Most people assume "personal data" at a hospital means their medical chart and not much else. Under India's DPDP Act, the definition is considerably wider, and it's worth understanding exactly what falls inside it — partly because hospitals themselves are still catching up on the full list.
Personal data, legally, is any data about a person who's identifiable by or in relation to it. In a hospital, that obviously covers your name, diagnosis, and prescriptions. Less obviously, it also covers the contact details of whoever accompanied you to your appointment, footage of you on a hospital corridor's CCTV camera, and data streamed from a wearable device if you're on a remote monitoring program after discharge.
It even extends to hospital staff themselves — their occupational health records and HR data fall under the exact same law. And there's a genuinely underexplored question around what happens to a patient's data after they pass away, since the Act allows for a nominee to be designated to manage a deceased person's data rights, meaning the record doesn't simply become unregulated.
None of this is trivia — it directly shapes what a hospital is supposed to protect, and how. For the fuller breakdown of what counts and what typically gets missed, this guide to understanding personal data in hospitals under the DPDP Act covers it in detail.