Sector guide
Healthcare processes some of the most sensitive personal data there is, usually across the least consolidated systems. Hospital information systems, laboratory systems, PACS imaging, pharmacy, insurance desks and increasingly ABDM-linked records each hold part of a patient's record, and very few providers can say precisely where all of it sits.
The obligations are the same as anyone else's. The estate is what differs.
The realistic answer is to separate clinical care from everything else. Treatment records generally do not rest on consent as their lawful basis; marketing, research participation, feedback campaigns and data sharing with partners usually do. Bundling all of it into one admission form is the common failure — it makes the whole bundle challengeable.
Notices must be available in a language the patient can read, which in most Indian hospitals means more than English.
Inventory the systems before touching consent forms. In healthcare the inventory itself is usually the revelation, because imaging archives and legacy lab systems tend to hold far more identifiable data, for far longer, than anyone assumes.
Then split the consent model: care, versus everything else.
Yes. A hospital determining the purpose and means of processing patients' digital personal data is a Data Fiduciary under the Act.
Clinical care generally does not rest on consent as its lawful basis. Marketing, research, feedback campaigns and sharing with partners usually do — which is why bundling all of it into one admission form is a weak position.
Data relating to children carries additional obligations, including verifiable parental consent and restrictions on tracking and targeted advertising. Paediatric records need to be identifiable as such in your inventory.
Priya Gupta — Priya writes on compliance operations at ProtectComply, including data principal rights, grievance handling and sector-specific programmes.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →