Behind the scenes at Indian hospitals right now, a quiet, methodical process is underway: mapping exactly where patient data lives, rewriting consent forms, and rebuilding how vendors handle sensitive records. This isn't happening because of a single new rule — it's the practical rollout of the DPDP Act, which became enforceable in stages starting November 2025.
What's interesting is how sequential this work actually is. Hospitals can't jump straight to fixing consent forms or vendor contracts without first knowing where all their patient data physically sits — across imaging servers, pharmacy systems, billing platforms, and, more often than compliance teams expect, informal spreadsheets and shared drives that grew up around slow official systems.
Once that mapping is done, the visible changes for patients start showing up: consent forms that ask permission for one specific purpose at a time instead of one blanket signature, and a genuine ability to withdraw that consent later. Hospitals are also being pushed to build multiple channels for patients to request access to or correction of their own records — including WhatsApp, which has become a practical necessity given how many Indian patients prefer messaging over web forms.
None of this happens overnight, and full enforcement isn't mandatory until May 2027. But the hospitals doing this well are treating it as a structured, multi-month rollout rather than a single compliance sprint. For anyone curious about the actual implementation sequence hospitals are following, this step-by-step guide to DPDP compliance for hospitals lays it out in detail.