One small fix can protect your patients and your clinic today.
A receptionist at a clinic in Delhi sent a patient's blood report on her personal WhatsApp. The patient's family saw it before the patient did. This happens every day in clinics and labs across India. Under the new DPDPA law, this is a serious problem. If your clinic or lab sends health reports carelessly, you can get into big trouble. Does this sound like your clinic?
Think about your clinic or lab right now. Does every staff member have access to all patient files? Can your receptionist send a report without asking the doctor? Do you use a shared WhatsApp number or a personal phone to send reports? These are common habits. But under DPDPA, health information is very sensitive. Only the right person should send reports. Only the right person should see files. You also need one person patients can call if they have a complaint about their information.
Decide who is allowed to send patient reports — write it down.
Remove open folder access — only give file access to staff who need it.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“The first healthcare privacy fix is often who can send what to whom.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.