More people see patient records than you think — and that's a big problem.
A patient comes to your clinic. They think only the doctor sees their report. But think again. The receptionist types their name and phone number. The billing staff sees their test results. The software company stores everything on their server. By the time one report is done, eight or nine people may have already seen it. Does this happen in your clinic or lab too?
Imagine a patient's blood report is sent on WhatsApp to the billing team. Then forwarded to the software vendor for a billing issue. Then shared with an outside IT person for a system problem. That one report has now gone to four people. Under the new DPDPA law, your clinic is responsible for all of this. You must know who sees patient information. You must control how it moves. A patient report is not like a normal office file.
Make a list of every person who sees patient records in your clinic.
Tell your staff: do not forward patient reports on WhatsApp without permission.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“A patient report should not travel like a normal office attachment.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.