Understanding Personal Data in Hospitals: What Falls Under the DPDP Act?

Personal Data

Personal data in hospitals, under India’s DPDP Act, means any digital data about an individual who is identifiable by or in relation to that data — a definition broad enough to cover far more than medical records alone. It includes a patient’s name and phone number, their diagnosis and prescriptions, but also their attendant’s contact details, a staff member’s own health records, data captured by a wearable device during remote monitoring, and in some cases, even a deceased patient’s information. Most hospital data inventories miss several of these categories entirely, which is where actual compliance gaps tend to originate.

What Counts as Personal Data Under the DPDP Act?

The Act defines personal data as any data about an individual who is identifiable by or in relation to that data — a deliberately broad standard that doesn’t require a name specifically; any combination of details that could reasonably identify a person counts. In a hospital, this reach extends well past the obvious fields on an admission form.

What Specific Types of Patient Data Fall Under the Act?

Patient-level personal data in a hospital typically includes: identifiers (name, phone number, address, Aadhaar or insurance ID), clinical data (diagnosis, prescriptions, lab results, imaging, discharge summaries), sensitive categories with no separate legal tier under DPDP but genuinely higher real-world risk (mental health notes, HIV or reproductive health status, genetic and genomic data), biometric identifiers (fingerprint scans used for OPD registration or access control), financial data tied to billing and insurance claims, and behavioral/digital data generated through appointment apps, patient portals, and telemedicine consultations. Each of these needs to appear in a hospital’s data inventory individually — treating “patient data” as one undifferentiated blob is exactly how gaps get missed.

Does Anonymized or De-Identified Data Count as Personal Data?

Genuinely and irreversibly anonymized data — where no reasonable technical means exists to re-identify the individual — generally falls outside the Act’s scope, since the definition hinges on identifiability. Pseudonymized or de-identified data, where a key or combination of fields could plausibly re-link the data to a person, does not get this exemption and remains personal data. Hospitals using “anonymized” datasets for research or AI model training need to verify, specifically, whether re-identification is genuinely impossible or merely inconvenient — the legal distinction rests entirely on that difference, and treating the two as equivalent is a common and risky mistake.

Do Digitized Paper Records Count as Personal Data?

Yes. The moment a paper chart, a handwritten prescription, or an old physical file gets scanned and stored digitally, it falls within the DPDP Act’s scope. A hospital’s obligations don’t stop at records that were born digital — any historical archive undergoing digitization needs to be brought into the same consent, security, and retention framework as newly collected data, which is a step several hospitals digitizing legacy archives currently skip.

What About Data Belonging to People Who Aren’t Patients?

Attendants accompanying a patient, emergency contacts listed on an intake form, and next-of-kin details collected for consent or billing purposes are all separate data principals under the Act, even though they never receive treatment themselves. This category is one of the most commonly missed in hospital data inventories, since these details typically live buried inside a patient’s file rather than being tracked as an independent record requiring its own consent and retention logic.

Hospital staff are data principals too. Employee health records collected for occupational health screening, background check details, and HR data all fall under the same Act — a hospital is simultaneously a Data Fiduciary for its patients and for its own workforce, and the two data sets need genuinely separate handling, not a shared assumption that “internal data” gets a lighter standard.

Does the Act Cover Data From Wearables and Remote Monitoring Devices?

Yes, and this is a category expanding faster than most hospital compliance frameworks are keeping pace with. Continuous glucose monitors, remote cardiac monitoring devices, and post-discharge wearables that stream data back to a hospital’s systems all generate personal data covered by the Act, often at a volume and frequency far higher than a traditional visit-based record. If a hospital’s remote monitoring program doesn’t have a specific consent flow and retention policy for this data stream, distinct from standard visit-based records, that’s a genuine gap worth closing before scaling the program further.

What Happens to a Deceased Patient’s Data?

This is a genuinely underexplored area of the Act, and it deserves direct acknowledgment rather than a confident answer the law doesn’t fully provide. The DPDP Act allows a data principal to nominate another individual to exercise their rights in the event of death or incapacity — meaning a patient’s data doesn’t automatically become unregulated the moment they pass away, particularly where a nominee has been designated. Hospitals should treat deceased patients’ records with continued care rather than assuming the Act’s obligations simply end, even though the precise operational mechanics here are still less developed in public guidance than other parts of the framework.

Does CCTV Footage in a Hospital Count as Personal Data?

Yes, where an individual is identifiable in the footage — which is most CCTV footage in a hospital reception, corridor, or ward setting. This is a category almost never included in a hospital’s data inventory despite being one of the most continuously generated data streams in any facility. Retention periods, access controls, and a genuine purpose limitation (security monitoring, not indefinite storage) all apply here exactly as they would to any other personal data category.

A Practical Data Inventory Checklist for Hospitals

Use this as a starting checklist when mapping what actually needs to be accounted for, not just the obvious clinical record set:

  • Patient identifiers and clinical records (across every department — pharmacy, radiology, pathology, not just the primary EHR)
  • Digitized historical paper records
  • Attendant, emergency contact, and next-of-kin data
  • Staff and employee health/HR data
  • Wearable and remote monitoring device data streams
  • Telemedicine consultation recordings and chat transcripts
  • CCTV footage across patient-facing areas
  • Billing, insurance, and payment data
  • Research datasets, with explicit verification of genuine anonymization status
  • Nominee and deceased-patient records still under active retention

A manual audit against this list tends to surface data sources hospitals genuinely didn’t know they were accountable for — which is precisely why continuous, automated data discovery across every system, rather than a one-time manual review, tends to catch categories like CCTV footage or attendant data that a checklist-based audit conducted once a year will predictably miss the second time around.

Where This Leaves You

Personal data in hospitals under the DPDP Act is a considerably wider category than “the EHR system,” and most compliance gaps originate exactly where the definition gets narrowed informally — attendant data folded into a patient’s file, staff health records treated as an HR-only matter, CCTV footage never inventoried at all. Getting the taxonomy right at the start is what makes every downstream compliance step — consent, breach response, vendor governance — actually complete rather than partially complete.

If you want a clear picture of exactly what personal data categories your hospital currently has mapped, and which ones are likely being missed, RuleExpert’s data discovery and classification tooling runs a continuous scan across your systems rather than a one-time audit. Check your free DPDP compliance score to see where your current data inventory actually stands.

Source: PIB press release on the DPDP Rules, 2025 notification.

Author Bio

Nitin Ray is a thought leader in DPDP compliance, data privacy, breach management, and governance technology. He regularly publishes insights on the Digital Personal Data Protection (DPDP) Act, 2023, helping organizations understand data protection obligations, manage privacy risks, and strengthen compliance programs. His articles focus on practical strategies for Breach Management in DPDP, incident response, privacy governance, vendor risk management, and compliance automation, enabling organizations to protect personal data, improve audit readiness, and build lasting stakeholder trust.

Frequently Asked Questions About Personal Data in Hospitals Under the DPDP Act

What is the legal definition of personal data under the DPDP Act?

Personal data is any data about an individual who is identifiable by or in relation to that data — a broad standard that doesn’t require a name specifically, since any combination of details that could reasonably identify a person qualifies.

Are lab results and diagnostic reports personal data under the DPDP Act?

Yes. Lab results, imaging, prescriptions, and discharge summaries are all personal data under the Act, treated with the same legal standard as any other identifying information, since the Act does not create a separate higher-protection tier for medical data.

Does anonymized patient data still count as personal data?

Genuinely and irreversibly anonymized data, where re-identification isn’t technically feasible, generally falls outside the Act’s scope. Pseudonymized or de-identified data that could still plausibly be re-linked to a person remains personal data.

Does the DPDP Act apply to old paper medical records that get scanned into a computer system?

Yes. Once a physical record is digitized, it falls within the Act’s scope in the same way as data collected digitally from the start.

Is a patient’s emergency contact or attendant’s information covered by the DPDP Act?

Yes. Attendants, emergency contacts, and next-of-kin details are separate data principals under the Act, even though they aren’t the patient receiving treatment, and this category is commonly missed in hospital data inventories.

Does hospital staff health data fall under the same rules as patient data?

Yes. Employee health records, occupational screening data, and HR information are personal data under the same Act, and a hospital is simultaneously a Data Fiduciary for its patients and its own workforce.

Does data from wearable devices or remote patient monitoring count as personal data?

Yes. Data streamed from continuous glucose monitors, remote cardiac devices, or post-discharge wearables is personal data under the Act, often generated at a much higher frequency than standard visit-based records.

Does CCTV footage in a hospital count as personal data under the DPDP Act?

Yes, where individuals are identifiable in the footage, which covers most hospital CCTV in reception areas, corridors, and wards. This category is frequently missing from hospital data inventories despite being continuously generated.