How a Healthcare Chain Became DPDPA Compliant in 8 Weeks — Without Disrupting Patient Care
A multi-location hospital chain in Gujarat was collecting Aadhaar numbers, medical records, and insurance details from thousands of patients daily — with no formal consent mechanism, no data mapping, and no breach notification process. With DPDPA enforcement approaching, they needed to get compliant fast without disrupting clinical operations.
8 Weeks
To Full Compliance
15,000+
Patient Records Mapped
0
Disruption to Clinical Ops
Client Background
A healthcare group operating 4 hospitals and 12 clinics across Gujarat. They process sensitive personal health data for over 15,000 patients monthly — Aadhaar numbers, prescriptions, diagnostic reports, insurance claims. None of this data handling had ever been formally assessed for privacy compliance.
The Problem
No consent mechanism — patients weren't informed how their data was used or shared
Personal health data was shared with insurance partners and labs without any processing agreements
No data inventory — nobody knew exactly what data lived where across their 16 locations
Staff had no training on data handling obligations under the new DPDPA
No breach notification process — if data leaked, they'd have no idea how to respond within the mandated timeline
What We Did
Conducted full data mapping across all 16 locations — identified every system, database, and paper process handling personal data
Designed and implemented consent management framework integrated into their patient registration workflow
Drafted and executed data processing agreements with all third-party labs, insurance partners, and IT vendors
Created breach notification playbook with clear escalation paths meeting DPDPA's timeline requirements
Trained 200+ staff (doctors, nurses, admin, IT) on their specific data handling obligations
Set up ongoing compliance monitoring with quarterly reviews
Technologies Used
Custom data mapping methodology for healthcare
Consent management integration with existing HMS (Hospital Management System)
Data Processing Agreement templates (DPDPA-compliant)
Breach response playbook framework
Results
Full DPDPA compliance achieved in 8 weeks
15,000+ patient records properly mapped and categorised
Consent collection integrated into existing registration workflow — adds less than 30 seconds per patient
Zero disruption to clinical operations during the entire project
All 34 third-party vendors now have signed data processing agreements
Staff compliance awareness jumped from 12% to 94% (post-training assessment)
Client Outcome
"We handle incredibly sensitive patient data every day, and honestly, we had no idea how exposed we were. The Nonce team understood healthcare workflows — they didn't give us some generic compliance checklist. Everything was designed around how our hospitals actually work. Our patients' data is finally being handled the way it should be."