Healthcare Pharma & Life Sciences Other Industries
All Services Performance Marketing ChatGPT Ads India · NEW Social Media Marketing SEO & AEO / LLM YouTube Marketing LLM Optimization Brand & Growth Consulting AI Solutions Industries We Serve
Enterprise Hub · All Solutions + Services Growth Transformation AI Transformation Revenue Operations Fractional CGO Growth Operating System Executive Growth Advisory
Clinic Launch Programme (Hub) NABH Consulting India Healthcare Brand Launch Clinic SOP Creation Logo Design (Healthcare) Brand Book Creation Clinic Launch Marketing D2C Brand Launch Clinic Interior Design
Workforce Hub For Employers — post a requirement For Professionals — register Public Openings Training Academy AI Training Flagship
Hawk · CRM Intelligence (NEW) YODA · YouTube Intelligence Angryturtle · GBP Intelligence (NEW) Prism Pulse · Instagram Analytics (NEW) Beacon · Attribution Agency OS · Dashboards Phoenix · Clinic Revenue HealthPro 360 · PMS/HMS AI Patient Lifecycle Bots AI Lead Management System Smart Appointment System Healthcare CRM Patient Feedback System AI, Analytics & Automation Digital Transformation Calculators Free Digital Health Audit →
All 13 calculators → 🎯 Business Exploration Matrix (New) Dental Clinic Setup IVF Clinic + Lab Setup Multi-Specialty Hospital Setup Aesthetic / Cosmetology Clinic Dermatology Clinic Setup Generic Clinic Setup Physiotherapy Clinic Setup Diagnostic Centre Setup CAC Calculator CPQL Calculator Franchise ROI Calculator Revenue Leakage Calculator CRM ROI Calculator
All Events Workshop 1 · Jun 13 · AI in Clinical Practice Workshop 2 · Jun 27–28 · AI in Growth & Governance Hospital Ops Workshop · Jul 12 Pre-Summit Seminar · Aug 16 Grand Summit 2.0 · Oct 10–11 Bihar AI Summit · Recap AI Innovation Awards · Aug 22 Grand Summit 2.0 · Oct 2026 Aarambh 2026 Recap
Case Studies Insights & Blog Research Reports Calculators AI in Healthcare Digest
Our Story Leaders @ Ichelon · IN · US · AU Ichelon India · Gurgaon Ichelon Global · Dallas, TX Ichelon Australia · Sydney Speakers & Panelists Client Elevation Programme 🤝 Partner Connect 🇦🇪 ICG UAE Careers
Book a Growth Diagnostic
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
Trusted by 150+ healthcare & life-sciences brands
Johnson & Johnson
Mankind Pharma
Adonis Phyto
Narang Biotec
Medanta
Redcliffe Labs
Sitaram Bhartia
Metro Hospitals
Tulasi Hospital
Bloom IVF
Milann
Prime IVF
MedLinks
Handa
Bhardwaj
Eye Q
Johnson & Johnson
Mankind Pharma
Adonis Phyto
Narang Biotec
Medanta
Redcliffe Labs
Sitaram Bhartia
Metro Hospitals
Tulasi Hospital
Bloom IVF
Milann
Prime IVF
MedLinks
Handa
Bhardwaj
Eye Q
Johnson & Johnson
Mankind Pharma
Adonis Phyto
Narang Biotec
Medanta
Redcliffe Labs
Sitaram Bhartia
Metro Hospitals
Tulasi Hospital
Bloom IVF
Milann
Prime IVF
MedLinks
Handa
Bhardwaj
Eye Q
Article

DPDP Act 2023 for GBP Lead Capture — Consent, Purpose, and Erasure

The Digital Personal Data Protection Act 2023 is India's comprehensive personal data protection framework. It came into force in 2023 and its enforcement provisions are being implemented progressively

ICG Editorial · · · 10 min read
Book a free 30-min Diagnostic Chat on WhatsApp

No pitch. Written root-cause diagnosis. AI-powered, healthcare only.

Editorial standards: This article was reviewed by the ICG Editorial Review Board for NMC Section 6 compliance, Schedule J screening, DPDP privacy, and source verification before publication. · Our editorial process →
ICG · AI-Powered Healthcare-Only Marketing Agency
Why are your CPQL numbers stuck? Talk to the team behind 150+ healthcare brands.
30-minute free diagnostic. Written, not pitched. CPQL benchmarks for your specialty, on the call.

Direct answer

The Digital Personal Data Protection Act 2023 is India's comprehensive personal data protection framework. It came into force in 2023 and its enforcement provisions are being implemented progressively

TL;DR

The Digital Personal Data Protection Act 2023 is India's comprehensive personal data protection framework. It came into force in 2023 and its enforcement provisions are being implemented progressively

TL;DR

  • The Digital Personal Data Protection Act 2023 applies to all patient data collected through GBP-adjacent channels: appointment booking forms, contact forms, WhatsApp messages, and review request campaigns
  • The most common DPDP violation ICG finds in healthcare lead capture: using patient phone numbers collected for appointment reminders to send marketing WhatsApp messages without separate marketing consent
  • Purpose limitation is the core principle: data collected for one purpose (booking an appointment) cannot be used for a different purpose (marketing) without new, specific consent
  • Review response DPDP risk: publicly confirming that a reviewer was your patient, or referencing their clinical situation, is a public disclosure of health data — the most sensitive personal data category under DPDP
  • Erasure requests: patients can request deletion of their personal data; your GBP-adjacent data systems must have a documented erasure workflow

The Digital Personal Data Protection Act 2023 is India's comprehensive personal data protection framework. It came into force in 2023 and its enforcement provisions are being implemented progressively through 2025–2026.

For healthcare businesses, the DPDP Act is not an IT department concern. It reaches into every patient touchpoint — including the data flows connected to your Google Business Profile: appointment booking forms, WhatsApp review request messages, satisfaction survey campaigns, and CRM remarketing using patient data.

Most healthcare practices have not audited these data flows against DPDP requirements. This guide is that audit.


Section 1 — The DPDP principles relevant to GBP lead capture

1.1 Lawful purpose and consent

Under the DPDP Act, personal data (including patient name, phone number, email, and health-related information) can only be processed for a specific, clearly stated purpose. The patient must give free, informed, specific, and unambiguous consent for that purpose.

Critically: consent for one purpose does not extend to another.

If a patient provides their phone number to book an appointment, they have consented to data processing for appointment management. They have not consented to:

  • WhatsApp health tips
  • Marketing messages for new services
  • Promotional offers
  • Recall campaigns for future appointments

Each additional use requires separate, explicit consent at the time of collection.

1.2 Data minimisation

Collect only the data needed for the stated purpose. An appointment booking form that asks for the patient's name, phone number, and preferred appointment time has collected what is needed. The same form asking for date of birth, gender, employer, insurance details, and medical history is collecting data for which the appointment booking purpose does not provide justification.

1.3 Storage limitation

Personal data should not be retained longer than necessary for the stated purpose. For appointment data: retain for the duration of the patient relationship plus a reasonable period for follow-up (typically 12–24 months for non-clinical contact data). For clinical records: Indian law establishes separate retention requirements (typically 7 years minimum for clinical records). These are different retention schedules and should be managed separately.

1.4 Data subject rights

The DPDP Act grants patients several rights over their personal data:

  • Right to access: patients can ask what data you hold about them
  • Right to correction: patients can ask for inaccurate data to be corrected
  • Right to erasure: patients can ask for their data to be deleted (with exceptions for data where legal retention requirements apply)
  • Right to nominate: patients can nominate someone to exercise these rights on their behalf

Your GBP-adjacent data systems must have documented processes to respond to these requests.


Section 2 — The GBP lead capture data flows and their DPDP implications

Angryturtle Optimization Checklist with completion status per item, priority ordering and one-click assign-to-owner
Angryturtle · Optimization ChecklistFull-listing checklist — completion status per item, priority ordering, one-click assign-to-owner. What the ICG team follows weekly.

2.1 Appointment booking form (website / GBP linked)

Data collected: Name, phone, email, preferred department or doctor, preferred date.

Lawful basis: Contractual necessity (the patient is requesting a service).

What you can do with this data: Contact the patient to confirm, reschedule, or follow up on the appointment. Send appointment reminders.

What you cannot do without additional consent: Send marketing messages, add to a newsletter list, use for remarketing campaigns, pass to a CRM for promotional follow-up.

DPDP-compliant appointment form design:

  • Collect only: name, phone, preferred appointment details (department, date/time preference)
  • Include a clear purpose statement: "Your details will be used to confirm your appointment and send appointment reminders."
  • Separate checkbox for marketing consent (unchecked by default): "I would also like to receive health tips and updates from [clinic name] via WhatsApp."

2.2 Walk-in patient registration

Data collected: Name, phone, address, DOB, health information.

Lawful basis: Contractual necessity (clinical care) — for clinical data. For marketing use: explicit consent required separately.

Most common DPDP violation in healthcare: Using the registration desk's patient phone number database (collected for clinical purposes) to send WhatsApp marketing campaigns. These are two different purposes. The clinical data collection does not provide lawful basis for the marketing use.

Compliant approach: Separate consent collection at registration — two distinct tick-boxes:

  1. "I consent to the collection and processing of my personal and health information for my clinical care." (implied or explicit consent for clinical care)
  2. "I would like to receive health tips, appointment reminders for future care, and updates from [clinic name] via WhatsApp." (explicit, unambiguous, separate consent for marketing communications)

Only patients who check box 2 can be added to marketing WhatsApp lists.

2.3 WhatsApp review request campaigns

The data flow: Patient phone numbers (collected at registration for clinical purposes) → WhatsApp message asking for a Google review.

DPDP analysis: The phone number was collected for clinical appointment management. Using it for a review request campaign is a different purpose — customer feedback and marketing — that was not covered by the original consent.

Compliant approach:

  • Option A: Collect explicit marketing consent at registration (box 2 above) and only send review requests to consenting patients.
  • Option B: Send the review request as part of the appointment follow-up (same purpose — appointment management) with a natural, non-pressured ask: "We hope your visit today was comfortable. If you'd like to share your experience: [link]." This sits closer to the original appointment purpose than a scheduled marketing campaign.
  • Option C: In-person review request at checkout — a staff member verbally asks the patient if they would be willing to share a review and hands them a card with the QR code. No personal data processing involved.

2.4 CRM list upload for Google/Meta remarketing

The data flow: Patient phone numbers or emails from CRM → hashed list uploaded to Google Ads / Meta Ads for Custom Audience remarketing.

DPDP analysis: This is a data sharing action — patient data is being transmitted to a third-party data processor (Google or Meta). This requires:

  • Explicit patient consent for marketing communications (same as 2.3)
  • A Data Processing Agreement (DPA) with Google/Meta as a data processor
  • Purpose limitation: the remarketing must be for a purpose consistent with what patients consented to

Compliant approach: Only upload consented marketing contacts (patients who have explicitly opted into marketing communications). Document the consent basis. Ensure your Google Ads and Meta Ads accounts have data processing terms accepted (both platforms have GDPR/DPA frameworks that serve as the DPA mechanism).

2.5 Review responses — the public data disclosure risk

The data flow: Patient writes a Google review → clinic responds publicly.

DPDP analysis: Health data is the most sensitive personal data category under the DPDP Act. If a clinic's response to a review confirms that the reviewer was their patient, references their clinical situation, or includes any information from their medical encounter — the clinic has publicly disclosed sensitive personal data without consent.

The patient chose to write a public review. That does not give the clinic consent to publicly add clinical context that was not in the patient's own review.

Non-compliant review response: "Dear Mr. Kumar, thank you for your review. We're glad your knee replacement surgery went well and that you're recovering comfortably. We look forward to seeing you at your 3-month follow-up."

Why it fails: confirms the patient's identity (name), confirms the clinical procedure (knee replacement), and references the care relationship — all without explicit consent for this public disclosure.

Compliant review response (for the same situation): "Thank you for taking the time to share your experience. We're delighted to hear you felt well-supported throughout your care journey. We look forward to continuing to provide the same standard of care. — [Clinic name] team"


Section 3 — The erasure request workflow

A patient can request deletion of their personal data. Your response workflow must:

For non-clinical marketing data (WhatsApp contact list, email newsletter list): Delete within a reasonable timeframe (30 days is the standard). Confirm deletion in writing to the patient.

For appointment data: Delete contact information after the reasonable appointment follow-up retention period. If the patient requests deletion before this period ends, comply unless there is a specific clinical or legal reason not to.

For clinical records: Clinical records (diagnosis, treatment, prescriptions, test results) have mandatory minimum retention periods under Indian law — typically 7 years. An erasure request cannot override these legal retention requirements. Inform the patient that clinical records are retained for the legally required period but will be deleted after that period ends.

Documentation: Every erasure request and your response must be documented. Date of request, patient identity, scope of data requested for deletion, action taken, date of completion.


Section 4 — DPDP compliance checklist for GBP-adjacent data systems

<a href=Meta Catalyst IQ long-term comparison view charting Meta Ads performance across quarters with spend, CPQL and volume overlaid" width="1200" height="675" loading="lazy" decoding="async" style="width:100%;height:auto;display:block;">
Meta Catalyst IQ · Long-Term ComparisonQuarterly trend of spend vs CPQL vs volume — the view that separates cyclical dip from structural regression.
Data flow Consent collected? Purpose documented? Retention policy? Erasure workflow?
Appointment booking form [ ] [ ] [ ] [ ]
Walk-in registration [ ] [ ] [ ] [ ]
WhatsApp recall/review campaign [ ] [ ] [ ] [ ]
CRM list upload for remarketing [ ] [ ] [ ] [ ]
Review response workflow [ ] (N/A — no data collected) [ ] [ ] (N/A) [ ] (N/A)
Satisfaction survey [ ] [ ] [ ] [ ]

All five boxes for every data flow should be checked before any lead capture or patient communication campaign goes live.


Frequently asked questions

Q1: Does the DPDP Act apply to small clinics and solo practitioners? Yes — the DPDP Act applies to all entities processing personal data of Indian citizens, regardless of organisation size. There is no SME exemption for healthcare entities. The practical enforcement priority is likely to focus initially on larger organisations, but the legal obligation applies from the Act's commencement.

Q2: Can we send WhatsApp appointment reminders without separate consent? Appointment reminders fall within the purpose for which the patient provided their phone number at booking (appointment management). This is generally considered within the original consent scope. Marketing campaigns, health tips, recall campaigns, and review requests go beyond appointment management and require separate, explicit consent.

Q3: What is a Data Processing Agreement and do we need one with Google/Meta? A DPA is a formal agreement with a third party that processes data on your behalf, specifying the terms and obligations of that data processing. When you upload patient data to Google or Meta for remarketing, they become data processors for that data. Both Google Ads and Meta Ads have standard DPA terms within their platforms — you need to have accepted these terms and have them on record. ICG reviews DPA compliance as part of setting up CRM remarketing for healthcare clients.

Q4: What is the penalty for DPDP non-compliance? The DPDP Act provides for penalties up to ₹250 crore for significant violations (such as failure to implement data protection obligations or breach notification failures). Penalties are imposed by the Data Protection Board of India. The enforcement mechanism is still being established as of 2026, but the legal framework and penalties are in place.

Q5: Do patients have the right to know what data we hold about them? Yes. Under the DPDP Act's right to access, patients can request information about what personal data you hold, for what purpose, and to whom it has been disclosed. You must respond to access requests — the timeframe will be specified in the DPDP Rules when finalised, but 30 days is a reasonable operational target.

Q6: How does ICG handle DPDP compliance in GBP-adjacent data workflows? ICG implements consent collection at appointment booking (separate clinical and marketing consent), uses only consented contacts for review request and recall campaigns, ensures review responses are DPDP-compliant (no patient data disclosed), and documents consent bases for all CRM remarketing uploads. For hospital clients, ICG's technical team can audit the appointment booking form and CRM data flows against DPDP requirements as part of the engagement.


Sources:

  • DPDP Act 2023 — meity.gov.in (Digital Personal Data Protection Act)
  • NMC Ethics Code 2026 — nmc.org.in (patient confidentiality provisions)
  • Google Ads Data Processing Terms — ads.google.com
  • Meta Data Processing Terms — facebook.com/legal/terms/dataprocessing
  • ICG internal DPDP compliance audit data, 2026

Compliance note. This article provides general guidance on DPDP Act compliance for GBP-adjacent data flows. It does not constitute legal advice. The DPDP Rules (which will specify operational implementation requirements) were pending finalisation as of mid-2026 — check meity.gov.in for current rules before implementing any data management policy changes. Consult a legal professional for specific compliance guidance.


Internal links:

Ready to move?

Book a free 30-minute Brand & Growth Diagnostic.

It's a working session, not a sales pitch — you leave with a written root-cause analysis you can act on, whether or not you engage ICG.

Frequently asked

Questions readers ask
about this topic.

Yes — the DPDP Act applies to all entities processing personal data of Indian citizens, regardless of organisation size. There is no SME exemption for healthcare entities. The practical enforcement priority is likely to focus initially on larger organisations, but the legal obligation applies from the Act's commencement.

Appointment reminders fall within the purpose for which the patient provided their phone number at booking (appointment management). This is generally considered within the original consent scope. Marketing campaigns, health tips, recall campaigns, and review requests go beyond appointment management and require separate, explicit consent.

A DPA is a formal agreement with a third party that processes data on your behalf, specifying the terms and obligations of that data processing. When you upload patient data to Google or Meta for remarketing, they become data processors for that data. Both Google Ads and Meta Ads have standard DPA terms within their platforms — you need to have accepted these terms and have them on record. ICG reviews DPA compliance as part of setting up CRM remarketing for healthcare clients.

The DPDP Act provides for penalties up to ₹250 crore for significant violations (such as failure to implement data protection obligations or breach notification failures). Penalties are imposed by the Data Protection Board of India. The enforcement mechanism is still being established as of 2026, but the legal framework and penalties are in place.

Yes. Under the DPDP Act's right to access, patients can request information about what personal data you hold, for what purpose, and to whom it has been disclosed. You must respond to access requests — the timeframe will be specified in the DPDP Rules when finalised, but 30 days is a reasonable operational target.

ICG implements consent collection at appointment booking (separate clinical and marketing consent), uses only consented contacts for review request and recall campaigns, ensures review responses are DPDP-compliant (no patient data disclosed), and documents consent bases for all CRM remarketing uploads. For hospital clients, ICG's technical team can audit the appointment booking form and CRM data flows against DPDP requirements as part of the engagement.

Trusted by

Healthcare brands
that already run on ICG.

A representative slice of the 150+ healthcare brands ICG has delivered for across India. Most engagements remain under NDA.

Read full client case studies →

Client video stories

What ICG clients say · on video.

Dr. Samyak Dhawan
Co-Founder, Kayakalp Global · Kayakalp Global (D2C Derma)

"Scale up of organic channels and business consulting. ICG has absolute domain authority in their field."

Dr. Nishi Singh
Founder, Prime IVF · Prime IVF · Gurgaon

"Working with ICG transformed how we acquire IVF patients in Gurgaon. They understand the fertility journey from inquiry to consult..."

Dr. Prerna Taneja
Founder, Clinic Eximus · Clinic Eximus · Delhi

"What Ichelon accomplished — they got all my ideas and worked over 3-4 months to create an amazing, super-customised website."

See all client video testimonials →
Healthcare growth services · explore the stack

Need help operationalising this?

Every ICG service is healthcare-only, NMC + DPDP-aware, and built around the patient-research patterns that drive Indian healthcare growth in 2026.

Healthcare SEO Healthcare PPC Meta Ads Content Marketing Local SEO + GMB AI Overview (AIO) Healthcare Branding Website Development YouTube Marketing

Stop guessing.
Book a Diagnostic.

30 minutes. Free. With the AI-powered healthcare-only marketing agency 150+ brands already run on. No slides, no pitch, no hard close.

The ICG technology stack

Nine tools. One compounding system. HealthApex OS
Built in-house. Deployed in every engagement.

ICG's results are reproducible because they are built on proprietary infrastructure — not agency intuition or generic tools. These nine HealthApex OS platforms are what power every ICG engagement.

Healthcare CRM

Nexus CRM

Healthcare CRM & Lead Management

ICG's healthcare-specific CRM and lead management system. Specialty-configured funnel stages for IVF, dental, aesthetic, ortho, hospital OPD. 1-click CAPI + GCLID via Beacon. Hawk intelligence built in. DPDP-compliant by architecture. Deployed across 300+ healthcare centres.

  • Specialty-specific funnel stages, not generic SaaS pipeline
  • 1-click CAPI + GCLID via Beacon attribution
  • Telecaller leaderboard + adherence scoring native
  • DPDP Act 2023 compliant by architecture
Explore Nexus CRM →
Business Layer

Hawk

CRM Intelligence & Lead-Ops MIS

Sits as the business intelligence layer above your CRM — Nexus, Salesforce, LeadSquared, HubSpot, Zoho, or any custom CRM. Shows where leads are leaking, which effort is wasted, and which good leads were quietly downgraded by automation — not by a human decision.

  • Sits above your existing LMS — no replacement
  • 83% of effort goes to dead leads — surfaced Day 1
  • ~75% qualified-lead downgrades by automation
  • Free Lead-Leak Audit in 48 hours
Explore Hawk + free audit →
Attribution Core

Beacon

Attribution Engine & CAPI Middleware

Sits at the centre of every ICG attribution architecture. CAPI middleware connecting Meta Ads, Google Ads, WhatsApp and IVR to your CRM. Lifts Event Match Quality from 2.5 to 6+, reducing CPM 30–40% from the same budget.

  • Server-side CAPI — bypasses iOS privacy changes
  • EMQ 2.5 → 6+ across portfolio
  • 30–40% CPM reduction from EMQ lift alone
  • Multi-touch: ad → consultation → revenue
Explore Beacon →
Practice Management

HealthPro 360

PMS with built-in revenue intelligence layer

The only PMS that tracks cross-sell and up-sell opportunities within your existing patient base. 12 modules covering OPD, IPD, Pharmacy, Labs, Billing, Inventory, Patient Portal, Smart Scheduling, RBAC, AES-256 encrypted storage.

  • Only PMS with built-in Revenue Intelligence
  • Cross-sell signal tracking within existing patients
  • 12 modules: OPD, IPD, Pharmacy, Labs, Billing+
  • Audit trails + RBAC + AES-256 encryption
Explore HealthPro 360 →
Revenue Layer

Phoenix

Revenue intelligence built over your existing PMS

If you already have a PMS — Akhil Systems, Practo, or any other — Phoenix builds the business intelligence layer on top of it without replacement. Currently live across 46 centres for a national chain.

  • Works over your existing PMS — no migration
  • Daily action queue: Prevent Loss / Maintain / Grow
  • Catches unbilled services, collection gaps, lapsing patients
  • CPQL variance ₹620–₹3,800 → ₹680–₹1,420
Explore Phoenix →
YouTube Intelligence

YODA

YouTube analytics that measures patients, not views

The only YouTube intelligence platform built for healthcare business outcomes. Connects video performance to actual consultation bookings — not views, not subscribers. Patient testimonial videos generate 6.9× more consultations per view than condition explainers.

  • Consultation attribution per video — not views
  • Demand-gap: what patients search that your channel misses
  • 50+ doctor channels tracked across India
  • AIO readiness scoring: which videos AI tools cite
Explore YODA →
Governance & Transparency

Agency OS

Full transparency. Instant diagnosis. Zero surprises.

ICG's centralised governance platform — every client sees everything in real time, and ICG's team sees every problem the moment it surfaces. 30+ real-time alert systems fire the moment a metric drifts outside its performance envelope.

  • GSC, GA4, Google Ads, Meta Ads, IVR — one live view
  • 30+ real-time alert systems per account
  • CPQL drift alert at >15% week-on-week change
  • Client login: full transparency on your account
Explore Agency OS →
AEO & LLM Intelligence

AIO Intel

AI Overview + LLM citation tracking, healthcare-tuned

Knows the moment ChatGPT, Perplexity, Google AI Overviews and Gemini cite your brand in patient answers — and which content drove the citation. Bot-aware dashboard with GA4-registered custom dims (AIO source, AIO referrer) and IndexNow + GSC API integration.

  • Live tracking across ChatGPT / Perplexity / Google AIO / Gemini
  • Bot-aware: knows human vs scraper traffic
  • Custom GA4 dims register AIO source + referrer
  • IndexNow + GSC API: content surfaced to LLMs within hours
View AIO Intel dashboard →
Competitor Intelligence

Prism Spy

Every Meta + Google ad your competitors run, watched daily

Tracks 75+ Indian healthcare brands, 2,150+ active ads, ₹50Cr+ aggregate ad spend visibility per month. Surfaces what's working, what's been killed, what offers are emerging. Powers every ICG Meta Ads brief, Performance Marketing diagnostic, and IVF / derm / dental specialty campaign with real competitive intelligence.

  • 75+ brands tracked across 30+ healthcare specialties
  • 2,150+ active ads · daily refresh
  • Activity Feed: every spend / hook / pause logged
  • Offers Intelligence: 250+ offers in market tracked
Explore Prism Spy →
GBP Intelligence Platform

Angryturtle

Every Google Business Profile scored, tracked, protected, and grown from one command centre

ICG's proprietary Google Business Profile intelligence platform. Scores every listing across 7 dimensions, tracks rank on a live geo-grid across your actual service area, audits NAP + citations, monitors 531 suspension-risk factors continuously, and drafts Google Posts on cadence. Currently managing 143 healthcare listings with 0 suspensions and 4.76★ portfolio average across 28,137 reviews.

  • 143 listings under management · 0 suspensions · 4.76★
  • 7-dimension Health Score + 5-factor Rank OS per listing
  • Geo-grid rank tracking + NAP + Citation audit + Profile Shield
  • NMC + NABH + ART Act + DPDP compliance built into every content + review workflow
Explore Angryturtle →

Every ICG engagement runs on some combination of these ten HealthApex OS tools. The diagnostic determines which combination is right for your practice.

Explore HealthApex OS → See the full stack live on your account — free 30-min audit
The team behind your account

Every diagnostic is led by a founder.
You'll know their names before the engagement begins.

ICG was built by three IIT BHU engineers who entered healthcare marketing with a specific intent: to build the tools that didn't exist and run the campaigns that most agencies couldn't. When you book a diagnostic, Rohit or Abhash leads it personally. Not an account manager. Not a senior executive. The people who built what you're evaluating.

The ICG team — 60+ healthcare marketing specialists at Gurgaon HQ

60+ specialists.
One growth engine.

Performance marketers, analysts, AI engineers, content strategists, and operations specialists — all healthcare-only. Headquartered in Gurgaon since 2018.

Rohit Gupta — Leader, ICG

Rohit Gupta

Business & Growth Lead & Director

IIT BHU · IIM Rohtak

Rohit's first question in every diagnostic: "When you ask your agency why patients aren't booking — what do they say?" He says the answer tells him more than any dashboard.

Full profile →
Abhash Kumar — Leader, ICG

Abhash Kumar

Strategy & Analytics Lead & Director

IIT BHU · IIM Bangalore

Abhash built Beacon because most agencies couldn't answer one question: "Which of my campaigns generated that consultation?" He decided the problem was solvable in code. It was.

Full profile →
Deep Das — Leader, ICG

Deep Das

Technology & AI Lead & Director

IIT BHU

Deep built the 4-Bot patient lifecycle system after watching a client lose 60+ qualified leads in one week to a 6-hour WhatsApp response window. He decided the problem was solvable in code. It was.

Full profile →
Chat with a Co-Founder
Chat with a Co-Founder