Healthcare Pharma & Life Sciences Other Industries
All Services Performance Marketing ChatGPT Ads India · NEW Social Media Marketing SEO & AEO / LLM YouTube Marketing LLM Optimization Brand & Growth Consulting AI Solutions Industries We Serve
Enterprise Hub · All Solutions + Services Growth Transformation AI Transformation Revenue Operations Fractional CGO Growth Operating System Executive Growth Advisory
Clinic Launch Programme (Hub) NABH Consulting India Healthcare Brand Launch Clinic SOP Creation Logo Design (Healthcare) Brand Book Creation Clinic Launch Marketing D2C Brand Launch Clinic Interior Design
Workforce Hub For Employers — post a requirement For Professionals — register Public Openings Training Academy AI Training Flagship
Hawk · CRM Intelligence (NEW) YODA · YouTube Intelligence Angryturtle · GBP Intelligence (NEW) Prism Pulse · Instagram Analytics (NEW) Beacon · Attribution Agency OS · Dashboards Phoenix · Clinic Revenue HealthPro 360 · PMS/HMS AI Patient Lifecycle Bots AI Lead Management System Smart Appointment System Healthcare CRM Patient Feedback System AI, Analytics & Automation Digital Transformation Calculators Free Digital Health Audit →
All 13 calculators → 🎯 Business Exploration Matrix (New) Dental Clinic Setup IVF Clinic + Lab Setup Multi-Specialty Hospital Setup Aesthetic / Cosmetology Clinic Dermatology Clinic Setup Generic Clinic Setup Physiotherapy Clinic Setup Diagnostic Centre Setup CAC Calculator CPQL Calculator Franchise ROI Calculator Revenue Leakage Calculator CRM ROI Calculator
All Events Workshop 1 · Jun 13 · AI in Clinical Practice Workshop 2 · Jun 27–28 · AI in Growth & Governance Hospital Ops Workshop · Jul 12 Pre-Summit Seminar · Aug 16 Grand Summit 2.0 · Oct 10–11 Bihar AI Summit · Recap AI Innovation Awards · Aug 22 Grand Summit 2.0 · Oct 2026 Aarambh 2026 Recap
Case Studies Insights & Blog Research Reports Calculators AI in Healthcare Digest
Our Story Leaders @ Ichelon · IN · US · AU Ichelon India · Gurgaon Ichelon Global · Dallas, TX Ichelon Australia · Sydney Speakers & Panelists Client Elevation Programme 🤝 Partner Connect 🇦🇪 ICG UAE Careers
Book a Growth Diagnostic
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
Trusted by 150+ healthcare & life-sciences brands
Johnson & Johnson
Mankind Pharma
Adonis Phyto
Narang Biotec
Medanta
Redcliffe Labs
Sitaram Bhartia
Metro Hospitals
Tulasi Hospital
Bloom IVF
Milann
Prime IVF
MedLinks
Handa
Bhardwaj
Eye Q
Johnson & Johnson
Mankind Pharma
Adonis Phyto
Narang Biotec
Medanta
Redcliffe Labs
Sitaram Bhartia
Metro Hospitals
Tulasi Hospital
Bloom IVF
Milann
Prime IVF
MedLinks
Handa
Bhardwaj
Eye Q
Johnson & Johnson
Mankind Pharma
Adonis Phyto
Narang Biotec
Medanta
Redcliffe Labs
Sitaram Bhartia
Metro Hospitals
Tulasi Hospital
Bloom IVF
Milann
Prime IVF
MedLinks
Handa
Bhardwaj
Eye Q
Article

DPDP Act 2023 for Healthcare Websites: Complete India Compliance Guide

A plain-English DPDP Act 2023 compliance guide for healthcare websites in India: what patient data counts as sensitive, which consent flows you now owe, how it changes forms and ads, penalties up to Rs 250 crore, and a 12-week readiness plan.

ICG Editorial · · · 12 min read
Book a free 30-min Diagnostic Chat on WhatsApp

No pitch. Written root-cause diagnosis. AI-powered, healthcare only.

Editorial standards: This article was reviewed by the ICG Editorial Review Board for NMC Section 6 compliance, Schedule J screening, DPDP privacy, and source verification before publication. · Our editorial process →
ICG · AI-Powered Healthcare-Only Marketing Agency
Why are your CPQL numbers stuck? Talk to the team behind 150+ healthcare brands.
30-minute free diagnostic. Written, not pitched. CPQL benchmarks for your specialty, on the call.

Direct answer

A plain-English DPDP Act 2023 compliance guide for healthcare websites in India: what patient data counts as sensitive, which consent flows you now owe, how it changes forms and ads, penalties up to Rs 250 crore, and a 12-week readiness plan.

TL;DR

A plain-English DPDP Act 2023 compliance guide for healthcare websites in India: what patient data counts as sensitive, which consent flows you now owe, how it changes forms and ads, penalties up to Rs 250 crore, and a 12-week readiness plan.

TL;DR

  • The Digital Personal Data Protection Act, 2023 (DPDP Act) treats every healthcare website in India as a Data Fiduciary the moment it captures a patient name, phone number or medical query. Enforcement penalties can reach Rs 250 crore per breach.
  • Appointment booking forms, WhatsApp click-to-chat CTAs, chatbot conversations, and analytics pixels all now need granular, purpose-specific consent recorded and retrievable on demand.
  • Hospitals and clinics in Delhi, Mumbai, Bengaluru, Chennai, Hyderabad and Pune have roughly 12-18 months from the DPDP Rules notification to overhaul consent, storage, retention and third-party sharing workflows.
  • Getting DPDP-ready early is a business advantage: enterprise hospital tenders, corporate wellness contracts and pharma-hospital tie-ups already ask for a data-protection audit trail.

Table of contents

Why the DPDP Act matters for Indian healthcare marketing

Most hospital marketing directors we speak with in Mumbai and Delhi still treat privacy as a legal team problem. It is not. From the day the DPDP Rules are notified, every appointment form on your site, every WhatsApp CTA, every downloaded lead list and every Meta lookalike audience becomes a compliance surface. Healthcare is the highest-risk category in the entire Act because of how sensitive the underlying data is.

India's healthcare digital ad spend crossed Rs 3,800 crore in FY 2024-25 and is on pace to double by FY 2027-28. Almost all of it is fuelled by personal data captured on hospital and clinic websites. If you run marketing for a 100-bed hospital in Pune, an IVF chain in Bengaluru, or a dental group in Gurugram, DPDP compliance is going to decide whether your funnel keeps running or gets frozen.

This guide is written for founders, marketing heads, agency owners and doctors running clinics as businesses. It is not legal advice. It is the operational checklist we use at ICG when we onboard a new healthcare brand.

What is the DPDP Act 2023 and why should healthcare websites care?

Short answer: The Digital Personal Data Protection Act, 2023 is India's first horizontal data-protection law. It governs how any digital business, including hospitals and clinics, collects, stores, processes and shares personal data of Indian residents. Healthcare websites fall squarely under it because they routinely capture name, phone, condition, city and appointment intent.

The Act was passed by Parliament in August 2023. The draft DPDP Rules were released for public consultation in January 2025, and industry expects notification and staggered enforcement over 12 to 18 months. Once notified, every hospital website, clinic microsite and pharma brand landing page is a "Data Fiduciary" under the law.

Three things flip on Day One of enforcement. First, you must have specific, informed, unambiguous consent before collecting any personal data. Pre-ticked boxes and hidden checkboxes will not survive audit. Second, you must be able to show a Data Principal (the patient) exactly what data you hold on them, why you hold it, and delete it on request. Third, the Data Protection Board of India can impose penalties per breach, and healthcare data attracts the highest slabs.

What most hospital and agency teams miss is that the Act follows the data, not the entity. If a Delhi clinic uses a Bengaluru agency, and the agency uses a Mumbai-hosted CRM, all three are on the hook. Everyone in the chain must document their role.

Which patient data does the DPDP Act treat as sensitive?

Short answer: The DPDP Act does not use the old "sensitive personal data" tag the earlier IT Rules used, but healthcare data is treated with maximum caution because it reveals medical condition, treatment history and financial ability. In practice, anything that hints at a patient's diagnosis, procedure interest, insurance status or family history is high-risk.

Here is the working list ICG uses when auditing a hospital or clinic website:

  • Name, mobile number, email captured on any form.
  • Age, gender, city, PIN code, and preferred hospital branch.
  • Symptom descriptions typed into a chatbot, WhatsApp bot or "Describe your concern" text field.
  • Condition-specific dropdowns (IVF cycle number, dental procedure type, cardiac risk category, cancer stage query).
  • Insurance provider, sum insured, corporate empanelment status.
  • Payment attempts, EMI queries, financial-help form entries.
  • Uploaded documents (prescriptions, reports, insurance cards).
  • Family medical history hints (fertility, oncology and cardiology sites collect a lot of this).

Even a filter like "Show me IVF packages under Rs 2 lakh in Delhi NCR" is a data event. It reveals condition and price sensitivity. Under DPDP, that filter interaction should be tied to a valid consent record if you are storing it against a user ID or cookie.

Short answer: You need a layered, granular consent architecture. That means separate opt-ins for appointment booking, marketing communication, WhatsApp updates, analytics cookies and third-party ad platforms, each in plain English and one Indian language, with a verifiable audit trail.

In our experience running websites for 300+ live healthcare clients, the biggest gap is treating "I agree to Terms & Conditions" as consent for everything. That will not hold up. A DPDP-ready consent flow looks like this:

1. Notice at the point of collection

Before any form field is filled, the patient sees a short notice: what data you are collecting, why, who processes it, how long you keep it, and who to contact for erasure. Ideally in English and Hindi at minimum, with regional language options for tier-2 city hospitals in Ahmedabad, Jaipur, Lucknow, Kolkata and Kochi.

2. Purpose-specific consent

Separate checkboxes for: book an appointment, receive marketing communication on offers, receive appointment reminders on WhatsApp, share data with a specific corporate partner or insurer. No bundling.

3. Consent receipt

An immutable log of who consented, to what, when, from which IP or device. This is what you will need if the Data Protection Board asks for evidence. Most Indian hospital websites do not log this today.

4. Withdrawal mechanism

A simple, always-visible "Manage my data" link in the footer that lets a patient view, export or delete their data. If you cannot honour a withdrawal within a reasonable timeline, you are exposed.

How does DPDP affect appointment booking, lead forms and WhatsApp capture?

Short answer: Every appointment form, callback form and WhatsApp click-to-chat button on your site now needs a purpose-specific consent notice, a consent log, and a clean handoff into a CRM that respects retention and deletion rules. Bulk lead download and "share on WhatsApp group" behaviour has to stop.

Here is what typically breaks in a real Indian hospital or clinic setup:

  • WhatsApp click-to-chat: The patient taps a button, lands in a WhatsApp thread, and starts describing their condition. Nobody has recorded a consent notice, and now sensitive health information sits on personal phones of front-desk staff. Fix: use a WhatsApp Business API deployment tied to a compliant CRM with role-based access.
  • Front-desk Excel sheets: Leads exported daily from the website into an Excel file that gets emailed around. Under DPDP, this is a classic breach vector. Fix: no local exports, no email attachments containing patient data.
  • Third-party form builders: Many clinics still embed generic form widgets whose data-processing terms have not been reviewed. Under DPDP, you are still the Data Fiduciary even if the processor is offshore.
  • Multi-branch consolidation: A hospital group with 6 branches in Mumbai should not be pooling leads into one shared inbox without documented internal purpose limits.

At ICG we use Nexus CRM, our Rs 14,999 per month healthcare-first CRM, precisely because it was built around Indian consent, retention and audit needs from day one. For groups running full RCM and EHR workflows on top, HealthPro 360 (also Rs 14,999 per month) layers the same principles across appointment, billing and follow-up flows.

What penalties can hospitals and healthcare agencies actually face?

Short answer: Under the DPDP Act, financial penalties can reach up to Rs 250 crore per instance of breach, depending on category. For healthcare specifically, breaches involving sensitive data, breach of a child's data, or failure to notify the Board attract the higher end of the scale.

The headline slabs to know:

  • Failure to prevent a personal data breach: up to Rs 250 crore.
  • Failure to notify the Data Protection Board about a breach: up to Rs 200 crore.
  • Breach of obligations related to processing children's data: up to Rs 200 crore. Paediatric hospitals, dental chains treating minors, and IVF centres capturing family data must pay particular attention here.
  • Failure to fulfil obligations of a Significant Data Fiduciary: up to Rs 150 crore. Large hospital chains with millions of records will almost certainly fall in this bucket once thresholds are notified.
  • Breach of any other provision: up to Rs 50 crore.

The reputational fallout is arguably worse. A single breach notification for a 500-bed hospital in Chennai will land on national news within hours and torpedo enterprise contracts under review. Compliance is now a business continuity issue, not a legal formality.

Does the DPDP Act change how you run Google Ads and Meta Ads for hospitals?

Short answer: Yes, significantly. Lead-form ads, remarketing audiences, lookalike modelling and offline conversion uploads all involve personal data. Under DPDP, you cannot push a patient's phone number into a Meta or Google ad platform without a clean, specific consent chain.

The three things that need to change immediately for most Indian healthcare advertisers:

  1. Consent-gated conversion uploads. If your agency is uploading offline conversions from a hospital CRM to Google or Meta for smart bidding, every uploaded record must trace back to a valid consent for "sharing my data with advertising platforms". Most CRMs today cannot show that trail.
  2. Cleaner remarketing lists. Building a remarketing audience of "IVF page visitors last 60 days" is fine only if visitors consented to analytics and advertising cookies through a valid consent management platform. Auto-firing pixels on page load will not pass audit.
  3. Retention rules. Long-lived custom audiences that hold patient identifiers for 540 days will need to be reviewed. Retention has to match the purpose the consent was given for.

Inside ICG this is where Meta Catalyst IQ, our Meta Ads engine for healthcare, and Prism Spy, our competitor Meta Ads intelligence tool, both push clients toward consent-first creative testing rather than aggressive identifier-based retargeting. Prism Pulse, our Instagram analytics tool, is built to answer performance questions using anonymised, aggregated data rather than raw personal identifiers.

How do you make a hospital or clinic website DPDP-ready in 12 weeks?

Meta Catalyst IQ Audience Size analysis showing the fatigue and saturation curves for each audience segment in a Meta Ads account
Meta Catalyst IQ · Audience SizeAudience fatigue + saturation curves per segment. When to broaden, when to duplicate, when to kill — with the numbers to defend the call.
Prism Pulse client-shareable monthly report with what-is-working, needs-attention and action-plan sections signed off for a healthcare Instagram account
Prism Pulse · Client ReportClient-shareable monthly report · What is working · Needs attention · Action plan. 10-day valid link — the deliverable clients actually read.
PrismSpy Service Cluster leaderboard scoring 419 distinct healthcare services 1-10 by brand count, active percentage, average score and trend
PrismSpy · Service Cluster419 distinct services tracked. Best-performing services scored 1-10. Leaderboard with brand count, active %, avg score, trend.

Short answer: Run a 12-week programme in three phases: weeks 1-4 discovery and mapping, weeks 5-8 build and integrate, weeks 9-12 rollout, training and audit rehearsal. Assign a single owner and a single external partner accountable end to end.

Here is the ICG 12-week template we run for hospital groups:

WeeksFocusDeliverables
1-2Data mappingEvery form, chatbot, WhatsApp CTA, pixel, cookie and CRM integration inventoried across all city pages.
3-4Gap analysisConsent gaps, retention gaps, third-party sharing gaps documented with risk ratings.
5-6Consent architectureNew consent notices, layered checkboxes, consent receipt logging, bilingual copy.
7-8Backend cleanupCRM retention policies, role-based access, deletion workflows, secure lead handoff.
9-10Ads and analyticsConsent-gated pixels, remarketing list cleanup, offline conversion audit trail.
11Team trainingFront-desk, tele-callers, marketing team and agency partners trained on the new flow.
12Audit rehearsalMock Data Principal request handled end to end within 72 hours.

A typical 50-100 bed hospital in Hyderabad or Ahmedabad can complete this with two internal owners plus one accountable external partner. Multi-city chains need a longer runway.

How does ICG approach DPDP compliance for healthcare marketing?

Short answer: We treat compliance as a growth lever, not a cost centre. Every website, CRM, ad account and content workflow we run for 300+ healthcare clients is built to survive a DPDP audit and still hit lead-volume targets.

Our approach differs from typical marketing agencies in three ways. First, discovery and mapping are baked into onboarding, not sold separately. Second, our own product stack, Angryturtle for Google Business Profile, YODA for YouTube, Meta Catalyst IQ for Meta Ads, Prism Spy for competitor intel, Prism Pulse for Instagram analytics, Nexus CRM and HealthPro 360, was built with Indian regulation in mind rather than retrofitted. Third, our engagement pricing follows a 70-30 fixed-variable model, so the compliance work is baked into the fixed fee rather than lurking as a "compliance add-on" line item.

The ICG 70-30 pricing model, made concrete

Our SEO and healthcare marketing engagements work on a 70-30 fixed-variable model. 70% of the monthly fee is fixed and covers strategy, execution, compliance work and reporting. 30% is variable and tied to a 12-month target on a sliding-scale slab. Three anchor tiers most healthcare brands start on:

  • Foundation, Rs 49,999 per month. Clinics, single-city practices, early growth.
  • Growth, Rs 74,999 per month. Multi-branch clinics, mid-size hospitals, active lead engines.
  • Scale, Rs 99,999 per month. Hospital groups, IVF and oncology chains, pharma brand teams.

DPDP readiness sits inside the fixed 70%. You are not surprised by a Rs 4 lakh compliance retainer six months in.

Frequently asked questions

YODA SEO Post-Publication first-72-hour signal monitor tracking impressions, CTR, retention curve and early ranking signals per video
YODA · SEO Post-PublicationFirst-72-hour signal monitoring after a video goes live. Impressions, CTR, retention curve, early ranking signals — flags what to A/B before the window closes.
Angryturtle On-Page Optimization deep dive continuing into attributes, services and structured-content coverage — the fields Google uses for local pack eligibility
Angryturtle · On-Page (Attributes & Services)On-page deep dive continues into attributes, services and structured-content coverage — the fields Google uses for local pack eligibility.

Is the DPDP Act 2023 already enforceable for hospital websites?

The Act is enacted but full enforcement follows the notification of the DPDP Rules and a staggered transition window. Draft Rules were released in January 2025. Healthcare brands should assume enforcement within the next 12-18 months and start work now.

Do small clinics with 1-2 doctors really need to comply?

Yes. The Act does not exempt small practices. A single dental clinic in Noida that captures name and phone number through a website form is a Data Fiduciary. The scale of penalties will vary, the obligation to have consent, notice and deletion mechanisms does not.

Can we still run WhatsApp campaigns for hospital appointments?

Yes, provided the patient gave specific consent to receive WhatsApp communication from your brand, the consent is logged, and there is a clear opt-out. Bulk-blasting WhatsApp from personal numbers to lead lists is not DPDP-safe.

Are Meta and Google lead-form ads still compliant under DPDP?

They can be, if consent language in the lead form is specific and the data flow from the ad platform to your CRM to any downstream tool is documented and consented to. Generic "I agree" checkboxes on lead forms will not be enough.

What happens if we get a Data Principal request to delete their record?

You must be able to locate the record across every system it lives in, delete it, and confirm back to the patient within a reasonable timeline. Most Indian hospital IT stacks cannot do this today because data is spread across HIS, CRM, marketing tools and spreadsheets.

Does hosting our website in India automatically make us compliant?

No. DPDP compliance is about consent, notice, retention, deletion, and third-party sharing behaviour, not just hosting location. Hosting in India helps with data residency conversations for enterprise clients but is not a compliance shortcut.

How does DPDP interact with ABDM and NMC telemedicine rules?

ABDM adds a health-specific data-sharing framework and NMC telemedicine guidelines add professional-conduct expectations. DPDP sits above both as the horizontal privacy law. For a full teleconsultation product, all three frameworks apply together.

Can our current agency handle DPDP work, or do we need a specialist?

If your current partner is running purely creative or generic performance marketing, they will likely need external help. Look for an agency that runs its own healthcare product stack and can show a documented compliance workflow, not a slide deck.

Ready to move?

Book a free 30-minute Brand & Growth Diagnostic.

It's a working session, not a sales pitch — you leave with a written root-cause analysis you can act on, whether or not you engage ICG.

Frequently asked

Questions readers ask
about this topic.

The Act is enacted but full enforcement follows notification of the DPDP Rules and a staggered transition window. Draft Rules were released in January 2025. Healthcare brands should assume enforcement within the next 12-18 months and start compliance work immediately rather than wait for a final date.

Yes. The Act does not exempt small practices. A single dental clinic in Noida that captures name and phone number through a website form is a Data Fiduciary under DPDP. The scale of penalties may vary, but the obligation to have consent, notice and deletion mechanisms does not.

Yes, provided the patient gave specific consent to receive WhatsApp communication from your brand, the consent is logged with a timestamp, and a clear opt-out is available. Bulk-blasting WhatsApp from personal numbers to purchased or scraped lead lists is not DPDP-safe.

They can be, if consent language in the lead form is specific and the data flow from the ad platform to your CRM to any downstream tool is documented and consented to. Generic 'I agree to terms' checkboxes on lead forms will not survive an audit.

You must be able to locate the record across every system it lives in, delete it, and confirm back to the patient within a reasonable timeline. Most Indian hospital IT stacks cannot do this today because data sits scattered across HIS, CRM, marketing tools, WhatsApp threads and spreadsheets.

No. DPDP compliance is about consent, notice, retention, deletion and third-party sharing behaviour, not just hosting location. India hosting helps with data residency conversations for enterprise and government clients but is not a compliance shortcut on its own.

ABDM adds a health-specific data-sharing framework and NMC telemedicine guidelines add professional-conduct expectations. DPDP sits above both as the horizontal privacy law. For a teleconsultation or digital health product, all three frameworks apply together and need to be mapped side by side.

If your current partner is running purely creative or generic performance marketing, they will likely need external help. Look for an agency that runs its own healthcare product stack, has worked with Indian hospitals at scale, and can show a documented compliance workflow rather than a slide deck.

Trusted by

Healthcare brands
that already run on ICG.

A representative slice of the 150+ healthcare brands ICG has delivered for across India. Most engagements remain under NDA.

Read full client case studies →

Client video stories

What ICG clients say · on video.

Dr. Samyak Dhawan
Co-Founder, Kayakalp Global · Kayakalp Global (D2C Derma)

"Scale up of organic channels and business consulting. ICG has absolute domain authority in their field."

Dr. Nishi Singh
Founder, Prime IVF · Prime IVF · Gurgaon

"Working with ICG transformed how we acquire IVF patients in Gurgaon. They understand the fertility journey from inquiry to consult..."

Dr. Prerna Taneja
Founder, Clinic Eximus · Clinic Eximus · Delhi

"What Ichelon accomplished — they got all my ideas and worked over 3-4 months to create an amazing, super-customised website."

See all client video testimonials →
Healthcare growth services · explore the stack

Need help operationalising this?

Every ICG service is healthcare-only, NMC + DPDP-aware, and built around the patient-research patterns that drive Indian healthcare growth in 2026.

Healthcare SEO Healthcare PPC Meta Ads Content Marketing Local SEO + GMB AI Overview (AIO) Healthcare Branding Website Development YouTube Marketing

Stop guessing.
Book a Diagnostic.

30 minutes. Free. With the AI-powered healthcare-only marketing agency 150+ brands already run on. No slides, no pitch, no hard close.

The ICG technology stack

Nine tools. One compounding system. HealthApex OS
Built in-house. Deployed in every engagement.

ICG's results are reproducible because they are built on proprietary infrastructure — not agency intuition or generic tools. These nine HealthApex OS platforms are what power every ICG engagement.

Healthcare CRM

Nexus CRM

Healthcare CRM & Lead Management

ICG's healthcare-specific CRM and lead management system. Specialty-configured funnel stages for IVF, dental, aesthetic, ortho, hospital OPD. 1-click CAPI + GCLID via Beacon. Hawk intelligence built in. DPDP-compliant by architecture. Deployed across 300+ healthcare centres.

  • Specialty-specific funnel stages, not generic SaaS pipeline
  • 1-click CAPI + GCLID via Beacon attribution
  • Telecaller leaderboard + adherence scoring native
  • DPDP Act 2023 compliant by architecture
Explore Nexus CRM →
Business Layer

Hawk

CRM Intelligence & Lead-Ops MIS

Sits as the business intelligence layer above your CRM — Nexus, Salesforce, LeadSquared, HubSpot, Zoho, or any custom CRM. Shows where leads are leaking, which effort is wasted, and which good leads were quietly downgraded by automation — not by a human decision.

  • Sits above your existing LMS — no replacement
  • 83% of effort goes to dead leads — surfaced Day 1
  • ~75% qualified-lead downgrades by automation
  • Free Lead-Leak Audit in 48 hours
Explore Hawk + free audit →
Attribution Core

Beacon

Attribution Engine & CAPI Middleware

Sits at the centre of every ICG attribution architecture. CAPI middleware connecting Meta Ads, Google Ads, WhatsApp and IVR to your CRM. Lifts Event Match Quality from 2.5 to 6+, reducing CPM 30–40% from the same budget.

  • Server-side CAPI — bypasses iOS privacy changes
  • EMQ 2.5 → 6+ across portfolio
  • 30–40% CPM reduction from EMQ lift alone
  • Multi-touch: ad → consultation → revenue
Explore Beacon →
Practice Management

HealthPro 360

PMS with built-in revenue intelligence layer

The only PMS that tracks cross-sell and up-sell opportunities within your existing patient base. 12 modules covering OPD, IPD, Pharmacy, Labs, Billing, Inventory, Patient Portal, Smart Scheduling, RBAC, AES-256 encrypted storage.

  • Only PMS with built-in Revenue Intelligence
  • Cross-sell signal tracking within existing patients
  • 12 modules: OPD, IPD, Pharmacy, Labs, Billing+
  • Audit trails + RBAC + AES-256 encryption
Explore HealthPro 360 →
Revenue Layer

Phoenix

Revenue intelligence built over your existing PMS

If you already have a PMS — Akhil Systems, Practo, or any other — Phoenix builds the business intelligence layer on top of it without replacement. Currently live across 46 centres for a national chain.

  • Works over your existing PMS — no migration
  • Daily action queue: Prevent Loss / Maintain / Grow
  • Catches unbilled services, collection gaps, lapsing patients
  • CPQL variance ₹620–₹3,800 → ₹680–₹1,420
Explore Phoenix →
YouTube Intelligence

YODA

YouTube analytics that measures patients, not views

The only YouTube intelligence platform built for healthcare business outcomes. Connects video performance to actual consultation bookings — not views, not subscribers. Patient testimonial videos generate 6.9× more consultations per view than condition explainers.

  • Consultation attribution per video — not views
  • Demand-gap: what patients search that your channel misses
  • 50+ doctor channels tracked across India
  • AIO readiness scoring: which videos AI tools cite
Explore YODA →
Governance & Transparency

Agency OS

Full transparency. Instant diagnosis. Zero surprises.

ICG's centralised governance platform — every client sees everything in real time, and ICG's team sees every problem the moment it surfaces. 30+ real-time alert systems fire the moment a metric drifts outside its performance envelope.

  • GSC, GA4, Google Ads, Meta Ads, IVR — one live view
  • 30+ real-time alert systems per account
  • CPQL drift alert at >15% week-on-week change
  • Client login: full transparency on your account
Explore Agency OS →
AEO & LLM Intelligence

AIO Intel

AI Overview + LLM citation tracking, healthcare-tuned

Knows the moment ChatGPT, Perplexity, Google AI Overviews and Gemini cite your brand in patient answers — and which content drove the citation. Bot-aware dashboard with GA4-registered custom dims (AIO source, AIO referrer) and IndexNow + GSC API integration.

  • Live tracking across ChatGPT / Perplexity / Google AIO / Gemini
  • Bot-aware: knows human vs scraper traffic
  • Custom GA4 dims register AIO source + referrer
  • IndexNow + GSC API: content surfaced to LLMs within hours
View AIO Intel dashboard →
Competitor Intelligence

Prism Spy

Every Meta + Google ad your competitors run, watched daily

Tracks 75+ Indian healthcare brands, 2,150+ active ads, ₹50Cr+ aggregate ad spend visibility per month. Surfaces what's working, what's been killed, what offers are emerging. Powers every ICG Meta Ads brief, Performance Marketing diagnostic, and IVF / derm / dental specialty campaign with real competitive intelligence.

  • 75+ brands tracked across 30+ healthcare specialties
  • 2,150+ active ads · daily refresh
  • Activity Feed: every spend / hook / pause logged
  • Offers Intelligence: 250+ offers in market tracked
Explore Prism Spy →
GBP Intelligence Platform

Angryturtle

Every Google Business Profile scored, tracked, protected, and grown from one command centre

ICG's proprietary Google Business Profile intelligence platform. Scores every listing across 7 dimensions, tracks rank on a live geo-grid across your actual service area, audits NAP + citations, monitors 531 suspension-risk factors continuously, and drafts Google Posts on cadence. Currently managing 143 healthcare listings with 0 suspensions and 4.76★ portfolio average across 28,137 reviews.

  • 143 listings under management · 0 suspensions · 4.76★
  • 7-dimension Health Score + 5-factor Rank OS per listing
  • Geo-grid rank tracking + NAP + Citation audit + Profile Shield
  • NMC + NABH + ART Act + DPDP compliance built into every content + review workflow
Explore Angryturtle →

Every ICG engagement runs on some combination of these ten HealthApex OS tools. The diagnostic determines which combination is right for your practice.

Explore HealthApex OS → See the full stack live on your account — free 30-min audit
The team behind your account

Every diagnostic is led by a founder.
You'll know their names before the engagement begins.

ICG was built by three IIT BHU engineers who entered healthcare marketing with a specific intent: to build the tools that didn't exist and run the campaigns that most agencies couldn't. When you book a diagnostic, Rohit or Abhash leads it personally. Not an account manager. Not a senior executive. The people who built what you're evaluating.

The ICG team — 60+ healthcare marketing specialists at Gurgaon HQ

60+ specialists.
One growth engine.

Performance marketers, analysts, AI engineers, content strategists, and operations specialists — all healthcare-only. Headquartered in Gurgaon since 2018.

Rohit Gupta — Leader, ICG

Rohit Gupta

Business & Growth Lead & Director

IIT BHU · IIM Rohtak

Rohit's first question in every diagnostic: "When you ask your agency why patients aren't booking — what do they say?" He says the answer tells him more than any dashboard.

Full profile →
Abhash Kumar — Leader, ICG

Abhash Kumar

Strategy & Analytics Lead & Director

IIT BHU · IIM Bangalore

Abhash built Beacon because most agencies couldn't answer one question: "Which of my campaigns generated that consultation?" He decided the problem was solvable in code. It was.

Full profile →
Deep Das — Leader, ICG

Deep Das

Technology & AI Lead & Director

IIT BHU

Deep built the 4-Bot patient lifecycle system after watching a client lose 60+ qualified leads in one week to a 6-hour WhatsApp response window. He decided the problem was solvable in code. It was.

Full profile →
Chat with a Co-Founder
Chat with a Co-Founder