If your clinic keeps patient details on a computer, a phone or in the cloud, India's data protection law now applies to you. The DPDP Act (Digital Personal Data Protection Act, 2023) has its operating rules in place, and the deadline is closer than it feels. This guide explains what matters for a small practice, in plain language, without legal jargon.

This is a general guide, not legal advice. For specific questions, especially about exemptions, speak to a lawyer.

What has actually changed

The Act was passed in August 2023. The government notified the DPDP Rules, 2025 on 14 November 2025, and set an 18-month phased timeline for organisations to comply. That puts full obligations at around May 2027, with some parts, such as the framework for consent managers, starting sooner.

Patient records are personal data, and health details are among the most sensitive kind. A clinic that decides why and how they are used is what the law calls a Data Fiduciary. The patient is the Data Principal.

What it means for a small clinic

You do not need a compliance department. You need a few clear habits:

  1. Tell patients what you collect and why. The Rules require a separate, clear consent notice explaining the specific purpose.
  2. Collect only what you need. A phone number for follow-up makes sense. An unrelated ID document usually does not.
  3. Protect what you hold. The law expects reasonable security safeguards.
  4. Report breaches. If patient data is exposed, affected people must be told promptly, in plain language, with contact details for help.
  5. Respond to patients' requests. Patients can ask to see, correct or, in some cases, erase their data. Requests must be answered within 90 days.
  6. Publish a contact for data queries. This can be you or a named person on your team.

What the penalties look like

The Act sets ceilings, not fixed amounts:

Failure Maximum penalty
Not keeping reasonable security safeguards Up to ₹250 crore
Not reporting a breach, or breaching children's data duties Up to ₹200 crore
Other violations Up to ₹50 crore

Real penalties depend on the seriousness and circumstances, and a small clinic is unlikely to see the top figures. The important point is that security safeguards carry the heaviest weight.

A practical checklist for your clinic

Use this as a starting point and tick items off over the next few months.

Know your data

  • List where patient data lives: your EMR, phones, WhatsApp chats, paper files, email attachments, lab-report folders.
  • Note who can see each one.

Collect with clarity

  • Add a short consent notice at registration, in the patient's language, explaining what you collect and why.
  • Remove fields you never use.

Control access

  • Give each staff member their own login. Never share one password at reception.
  • Limit what each role can see. A receptionist rarely needs full clinical notes.
  • Remove access the day someone leaves.

Secure it

  • Use screen locks and strong passwords on every device.
  • Keep backups, and check they can be restored.
  • Avoid sending records over personal email or unprotected chat groups.
  • Keep software updated.

Plan for a bad day

  • Decide in advance who does what if a phone is lost or an account is hacked.
  • Keep a simple written log of any incident.

Handle requests and deletion

  • Know how to find, correct and export one patient's data.
  • Decide how long you keep records, and do not keep data indefinitely without a reason.

Where WhatsApp and photos fit in

Many clinics run on WhatsApp: prescriptions sent to patients, reports received from them, photos of wounds. That is convenient, but it spreads patient data across personal phones. Two habits help:

  • Send prescriptions from a clinic account or system, not from a staff member's personal phone where possible. See how to create a digital prescription.
  • Do not leave reports and images only in chat history. Store them in the patient's record so you can find, correct or remove them when asked.

Working with vendors

Your software and cloud providers process patient data on your behalf, but you remain responsible for it. Ask any vendor:

  1. Who can access our patients' data, and how is that logged?
  2. Where is the data stored, and how is it backed up?
  3. How do you handle a security incident, and how quickly will you tell us?
  4. Can we export or delete a patient's data on request?
  5. What happens to our data if we stop using the service?

The same questions belong on your EMR checklist. An EMR system that gives each user a separate login and keeps a clear record in one place makes several items above easier. It does not make you compliant on its own.

AI scribes and recorded audio

If you use an AI medical scribe, consultation audio is personal data too. Tell patients when recording is on, use it only for documentation, and ask the vendor how long audio is kept and who can access it.

Children's data

The Act has stronger duties for data about children, including a role for a parent or guardian. Paediatric and family practices should read this part carefully with their lawyer.

A simple 90-day plan

  • Days 1 to 30: map where data lives, give every staff member their own login, and start a consent notice at registration.
  • Days 31 to 60: clean up shared chats and personal-phone storage, check backups and write a one-page incident plan.
  • Days 61 to 90: review vendors with the five questions above, publish a contact for data queries and decide your retention approach.

What a simple consent notice can say

The Rules ask for a clear, separate notice that explains the specific purpose. It does not need to be long. A registration notice might say:

We collect your name, age, phone number and health details to treat you, keep your records, send prescriptions and remind you about follow-ups. Only our clinic team can see them. You can ask to see, correct or delete your data by contacting [name and number]. This notice is available in [language].

Have your lawyer check the wording, put it where patients will actually see it, and keep a record that it was shown.

What to do if something goes wrong

A lost phone with patient chats, a hacked email account or a report sent to the wrong number can all count as a breach. Act in this order:

  1. Contain it. Change passwords, sign out lost devices and stop the sharing.
  2. Write down what happened. Note what data was involved, how many patients and when you found out.
  3. Tell the people affected, in plain language: what happened, what it could mean for them, what you have done and who to contact.
  4. Ask your lawyer about your duty to inform the Data Protection Board, and follow their advice on timing.
  5. Fix the cause, so the same gap is closed.

Having this page ready before an incident makes the real thing far less stressful.

Common mistakes to avoid

  • Sharing one login across the front desk, so nobody can tell who opened what.
  • Keeping old patient data forever in chat apps and downloads folders.
  • Assuming the vendor handles everything. You remain responsible for your patients' data.
  • Treating consent as a one-time signature. Patients can withdraw it, and your process should allow for that.

The bottom line

The DPDP Act is not a reason to panic, but it is a reason to stop treating patient data casually. Clear consent, separate logins, sensible storage and a plan for breaches cover most of what a small clinic needs. Starting now, well before 2027, turns a legal deadline into a normal part of running a trusted practice.

For how a clinic workspace can keep records in one place, see clinic management software and our note on maintaining patient history digitally. You can also read Medabha's data policy.

Want to work through this as a team? Use our free DPDP Act checklist for clinics.

Frequently asked questions

Does the DPDP Act apply to a small clinic?

The Act applies to anyone who decides why and how digital personal data is processed, and a clinic that keeps patient names, phone numbers and records on a computer or phone does exactly that. Ask a lawyer about any exemption you think might apply, rather than assuming one does.

When do clinics have to comply?

The DPDP Rules were notified on 14 November 2025 with an 18-month phased timeline, so full obligations arrive around May 2027. Some parts start earlier, so it is safer to begin now.

What are the penalties?

The Act allows penalties of up to ₹250 crore for failing to keep reasonable security safeguards and up to ₹200 crore for not reporting a breach. Actual penalties depend on the case, but the ceilings show how seriously the law treats safeguards.

Do I need a Data Protection Officer?

The Rules require every organisation to publish contact details for data queries, which can be a designated person. Stricter duties, including a Data Protection Officer, apply to organisations designated as Significant Data Fiduciaries, which is unlikely for a small clinic.

Does using clinic software make me compliant?

No. Software can make good practice easier, through access controls and audit trails, but compliance is about how the clinic collects, uses, protects and deletes data.

See Medabha in your own clinic

AI medical scribe, WhatsApp prescriptions, specialty charts and a built-in clinic website. Book a 15-minute walkthrough.

Book a demo

This article is general information about clinic software and documentation workflows, not medical, legal or regulatory advice. Check current requirements with the relevant authority before making compliance decisions.