Healthcare Pharma & Life Sciences Other Industries
All Services Performance Marketing ChatGPT Ads India · NEW Social Media Marketing SEO & AEO / LLM YouTube Marketing LLM Optimization Brand & Growth Consulting AI Solutions Industries We Serve
Enterprise Hub · All Solutions + Services Growth Transformation AI Transformation Revenue Operations Fractional CGO Growth Operating System Executive Growth Advisory
Clinic Launch Programme (Hub) NABH Consulting India Healthcare Brand Launch Clinic SOP Creation Logo Design (Healthcare) Brand Book Creation Clinic Launch Marketing D2C Brand Launch Clinic Interior Design
Workforce Hub For Employers — post a requirement For Professionals — register Public Openings Training Academy AI Training Flagship
Hawk · CRM Intelligence (NEW) YODA · YouTube Intelligence Angryturtle · GBP Intelligence (NEW) Prism Pulse · Instagram Analytics (NEW) Beacon · Attribution Agency OS · Dashboards Phoenix · Clinic Revenue HealthPro 360 · PMS/HMS AI Patient Lifecycle Bots AI Lead Management System Smart Appointment System Healthcare CRM Patient Feedback System AI, Analytics & Automation Digital Transformation Calculators Free Digital Health Audit →
All 13 calculators → 🎯 Business Exploration Matrix (New) Dental Clinic Setup IVF Clinic + Lab Setup Multi-Specialty Hospital Setup Aesthetic / Cosmetology Clinic Dermatology Clinic Setup Generic Clinic Setup Physiotherapy Clinic Setup Diagnostic Centre Setup CAC Calculator CPQL Calculator Franchise ROI Calculator Revenue Leakage Calculator CRM ROI Calculator
All Events Workshop 1 · Jun 13 · AI in Clinical Practice Workshop 2 · Jun 27–28 · AI in Growth & Governance Hospital Ops Workshop · Jul 12 Pre-Summit Seminar · Aug 16 Grand Summit 2.0 · Oct 10–11 Bihar AI Summit · Recap AI Innovation Awards · Aug 22 Grand Summit 2.0 · Oct 2026 Aarambh 2026 Recap
Case Studies Insights & Blog Research Reports Calculators AI in Healthcare Digest
Our Story Leaders @ Ichelon · IN · US · AU Ichelon India · Gurgaon Ichelon Global · Dallas, TX Ichelon Australia · Sydney Speakers & Panelists Client Elevation Programme 🤝 Partner Connect 🇦🇪 ICG UAE Careers
Book a Growth Diagnostic
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
Trusted by 150+ healthcare & life-sciences brands
Johnson & Johnson
Mankind Pharma
Adonis Phyto
Narang Biotec
Medanta
Redcliffe Labs
Sitaram Bhartia
Metro Hospitals
Tulasi Hospital
Bloom IVF
Milann
Prime IVF
MedLinks
Handa
Bhardwaj
Eye Q
Johnson & Johnson
Mankind Pharma
Adonis Phyto
Narang Biotec
Medanta
Redcliffe Labs
Sitaram Bhartia
Metro Hospitals
Tulasi Hospital
Bloom IVF
Milann
Prime IVF
MedLinks
Handa
Bhardwaj
Eye Q
Johnson & Johnson
Mankind Pharma
Adonis Phyto
Narang Biotec
Medanta
Redcliffe Labs
Sitaram Bhartia
Metro Hospitals
Tulasi Hospital
Bloom IVF
Milann
Prime IVF
MedLinks
Handa
Bhardwaj
Eye Q
Article

DPDP Act 2023 for Healthcare — Complete Compliance Checklist 2026

India's healthcare sector generates some of the most sensitive personal data in existence — diagnoses, prescriptions, lab results, surgical histories, mental health records, genetic information. For y

ICG Editorial · · · 11 min read
Book a free 30-min Diagnostic Chat on WhatsApp

No pitch. Written root-cause diagnosis. AI-powered, healthcare only.

Editorial standards: This article was reviewed by the ICG Editorial Review Board for NMC Section 6 compliance, Schedule J screening, DPDP privacy, and source verification before publication. · Our editorial process →
ICG · AI-Powered Healthcare-Only Marketing Agency
Why are your CPQL numbers stuck? Talk to the team behind 150+ healthcare brands.
30-minute free diagnostic. Written, not pitched. CPQL benchmarks for your specialty, on the call.

Direct answer

India's healthcare sector generates some of the most sensitive personal data in existence — diagnoses, prescriptions, lab results, surgical histories, mental health records, genetic information. For y

TL;DR

India's healthcare sector generates some of the most sensitive personal data in existence — diagnoses, prescriptions, lab results, surgical histories, mental health records, genetic information. For y

TL;DR

  • DPDP Act 2023 (Digital Personal Data Protection Act) is India's first comprehensive data protection law — healthcare data is "sensitive personal data" under the Act
  • Core obligations: explicit consent before collecting patient data, purpose limitation, right to erasure, data breach notification (72-hour rule), DPO appointment for large healthcare entities
  • Penalty: up to ₹250 crore per violation for significant data fiduciaries; ₹50–₹200 crore for smaller entities
  • Healthcare-specific intersection: patient records, CRM systems, telemedicine platforms, lab data, and marketing databases all fall under the Act
  • ABDM's Consent Manager framework directly supports DPDP Act compliance — hospitals integrating ABDM are ahead

India's healthcare sector generates some of the most sensitive personal data in existence — diagnoses, prescriptions, lab results, surgical histories, mental health records, genetic information. For years, this data was managed under a patchwork of sector-specific guidelines with limited patient rights and no unified enforcement.

The Digital Personal Data Protection Act 2023 (DPDP Act) changed this. Healthcare organisations are now "Data Fiduciaries" with defined obligations to their patients — "Data Principals" — with real penalties for non-compliance.


What the DPDP Act 2023 means for healthcare

The DPDP Act (full text available at meity.gov.in) received Presidential assent on August 11, 2023. Enforcement rules are being operationalised in phases through 2024–2026, with the Data Protection Board of India (DPBI) established as the enforcement authority.

Why healthcare is uniquely affected:

Healthcare data is processed at every touchpoint — OPD registration, lab testing, insurance claim, CRM follow-up, telemedicine consultation, hospital marketing database, and research datasets. The breadth of data collection, the sensitivity of the information, and the power asymmetry between provider and patient make healthcare one of the highest-risk sectors for DPDP non-compliance.

Who in healthcare must comply:

Entity type DPDP obligations
Hospitals and clinics Patient consent, records management, breach notification
Diagnostic labs Sample data, report data, patient identity data
Telemedicine platforms All consultation data, prescriptions, video sessions
Healthcare CRM/marketing databases Lead data, patient communication databases, re-engagement programmes
Pharma companies HCP data, patient registry data, clinical trial data
Health insurance companies Claims data, medical history, treatment records
Healthcare app developers In-app health data, wearable data, symptom logs

Key definitions under DPDP Act

Data Principal: The patient — the individual whose personal data is being processed.

Data Fiduciary: The healthcare organisation (hospital, clinic, lab, pharma company) that determines the purpose and means of processing personal data.

Significant Data Fiduciary (SDF): The Central Government may designate certain large healthcare organisations as SDFs based on volume of data processed, risk, national security implications. SDFs face additional obligations (DPO appointment, data protection impact assessments, periodic audits).

Consent Manager: An entity registered with DPBI through which a Data Principal can give, manage, review, and withdraw consents. ABDM's Consent Manager is a government-approved Consent Manager for health data.


The 5 core DPDP obligations for healthcare organisations

Obligation 1: Lawful and consensual processing

The Act requires that personal data — including health data — is processed only on a lawful basis. For most patient data in healthcare, the basis is consent. The Act specifies that consent must be:

  • Free (not a condition of service where withholding would deny care — healthcare has a specific nuance here)
  • Specific (for the stated purpose — not blanket)
  • Informed (the patient must know what data, for what purpose)
  • Unambiguous (clear affirmative action — pre-ticked boxes don't count)
  • Withdrawable (the patient can withdraw consent; withdrawal does not affect data processing before withdrawal)

Healthcare-specific nuance: For clinical care data (necessary to provide the requested treatment), the basis is deemed consent under Section 7 — the patient is seeking medical help, so processing data necessary for that help is lawful. But for secondary use — marketing communications, research, sharing with third parties, insurance pre-authorisation beyond the immediate claim — explicit consent is required.

Practical implications:

  • Your OPD registration form must separate "clinical care" consent from "marketing communication" consent
  • Telemedicine platforms must present DPDP-compliant consent screens
  • Insurance pre-authorisation sharing requires documented consent (going beyond what clinical necessity covers)
  • Hospital CRM / remarketing database requires explicit opt-in, not assumed inclusion from registration

Obligation 2: Purpose limitation

Data collected for clinical care cannot be used for marketing. Data collected for Treatment A cannot be used for unrelated Treatment B research without additional consent. Data shared with your insurance partner cannot be shared by them with a pharmaceutical company.

Practical implications:

  • Your HIS, CRM, and analytics systems must have purpose-tagging for data fields
  • Data collected at registration for appointment purposes cannot be used to send promotional messages about new services without separate consent
  • If you use a third-party marketing analytics platform (Google Analytics, Meta Pixel on your website), patient data passing through these platforms requires disclosure and consent

Obligation 3: Right to erasure (Right to be forgotten)

Data Principals have the right to request erasure of their personal data. For healthcare, this intersects with mandatory clinical record retention requirements (typically 7 years post-treatment under Indian law).

How to handle the intersection:

  • Clinical records: Retain as legally required; inform the patient that erasure of clinical records cannot be honoured during the mandatory retention period
  • Marketing data, CRM profiles, communication histories: Erasure must be honoured within a reasonable timeframe (the Act does not specify days; best practice is 30 days)
  • Consent records: Retain even after erasure of personal data (you need to prove consent existed)

Practical implication: Your CRM must have a documented erasure process. "Delete from CRM within 30 days of request" must be an operational SOP, not just a policy.

Obligation 4: Data breach notification — the 72-hour rule

If a security breach occurs — unauthorised access to patient records, ransomware attack on your HIS, accidental email of patient data — you must notify:

  1. The Data Protection Board of India (DPBI): As soon as possible after becoming aware; the Act doesn't specify hours but international best practice and draft rules suggest 72 hours
  2. Each affected Data Principal (patient): In a form and language they can understand, explaining what happened, what data was affected, and what steps you are taking

Healthcare-specific breach scenarios:

  • HIS ransomware attack (increasingly common — healthcare is the most targeted sector for ransomware globally)
  • Accidental sharing of patient records via email or WhatsApp (common in smaller hospitals)
  • Lab report SMS sent to wrong number
  • Telemedicine session recording shared without patient consent
  • Staff accessing patient records without clinical need (snooping)

What a breach response SOP must cover:

  1. Incident detection and classification (breach vs near-miss)
  2. Immediate containment actions
  3. DPBI notification (content: nature of breach, categories of data, approximate data subjects affected, steps taken)
  4. Patient notification (content: what happened, what data, what you are doing)
  5. CAPA documentation

Obligation 5: Data Protection Officer (DPO) appointment

Significant Data Fiduciaries (large hospitals, hospital chains, health insurance companies, large telemedicine platforms) designated by the Central Government must appoint a Data Protection Officer. DPO responsibilities:

  • Point of contact for Data Principals exercising their rights
  • Point of contact for the DPBI
  • Internal monitoring of DPDP compliance
  • Conducting or overseeing data protection impact assessments

For hospitals not yet designated as SDFs: appointing a DPO (or at minimum a "data protection focal point") is still best practice — and likely to become mandatory as the designation framework evolves.


20-point DPDP compliance checklist for hospitals

Hospital DPDP Compliance Checklist

  • OPD registration form updated — clinical care consent and marketing consent separated
  • Website privacy policy updated for DPDP Act 2023
  • Cookie consent mechanism on hospital website (for tracking pixels/analytics)
  • Telemedicine platform consent screens updated
  • HIS vendor DPDP compliance letter obtained
  • CRM / patient database DPDP compliance verified with vendor
  • Data inventory completed (what data, where stored, who has access, retention period)
  • Purpose-tagging implemented in CRM and HIS
  • Data breach response SOP documented and tested
  • DPBI notification template prepared
  • Patient breach notification template prepared
  • Erasure request process documented (30-day SLA)
  • Consent withdrawal process documented
  • Staff access logs for HIS and CRM reviewed quarterly
  • Role-based access control (RBAC) implemented in HIS
  • Third-party vendor data processing agreements (DPA) signed
  • Insurance TPA data sharing agreements updated
  • Research data anonymisation process documented
  • DPO / data protection focal point appointed and contact published
  • Annual DPDP review scheduled (data inventory refresh, policy updates)

15-point DPDP compliance checklist for clinics

Clinic DPDP Compliance Checklist

  • Registration form updated — clinical and marketing consent separated
  • WhatsApp broadcast list reviewed — confirm patients have opted in
  • Patient data not shared in group chats (staff WhatsApp groups with patient names)
  • SMS marketing database — verify opt-in status for all contacts
  • Clinic software (HIS/CMS) vendor DPDP compliance confirmed
  • Paper records locked in secure cabinets; access log maintained
  • Digital records password-protected with role-based access
  • Lab report email process — verify correct patient email before sending
  • Erasure request process in place (respond within 30 days)
  • Patient on request — can you provide all data you hold on them? Process documented.
  • Privacy notice at reception desk (physical + digital)
  • Staff briefed on not sharing patient names/details on personal devices
  • If using Google Forms / Survey Monkey for patient feedback — DPDP implications reviewed
  • Any referral partner data sharing — agreement updated
  • Annual review scheduled

DPDP Act and ABDM intersection

The ABDM Consent Manager is a DPBI-aligned mechanism for health data consent. Hospitals integrated with ABDM benefit from:

  • Patient consent managed through the ABHA app — DPDP-compliant consent artefacts
  • Purpose-limited data sharing built into the Consent Manager protocol
  • Audit trail of consent grants and withdrawals

Hospitals integrating ABDM are simultaneously building DPDP compliance infrastructure for health record sharing. See our ABDM integration guide.


Penalties under DPDP Act 2023

The Act's penalty structure under Section 33:

Violation Maximum penalty
Failure to implement adequate security measures ₹250 crore
Failure to notify breach (DPBI + Data Principals) ₹200 crore
Breach of children's data obligations ₹200 crore
Failure to comply with Data Principal's rights requests ₹50 crore
Failure to register Consent Manager (for Consent Managers) ₹500 crore
General violations of the Act ₹50 crore

"Healthcare organisations that treat DPDP compliance as a legal checkbox will miss the strategic opportunity. Patient data trust is becoming a competitive differentiator. A hospital that can demonstrably tell patients 'your data is protected, here is how you control it, here is your ABHA-linked record' will outcompete hospitals that continue to process patient data opaquely. DPDP compliance isn't just about avoiding ₹250 crore penalties — it's about building the patient relationship of the next decade."Deep Bhandari, Co-Founder — Product & AI Strategy, ICG


Children's data — special protection

The DPDP Act provides heightened protection for personal data of minors (under 18):

  • Processing children's personal data requires consent of the parent or guardian (not the child)
  • No targeted advertising or profiling of children is permitted
  • For paediatric hospitals and clinics, this means: registration data, lab data, and CRM contact data for minor patients must be linked to parent/guardian consent

Practical implication: Your registration form must capture guardian details for minor patients, with explicit consent. Your CRM must tag minor patient records and exclude them from standard marketing communications.


Case snapshot

A 12-clinic ophthalmology chain in South India with 85,000 patient records in their CRM engaged ICG to conduct a DPDP readiness review. Findings: 62% of CRM contacts had no documented opt-in for marketing communications; the HIS vendor had no DPDP compliance statement; breach response SOP was absent; lab report emails were sent from a shared staff inbox with no access log. ICG's 90-day programme: consent re-capture campaign (28,000 valid opt-ins retained), HIS vendor DPA signed, breach SOP drafted and tabletop-tested, role-based HIS access implemented. DPDP-ready status achieved within 90 days. (ICG healthcare technology engagement, 2026.)


FAQ

Q1: Does DPDP Act apply to small clinics? Yes — the Act does not have a small-entity exemption for healthcare. Any entity processing personal health data of Indian citizens is a Data Fiduciary with obligations. The penalty thresholds mean enforcement focus will likely begin with larger entities, but compliance obligations exist regardless of size.

Q2: What consent is required for patient data processing under DPDP? For clinical care: deemed consent (processing necessary for the requested treatment). For marketing, research, insurance pre-authorisation beyond clinical necessity: explicit, informed, purpose-specific consent. The OPD registration form must separate these purposes.

Q3: Do hospitals need to appoint a DPO under DPDP Act? Mandatory for Significant Data Fiduciaries designated by the Central Government. Recommended best practice for all hospitals processing large volumes of patient data. The designation framework is being operationalised — monitor DPBI notifications.

Q4: What is the DPDP Act's 72-hour breach notification rule? The Act requires notifying DPBI "as soon as possible" after becoming aware of a data breach. Draft rules and international best practice suggest 72 hours as the target. Patient notification must also occur.

Q5: How does DPDP Act affect healthcare marketing CRM databases? All patient contacts in your CRM used for marketing must have documented opt-in consent under DPDP. Patients who registered for clinical care but did not separately consent to marketing communications must be excluded from marketing until consent is obtained.

Q6: What is the intersection between DPDP Act and ABDM? ABDM's Consent Manager framework implements purpose-limited, patient-controlled data sharing that aligns with DPDP Act consent obligations for health records. Hospitals integrating ABDM are ahead on DPDP compliance for health record sharing.

Q7: What is the maximum penalty under DPDP Act for healthcare? ₹250 crore for failure to implement adequate security measures. ₹200 crore for failure to notify a data breach. These are per-incident maximum penalties, not aggregate annual caps.

Q8: Does the DPDP Act affect hospital research databases and patient registries? Yes — using patient data for research (beyond the clinical care episode) requires separate consent under DPDP. Existing patient registries built without explicit research consent may require re-consenting campaigns.


Internal links

External sources

  1. DPDP Act 2023 full text — meity.gov.in
  2. Data Protection Board of India (DPBI) — dpbi.gov.in
  3. ABDM Consent Manager — abdm.gov.in
  4. MoHFW health data governance policy
  5. NHA on patient consent in digital health

Compliance note. This article discusses the DPDP Act 2023 as it applies to healthcare organisations. The Act's rules and enforcement guidance are being phased in through 2024–2026 — some provisions may have been updated after this article's publication. Verify current requirements with a DPDP-qualified legal or compliance professional. This article is for informational purposes only and does not constitute legal advice.

Ready to move?

Book a free 30-minute Brand & Growth Diagnostic.

It's a working session, not a sales pitch — you leave with a written root-cause analysis you can act on, whether or not you engage ICG.

Trusted by

Healthcare brands
that already run on ICG.

A representative slice of the 150+ healthcare brands ICG has delivered for across India. Most engagements remain under NDA.

Read full client case studies →

Client video stories

What ICG clients say · on video.

Dr. Samyak Dhawan
Co-Founder, Kayakalp Global · Kayakalp Global (D2C Derma)

"Scale up of organic channels and business consulting. ICG has absolute domain authority in their field."

Dr. Nishi Singh
Founder, Prime IVF · Prime IVF · Gurgaon

"Working with ICG transformed how we acquire IVF patients in Gurgaon. They understand the fertility journey from inquiry to consult..."

Dr. Prerna Taneja
Founder, Clinic Eximus · Clinic Eximus · Delhi

"What Ichelon accomplished — they got all my ideas and worked over 3-4 months to create an amazing, super-customised website."

See all client video testimonials →
Healthcare growth services · explore the stack

Need help operationalising this?

Every ICG service is healthcare-only, NMC + DPDP-aware, and built around the patient-research patterns that drive Indian healthcare growth in 2026.

Healthcare SEO Healthcare PPC Meta Ads Content Marketing Local SEO + GMB AI Overview (AIO) Healthcare Branding Website Development YouTube Marketing

Stop guessing.
Book a Diagnostic.

30 minutes. Free. With the AI-powered healthcare-only marketing agency 150+ brands already run on. No slides, no pitch, no hard close.

The ICG technology stack

Nine tools. One compounding system. HealthApex OS
Built in-house. Deployed in every engagement.

ICG's results are reproducible because they are built on proprietary infrastructure — not agency intuition or generic tools. These nine HealthApex OS platforms are what power every ICG engagement.

Healthcare CRM

Nexus CRM

Healthcare CRM & Lead Management

ICG's healthcare-specific CRM and lead management system. Specialty-configured funnel stages for IVF, dental, aesthetic, ortho, hospital OPD. 1-click CAPI + GCLID via Beacon. Hawk intelligence built in. DPDP-compliant by architecture. Deployed across 300+ healthcare centres.

  • Specialty-specific funnel stages, not generic SaaS pipeline
  • 1-click CAPI + GCLID via Beacon attribution
  • Telecaller leaderboard + adherence scoring native
  • DPDP Act 2023 compliant by architecture
Explore Nexus CRM →
Business Layer

Hawk

CRM Intelligence & Lead-Ops MIS

Sits as the business intelligence layer above your CRM — Nexus, Salesforce, LeadSquared, HubSpot, Zoho, or any custom CRM. Shows where leads are leaking, which effort is wasted, and which good leads were quietly downgraded by automation — not by a human decision.

  • Sits above your existing LMS — no replacement
  • 83% of effort goes to dead leads — surfaced Day 1
  • ~75% qualified-lead downgrades by automation
  • Free Lead-Leak Audit in 48 hours
Explore Hawk + free audit →
Attribution Core

Beacon

Attribution Engine & CAPI Middleware

Sits at the centre of every ICG attribution architecture. CAPI middleware connecting Meta Ads, Google Ads, WhatsApp and IVR to your CRM. Lifts Event Match Quality from 2.5 to 6+, reducing CPM 30–40% from the same budget.

  • Server-side CAPI — bypasses iOS privacy changes
  • EMQ 2.5 → 6+ across portfolio
  • 30–40% CPM reduction from EMQ lift alone
  • Multi-touch: ad → consultation → revenue
Explore Beacon →
Practice Management

HealthPro 360

PMS with built-in revenue intelligence layer

The only PMS that tracks cross-sell and up-sell opportunities within your existing patient base. 12 modules covering OPD, IPD, Pharmacy, Labs, Billing, Inventory, Patient Portal, Smart Scheduling, RBAC, AES-256 encrypted storage.

  • Only PMS with built-in Revenue Intelligence
  • Cross-sell signal tracking within existing patients
  • 12 modules: OPD, IPD, Pharmacy, Labs, Billing+
  • Audit trails + RBAC + AES-256 encryption
Explore HealthPro 360 →
Revenue Layer

Phoenix

Revenue intelligence built over your existing PMS

If you already have a PMS — Akhil Systems, Practo, or any other — Phoenix builds the business intelligence layer on top of it without replacement. Currently live across 46 centres for a national chain.

  • Works over your existing PMS — no migration
  • Daily action queue: Prevent Loss / Maintain / Grow
  • Catches unbilled services, collection gaps, lapsing patients
  • CPQL variance ₹620–₹3,800 → ₹680–₹1,420
Explore Phoenix →
YouTube Intelligence

YODA

YouTube analytics that measures patients, not views

The only YouTube intelligence platform built for healthcare business outcomes. Connects video performance to actual consultation bookings — not views, not subscribers. Patient testimonial videos generate 6.9× more consultations per view than condition explainers.

  • Consultation attribution per video — not views
  • Demand-gap: what patients search that your channel misses
  • 50+ doctor channels tracked across India
  • AIO readiness scoring: which videos AI tools cite
Explore YODA →
Governance & Transparency

Agency OS

Full transparency. Instant diagnosis. Zero surprises.

ICG's centralised governance platform — every client sees everything in real time, and ICG's team sees every problem the moment it surfaces. 30+ real-time alert systems fire the moment a metric drifts outside its performance envelope.

  • GSC, GA4, Google Ads, Meta Ads, IVR — one live view
  • 30+ real-time alert systems per account
  • CPQL drift alert at >15% week-on-week change
  • Client login: full transparency on your account
Explore Agency OS →
AEO & LLM Intelligence

AIO Intel

AI Overview + LLM citation tracking, healthcare-tuned

Knows the moment ChatGPT, Perplexity, Google AI Overviews and Gemini cite your brand in patient answers — and which content drove the citation. Bot-aware dashboard with GA4-registered custom dims (AIO source, AIO referrer) and IndexNow + GSC API integration.

  • Live tracking across ChatGPT / Perplexity / Google AIO / Gemini
  • Bot-aware: knows human vs scraper traffic
  • Custom GA4 dims register AIO source + referrer
  • IndexNow + GSC API: content surfaced to LLMs within hours
View AIO Intel dashboard →
Competitor Intelligence

Prism Spy

Every Meta + Google ad your competitors run, watched daily

Tracks 75+ Indian healthcare brands, 2,150+ active ads, ₹50Cr+ aggregate ad spend visibility per month. Surfaces what's working, what's been killed, what offers are emerging. Powers every ICG Meta Ads brief, Performance Marketing diagnostic, and IVF / derm / dental specialty campaign with real competitive intelligence.

  • 75+ brands tracked across 30+ healthcare specialties
  • 2,150+ active ads · daily refresh
  • Activity Feed: every spend / hook / pause logged
  • Offers Intelligence: 250+ offers in market tracked
Explore Prism Spy →
GBP Intelligence Platform

Angryturtle

Every Google Business Profile scored, tracked, protected, and grown from one command centre

ICG's proprietary Google Business Profile intelligence platform. Scores every listing across 7 dimensions, tracks rank on a live geo-grid across your actual service area, audits NAP + citations, monitors 531 suspension-risk factors continuously, and drafts Google Posts on cadence. Currently managing 143 healthcare listings with 0 suspensions and 4.76★ portfolio average across 28,137 reviews.

  • 143 listings under management · 0 suspensions · 4.76★
  • 7-dimension Health Score + 5-factor Rank OS per listing
  • Geo-grid rank tracking + NAP + Citation audit + Profile Shield
  • NMC + NABH + ART Act + DPDP compliance built into every content + review workflow
Explore Angryturtle →

Every ICG engagement runs on some combination of these ten HealthApex OS tools. The diagnostic determines which combination is right for your practice.

Explore HealthApex OS → See the full stack live on your account — free 30-min audit
The team behind your account

Every diagnostic is led by a founder.
You'll know their names before the engagement begins.

ICG was built by three IIT BHU engineers who entered healthcare marketing with a specific intent: to build the tools that didn't exist and run the campaigns that most agencies couldn't. When you book a diagnostic, Rohit or Abhash leads it personally. Not an account manager. Not a senior executive. The people who built what you're evaluating.

The ICG team — 60+ healthcare marketing specialists at Gurgaon HQ

60+ specialists.
One growth engine.

Performance marketers, analysts, AI engineers, content strategists, and operations specialists — all healthcare-only. Headquartered in Gurgaon since 2018.

Rohit Gupta — Leader, ICG

Rohit Gupta

Business & Growth Lead & Director

IIT BHU · IIM Rohtak

Rohit's first question in every diagnostic: "When you ask your agency why patients aren't booking — what do they say?" He says the answer tells him more than any dashboard.

Full profile →
Abhash Kumar — Leader, ICG

Abhash Kumar

Strategy & Analytics Lead & Director

IIT BHU · IIM Bangalore

Abhash built Beacon because most agencies couldn't answer one question: "Which of my campaigns generated that consultation?" He decided the problem was solvable in code. It was.

Full profile →
Deep Das — Leader, ICG

Deep Das

Technology & AI Lead & Director

IIT BHU

Deep built the 4-Bot patient lifecycle system after watching a client lose 60+ qualified leads in one week to a 6-hour WhatsApp response window. He decided the problem was solvable in code. It was.

Full profile →
Chat with a Co-Founder
Chat with a Co-Founder