Compliance

Patient Data Security in Hospital Software: DPDP Act, Access Control and Consent

What the DPDP Act, 2023 and DPDP Rules, 2025 mean for hospital software, and the practical controls every HMS should support to protect patient data.

Hospital software holds some of the most sensitive personal data there is. India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 make protecting it a legal obligation, not just good practice. This guide explains what that means for hospital software and the controls every HMS should support.

This article is general information, not legal advice. Consult your legal adviser about your hospital’s specific obligations.

The DPDP Act and Rules in brief

The Digital Personal Data Protection Act, 2023 governs how organisations process digital personal data in India. The DPDP Rules, 2025, notified by the Ministry of Electronics and Information Technology in November 2025, set out how it works in practice, including notices, consent, breach reporting and the Data Protection Board, with obligations coming into force in phases. Hospitals, public and private, that process patient data digitally are covered.

Hospitals as data fiduciaries

Under the Act, the organisation that decides why and how personal data is processed is a data fiduciary. For patient records, that is usually the hospital. The software vendor that processes data on the hospital’s behalf acts as a data processor. The hospital remains responsible, so it needs software, contracts and processes that support its obligations.

Controls every hospital management system should support

  • Unique logins. Every staff member has their own account; shared counter logins make accountability impossible.
  • Role-based access and least privilege. Staff see only the modules and departments their job needs, with separate add, view, edit and delete permissions.
  • Sign-in records. Who signed in, when and from which device.
  • Activity logging. The ability to record who accessed or changed what, where the hospital needs it.
  • Encryption in transit. The system served only over HTTPS, with secure session cookies.
  • Backups and recovery. Regular, tested backups stored securely.
  • Data export and deletion. The ability to retrieve or remove data when legally required.
  • Hosting choice. On-premise deployment where data must stay within the hospital.

Patients should be told what data is collected and why, in clear language. Where processing relies on consent, it must be free, specific and informed, and patients should be able to withdraw it. ABDM already follows a consent-first model for sharing records between facilities, which aligns well with these principles.

Breach response: have a plan before you need it

The DPDP Rules require data fiduciaries to inform the Data Protection Board and affected individuals of a personal data breach without delay, with a detailed report to the Board to follow within the prescribed time. A hospital should know in advance who decides, who investigates, who contacts the vendor, and who communicates with patients.

Vendor contracts

  • Define the vendor’s role as a processor and the data it may access.
  • Require security measures, breach notification to the hospital and cooperation.
  • Cover data location, backups, return and deletion at contract end.
  • Limit vendor staff access to production data to what support genuinely needs.

A practical checklist

AreaQuestion to ask
AccessDoes every user have a personal login and only the access their role needs?
VisibilityCan we see who signed in, and who accessed or changed sensitive records?
TransportIs the system HTTPS-only, including internal access?
BackupsAre backups automatic, encrypted and tested?
PatientsAre notices clear, and is consent recorded where required?
IncidentsDo we have a written breach response plan with named people?
VendorsDo contracts cover processing, security and breach notification?

How Swastik HMS helps

Swastik HMS gives every user a role and department with separate add, view, edit and delete permissions, records staff sign-ins and sign-outs with time, IP address and device through the attendance module, supports an optional request activity log, is served over HTTPS, and can be deployed on the hospital’s own server. Its ABDM integration shares records only within the patient’s consent, encrypted end to end. Read more on our security page.

Reviewing your hospital software against DPDP? Talk to our team about access control, hosting and data protection.

In Swastik HMS

Modules mentioned in this article

Keep reading

Related articles

All articles

See Swastik HMS with your hospital’s departments

Book a walkthrough focused on the modules you want to start with.