Patient data under DPDP: what clinics must change before 2027

Health data carries the highest breach cost and clinics hold it in the least controlled systems. Six changes worth starting now.

Clinics and hospitals hold the most sensitive category of personal data most Indian organisations will ever process, frequently in the least controlled systems. DPDP full compliance lands 13 May 2027, and healthcare has further to travel than most sectors.

Where patient data actually lives

Map it honestly and the list is longer than the practice management system. Appointment records in a spreadsheet. Patient phone numbers in the receptionist personal WhatsApp. Reports on a shared drive. Photographs on a practitioner phone. Enquiry forms feeding an email inbox nobody has audited. Third-party labs and diagnostic partners.

Every one of those is in scope. The WhatsApp one is where most clinics have the largest exposure, because staff turnover means patient data walks out with departing employees.

Six changes worth starting now

Move patient communication off personal devices onto a clinic-controlled number or system. This is the single highest-value change and the hardest operationally, because it changes how staff work.

Separate treatment consent from marketing consent. Agreeing to a procedure is not agreeing to receive promotional messages, and bundling them fails.

Set retention periods per record type, informed by medical record-keeping requirements, and delete on schedule rather than keeping everything indefinitely.

Get written processing terms with labs, diagnostic partners and any software vendor touching patient records.

Restrict access by role. Reception does not need clinical notes. Most small clinic systems give everyone everything by default.

Write a breach response plan naming who decides, who reports, and within what timeframe. Health data breaches carry the highest penalty exposure under the Act.

The marketing-specific point

Using treatment history to target marketing is the practice most likely to cause a problem. Messaging patients about a related service based on their diagnosis processes health data for a purpose they did not consent to, and the recipient is likely to notice and object.

If you intend to do it at all, it requires separate, specific, informed consent that names exactly this use. Most clinics doing it today have nothing of the kind.

General information, not legal advice. Rules current as of July 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *