DPDP-Compliant Patient Management System: 8-Point Checklist for Indian Clinics (2026)
The Digital Personal Data Protection Act 2023 is now enforced. Every Indian clinic's patient management system must demonstrate 8 specific compliance capabilities. Here's the checklist + what to ask vendors.
No pitch. Written root-cause diagnosis. AI-powered, healthcare only.
Direct answer
The Digital Personal Data Protection Act 2023 is now enforced. Every Indian clinic's patient management system must demonstrate 8 specific compliance capabilities. Here's the checklist + what to ask vendors.
TL;DR
The Digital Personal Data Protection Act 2023 (DPDP Act) is now enforced for Indian healthcare. Every clinic, hospital, and healthcare brand processing patient data must demonstrate specific compliance capabilities — and the patient management system (PMS) is where most of this compliance lives or fails.
This article covers the 8 DPDP-compliance capabilities your PMS must demonstrate, the specific clauses of the DPDP Act that drive each requirement, and the exact questions to ask any PMS vendor before signing a contract.
Why this matters now
DPDP Act 2023 enforcement is not theoretical. Penalties for non-compliance scale up to ₹250 crore per violation. The Data Protection Board has been operationalised. Patient lawsuits citing DPDP are appearing in Indian courts. Clinic insurance policies are starting to require DPDP attestation.
For Indian clinics, the most common DPDP failures occur at the PMS layer — not because clinic owners are negligent, but because most legacy Indian PMS products (Practo Ray, Akhil Systems, eClinicWorks, MediXcel in older deployments) were built before DPDP Act 2023 and treat compliance as an add-on rather than an architectural feature.
The 8 DPDP capabilities every Indian PMS must demonstrate
1. AES-256 encryption at rest AND in transit (DPDP Section 8(5))
DPDP requires "reasonable security safeguards." AES-256 is the industry standard. Many older Indian PMS products encrypt at rest but transmit unencrypted to backup or to integrated services — that's a Section 8(5) violation.
Ask the vendor: Show me the encryption-at-transit configuration for backups, integrations, mobile apps, and patient portal connections. AES-256 required.
2. Granular role-based access control (DPDP Section 8(4))
DPDP requires that "personal data is processed only by authorised persons." Generic PMS access (everyone-sees-everything) is a Section 8(4) violation. Granular RBAC means a junior doctor cannot access a senior consultant's notes outside their scope, a billing clerk cannot read clinical notes, a marketing user cannot access patient data without explicit consent purpose.
Ask the vendor: Show me the role hierarchy + permission matrix. Demonstrate that user A cannot access patient data outside user A's scope.
3. Audit trail logging every patient-data access (DPDP Section 13)
DPDP gives patients the "right to know" who accessed their data, when, and why. This requires every access (read, edit, export, delete) to be logged with user/timestamp/IP/purpose. The log must be tamper-resistant and retained for the DPDP-mandated period.
Ask the vendor: Show me an audit report for a single patient — every access in the last 30 days, with purpose justification.
4. Patient consent management with timestamped versions (DPDP Section 5)
DPDP requires "specific, informed, free" consent for each data-processing purpose. Marketing consent is separate from clinical consent which is separate from research consent. Each consent must have a timestamped version with the exact language the patient agreed to.
Ask the vendor: Show me the consent-version table for a sample patient. Demonstrate that a patient withdrew marketing consent on date X and the system stopped using their data for marketing from date X.
5. Right-to-erasure workflow (DPDP Section 12)
DPDP requires that patients can request erasure of their personal data, and the data fiduciary (the clinic) must comply within a specified period. The PMS must support a "delete all data for patient X across all integrated systems" workflow — not just within the PMS but across CRM, billing, marketing, analytics.
Ask the vendor: Show me the right-to-erasure flow. Where does data still persist after erasure? (Anonymised aggregates allowed; identifiable data not.)
6. Breach notification automation (DPDP Section 8(6))
DPDP requires that data breaches be notified to the Data Protection Board AND to affected patients within a specified period. The PMS must support automated detection of suspicious access patterns and automated notification workflows.
Ask the vendor: Show me the breach detection rules. What triggers a breach notification? How long from detection to patient notification?
7. Data localisation on Indian servers (DPDP Section 16)
DPDP introduces conditions on cross-border transfer of personal data. The default safe path is localisation on Indian servers. Cloud PMS products hosted outside India (Cliniko in AU, Pabau in UK, eClinicWorks in US) face significant compliance burden.
Ask the vendor: Confirm that all patient data — primary, backup, log, archive — sits on Indian-localised servers. Demonstrate the server location with documentation.
8. Patient data export in machine-readable format (DPDP Section 11)
DPDP gives patients the "right to data portability" — the ability to receive their personal data in a structured, commonly-used, machine-readable format that they can transfer to another data fiduciary (e.g., a new clinic, an ABDM PHR provider).
Ask the vendor: Demonstrate the data-export workflow. Format: FHIR (preferred), HL7 v2, or a documented JSON schema with all clinical + administrative data.
How ICG's HealthApex OS handles all 8
HealthPro 360 + Nexus CRM — the operations layer of ICG's HealthApex OS — was built DPDP-compliant by architecture, not as an add-on. All 8 capabilities are first-class features. Compliance is maintained automatically — no separate compliance officer setup required.
For details on ICG's full integrated stack, see our Patient Management System India page.
The vendor evaluation prompt
When evaluating any Indian PMS vendor, send them this checklist and require written evidence (screenshot/demo/documentation) for each of the 8 capabilities. Vendors that cannot demonstrate all 8 are not DPDP-compliant — period.
Related reads
- Patient Management System India — ICG's full-lifecycle PMS
- Clinic Management System India — CRM + PMS + EMR integrated
- Healthcare CRM Agency India — implementation + migration partner
- EMR Software India — the EMR layer of the stack
Book a free CRM stack review.
Deep Das walks through your current setup, integration friction with ABDM/DPDP requirements, and whether a build vs buy vs Nexus fit works for your scale.
Questions readers ask
about this topic.
The three platforms
behind every ICG engagement.
Beacon
CAPI middleware that fixes Event Match Quality, translates CRM statuses to Meta-standard events, dedups across channels.
Agency OS
Live client dashboard. GSC, GA4, Google Ads, Meta Ads, IVR calls in one view. Login anytime, not monthly.
Phoenix
Clinic revenue intelligence over your PMS. Daily action queue: Prevent Loss, Maintain & Engage, Grow Revenue. 46-centre rollout.
Or book a free 30-min audit to see all three in action on your account.
Healthcare brands
that already run on ICG.
A representative slice of the 150+ healthcare brands ICG has delivered for across India. Most engagements remain under NDA.
What ICG clients say · on video.
"Scale up of organic channels and business consulting. ICG has absolute domain authority in their field."
"Working with ICG transformed how we acquire IVF patients in Gurgaon. They understand the fertility journey from inquiry to consult..."
"What Ichelon accomplished — they got all my ideas and worked over 3-4 months to create an amazing, super-customised website."
Need help operationalising this?
Every ICG service is healthcare-only, NMC + DPDP-aware, and built around the patient-research patterns that drive Indian healthcare growth in 2026.
More from
ICG.
Healthcare AIO is the discipline of getting your clinic or hospital cited inside Google AI Overviews, ChatGPT and Perplexity answers — not j...
Conversational-search advertising places brand messages inside AI chat answers — ChatGPT, Perplexity, Copilot — rather than beside a results...
NABH digital compliance means every claim, image and testimonial your hospital publishes online matches what an accreditation surveyor can v...
Stop guessing.
Book a Diagnostic.
30 minutes. Free. With the AI-powered healthcare-only marketing agency 150+ brands already run on. No slides, no pitch, no hard close.