Sharing Medical Reports on WhatsApp: The DPDPA Risk Hospitals Ignore
Sharing Medical Reports on WhatsApp: The DPDPA Risk Hospitals Ignore
Fast delivery. Permanent copies.
The scene
The lab's turnaround time was the best in the city because reports went straight to patients on WhatsApp. They also went to the referring doctor, the doctor's assistant, a family group, and the phone gallery of every one of them. When a report reached the wrong number, the lab had no way to recall it.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
Messaging is encrypted, so it's secure.
Encryption protects transit, not the copies on devices at either end.
Deliver through a controlled link that expires.
Once the patient has it, it's theirs.
Copies held by your staff and doctors remain within your responsibility.
Stop staff phones becoming storage.
Designing a safer channel
A secure link with expiry and access logs gives the same speed with a fraction of the copies. It also gives you evidence of reasonable safeguards under Section 8(5).
Monday morning
01 Find every team that sends reports by personal messaging.
02 Count the phones involved.
03 Pilot an expiring-link delivery for one location.
Questions, answered plainly
Is it lawful to send medical reports over WhatsApp under DPDPA? +
DPDPA does not ban specific apps, but the Data Fiduciary must take reasonable security safeguards. Uncontrolled copies on staff and third-party devices make it harder to meet that duty and to respond to a breach.
What counts as a personal data breach in a hospital? +
Under DPDPA a breach includes unauthorised processing, accidental disclosure, loss of access and similar events that compromise confidentiality, integrity or availability of personal data. A report sent to the wrong person can qualify.
Sector · Healthcare & Pharma The Act has no 'sensitive' category. Your patients do. Read →
Healthcare & Pharma · Deep dive Treatment is not a blank cheque. Read →
Healthcare & Pharma · Deep dive Consent for the trial is not consent for the product. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).