Clinitricks — AI-Led Clinic Management

The DPDP checklist for small clinics

8 August 2026 · Clinitricks

"We're too small for this to apply to us" is the most common — and most wrong — assumption about the Digital Personal Data Protection Act, 2023. The Act doesn't have a size exemption for clinics. If you store patient data digitally, even in a spreadsheet, you're a data fiduciary, and health data is explicitly sensitive personal data under the Act. A 2-doctor clinic and a hospital chain are in the same legal category — one just has a compliance department, and the other is the doctor doing everything else too.

The DPDP Rules 2025, which give the Act its operational detail, were notified in November 2025 — recent enough that a fair amount of "DPDP for healthcare" content still describes the pre-Rules version of the law. Here's the practical checklist, current as of this Rules text.

1. Consent has to be specific, not blanket

A single "I agree to terms & conditions" checkbox at registration doesn't meet the standard. The Act expects consent that's informed and itemised — the patient should be able to tell, and agree to, what their data is being used for. In practice, that means separating out the different reasons you might use someone's data:

  • Processing their data to run the clinic — records, scheduling, billing (this one is close to unavoidable if they want treatment)
  • Using their data for the treatment itself — the clinical purpose
  • Sending them communications — appointment reminders, health tips, marketing — this is genuinely optional and should be asked for separately
  • Sharing their data with a third party — a lab, a referring doctor, an insurer — each instance is its own decision, not implied by the first three

2. Consent needs a timestamp and a version

If your consent language changes, you need to know which version a given patient actually agreed to, and when. A verbal "yes" at the front desk with nothing recorded doesn't hold up the way a timestamped, versioned record does.

3. Withdrawal has to be real, not theoretical

A patient can withdraw consent at any point, and it can't be harder than giving it was — no "call this number during business hours" while giving it was one tap. Withdrawing consent for marketing communications, specifically, must never affect their access to care.

4. You need a way to prove all of the above

Not just that you asked for consent, but that you can produce the record if asked — what was agreed to, when, in what form (in-person or via a link), and whether it was later withdrawn.

What this doesn't mean

It doesn't mean you need a lawyer on retainer, and it doesn't mean patient care grinds to a halt while someone fills out four separate forms. It means the consent capture needs to actually distinguish between "treat me" and "message me about offers" — most clinics that get this wrong aren't being reckless, they just never separated the two.

Clinitricks captures all four consent types — data processing, treatment, communications, and data sharing — each versioned, timestamped, and withdrawable by the patient at any time, in person or via a secure link. It's built into every plan, not an add-on.

Get the free consent template pack (PDF) → Request a demo →

This is general information, not legal advice — for anything specific to your clinic's situation, a qualified professional is the right call.

Related reading