Medical-records regulation keeps an inpatient record for three years; a hospital’s own medico-legal defence keeps it far longer. The DPDP Act does not fight that — retention required by law defeats erasure. What it demands is the unregulated middle: the marketing lists, engagement-app data, camp leads and inactive registrations that no named law protects, which a hospital must now segment, justify and erase on request. Layer on a second consent regime from ABDM, a claims chain through insurers and TPAs that concentrates the most sensitive data in the country, and a children’s exemption narrower than the sector assumes.
FROM THE SEPTEMBER 2026 PROBLEM REGISTER · 7 HEALTHCARE PROBLEMS SWEPT · 4 SHOWN HERE · HOW THIS WAS BUILT
Each of these is marked confirmed: two independent sources, at least one the instrument itself or a practitioner record. Sources are linked so your counsel can read them.
DPDP s.8(7) and s.12 meet the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002: regulation 1.3.1 keeps indoor-patient records three years from commencement of treatment, and regulation 1.3.2 requires records to be supplied to the patient within seventy-two hours of a request — tighter than DPDP’s own response window. The regulation covers only inpatient records; the Third Schedule names e-commerce, gaming and social media, not health. Every erasure request forces per-category legal triage.
SOURCES · IMC Regulations 2002, reg. 1.3.1–1.3.2 (instrument, NMC text) · DPDP Act s.8(7), s.12 (statute)
Confirmed · sweep of 2 Sep 2026DPDP ss.5–6 and the Rule 4 consent-manager framework meet the National Health Authority’s purpose-coded, time-bound, per-provider consent artefacts. The HDM Policy is an NHA policy, not statute; an ABDM artefact does not discharge a DPDP consent obligation; and their withdrawal semantics differ — artefact expiry or revocation is not a DPDP withdrawal that triggers s.8(7) erasure. Treating the ABHA artefact log as the DPDP consent register fails Rule 3’s notice content and withdrawal propagation.
SOURCES · ABDM implementer documentation (the artefact structure) · DPDP Act ss.5–6; DPDP Rules 2025, Rules 3–4 (text) · practitioner analyses (context)
Confirmed · Rule 4 registration opens mid-Nov 2026DPDP s.8(2) permits a processor only under a valid contract, with the fiduciary liable for it; s.8(7) reaches the record wherever it went. The IRDAI (TPA – Health Services) Regulations, 2016 govern the TPA under an insurer-authorisation model that predates processor contracts, breach clocks and principal rights. Whether the TPA is the insurer’s processor, the hospital’s, or an independent fiduciary is unsettled. An erasure at the hospital does not reach the TPA’s claim copy. The two largest Indian insurance breaches on record, in 2024, were both of exactly this data class.
SOURCES · IRDAI TPA Regulations, 2016 (instrument) · DPDP Act s.8(2), s.8(7) (statute) · NATHEALTH paper on the National Health Claims Exchange (practitioner)
Confirmed · every cashless claim in IndiaDPDP s.9(1) requires verifiable parental consent and s.9(3) bans tracking, behavioural monitoring and targeted advertising directed at children. The Fourth Schedule, Part A disapplies both for clinical and mental-health establishments and healthcare professionals, but strictly for protection of the child’s health and with no secondary use. Adherence gamification, caregiver-app analytics, growth-tracker notifications and family marketing fall back under full s.9 and Rule 10 — a mechanism whose Digital Locker providers have not been notified.
SOURCES · DPDP Rules 2025, Fourth Schedule Part A and Rule 10 (text) · DPDP Act s.9 (statute) · practitioner commentary on the exemption boundary (context)
Confirmed · true, but narrower than the sector assumesHealthcare retention is the area where the most confident wrong numbers circulate. The register read the instruments and replaced them.
IMC regulation 1.3.1: indoor-patient records three years from commencement of treatment. There is no central lifetime mandate. Longer periods come from variable state Clinical Establishments rules and from defensive practice, not from a named instrument. Outpatient records have no central retention mandate at all.
That figure traces only to a 2021 National Health Authority consultation paper. No binding period was established. We do not quote it, and we would ask anyone who does for the notification.
IMC regulation 1.3.2 requires medical records to be supplied to the patient within seventy-two hours of a request — a clock that already runs today, tighter than the response period a fiduciary publishes under DPDP Rule 14. The two obligations will coexist on the same desk.
Fourth Schedule Part A disapplies s.9(1) and s.9(3) only, and only to the extent necessary for the protection of the child’s health, with no secondary use. The treatment path is safe; the engagement and analytics stack is not.
The penalty provisions commence in mid-May 2027 and the Board had no members as of 1 August 2026. No Significant Data Fiduciary class has been notified. The penalty schedule is stated plainly here, once.
RULES NOTIFIED MID-NOV 2025 · CONSENT-MANAGER REGISTRATION OPENS MID-NOV 2026 · DUTIES, RIGHTS AND PENALTIES MID-MAY 2027 · DATES STATED AS THE NOTIFICATIONS STATE THEM
Everything below is live today and maps to shipped code — the same rule as every page on this site. Capabilities we are still building are not listed here.
Every access, correction and erasure request carries a response deadline computed when it is filed and an escalation ladder when it slips. Erasure is executed against the stores you connect and the destruction recorded, not asserted; the written refusal for the clinical record you retain under regulation 1.3.1 lands in the same audit chain, dated and attributable. The two-tier architecture the register describes is what this evidences.
Live: DSR orchestration · SLA tracking · grievance workflowsConsent is captured per specified purpose with a versioned, itemised notice, withdrawable as easily as it was given, with a receipt the patient can keep. This is the DPDP consent ledger. We do not integrate with ABDM and this page does not claim to: the ABHA artefact stays the ABHA artefact, and the direction of travel the register recommends — feed its withdrawal events into the DPDP ledger — is your integration, not a box we tick.
Live: purpose-by-purpose consent · versioned notices · PDF receiptsThe platform models you as the fiduciary and holds your processors — the insurer desk’s counterparties, the TPA, the engagement vendor — with each data-processing agreement tracked and scored. It does not allocate fiduciary-versus-processor roles across a claims chain; no tool the register found does, and ours does not either. For under-18 patients, a guardian’s consent is captured as its own record with its verification method stated, never a stronger claim than the mechanism supports.
Live: processor & DPA register · guardian consent flowsNotices and consent flows are rendered in twenty-two Indian languages by a self-hosted translation model — nothing leaves our systems, which matters more for health data than anywhere else. Every consent, erasure, refusal and notice publication is a linked record bound to the one before it, periodically stamped by an independent timestamp authority. Anyone can check it.
Live: 22 Indian languages · tamper-evident audit trail · verifiable receipts