Solutions · Healthcare & healthtech

The clinical record stays.
Everything around it must be justified.

Medical-records regulation keeps an inpatient record for three years; a hospital’s own medico-legal defence keeps it far longer. The DPDP Act does not fight that — retention required by law defeats erasure. What it demands is the unregulated middle: the marketing lists, engagement-app data, camp leads and inactive registrations that no named law protects, which a hospital must now segment, justify and erase on request. Layer on a second consent regime from ABDM, a claims chain through insurers and TPAs that concentrates the most sensitive data in the country, and a children’s exemption narrower than the sector assumes.

FROM THE SEPTEMBER 2026 PROBLEM REGISTER · 7 HEALTHCARE PROBLEMS SWEPT · 4 SHOWN HERE · HOW THIS WAS BUILT

What the ground actually looks like

Four collisions, each read from the instrument.

Each of these is marked confirmed: two independent sources, at least one the instrument itself or a practitioner record. Sources are linked so your counsel can read them.

01 · THE UNREGULATED MIDDLE

A hospital must honour erasure on demand while medical-records regulation and its own defence require keeping the clinical record — and no notified schedule says where the line is.

DPDP s.8(7) and s.12 meet the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002: regulation 1.3.1 keeps indoor-patient records three years from commencement of treatment, and regulation 1.3.2 requires records to be supplied to the patient within seventy-two hours of a request — tighter than DPDP’s own response window. The regulation covers only inpatient records; the Third Schedule names e-commerce, gaming and social media, not health. Every erasure request forces per-category legal triage.

SOURCES · IMC Regulations 2002, reg. 1.3.1–1.3.2 (instrument, NMC text) · DPDP Act s.8(7), s.12 (statute)

Confirmed · sweep of 2 Sep 2026
02 · TWO CONSENT REGIMES, ONE RECORD

An ABDM-integrated hospital runs the ABHA consent-artefact flow and DPDP consent for the same record; neither substitutes for the other, and the Health Data Management Policy is not law.

DPDP ss.5–6 and the Rule 4 consent-manager framework meet the National Health Authority’s purpose-coded, time-bound, per-provider consent artefacts. The HDM Policy is an NHA policy, not statute; an ABDM artefact does not discharge a DPDP consent obligation; and their withdrawal semantics differ — artefact expiry or revocation is not a DPDP withdrawal that triggers s.8(7) erasure. Treating the ABHA artefact log as the DPDP consent register fails Rule 3’s notice content and withdrawal propagation.

SOURCES · ABDM implementer documentation (the artefact structure) · DPDP Act ss.5–6; DPDP Rules 2025, Rules 3–4 (text) · practitioner analyses (context)

Confirmed · Rule 4 registration opens mid-Nov 2026
03 · THE CLAIMS CHAIN

One claim moves a patient’s file through hospital, insurer, TPA and beyond, and nobody can show the DPDP-required contract chain or answer an erasure request across it.

DPDP s.8(2) permits a processor only under a valid contract, with the fiduciary liable for it; s.8(7) reaches the record wherever it went. The IRDAI (TPA – Health Services) Regulations, 2016 govern the TPA under an insurer-authorisation model that predates processor contracts, breach clocks and principal rights. Whether the TPA is the insurer’s processor, the hospital’s, or an independent fiduciary is unsettled. An erasure at the hospital does not reach the TPA’s claim copy. The two largest Indian insurance breaches on record, in 2024, were both of exactly this data class.

SOURCES · IRDAI TPA Regulations, 2016 (instrument) · DPDP Act s.8(2), s.8(7) (statute) · NATHEALTH paper on the National Health Claims Exchange (practitioner)

Confirmed · every cashless claim in India
04 · THE CHILDREN’S EXEMPTION IS NARROW

The Rules exempt clinical establishments from parental-consent mechanics only to the extent necessary for the protection of the child’s health — a health app’s engagement features sit on the wrong side of the line.

DPDP s.9(1) requires verifiable parental consent and s.9(3) bans tracking, behavioural monitoring and targeted advertising directed at children. The Fourth Schedule, Part A disapplies both for clinical and mental-health establishments and healthcare professionals, but strictly for protection of the child’s health and with no secondary use. Adherence gamification, caregiver-app analytics, growth-tracker notifications and family marketing fall back under full s.9 and Rule 10 — a mechanism whose Digital Locker providers have not been notified.

SOURCES · DPDP Rules 2025, Fourth Schedule Part A and Rule 10 (text) · DPDP Act s.9 (statute) · practitioner commentary on the exemption boundary (context)

Confirmed · true, but narrower than the sector assumes
What the law actually says — and what it doesn’t

Claims we corrected before putting them here.

Healthcare retention is the area where the most confident wrong numbers circulate. The register read the instruments and replaced them.

“Medical records: lifetime plus three years” is disproved.

IMC regulation 1.3.1: indoor-patient records three years from commencement of treatment. There is no central lifetime mandate. Longer periods come from variable state Clinical Establishments rules and from defensive practice, not from a named instrument. Outpatient records have no central retention mandate at all.

There is no binding “eight-year ABDM retention period.”

That figure traces only to a 2021 National Health Authority consultation paper. No binding period was established. We do not quote it, and we would ask anyone who does for the notification.

Seventy-two hours already applies to supplying the record.

IMC regulation 1.3.2 requires medical records to be supplied to the patient within seventy-two hours of a request — a clock that already runs today, tighter than the response period a fiduciary publishes under DPDP Rule 14. The two obligations will coexist on the same desk.

“The Rules exempt healthcare from the children’s provisions” is true but narrower.

Fourth Schedule Part A disapplies s.9(1) and s.9(3) only, and only to the extent necessary for the protection of the child’s health, with no secondary use. The treatment path is safe; the engagement and analytics stack is not.

No DPDP penalty can be imposed on anyone today.

The penalty provisions commence in mid-May 2027 and the Board had no members as of 1 August 2026. No Significant Data Fiduciary class has been notified. The penalty schedule is stated plainly here, once.

RULES NOTIFIED MID-NOV 2025 · CONSENT-MANAGER REGISTRATION OPENS MID-NOV 2026 · DUTIES, RIGHTS AND PENALTIES MID-MAY 2027 · DATES STATED AS THE NOTIFICATIONS STATE THEM

Where Consent Tree fits today

The DPDP ledger beside the clinical record,
not inside it.

Everything below is live today and maps to shipped code — the same rule as every page on this site. Capabilities we are still building are not listed here.

FOR 01 · THE UNREGULATED MIDDLE

A rights request executed against the erasable tier, with the clinical refusal evidenced

Every access, correction and erasure request carries a response deadline computed when it is filed and an escalation ladder when it slips. Erasure is executed against the stores you connect and the destruction recorded, not asserted; the written refusal for the clinical record you retain under regulation 1.3.1 lands in the same audit chain, dated and attributable. The two-tier architecture the register describes is what this evidences.

Live: DSR orchestration · SLA tracking · grievance workflows
FOR 02 · THE DPDP SIDE OF TWO REGIMES

Purpose-level consent, versioned notices, withdrawal — the register that the artefact log is not

Consent is captured per specified purpose with a versioned, itemised notice, withdrawable as easily as it was given, with a receipt the patient can keep. This is the DPDP consent ledger. We do not integrate with ABDM and this page does not claim to: the ABHA artefact stays the ABHA artefact, and the direction of travel the register recommends — feed its withdrawal events into the DPDP ledger — is your integration, not a box we tick.

Live: purpose-by-purpose consent · versioned notices · PDF receipts
FOR 03 AND 04 · THE CHAIN, AND THE CHILD

Your processors and their DPAs as a scored register; guardian consent flows for age-gated processing

The platform models you as the fiduciary and holds your processors — the insurer desk’s counterparties, the TPA, the engagement vendor — with each data-processing agreement tracked and scored. It does not allocate fiduciary-versus-processor roles across a claims chain; no tool the register found does, and ours does not either. For under-18 patients, a guardian’s consent is captured as its own record with its verification method stated, never a stronger claim than the mechanism supports.

Live: processor & DPA register · guardian consent flows
FOR ALL OF IT · EVIDENCE, IN 22 LANGUAGES

Notices in the Eighth Schedule languages, and an audit trail a regulator can verify without trusting us

Notices and consent flows are rendered in twenty-two Indian languages by a self-hosted translation model — nothing leaves our systems, which matters more for health data than anywhere else. Every consent, erasure, refusal and notice publication is a linked record bound to the one before it, periodically stamped by an independent timestamp authority. Anyone can check it.

Live: 22 Indian languages · tamper-evident audit trail · verifiable receipts