Hospital & Specialty Training
Data Privacy (DPDP Act)
Handling patient data lawfully - consent, purpose limitation, breach reporting and data principal rights under Indian law.
- track
- Hospital & Specialty Training
- format
- Self-paced
What this module covers
Handling patient data lawfully - consent, purpose limitation, breach reporting and data principal rights under Indian law.
This is a self-paced training module that maps to Digital Personal Data Protection (DPDP) Act, 2023. It is delivered inside the MedNext app so clinicians and hospital staff can work through it between shifts, with no live sessions or fixed deadlines.
What it covers in detail
Data Privacy (DPDP Act)
- The core concepts of the Act: data principal (the patient), data fiduciary (the hospital) and personal data, and how they apply in healthcare.
- Lawful processing on the basis of consent or certain legitimate uses, and the principles of purpose limitation and data minimisation.
- The rights of the data principal, including access, correction and erasure, and the duty to respond.
- Security safeguards, the duty to prevent breaches, and breach-notification obligations.
- Everyday practices that protect patient data: access control, not sharing images or records inappropriately, and secure disposal.
Who should complete this, and why
Everyone who handles patient information, clinical, administrative and IT staff, is affected, because a hospital is a data fiduciary responsible for the personal data it holds. The DPDP Act, 2023 introduces obligations and penalties around consent, security and breach reporting that reach into daily record-keeping and communication.
What you will be able to do after this module
On completion you should be able to
- Explain who the data principal and data fiduciary are in a hospital.
- Apply purpose limitation and data minimisation to patient data.
- Support a patient's rights of access, correction and erasure.
- Recognise a data breach and the obligation to report it.
Frequently asked questions
Who is the data fiduciary in a hospital setting?
The hospital or clinic that determines the purpose and means of processing patient data is the data fiduciary, and the patient whose data is processed is the data principal. The fiduciary carries the legal duties for lawful, secure processing.
Can I share a patient's scan on a personal messaging app for advice?
Not without a lawful basis and appropriate safeguards. Sharing identifiable patient data through insecure personal channels risks breaching both confidentiality and the DPDP Act's security obligations; use approved, secure channels and minimise identifiable data.
Other programmes in this track
Radiation Safety
ALARA principles, dose monitoring, shielding and regulatory duties for staff working with ionising radiation.
Learn moreOrgan Transplant Awareness
Legal framework for organ donation and transplantation, brain-stem death certification and counselling basics.
Learn moreDisaster Management
Hospital disaster plan, triage under mass-casualty conditions, surge capacity and staff roles in internal and external disasters.
Learn moreQuality Improvement (PDCA/RCA)
Quality tools in practice - PDCA cycles, root cause analysis, indicators and participation in hospital QI projects.
Learn moreAnti-Microbial Stewardship
Rational antibiotic use - hospital antibiogram, escalation/de-escalation, restricted antimicrobials and AMR containment.
Learn moreNeedle Stick & Sharps Safety
Safe sharps handling and disposal, and the post-exposure prophylaxis pathway after needle-stick injury.
Learn moreStart Data Privacy (DPDP Act) in the MedNext app
Explore clinician-written learning resources, structured revision and practice across the MedNext platform.
Open in the MedNext appSee plans
