Patient records are among the most sensitive data a hospital holds, and India’s Digital Personal Data Protection Act, 2023 (DPDP Act) sets expectations for how you handle them. This is a plain-English starting checklist, not legal advice — for your specific obligations, talk to a qualified advisor.
1. Collect with notice and consent
Tell patients what you collect and why, in clear language, and collect only what you need. A registration form that quietly hoovers up everything is the opposite of data minimisation.
2. Limit who can see what
Access should be role-based and least-privilege: front desk, doctors and admins each see only what their job requires. This should be enforced by the system on every request, not left to good intentions. See how we approach this.
3. Keep records separate
If you run more than one hospital, each hospital’s data must stay isolated — one branch should never see another’s patients. Central tenant isolation makes that structural rather than hopeful.
4. Honour access and correction requests
Patients can ask what you hold and ask you to correct it. Have a simple process to respond.
5. Secure it and keep it in India
Encrypt data in transit and at rest, keep backups, and consider data residency — hosting in India matters for many hospitals under the DPDP Act.
6. Be honest about your posture
Don’t claim certifications you don’t hold. Know exactly what is and isn’t in place, and say so plainly if a patient or partner asks.
OlivHealth is built around these principles — isolation, role-based access, encryption, India hosting — while being honest about what we don’t yet certify.