A slow response to a health data leak can hurt you more than the leak itself.

Imagine this: someone calls your clinic and says patient records are showing up on WhatsApp groups. What do you do? Who do you call first? Most small hospitals and clinics have no answer ready. That silence — that delay — is what destroys trust. Under India's new data law, you must act fast when patient information is leaked or stolen. Today we give you a simple step-by-step plan.
Say a staff member at your clinic sends patient Aadhaar copies on a WhatsApp group by mistake. That is an incident. Your front desk person spots it. They must tell the clinic manager immediately. The manager checks what happened. The owner decides if patients need to be told. This whole chain must happen fast — within hours, not days. If you wait too long, patients lose trust. The law also notices the delay. Having a written plan ready saves you from panic.
Write down who reports a data problem and to whom — in one page.
Tell your front desk and nursing staff what counts as a data incident.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“In healthcare a delayed response can damage trust twice: once in the incident and once in the silence.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.