Board meetings at Indian hospital groups look a little different these days. Alongside the usual clinical performance review, there's now a conversation about consent systems and vendor data risk — topics that used to live quietly inside the IT department and rarely surfaced at leadership level.
The reason is structural. India's DPDP Act makes the hospital itself — not the IT team, not an outside vendor — legally accountable for how patient data is handled. That accountability travels straight to whoever owns the governance decisions, which increasingly means the board itself, especially for larger hospital networks that may be designated "Significant Data Fiduciaries" given how much sensitive health data they process.
What's pushing this further up the priority list isn't just the threat of penalties, real as those are. Insurers and referral networks are starting to ask hospitals to prove their data protection readiness before signing contracts. Investors evaluating hospital acquisitions are treating data governance as a standard part of due diligence. And when something does go wrong, the reputational fallout — patient advocacy groups, local news coverage — moves faster than any formal regulatory process, which means the "how does this look tomorrow" question has become a genuine board-level concern rather than a compliance footnote.
For a deeper look at why healthcare specifically is drawing this level of board attention, this piece on DPDP compliance as a boardroom priority covers the mechanics in detail.