AMLEGALS — Strategic Lawyering
Health & Life Sciences

Health data privacy in India: DPDPA obligations for hospitals, healthtech and insurers

Patient records, diagnostic images, genomic data, insurance claims, clinical trial datasets—health data is among the most intimate personal data processed at scale. The DPDPA applies to every entity that processes health data about identifiable individuals in India. While the Act does not create a separate sensitive-data category, the nature of health data triggers heightened expectations under the security-safeguard obligation (Section 8(5)) and, for large-scale processors, the Significant Data Fiduciary framework (Section 10).

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 4 min read

Abstract medical cross shape formed by interlocking data hexagons on navy and gold background
Short answer

Health data is personal data under the DPDPA. Hospitals, healthtech platforms, insurers and clinical research organisations must obtain consent under Section 6 (or rely on Section 7 legitimate uses such as medical emergency), issue a Section 5 notice, implement Section 8(5) security safeguards appropriate to the sensitivity of health records, and honour Data Principal rights under Sections 11–14. Section 16(2) preserves stricter sector-specific rules—including the Clinical Establishments Act, NABH standards, and IRDAI data-handling guidelines.

  • Health Data
  • DPDPA
  • Hospital Compliance
  • Healthtech
  • Clinical Data
  • Patient Privacy
Health data status
Personal data (no separate tier)
Consent
S.6 or S.7 legitimate use (medical emergency)
Security
Reasonable safeguards (S.8(5))
Sector overlay
Clinical Establishments Act, IRDAI, NABH

How the DPDPA classifies health data

The DPDPA defines personal data as any data about an individual who is identifiable by or in relation to such data (Section 2(t)). Patient names, hospital IDs, medical histories, diagnostic images, prescriptions, insurance policy numbers and genomic sequences all fall within this definition.

Unlike the GDPR (which designates health data as a “special category” under Article 9) or the 2011 SPDI Rules (which listed medical records as “sensitive personal data”), the DPDPA applies a uniform consent and safeguard framework. Heightened obligations emerge not from the data category but from the processing scale (SDF designation under Section 10) and from sector-specific regulations preserved by Section 16(2).

Security safeguards for health records

Section 8(5) requires reasonable security safeguards to prevent a personal data breach. For health data, “reasonable” must reflect the data’s sensitivity—a leaked medical diagnosis can cause irreversible reputational and personal harm.

Rule 6 of the DPDP Rules 2025 requires technical and organisational measures appropriate to the nature and volume of personal data processed. Industry benchmarks for health data include:

  • Encryption of patient records at rest (AES-256) and in transit (TLS 1.2+)
  • Role-based access control—physicians, nurses, billing staff see different data subsets
  • Audit logging of every access to patient records, with tamper-proof storage
  • Data-loss prevention controls on outbound channels (email, USB, API)
  • Periodic vulnerability assessments and penetration testing of clinical systems

Sector-specific rules preserved by Section 16(2)

Section 16(2) preserves stricter obligations in other laws. For the health sector, this includes:

  • Clinical Establishments (Registration and Regulation) Act, 2010: record-keeping obligations for registered hospitals and clinics
  • NABH accreditation standards: data-handling, access-control and retention requirements
  • IRDAI (Protection of Policyholders’ Interests) Regulations: handling of health insurance claims data
  • Indian Council of Medical Research (ICMR) guidelines on biomedical and health research: consent and data-protection standards for clinical trials
  • Drugs and Clinical Trials Rules, 2019: informed consent and data-handling for trial participants

Where a sector-specific rule imposes a stricter standard—longer retention, more detailed consent or additional security measures—that standard applies alongside the DPDPA. Compliance with the DPDPA alone is not sufficient if the sector rule demands more.

How AMLEGALS assists with health data compliance

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm advises hospitals, healthtech platforms, insurers and clinical research organisations on mapping their health-data processing to the DPDPA framework, structuring consent flows for clinical and operational contexts, and designing security-safeguard programmes that satisfy both the DPDPA and sector-specific regulators.

Bottom line

The DPDPA applies to all health data processing. There is no sensitive-data exemption—compliance requires satisfying both the DPDPA and sector-specific regulations (NABH, IRDAI, ICMR) in parallel.

Key terms
Medical emergency (S.7(h))
A situation involving a threat to life or immediate threat to the health of a Data Principal or another individual—allows processing without consent.
Significant Data Fiduciary
A Data Fiduciary notified under Section 10 based on volume, sensitivity or risk of processing—subject to DPIA, DPO and audit obligations.
Questions and answers

Health Data Privacy: common questions

Is health data sensitive personal data under the DPDPA?

No. The DPDPA does not create a separate sensitive-data category. Health data is personal data and attracts the full set of DPDPA obligations. Heightened duties arise from the SDF designation (Section 10) and sector-specific regulations, not from a data-type tier.

Can a hospital process patient data in a medical emergency without consent?

Yes. Section 7(h) allows processing without consent when there is a medical emergency involving a threat to life or immediate threat to health of the Data Principal or another individual. A Section 5 notice should be provided as soon as practicable after the emergency.

Does the DPDPA override NABH or IRDAI data-handling requirements?

No. Section 16(2) preserves stricter obligations in other laws. If NABH or IRDAI standards impose requirements beyond the DPDPA—such as longer retention periods or additional consent disclosures—those requirements continue to apply.

What is the penalty for a health data breach?

Failing to implement reasonable security safeguards under Section 8(5) carries a ceiling of up to ₹250 crore. Failing to notify a breach under Section 8(6) carries a ceiling of up to ₹200 crore. The Board determines the amount after inquiry, considering factors listed in Section 33(2).

Contact

Need guidance on health data compliance?

Submit a question about DPDPA obligations for hospitals, healthtech or insurance.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

Health Data Privacy: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Health Data Privacy?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Health Data Privacy under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Health Data Privacy under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Health Data Privacy?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Health Data Privacy rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Health Data Privacy?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Health Data Privacy · DPDPA Exposure Assessment