Regulation and compliance
HIPAA in India: does it apply, and what the Indian equivalent is
HIPAA is a United States federal law. It does not apply to an Indian hospital, laboratory or imaging centre unless that organisation processes data for a US covered entity under contract. What binds Indian healthcare providers is the Digital Personal Data Protection Act 2023 with the DPDP Rules 2025, the SPDI Rules 2011 under the IT Act, and sector-specific regulation.
HIPAA does not apply to Indian hospitals. The Health Insurance Portability and Accountability Act of 1996 is a United States federal statute, and its Privacy, Security and Breach Notification Rules bind “covered entities” and their “business associates” as defined in US regulation.1 An Indian imaging centre treating Indian patients is not a covered entity. It becomes subject to HIPAA obligations only by contract, when it processes protected health information for a US covered entity, for example as an offshore reporting, transcription or billing vendor that has signed a business associate agreement.
The rules that do bind an Indian hospital are the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025, the SPDI Rules 2011 under section 43A of the IT Act for as long as that section remains, and the sectoral rules of medical practice. The DPDP guide for hospitals covers those obligations in detail; this guide maps them against the HIPAA vocabulary that vendors use.
What HIPAA is
HIPAA is a US law administered by the Department of Health and Human Services through its Office for Civil Rights. Its Privacy Rule sets out when protected health information (PHI) may be used and disclosed; its Security Rule requires administrative, physical and technical safeguards for PHI held electronically; and its Breach Notification Rule requires covered entities to notify affected individuals, the Department and in larger breaches the media.1 Covered entities are health plans, health care clearinghouses and health care providers that transmit health information electronically in connection with standard transactions. A business associate is a person or organisation that handles PHI on a covered entity’s behalf, bound by a business associate agreement.1
Two features of HIPAA are worth knowing because vendors borrow them. The “minimum necessary” standard requires uses and disclosures of PHI to be limited to what the purpose needs. And the Breach Notification Rule sets a 60-day outer limit for notifying individuals after a breach is discovered.2 Neither is Indian law, but both have Indian analogues.
Why Indian vendors talk about HIPAA
Because many of them serve US clients. Indian teleradiology and transcription companies have reported for American hospitals for two decades, and a vendor with US customers must satisfy HIPAA’s Security Rule under its business associate agreements. Having done that work, the vendor describes itself as “HIPAA compliant” to Indian buyers as well, where the phrase functions as a general assurance of security rather than a legal statement.
There is no HIPAA certification. No US agency certifies a vendor as compliant; the phrase reflects the vendor’s own assessment or a third-party audit against HIPAA’s requirements. It tells an Indian hospital nothing about whether the vendor has a DPDP-compliant processor contract, keeps data in India, or can support the hospital’s own 72-hour breach report.
What actually applies in India
| Instrument | Status | What it requires |
|---|---|---|
| Digital Personal Data Protection Act 2023 and DPDP Rules 2025 | Rules notified 14 November 2025; Board provisions in force; substantive rules around May 20273 | Notice and consent, security safeguards, breach notification, erasure, data principal rights, processor contracts, penalties up to ₹250 crore |
| SPDI Rules 2011 under IT Act section 43A | In force until section 43A is omitted at the eighteen-month mark6 | Medical records treated as sensitive personal data; published privacy policy, consent, reasonable security practices |
| Sectoral rules of medical practice | In force | MCI Regulations 2002 on record retention and production; PC-PNDT records; AERB licensing; the Telemedicine Practice Guidelines 2020 |
The DPDP Act treats all personal data alike; health data is not a separately defined sensitive category, though it is high-risk in practice.7 Cross-border transfer is permitted under Rule 15 unless the Central Government restricts a country by order, and no order has been notified, so “data in India” is a contractual promise to extract from a vendor rather than a statutory guarantee.8
HIPAA concepts and their Indian equivalents
| HIPAA concept | Indian equivalent | Where |
|---|---|---|
| Protected health information (PHI) | Personal data, including health data; sensitive personal data under the SPDI Rules | DPDP Act s.2; SPDI Rules 2011, Rule 3 |
| Covered entity | Data fiduciary (the hospital or imaging centre) | DPDP Act s.2 |
| Business associate | Data processor (the reporting platform, cloud host, laboratory system) | DPDP Act s.2 |
| Business associate agreement (BAA) | Data processing agreement or processor contract | DPDP Rules, Rule 64 |
| Breach notification within 60 days | Affected individuals without delay; Board without delay, then detailed report within 72 hours | DPDP Rules, Rule 75 |
| Minimum necessary standard | Purpose limitation: process only for the specified purpose, erase when served | DPDP Act s.4 to s.6; DPDP Rules, Rule 8 |
| Security Rule safeguards | Reasonable security safeguards: encryption or masking, access control, monitored logs, continuity, one-year log retention | DPDP Rules, Rule 64 |
| Office for Civil Rights | Data Protection Board of India | DPDP Act s.18 to s.28; DPDP Rules 17 to 21 |
| Privacy notice of practices | Standalone plain-language notice with purpose, withdrawal route and grievance contact | DPDP Rules, Rule 3 |
The mapping is close but not exact. HIPAA has no consent requirement for treatment, payment and operations; the DPDP Act rests routine processing on consent, with limited legitimate uses. HIPAA’s penalty tiers are set in US dollars per violation; the DPDP Act sets maximum penalties per category of failure, from ₹50 crore to ₹250 crore.3
What to ask a vendor instead
“Are you HIPAA compliant?” gets a yes from every vendor and tells a hospital nothing it can act on. These questions do.
- Will you sign a data processing agreement naming the Rule 6 safeguards, listing your sub-processors and fixing a breach-notice window short enough for our 72-hour Board report?
- Where, physically, are our studies and reports stored, and does any patient data leave India, including to AI or language-model services?
- What does a reporting radiologist see: the patient’s name, or a pseudonym with age, sex and clinical history?
- Can you show us an access log for a given study, who opened it and when, and how long are logs kept?
- Is two-factor authentication mandatory for radiologists and administrators, and is access role-based?
- How long do you keep reports and images, can you export them within 72 hours, and what happens at contract end?
- Is the report signed with a DSC or Aadhaar eSign rather than a scanned signature image?
Raydiac answers these in writing during onboarding. Studies are pseudonymised for reading and re-identified server-side at signing; identity sits in a separate encrypted vault. Data stays on Raydiac servers in India, with no patient data sent to foreign AI services. Access is role-based with mandatory two-factor authentication, and every view, edit and signature is written to an append-only, hash-chained audit trail kept for at least a year. Reports are signed with the radiologist’s Aadhaar eSign and a platform counter-signature.
The security page lists the controls in full. For the medical-practice rules that sit alongside data protection, see the teleradiology regulations guide.
Questions people ask
Does HIPAA apply in India?
What is the Indian equivalent of HIPAA?
Is “HIPAA compliant” a meaningful claim from an Indian vendor?
What is the Indian equivalent of a business associate agreement?
How do breach notification timelines compare between HIPAA and the DPDP Rules?
Sources
- 1.US Department of Health and Human Services, “HIPAA for professionals”
- 2.US Department of Health and Human Services, “Breach Notification Rule”
- 3.PIB, backgrounder on the DPDP Rules 2025, 17 Nov 2025
- 4.DPDP Rules 2025, Rule 6 (reasonable security safeguards), text at dpdpa.com
- 5.DPDP Rules 2025, Rule 7 (intimation of personal data breach), text at dpdpa.com
- 6.S&R Associates, “India’s digital personal data protection regime takes effect”, 2025
- 7.AMLegals, “Health data and the DPDP Act: a practical guide”, 20 Nov 2025
- 8.DPDP Rules 2025, Rule 15 (transfer outside India), text at dpdpa.com
This guide is general information for hospitals, diagnostic centres and radiologists in India. It is not legal, tax or medical advice. Regulations change; check the primary source before acting, and see the medical disclaimer.