India's Digital Personal Data Protection Act (DPDP) 2023 sets explicit rules for how clinic patient data must be handled.
The non-negotiable checklist
- India-hosted: data residency in Indian data centres. The DPDP Act allows transfers abroad except to countries the government restricts, but keeping health data in India is the simplest and safest choice.
- Encryption at rest: 256-bit AES is the modern minimum.
- Encryption in transit: TLS 1.2 or higher between client and server.
- Consent capture: patient must opt in to data collection at first visit, with the opt-in record stored.
- Right to export: the clinic should be able to download its patient data in a standard format, such as Excel or CSV, whenever it needs to.
- Right to delete: clinic must be able to delete a specific patient's record on request.
- Audit log: every access to patient data should be logged with timestamp and user.
Red flags that signal non-compliance
- Vendor can't tell you where the database physically lives.
- "Data export" requires writing to support and waiting days.
- No consent dialog at patient registration.
- Patient data treated as a marketing asset of the platform.
- No incident response or breach notification policy.
Questions to put to any vendor
- Which cloud region is the database in? Ask for the answer in writing.
- Is data encrypted at rest and in transit?
- How often is data backed up?
- Can the clinic export its own data, without paying extra?
- What happens to the data if the clinic stops paying?
Why this matters now
Penalties under the DPDP Act for failing to protect personal data are severe, and a data leak costs a clinic patient trust. The effort to get this right is small compared with the risk.
Vaidya OS stores data on servers in India (Mumbai), encrypted at rest and in transit, and backs it up every day. Your clinic can export its patient list to Excel at any time, and patients can give consent through the QR check-in form. See how Vaidya OS keeps patient records.