Skip to content

Healthcare

DPDP compliance for hospitals, clinics, labs and health apps

Patient records are among the most sensitive data a business can hold. The Act lets you act in an emergency without waiting for consent, but expects strong safeguards around everything else.

The data you hold

  • Patient names and contact details
  • Diagnoses, prescriptions and reports
  • Insurance and payment details
  • Children's medical records
  • Staff records

What the Act asks of you

Strong safeguards for health data
A leak of medical details causes serious harm, so the safeguards have to match: access limited to those treating the patient, encryption, logs and backups.
Section 8(5), Rule 6
Emergencies don't wait for consent
Responding to a medical emergency that threatens someone's life or health is a legitimate use under the Act, so it doesn't need consent first. Routine care and marketing still do.
Section 7
Children's records need a parent's consent
For patients under 18, consent comes from a parent or guardian, checked as an identifiable adult.
Section 9(1), Rule 10
Labs, insurers and software vendors
Every outside lab, TPA, billing or software vendor that handles patient data on your behalf needs a valid contract.
Section 8(2)

How GRC Flow handles it

  • Discovery finds health details, including those typed into free-text notes.

    See how it works
  • Evidence for each safeguard, and a tamper-evident log of who changed what.

    See how it works
  • The vendor register tracks contracts, data shared and where each vendor processes it.

    See how it works