Healthcare
DPDP compliance for hospitals, clinics, labs and health apps
Patient records are among the most sensitive data a business can hold. The Act lets you act in an emergency without waiting for consent, but expects strong safeguards around everything else.
The data you hold
- Patient names and contact details
- Diagnoses, prescriptions and reports
- Insurance and payment details
- Children's medical records
- Staff records
What the Act asks of you
- Strong safeguards for health data
- A leak of medical details causes serious harm, so the safeguards have to match: access limited to those treating the patient, encryption, logs and backups.
- Section 8(5), Rule 6
- Emergencies don't wait for consent
- Responding to a medical emergency that threatens someone's life or health is a legitimate use under the Act, so it doesn't need consent first. Routine care and marketing still do.
- Section 7
- Children's records need a parent's consent
- For patients under 18, consent comes from a parent or guardian, checked as an identifiable adult.
- Section 9(1), Rule 10
- Labs, insurers and software vendors
- Every outside lab, TPA, billing or software vendor that handles patient data on your behalf needs a valid contract.
- Section 8(2)
How GRC Flow handles it
Discovery finds health details, including those typed into free-text notes.
See how it worksEvidence for each safeguard, and a tamper-evident log of who changed what.
See how it worksThe vendor register tracks contracts, data shared and where each vendor processes it.
See how it works