In November 2022, ransomware attackers breached the servers of AIIMS Delhi, India's most prestigious government hospital, encrypting patient data and holding it hostage for ten days. Nearly 1.3 terabytes of information, including names, addresses, medical histories, and financial details of an estimated four crore patients, was feared compromised. Hospital operations across outpatient, inpatient, and laboratory services had to be run manually on paper for over a week. It was a stark reminder that as India's healthcare system rapidly digitises, from hospital records to lab reports to health apps, patient data has become both more useful and more vulnerable than ever before.
This is precisely the gap the Digital Personal Data Protection Act, 2023 (DPDP Act), and its accompanying DPDP Rules, 2025, notified in November 2025, are designed to close. If you have ever uploaded a lab report to an app, booked a diagnostic test online, or used a telemedicine service, this law directly affects how your medical information is collected, stored, and shared. Here is what every Indian patient should understand about it.
What Is the DPDP Act, and Why Does It Matter for Health Data?
The Digital Personal Data Protection Act received Presidential assent on 11 August 2023, making India the 19th G20 nation to adopt a comprehensive data protection law. Unlike sector-specific rules for banking or telecom, the DPDP Act applies broadly to all digital personal data, information that can identify a living individual, and the organisations that collect it.
Crucially for patients, the Act does not carve out a separate, more stringent category for health data the way some international laws (like Europe's GDPR) treat medical information as "special category data" requiring extra protection. Instead, health records, prescriptions, diagnostic reports, and hospital admission details are treated as regular personal data under the Act, though in practice they are among the most sensitive information most people will ever share with an organisation.
Under the Act, any hospital, diagnostic lab, health app, or insurance company that collects your data is called a Data Fiduciary, and you, the patient, are the Data Principal. The law sets out what fiduciaries must do to lawfully collect, store, and use your data, and what rights you hold over information about your own body and health.
The DPDP Rules, 2025: What Changed
While the Act itself was passed in 2023, it required detailed operating rules to actually take effect. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, setting out phased compliance deadlines for organisations. Full enforcement, including Schedule 1 financial penalties of up to ₹250 crore for serious violations, is expected to take effect by 13 May 2027, giving hospitals, labs, and health-tech companies a transition window to build compliant systems.
For patients, the Rules clarify several practical points:
- Consent Managers: Larger data fiduciaries, including many hospital networks, must appoint registered Consent Managers, intermediaries who help you view, grant, and withdraw consent for how your data is used, ideally through a single dashboard rather than scattered paper forms.
- Plain-language notices: Before collecting your data, a hospital or app must show you a clear, standalone notice, not buried in fine print, explaining exactly what data is being collected, why, and how you can withdraw consent later.
- Data minimisation: Organisations are expected to collect only the data genuinely necessary for the stated purpose, rather than harvesting everything they possibly can "just in case."
- Breach notification: If a data fiduciary suffers a breach, similar to the AIIMS incident, they are obligated to notify both the Data Protection Board of India and affected individuals.
Your Rights as a Patient Under the DPDP Act
The Act gives you, as a Data Principal, several concrete rights over your own medical information:
| Right | What It Means for You |
|---|---|
| Right to access | You can ask a hospital or lab what personal data they hold about you and how it is being processed |
| Right to correction | You can request that inaccurate or outdated medical records be corrected |
| Right to erasure | You can ask for your data to be deleted once it is no longer needed for the purpose it was collected for |
| Right to grievance redressal | You can file a complaint with the organisation, and escalate to the Data Protection Board of India if unresolved |
| Right to nominate | You can nominate another person to exercise these rights on your behalf in case of death or incapacity, relevant for elderly parents or dependents |
In practice, exercising these rights today still often means writing a formal letter or email to a hospital's data protection officer, the promised unified Consent Manager dashboards are still rolling out across the healthcare sector as compliance deadlines approach.
How to Actually Exercise Your Rights: A Step-by-Step Approach
Knowing you have a right on paper is different from knowing how to use it. If you want to find out what data a hospital, lab, or health app holds about you, the practical process today generally looks like this:
- Locate the fiduciary's grievance or data protection contact. Under the Rules, every data fiduciary must publish contact details for grievance redressal, often listed in the privacy policy or discharge summary of larger hospital chains.
- Submit a written request specifying what you want: access to your records, correction of an error (a wrong blood group or an outdated diagnosis, for instance), or erasure once treatment has concluded.
- Allow for a response window. The Rules require fiduciaries to respond within a specified period, though exact timelines vary by the nature of the request and are still being standardised as compliance rolls out.
- Escalate to the Data Protection Board of India if the organisation does not respond adequately. The Board is the dedicated authority set up under the Act to hear grievances and impose penalties for non-compliance.
This process is far more workable for a large hospital chain with a dedicated compliance team than for a small neighbourhood clinic or standalone diagnostic centre, which is part of why the 2027 enforcement deadline gives smaller providers time to build this infrastructure.
Telemedicine, Health Apps, and Third-Party Data Sharing
The rise of teleconsultation platforms like eSanjeevani (India's free government telemedicine service) and numerous private health apps has added another layer of complexity. Every time you consult a doctor over video call, upload a report to an app, or use a wellness tracker, that data typically passes through the app's own servers, and sometimes third-party cloud providers or analytics tools, before reaching your doctor.
Under the DPDP Act, any such platform is itself a Data Fiduciary and must have your consent for exactly how your data is used, including whether it is shared with advertisers, used to train algorithms, or sold to third parties. Before using any telemedicine or health app, it is worth checking: does the privacy policy clearly state whether your data is shared with anyone beyond your treating doctor? If it is vague or silent on this, that is a reasonable basis for caution. You can read more about how India's telemedicine ecosystem works in our guide to eSanjeevani.
How This Connects to ABDM and ABHA
India's health data landscape already has another major digital initiative running in parallel: the Ayushman Bharat Digital Mission (ABDM) and its ABHA (Ayushman Bharat Health Account) health ID. ABDM aims to create interoperable digital health records across hospitals, so your prescriptions and reports can, in theory, follow you from one facility to another with your consent.
The DPDP Act does not replace ABDM's consent framework, the two operate alongside each other, but it does add a broader legal backbone. Where ABDM's Health Data Management Policy sets out sector-specific consent rules for the ABDM ecosystem, the DPDP Act now applies data protection obligations to virtually every hospital, lab, pharmacy app, and health-tech platform in the country, whether or not they participate in ABDM. If you have an ABHA card, it is worth understanding both frameworks together. Our dedicated guide on the ABHA Card and Ayushman Bharat Health Account covers how that system works in more detail.
Why Healthcare Data Is a Particularly Attractive Target
Medical records are valuable to cybercriminals precisely because they are so hard to change. A leaked password can be reset in seconds; a leaked diagnosis, blood group, or HIV status cannot be "reset" at all. India's CERT-In reported a roughly 53% year-on-year increase in ransomware attacks in 2022 alone, with over 13.9 lakh cybersecurity incidents recorded that year, nearly three times the 3.94 lakh incidents reported in 2019. Hospitals, often running on a patchwork of legacy IT systems with limited cybersecurity budgets, have increasingly become targets.
This is precisely why the DPDP Act's breach-notification and security-safeguard requirements matter so much for the healthcare sector specifically. When your test results, prescriptions, and diagnosis history are digitised, whether by your hospital, your insurer, or an app on your phone, you have a right to understand how well that data is protected.
What This Means for You as a Patient, Practically
Understanding the DPDP Act is not just an academic exercise. Here is what you can actually do with this knowledge:
- Read consent notices before agreeing to them, particularly when a new hospital, diagnostic lab, or health app asks to collect your data. Under the Rules, this notice should now be clear and specific rather than generic legal boilerplate.
- Ask hospitals and labs what happens to your data after treatment ends. You have a right to request erasure once your data is no longer needed for the original purpose.
- Be selective about which health apps you use, and prefer ones that are transparent about their data practices, store data securely, and do not share it with unrelated third parties for advertising.
- Keep your own independent copy of your medical records. Relying solely on a hospital's server means that if that hospital suffers a breach, outage, or simply loses old records during a system migration, as has happened repeatedly across India's under-digitised smaller hospitals and clinics, you may have no way to reconstruct your own health history.
This last point is where a personal, patient-controlled health record becomes genuinely valuable, rather than depending entirely on any single hospital's IT system or a government health record you don't directly control. With MedicalVault, you own a secure, personal copy of every report you upload, independent of any single hospital or lab's servers, with the OCR engine extracting structured data so you can track trends over time. Using MedicalVault's family sharing feature, you can also securely extend access to a spouse or adult child managing your care, on your own terms, rather than an institution's.
Looking Ahead: What to Expect by 2027
With full enforcement of the DPDP Rules expected by May 2027, Indian hospitals, diagnostic chains, and health-tech platforms are actively building out compliance infrastructure right now, appointing Data Protection Officers, revising consent forms, and in many cases, for the first time, actually documenting exactly what patient data they hold and why. As a patient, this transition period is a good time to start asking questions of your own healthcare providers: what data do you hold about me, how long do you keep it, and who else can see it?
Key Takeaways
- The DPDP Act, 2023, and its 2025 Rules apply to all personal data in India, including hospital records, lab reports, and health app data, though health data isn't given special extra-protected status.
- As a "Data Principal," you have rights to access, correct, erase, and seek grievance redressal over your medical data, exercised through hospitals' or apps' designated Consent Managers.
- Full enforcement with penalties up to ₹250 crore is expected by 13 May 2027, giving healthcare organisations a transition window to comply.
- The DPDP Act works alongside, not instead of, the Ayushman Bharat Digital Mission and ABHA health ID system.
- India's healthcare sector has already suffered major breaches, including the 2022 AIIMS Delhi ransomware attack affecting an estimated four crore patients, underscoring why these protections matter.
- Reading consent notices, asking about data retention, and being selective about which health apps you trust are practical steps you can take today.
- Keeping your own independent, patient-controlled copy of your reports, such as through MedicalVault, protects you even if a hospital's own systems are breached, lost, or migrated.
Data protection law is still evolving in India, and how individual hospitals and platforms implement these rules will vary. If you have specific concerns about how a particular provider is handling your medical data, consult that provider directly or refer to our FAQ page for more on how MedicalVault safeguards your reports.