Blog · FEB 5, 2024 · 4 min read

India's DPDP Act: What Healthcare Vendors Need to Know

DPDP treats a patient's phone number the same as their diagnosis, healthcare vendors who haven't mapped both will be caught out.

By Team Medismo•Compliance

The Digital Personal Data Protection Act changes the compliance calculus for any software vendor touching patient or healthcare-provider data in India, and healthcare-adjacent vendors have less runway than they think before enforcement mechanisms are fully active.

The parts that matter most for healthcare software

Consent under DPDP has to be specific, informed, and revocable, a blanket "by using this app you agree" clause buried in a terms page doesn't meet the bar. For any product collecting patient data, doctor prescribing data, or field-visit records that reference identifiable individuals, that means consent capture has to be built into the product flow itself, not left to a legal disclaimer. The Act also introduces the concept of "significant data fiduciaries" with heavier obligations, data protection officers, audits, impact assessments, and while thresholds for that classification are still being finalized, healthcare data's sensitivity makes it a likely candidate for stricter default treatment once rules solidify.

Where vendors typically have gaps

  • •No clear data map showing exactly which fields count as personal data under the Act's broad definition, which includes far more than medical records, extending to names, phone numbers, and location data collected incidentally
  • •Consent language written once at signup and never revisited, with no mechanism for a user to withdraw consent or request deletion
  • •Third-party data sharing, analytics tools, cloud storage, offshore processing, happening without a documented basis that would satisfy a DPDP audit
  • •No breach notification process defined internally, despite the Act introducing mandatory reporting obligations

What to do before enforcement tightens

The practical starting point is a data inventory: what personal data does the product collect, where does it flow, and can each flow be traced back to a specific, documented consent. Companies that treat this as a one-time legal review tend to fall behind again within a year, because product changes quietly introduce new data flows that were never assessed. The vendors best positioned when enforcement rules are finalized will be the ones who built data mapping into their release process now, rather than the ones planning to retrofit compliance once a penalty notice arrives.

dpdpprivacycompliance