Answers
    Patient records & data

    Where should clinic patient data be stored to be DPDP-compliant?

    Last reviewed: 26 September 2026 Gaurav, Founder, Vaidya OS
    Quick answer

    On servers in India, with encryption for stored data and for data in transit, a record of patient consent, and a way for your clinic to export its data. Avoid tools that store data abroad without saying so, have no clear export, or treat your patient list as their own. The DPDP Act 2023 makes the clinic responsible for how patient data is handled.

    In this answer

    India's Digital Personal Data Protection Act (DPDP) 2023 sets explicit rules for how clinic patient data must be handled.

    The non-negotiable checklist

    1. India-hosted: data residency in Indian data centres. The DPDP Act allows transfers abroad except to countries the government restricts, but keeping health data in India is the simplest and safest choice.
    2. Encryption at rest: 256-bit AES is the modern minimum.
    3. Encryption in transit: TLS 1.2 or higher between client and server.
    4. Consent capture: patient must opt in to data collection at first visit, with the opt-in record stored.
    5. Right to export: the clinic should be able to download its patient data in a standard format, such as Excel or CSV, whenever it needs to.
    6. Right to delete: clinic must be able to delete a specific patient's record on request.
    7. Audit log: every access to patient data should be logged with timestamp and user.

    Red flags that signal non-compliance

    • Vendor can't tell you where the database physically lives.
    • "Data export" requires writing to support and waiting days.
    • No consent dialog at patient registration.
    • Patient data treated as a marketing asset of the platform.
    • No incident response or breach notification policy.

    Questions to put to any vendor

    1. Which cloud region is the database in? Ask for the answer in writing.
    2. Is data encrypted at rest and in transit?
    3. How often is data backed up?
    4. Can the clinic export its own data, without paying extra?
    5. What happens to the data if the clinic stops paying?

    Why this matters now

    Penalties under the DPDP Act for failing to protect personal data are severe, and a data leak costs a clinic patient trust. The effort to get this right is small compared with the risk.

    Vaidya OS stores data on servers in India (Mumbai), encrypted at rest and in transit, and backs it up every day. Your clinic can export its patient list to Excel at any time, and patients can give consent through the QR check-in form. See how Vaidya OS keeps patient records.

    Related questions

    Does patient data have to stay in India?
    The DPDP Act allows some transfers abroad, but storing health data on servers in India is the simplest and safest choice for a clinic.
    Who is responsible for patient data, the clinic or the software company?
    Under the DPDP Act, the clinic decides how patient data is used and is responsible for it. The software company processes it on the clinic's behalf, so choose one that protects it well.
    Where does Vaidya OS store data?
    On servers in India, in Mumbai (ap-south-1), encrypted at rest and in transit, with a backup every day.

    Sources

    1. DPDP Act 2023
    G
    Gaurav
    Founder, Vaidya OS
    Last reviewed 26 September 2026 · Published 9 May 2026
    Chat with us on WhatsAppGet started in 60 seconds. No forms, no waiting.

    Run your clinic on Vaidya OS

    14-day free trial. No credit card needed.