Hospital software holds some of the most sensitive personal data there is. India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 make protecting it a legal obligation, not just good practice. This guide explains what that means for hospital software and the controls every HMS should support.
This article is general information, not legal advice. Consult your legal adviser about your hospital’s specific obligations.
The DPDP Act and Rules in brief
The Digital Personal Data Protection Act, 2023 governs how organisations process digital personal data in India. The DPDP Rules, 2025, notified by the Ministry of Electronics and Information Technology in November 2025, set out how it works in practice, including notices, consent, breach reporting and the Data Protection Board, with obligations coming into force in phases. Hospitals, public and private, that process patient data digitally are covered.
Hospitals as data fiduciaries
Under the Act, the organisation that decides why and how personal data is processed is a data fiduciary. For patient records, that is usually the hospital. The software vendor that processes data on the hospital’s behalf acts as a data processor. The hospital remains responsible, so it needs software, contracts and processes that support its obligations.
Controls every hospital management system should support
- Unique logins. Every staff member has their own account; shared counter logins make accountability impossible.
- Role-based access and least privilege. Staff see only the modules and departments their job needs, with separate add, view, edit and delete permissions.
- Sign-in records. Who signed in, when and from which device.
- Activity logging. The ability to record who accessed or changed what, where the hospital needs it.
- Encryption in transit. The system served only over HTTPS, with secure session cookies.
- Backups and recovery. Regular, tested backups stored securely.
- Data export and deletion. The ability to retrieve or remove data when legally required.
- Hosting choice. On-premise deployment where data must stay within the hospital.
Notices and consent
Patients should be told what data is collected and why, in clear language. Where processing relies on consent, it must be free, specific and informed, and patients should be able to withdraw it. ABDM already follows a consent-first model for sharing records between facilities, which aligns well with these principles.
Breach response: have a plan before you need it
The DPDP Rules require data fiduciaries to inform the Data Protection Board and affected individuals of a personal data breach without delay, with a detailed report to the Board to follow within the prescribed time. A hospital should know in advance who decides, who investigates, who contacts the vendor, and who communicates with patients.
Vendor contracts
- Define the vendor’s role as a processor and the data it may access.
- Require security measures, breach notification to the hospital and cooperation.
- Cover data location, backups, return and deletion at contract end.
- Limit vendor staff access to production data to what support genuinely needs.
A practical checklist
| Area | Question to ask |
|---|---|
| Access | Does every user have a personal login and only the access their role needs? |
| Visibility | Can we see who signed in, and who accessed or changed sensitive records? |
| Transport | Is the system HTTPS-only, including internal access? |
| Backups | Are backups automatic, encrypted and tested? |
| Patients | Are notices clear, and is consent recorded where required? |
| Incidents | Do we have a written breach response plan with named people? |
| Vendors | Do contracts cover processing, security and breach notification? |
How Swastik HMS helps
Swastik HMS gives every user a role and department with separate add, view, edit and delete permissions, records staff sign-ins and sign-outs with time, IP address and device through the attendance module, supports an optional request activity log, is served over HTTPS, and can be deployed on the hospital’s own server. Its ABDM integration shares records only within the patient’s consent, encrypted end to end. Read more on our security page.
Reviewing your hospital software against DPDP? Talk to our team about access control, hosting and data protection.