Cybersecurity 2026

INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group

part of designated CII, parallel reporting to the NCIIPC is required. 6.3 Cybersecurity in the Healthcare Sector Under the DPDPA and the DPDP Rules, hospitals, clinics, doctors, health-tech platforms, pharmaceuti - cal companies, diagnostics labs, healthcare supply- chain organisations and all healthcare-related industry players are formally categorised as data fiduciaries, making them directly responsible for lawful and secure processing of digital personal data. The Act mandates explicit, informed consent for col - lecting and using patients’ data and individuals can access, correct and erase their health data. The DPDP Rules provide limited exemptions for processing a child’s personal data where such processing is strictly necessary for the child’s health or medical treatment. Data fiduciaries are required to implement reasonable security safeguards to prevent personal data breach - es and to notify the DPBI and affected individuals of reportable breaches within prescribed timelines.

The Ministry of Health and Family Welfare approved the Health Data Management Policy, 2020 (the “HDM Policy”) largely based on the DPDPA to govern data in the National Digital Health Ecosystem. The HDM Policy recognises entities such as data fiduciaries and data processors similar to the DPDPA, and establishes a consent-based data-sharing framework. Further, under the Policy, the Health Information Exchange and Consent Manager (HIE-CM) system has also been developed for enhanced security and privacy of electronic health data records. It operates on a decen - tralised network and ensures that the exchange and maintenance of personal health data across different healthcare providers is carried out using secure pro - tocols and based on explicit patient consent. There have also been attempts to regulate health data through specific laws. The Digital Information Secu - rity in Healthcare Act (the “DISH Act”), is one such attempt to protect health data of patients in India. Key provisions of the Act, include setting up of Health Information Exchange, and creation of regulatory and adjudicatory authorities at the national and state level.

205 CHAMBERS.COM

Powered by