ABDM and DPDP Act for Hospitals: What Your HMS Must Build

Founder and CEO, Accucia Softwares Pvt. Ltd.

Quick Answer

Hospital management software in India now carries two regulatory jobs. ABDM asks the HMS to create and verify ABHA, share records as a Health Information Provider and fetch them as a Health Information User, certified through the NHA sandbox. The DPDP Act makes the hospital a Data Fiduciary, with notice, consent, breach and security duties enforceable from May 2027. By Mr. Sumeet Katariya, Founder and CEO, Accucia Softwares Pvt. Ltd.

A 50 to 300 bed hospital does not have a compliance department. It has an administrator, a medical superintendent who also runs a ward, and an IT person who also fixes the printers. Every obligation that lands on the hospital lands on the software; nobody else is there to catch it.

That makes choosing hospital management software a regulatory decision as much as an operational one.

Why the 50 to 300 bed hospital is the one caught in the middle

Mid-size hospital balancing ABDM integration and upcoming DPDP compliance requirements.
Mid-size hospitals face growing pressure to prepare their HMS for both ABDM integration and DPDP compliance.

The corporate chain has a technology team and a legal team. The ten bed nursing home sits below most scrutiny. The hospital in between has the patient volumes of an institution and the staffing of a family business.

Two clocks are running against it.

The first is ABDM. We found no notification making participation a legal mandate for a private hospital, but the National Health Authority's HIP and HIU guidelines are plain: "Any healthcare provider who is creating health data (diagnostic reports, discharge summaries, prescriptions, etc.) digitally, should participate in ABDM."

The Digital Health Incentive Scheme has paid for ABHA-linked records since January 2023; its latest extension, Corrigendum 7 of 9 April 2026, runs to September 2026 and pays Rs 10 per KYC-verified diagnostic report or discharge summary above 100 transactions a month. Check the NHA page before counting on a further extension.

The second clock is the DPDP Act, assented to on 11 August 2023. On 13 November 2025 MeitY notified the commencement schedule, G.S.R. 843(E), and the Rules, G.S.R. 846(E).

The Data Protection Board provisions took effect on publication. The substantive duties of a Data Fiduciary, sections 3 to 17 broadly, and the Board's inquiry and penalty provisions in sections 28 to 34, take effect eighteen months from publication, which lands in May 2027.

Rules 3 and 5 to 16 follow the same schedule.

An HMS bought this quarter has to be ready by then. One bought three years ago almost certainly is not.

What ABDM integration actually asks of the HMS

ABDM has three registries, ABHA for patients, the Healthcare Professionals Registry for clinicians and the Health Facility Registry for the hospital, and one exchange, the HIE-CM, through which records move only after the patient consents.

The vendor's work is graded into three sandbox milestones, each passed through NHA's test harness and certification before production keys are issued.

In NHA's words, Milestone 1 is "ABHA Number creation and capture & verification for seamless patient registration", Milestone 2 is "Building Health Information Provider (HIP) services to share digital records" via the ABHA app, and Milestone 3 is "Developing Health Information User (HIU) services" to view a patient's history with consent.

The same guidelines set the floor: a hospital HMIS "shall be compliant with at least M2 milestone of ABDM Integration i.e. HIP."

A vendor that stops at M1 has given you an ABHA lookup box.

Health Facility Registry (HFR)

ABDM integration requirements covering HFR, HPR, ABHA, HIP, HIU, and FHIR records.
A clear overview of the key ABDM integration requirements an HMS must support for compliant digital healthcare.

What the software must do: Hold the HFR ID on the facility record and use it in every ABDM call; configure the keys issued after approval.

Who registers: The hospital, at facility.abdm.gov.in.

Healthcare Professionals Registry (HPR)

What the software must do: Store each clinician's HPR ID so authored records carry a verified identity.

Who registers: Each doctor and health professional, at hpr.abdm.gov.in.

M1: ABHA creation and verification

What the software must do: Create ABHA via Aadhaar OTP or other permitted KYC, verify an existing ABHA or QR, and store the ABHA address against the hospital's own patient ID.

Capture stays voluntary; NHA says the hospital "will not force any patient".

Who handles it: The vendor builds it; the front desk runs it.

M2: Health Information Provider service

What the software must do: Link each discharge summary, report and prescription to the ABHA address, notify ABDM on creation, and run an always-on HIP service that releases data only against a valid consent artefact.

ABDM measures uptime with heartbeats; on-premise needs a static public IP.

Who handles it: The vendor builds and certifies; the hospital hosts or contracts hosting.

M3: Health Information User service

What the software must do: Raise consent requests stating purpose and duration, receive records once approved, show them to authorised clinicians and honour revocation.

Who handles it: The vendor builds and certifies; the hospital registers as an HIU.

Structured records (FHIR)

What the software must do: FHIR bundles with SNOMED-CT, LOINC and ICD-11.

NHA requires fully structured data "within one year of obtaining ABDM certification."

Who handles it: The vendor. Ask which HI types are structured today.

One operator observation: what stalls ABDM at a mid-size hospital is rarely the API. It is HPR enrolment. Visiting consultants do not enrol until someone sits with them.

Build the missing-HPR report in from day one and give it to the medical superintendent, not IT.

What the DPDP Act asks of the hospital, and therefore of the software

The hospital is the Data Fiduciary and the patient the Data Principal. The HMS vendor is at most a Data Processor, and section 8(1) keeps the Fiduciary responsible "irrespective of any agreement to the contrary".

Your vendor's failure is your penalty.

The Act does give a hospital lawful bases: section 7(a) for data the patient volunteers for a specified purpose, and 7(f) for "responding to a medical emergency involving a threat to the life or immediate threat to the health".

The Schedule sets the exposure.

A breach of the security safeguards duty under section 8(5) "may extend to two hundred and fifty crore rupees."

Failing to notify a breach, or breaching the children's provisions, may each extend to two hundred crore.

Ceilings, but ones no 200 bed hospital can absorb.

Notice

Obligation on the hospital: Provide notice itemising the data, the purpose, and how to withdraw, exercise rights and complain to the Board under section 5 and Rule 3, in English or an Eighth Schedule language.

Software control that satisfies it: A versioned notice screen and printed slip at registration, purpose codes on each data field, Marathi, Hindi and English variants, and a record of which version the patient saw.

Consent

Obligation on the hospital: Consent must be "free, specific, informed, unconditional and unambiguous with a clear affirmative action", withdrawable as easily as it was given, and provable by the hospital under section 6.

Software control that satisfies it: A per-patient consent log with timestamp, channel, notice version and purposes, one-tap withdrawal at the counter and in the patient app, and no pre-ticked boxes.

Reasonable security safeguards

Obligation on the hospital: Encryption or masking, access control, access logging, backups, one-year log retention and processor contract terms under Rule 6.

Software control that satisfies it: Encryption at rest and in transit, role-based access by ward, an immutable audit trail of who viewed what, tested backups and twelve-month log retention.

Breach intimation

Obligation on the hospital: Notify each affected patient "without delay", and notify the Board without delay with detail within seventy-two hours under section 8(6) and Rule 7.

Software control that satisfies it: An incident register that derives the affected-patient list from access logs, a templated patient notice, and a Board report pack mapped to Rule 7(2)'s six items.

Erasure

Obligation on the hospital: Erase data when consent is withdrawn or the purpose is served, unless law requires retention, under section 8(7) and Rule 8.

Software control that satisfies it: Retention rules per record class, a legal-hold flag, and an erasure instruction to every processor including the vendor's hosting.

Children

Obligation on the hospital: Verifiable parental consent, with no tracking or targeted advertising under section 9.

The Fourth Schedule exempts a clinical establishment where "processing is restricted to provision of health services to the child".

Software control that satisfies it: A minor flag that lets treatment run without an extra step but blocks the paediatric list from any marketing or camp broadcast and routes anything outside care to guardian consent.

Patient rights

Obligation on the hospital: Provide a summary of data processed and "the identities of all other Data Fiduciaries and Data Processors" it was shared with under section 11; correction and erasure under section 12; and grievances answered within ninety days under section 13 and Rule 14.

Software control that satisfies it: A rights request form, a disclosure ledger recording every outward share, a correction workflow with clinician sign-off, and a grievance queue with a ninety-day clock.

The ward reality: how admissions, nursing notes, pharmacy, billing and discharge actually run

Hospital ward workflow covering admissions, nursing, pharmacy, billing, discharge, and ABDM compliance.
Real hospital workflows reveal whether ABDM and DPDP compliance actually works beyond the demo screen.

Most HMS demos open on a clean registration screen and a patient with Aadhaar in hand.

Real admissions open in casualty at 11 at night with a relative holding the patient's phone but not the Aadhaar, and a bed still occupied on the system because the last discharge is waiting on pharmacy returns.

That first hour decides whether ABDM and DPDP work in your hospital.

If ABHA capture is a mandatory field on the admission form, the night clerk types a placeholder and the record is unlinkable forever.

If it can be completed any time before discharge, with a queue the day shift clears, linkage goes up and nobody was forced.

The DPDP notice is the same.

Read to a frightened relative at 11 at night it is theatre. Served on the bedside tablet next morning it is compliance, and decency. Section 7(f) covers the emergency; consent follows.

Nursing notes are where access control gets tested.

A ward nurse needs every patient on her ward and none on the next. A night resident needs everyone for eight hours and should then lose it.

A vendor offering "doctor" and "nurse" as the two roles has not walked a ward.

Rule 6 in practice means roster-driven access and a readable audit trail.

Pharmacy quietly breaks retention.

Dispensing records carry their own retention duties under drug regulation while erasure rights sit under DPDP. A system storing prescription, dispensing entry and demographics as one blob cannot erase one without the other.

Billing is where the disclosure ledger earns its keep.

One stay can push data to a TPA, a referring doctor, an outside lab and an ABDM HIU. Log each share as it happens and the section 11 answer is a printout.

Discharge is the ABDM moment that pays.

It is the record the incentive scheme rewards most and the one the next hospital will request.

A vendor that starts from the demo screen builds it as a print button.

A vendor that starts from the ward builds it as a structured FHIR document assembled from the nursing notes, medication chart and diagnosis codes already in the system, pushed when the consultant signs.

And when the internet goes down, the HIP service must keep answering ABDM's heartbeats while the ward keeps working without it.

Two separate engineering decisions.

The eleven questions to ask an HMS vendor

  1. Which ABDM milestones is the product certified for, and can we see the milestone letters? NHA's letter confirms initial integration only, not ongoing compliance.
  2. Which health information types are pushed as structured FHIR today, and which are still PDF?
  3. Where is the HIP service hosted, what uptime has it held against ABDM heartbeats, and what happens when connectivity drops?
  4. Does the system run on an ABDM API version NHA currently supports, and who pays when NHA deprecates one?
  5. Show the DPDP notice as a patient sees it, in Marathi, Hindi and English, and where the system records which version each patient saw.
  6. Show one patient's consent log and the withdrawal path. How many taps to withdraw?
  7. Walk us through a breach: how does the system produce the affected-patient list, the patient notices and the seventy-two-hour Board report?
  8. Can access follow the duty roster and expire with the shift, and can the nursing superintendent read the access log herself?
  9. For one discharged patient, list every party the system shared data with during the stay.
  10. Where is patient data stored, who are your sub-processors, and what does the contract say about erasure when we leave?
  11. Who from your team is on our wards in month one, and what does support look like in month six?

A vendor who answers all eleven with screens rather than slides is the one to shortlist.

One who answers question ten with "in the cloud" has not read section 8(2).

Accucia's view

We build hospital management software around how the wards run, because it changes the product.

Admission is a process that finishes at discharge.

Roles follow rosters.

Discharge is a structured document.

Get those right and ABDM and DPDP stop being bolt-ons.

ABDM integration is a priced, named line item in our proposals, with the milestone scope written down so the hospital can hold us to it.

We deploy in an Indian cloud region of the hospital's choosing, infrastructure billed at cost, or on the hospital's own servers.

On certifications we will not overstate: ISO 27001 is not held, an auditor has been appointed and certification is targeted for Q1 2027.

Our trust page says what we can and cannot yet prove; how we work explains scoping.

We do not hand over a build and disappear.

The month after go-live is when linkage rates and consent capture become habit or get worked around, so adoption support on the wards is part of the engagement.

Proof, with India named.

In healthcare delivery, Lotus Imaging Clinic, Panvel, India runs six centres on one platform with over 80 percent less manual communication.

On the hospital side, Galaxy Hospital and Matruseva Women's Hospital in Ahilyanagar, India, run a mobile app and website we built for grievance management and brand positioning.

Across 8 years we have delivered 730+ systems for 500+ clients across 25+ industry verticals; our healthcare industry page has the rest.

If you want your current HMS checked against ABDM and DPDP before May 2027 rather than after, talk to us.

We will also tell you what is already fine.

Frequently Asked Questions

Is ABDM integration mandatory for a private hospital in India?

We could not find a notification that makes it a legal mandate for private hospitals.

NHA's guidelines say any provider creating digital health records should participate, and the Digital Health Incentive Scheme pays hospitals for ABHA-linked records.

Staying outside the Health Facility Registry carries a practical cost.

What do the ABDM milestones M1, M2 and M3 mean for hospital software?

M1 is ABHA creation, capture and verification at registration.

M2 makes the software a Health Information Provider that links records to the patient's ABHA address and shares them on consent.

M3 makes it a Health Information User that fetches records from other facilities.

NHA expects a hospital HMIS to reach M2 at least.

Is the DPDP Act in force for hospitals in September 2026?

Partly.

The Data Protection Board provisions took effect on 13 November 2025.

The duties on a hospital as Data Fiduciary, including notice, consent, security safeguards and breach reporting, take effect eighteen months from that notification, in May 2027.

Rules 3 and 5 to 16 follow the same schedule under G.S.R. 846(E).

How quickly must a hospital report a data breach under the DPDP Rules?

Rule 7 requires intimation to each affected patient without delay.

The Board must be told without delay, with detailed information within seventy-two hours of becoming aware of the breach, or a longer period the Board allows in writing.

The Schedule penalty for failing to notify may extend to Rs 200 crore.

Does a hospital need parental consent under DPDP to treat a child?

Not for treatment itself.

The Fourth Schedule to the DPDP Rules exempts a clinical establishment from the verifiable consent and tracking bars in section 9 where processing is restricted to providing health services to the child, to the extent necessary for her health.

Anything beyond care, such as marketing, needs verifiable parental consent.

Make Your HMS Compliance-Ready.

Similar Articles

Continue exploring related topics

Reviewed & Approved by

Mr. Sumeet Katariya

Founder & CEO, Accucia Softwares Pvt. Ltd.

15+ Years IT & Automation Experience | Founder of ElevatorPlus & AdBanao

Chat With Us