jun 15, 2026

What is ROPA? Record of processing activities under India's DPDP Act

Why Privy by IDfy's #1 MeitY-NeGD Ranking Matters for India's DPDP Compliance
DPDP Rules

Jul 09, 2026

Why Privy by IDfy's #1 MeitY-NeGD Ranking Matters for India's DPDP Compliance

Share