Indian healthcare gets privacy backbone from new data protection rules

The notification of the Digital Personal Data Protection Rules 2025 has activated provisions of the DPDP Act 2023, significantly impacting the healthcare sector. The law designates medical institutions as data fiduciaries and grants patients rights over their data. Yet, ambiguities in the details pose challenges for healthcare providers.

The Digital Personal Data Protection Act 2023, along with the recently notified Rules of 2025, marks India's most significant privacy reform since the IT Act 2000. These measures promote respect for individual rights and data accountability. In healthcare, every clinic, hospital, laboratory, and telemedicine application is elevated to the status of a "data fiduciary," without distinction based on size. Personal data in digital form, or later digitized, falls under the Act's scope.

Patients become "data principals" entitled to access, correct, and erase their medical information. Hospital consent forms have often relied on blind faith rather than informed choice, but the DPDP Act introduces transparency. During medical emergencies or public health crises, data processing without consent is permitted. However, ambiguities persist in areas like post-operative ICU care, chronic illness management, and follow-up treatments.

Withdrawing consent or requesting data erasure creates complications for healthcare providers. Fiduciaries must delete the data and cease processing it, yet legal obligations in healthcare remain intact. The Act's definition of "processing" includes "erasure," potentially requiring consent even for deletions. Schedule III of the Rules prescribes data retention timelines for various sectors, but healthcare is notably absent, leaving institutions uncertain about record-keeping.

For data collected before the Act's commencement, fiduciaries must notify principals "as soon as reasonably practicable," with no defined time limit. According to authors Tishampati Sen, an advocate at the Supreme Court, and Harsh Mahajan, founder of Mahajan Labs and FICCI health mentor, the healthcare sector warrants sector-specific guidelines due to its critical nature. Overall, the law empowers patients by affirming their data rights and reminds providers that duty of care now extends to digital realms.

Makala yanayohusiana

Illustration of a doctor disappointed by low 3.6% usage stats for electronic patient records in a clinic waiting room.
Picha iliyoundwa na AI

Usage of electronic patient record remains low

Imeripotiwa na AI Picha iliyoundwa na AI

Despite new obligations for doctor's offices and clinics, only 3.6 percent of statutory insured use the electronic patient record actively. A survey by the RedaktionsNetzwerks Deutschland among major health insurers shows a slight increase since July 2025. Hopes for stronger usage through automatic filling of the records have not been fulfilled.

Ofisi ya Msimamizi wa Ulinzi wa Data (ODPC) imetoa onyo kwa kampuni za usalama binafsi nchini Kenya kwa kukusanya data ya kibinafsi nyingi bila kisheria kutoka kwa wageni. Katika taarifa ya mwongozo iliyotolewa, ODPC inasema kuwa ni lazima kukusanya tu majina, nambari za kitambulisho na wakati wa kuingia kwa idhini ya kuingia. Hii inatokea wakati wa kuongezeka kwa vitisho vya mtandao na uvunjaji wa data nchini.

Imeripotiwa na AI

Serikali ya Kenya imetekeleza mfumo mpya wa kidijitali kufuatilia utoaji wa huduma za afya kwa wakati halisi, kama ilivyoelezwa na Waziri Mkuu wa Afya Mary Muthoni. Mfumo huu, unaowezeshwa na Sheria ya Afya ya Kidijitali ya 2023, unafuatilia shughuli katika kaunti zote 47 ili kuhakikisha uwajibikaji na kuzuia udanganyifu.

India's Ministry of Electronics and Information Technology (MeitY) has released a draft amendment to the IT Rules 2021, bringing news content posted by individual users under the same framework as publishers. Social media platforms must comply with ministry guidelines or face legal action. Comments are invited until April 14.

Imeripotiwa na AI

Chile's National Consumer Service (Sernac) has issued a formal request to Clínica Dávila following a cyberattack that leaked about 250 gigabytes of sensitive patient data. The agency demands detailed information within 10 business days on the incident, attributed to a foreign ransomware group named Devman. Compromised data includes clinical records, diagnoses, and medical test results, such as HIV screenings.

Mahakama Kuu ya Kenya imeamua kuwa nambari za simu zilizosajiliwa ni data ya kibinafsi inayolindwa na katiba, na haziwezi kuzimwa au kugawiwa upya bila idhini ya mmiliki. Hii ni baada ya maombi yaliyowasilishwa Juni 2024 dhidi ya kampuni za mawasiliano kurejesha nambari za simu katika muktadha wa udanganyifu unaoongezeka.

Imeripotiwa na AI

Following recent calls from dozens of health groups to phase out the controversial Medical Assistance to Indigent and Financially Incapacitated Patients (MAIFIP) program, Senate committees have endorsed a bill to make it a permanent part of the Universal Health Care (UHC) system—despite critics labeling it lawmakers' 'health pork.' Senate Bill No. 1593, consolidating four proposals, was approved at the committee level and awaits plenary debate.

Jumatatu, 23. Mwezi wa tatu 2026, 15:57:40

Sebi revamps conflict-of-interest framework, eases FPI norms

Jumamosi, 21. Mwezi wa pili 2026, 01:17:35

India's AI healthcare strategy emphasizes equity and governance

Jumatatu, 9. Mwezi wa pili 2026, 16:49:41

Health Ministry project would transfer six million EPS users

Jumamosi, 7. Mwezi wa pili 2026, 09:21:35

Hong Kong plans to revive mandatory data breach reporting law

Jumatano, 21. Mwezi wa kwanza 2026, 06:14:09

EPIC report warns of health privacy crisis in US

Jumanne, 20. Mwezi wa kwanza 2026, 20:48:40

Before AI summit, an ethics checklist urged

Ijumaa, 16. Mwezi wa kwanza 2026, 04:50:43

Information regulator orders JSE to disclose suspicious trades

Jumatatu, 15. Mwezi wa kumi na mbili 2025, 16:56:25

EU council prepares for wider data retention targeting VPN providers

Alhamisi, 11. Mwezi wa kumi na mbili 2025, 10:04:07

Mahakama inasitisha mkataba wa afya Kenya-Marekani juu ya faragha ya data

Jumatano, 10. Mwezi wa kumi na mbili 2025, 19:20:01

Cofek na Omtatah wanapinga mkataba wa afya wa Kenya na Marekani mahakamani

 

 

 

Tovuti hii inatumia vidakuzi

Tunatumia vidakuzi kwa uchambuzi ili kuboresha tovuti yetu. Soma sera ya faragha yetu kwa maelezo zaidi.
Kataa