A list a clinic can work through in ten minutes, each line saying whether MedAppz enforces it for you, gives you the desk to do it, or cannot help at all. The score is worked out here in your browser and nothing you tick leaves it.
Read this first
This is not legal advice, and answering every line “yes” is not a certification. The section references point at the Digital Personal Data Protection Act, 2023 so that you can go and read the section — they are not a substitute for reading it, and no statutory text, period, penalty or schedule is reproduced anywhere on this page.
No named compliance reviewer has signed this page off yet. Several lines depend on the Rules rather than on the Act, and those are marked for a compliance reviewer where they appear. Take those first.
What this page can be exact about is the other half: what a clinic running MedAppz gets enforced for it, what it merely gets a desk and a clock for, and what no software can do on its behalf. Every one of those sentences names a mechanism in the running product, and the trust centre lists them with their evidence — including an honest list of what MedAppz does not do yet.
0 of 29 in placeAnswer the lines below and the count fills in as you go.The count is worked out on this page. Nothing you tick is sent anywhere, and refreshing starts again — this is a worksheet, not an account.
What the three labels mean
MedAppz does thisThe running system enforces it. You do not have to remember, and you can show an assessor where it is enforced.MedAppz gives you the deskThe register, the clock and the trail are there. A person still has to do the work and sign it.Yours to doNo software can do this one for you. It is on the page because leaving it out would make the list look easier than it is.
Notice and consent
What you told the patient before you took anything, and whether you can still produce the version they agreed to.
Does a patient see a notice — what you collect, what for, and how to complain — before you collect it?MedAppz gives you the desk
The notice is what makes the consent informed. It has to be available in English and in the languages of the Eighth Schedule.A consent definition carries its notice text and a version number, and the version a patient agreed to is stored on their consent record — so “which words did they see in March” has an answer in March’s row. The words themselves are yours to write.
DPDP s.5
Is consent taken for a stated purpose, rather than as one tick that covers everything?MedAppz does this
Consent under the Act is for a specified purpose. A single blanket agreement is the commonest thing a clinic gets wrong.Consent is stored per purpose, never as a flag on the patient. Messaging ships with two purposes that are deliberately separate: care messages about your own appointments, reports and bills, and campaigns. A campaign send cannot borrow the care consent.
DPDP s.6
Is marketing consent explicit, separate, and never pre-ticked?MedAppz does this
Anything that is not part of the care the patient came for needs its own agreement.The campaigns definition is marked as requiring explicit consent, so the engine refuses to treat an implied agreement as one, and it expires after a year rather than lasting forever. The enquiry form on this website obeys the same rule — that unticked box below is the same pattern.
DPDP s.6
Is consent checked at the moment a message goes out, not at the moment the list was built?MedAppz does this
A list built on Monday and sent on Friday is the gap complaints live in.Every outbound message writes a consent check row before it is queued — allowed or denied, with the reason, the purpose and what was being attempted. There is no read-only variant that skips the row, so a message you cannot find a check for did not happen.
DPDP s.6
Can a patient withdraw as easily as they agreed — and does withdrawing actually stop what is already queued?MedAppz does this
Withdrawal has to be as easy as giving. Stopping only the next send leaves tomorrow morning’s batch going out anyway.A withdrawal emits an event the messaging engine subscribes to, and everything already queued for that purpose is cancelled and marked as cancelled for that reason. Staff can record a withdrawal from the consent desk; a patient can ask anyone at the clinic.For a compliance reviewer: A STOP or UNSUBSCRIBE keyword on the inbound WhatsApp and SMS paths is not built yet. Until it is, withdrawal is a route a person answers, not a keyword — which is what this website’s own forms say.
DPDP s.6(6)
For a child’s record, do you take verifiable consent from a parent or guardian — and never use it for tracking or targeted advertising?Yours to do
A child’s data carries a stricter regime than an adult’s, and paediatric practices hit it every day.A consent record can name the proxy who gave it and their relationship, so the fact is on the record. MedAppz does not verify that the proxy is who they say they are, and it does not derive the requirement from the patient’s age — you have to apply it. Nothing in the product tracks a patient for advertising.For a compliance reviewer: How consent is to be verified is set by the Rules, not by the Act’s text. Confirm the method your clinic uses against the Rules in force.
DPDP s.9
The rights desk
What happens when a patient asks for their data, asks you to correct it, or asks you to erase it.
Can you give a patient a copy of what you hold about them, and a list of who you shared it with?MedAppz gives you the desk
The right to access is the one most likely to be exercised first, usually by someone who is already unhappy.The privacy desk takes the request, holds it against a clock, and refuses to let anybody act on it until the requester’s identity is verified and the record is matched — both are database constraints, not screen validation. There is also a printable statement of exactly who opened that patient’s file and why, with emergency access called out.
DPDP s.11
Is there a route to correct or complete a record, and does it leave a trail?MedAppz does this
Correcting a clinical record is not editing it. The old value has to remain visible.A signed clinical entry is amended, never edited — the database refuses an in-place change — so a correction is an addition with a name and a time on it, which is what both this Act and a medico-legal case want.
DPDP s.12
Can you act on an erasure request without destroying the clinical record you are required to keep?MedAppz does this
The two obligations look contradictory and are not. Identifiers go; the clinical facts stay under the retention you are required to apply.Erasure runs as pseudonymise-in-place: the name becomes a placeholder, contact points are emptied, the birth date keeps its year and loses its day and is marked estimated, and every stored government identifier becomes a marker. The MRN and the clinical facts survive, because that is what the record is.
DPDP s.12
When you keep something despite an erasure request, do you tell the person what you kept and why?MedAppz does this
Keeping data because a law requires it is allowed. Not saying so is the part that goes wrong.Each class of record considered produces a line the patient is handed — erased or retained, how many, and a sentence in plain words with the clinic’s own citation beside it. A record under a live legal hold refuses erasure outright and produces the written refusal, naming the hold.
DPDP s.12(3)
Can a patient nominate someone to exercise their rights if they cannot?MedAppz gives you the desk
The nomination right is short, easily missed, and matters most in exactly the cases a hospital sees.Nomination is one of the six request types the desk takes, and the requester’s relationship — self, nominee, parent, guardian, legal heir — is recorded on the request rather than assumed.
DPDP s.14
Have you named a grievance officer, and can a patient find how to reach them without asking you?MedAppz gives you the desk
A named, reachable officer is the route a complaint takes before it becomes a complaint to the Board.One live privacy officer per organisation, with designation, email and address, effective-dated — so “who was the officer in March” still has an answer after a handover. Publishing it on your own notice is your step.
DPDP s.13
Do you answer a rights request within a fixed period, and can you show when the clock started?MedAppz gives you the desk
A deadline you cannot evidence is a deadline you will be assumed to have missed.The due date is written onto the request when it is received, not computed when somebody opens the screen — so changing a setting cannot move a deadline that has already been given. The desk defaults to thirty days and shows what is past it.For a compliance reviewer: The response period comes from the Rules and not from the Act’s text, and this repository’s own notes have carried two different numbers. Confirm the period in force before relying on the default.
DPDP s.11–14 and the Rules
What you hold, and for how long
The half of the Act that is about deleting, which is the half nobody has a process for.
Have you written down how long you keep each kind of record, with the source you are relying on?MedAppz gives you the desk
A retention period with no citation is a number somebody invented, and it will not survive being asked about.Retention is stored as a rule with the basis beside it, and the patient’s erasure notice quotes that citation back. MedAppz ships no periods at all: a new clinic has none until it states its own, and the notice says exactly that rather than implying a policy exists.
DPDP s.8(7)
Does anything actually delete on schedule, or is the policy a document?MedAppz gives you the desk
A retention policy that nothing executes is the commonest finding in any data audit.Sweeps run against the sources they understand, and each run records what it looked at, what it acted on, what it skipped because of a hold, and — when nothing happened — why. A dry run cannot have acted on anything; that is a database constraint. Which sources are swept is a short, named list rather than everything.
DPDP s.8(7)
Can you stop a deletion when a record is wanted for a court case, a police matter or an inquiry?MedAppz does this
Deleting under an investigation is a worse problem than keeping too long.A legal hold blocks both the sweep and an erasure request, and a hold whose scope the code cannot read blocks them too rather than being ignored — a malformed order refuses the deletion instead of failing open.
DPDP s.12(3)
Does the same answer hold for paper — files, registers, consent forms in a cupboard?Yours to do
The Act does not stop at the software, and a hospital’s paper is usually where the oldest identifiers are.MedAppz tracks physical file movement and chases record deficiencies, but paper you never registered is paper it does not know about. The cupboard is yours.
DPDP s.8
Reasonable security safeguards
The Act says “reasonable”; an assessor and a plaintiff will both ask what you actually did.
Does each person see only what their job needs?MedAppz does this
Everybody-sees-everything is the default in most clinic software and the first thing a questionnaire asks about.Every table holding a clinic’s records carries row-level security the account the application runs as is not allowed to switch off, and each screen and each write carries a permission on top of that. There is one deliberate exception — the API-key table, which authentication has to read before it knows which clinic you are — and it holds no patient data; the exemption is written into the database itself, so a second one cannot be granted quietly.
DPDP s.8(5)
Is there a record of who opened, searched and exported a patient’s file — one that cannot be quietly edited?MedAppz does this
A trail an insider can edit answers nothing.Record opens, searches and exports are written once — who, when, from which address, under which permission — and the log is hash-chained day by day, so removing or altering an entry breaks the chain. The chain is re-verified nightly.
DPDP s.8(5)
Is a second factor available, and required for the people who can see everything?MedAppz does this
A password on its own is the whole of most clinics’ perimeter.Two-factor is available to every user, and an organisation can require it of its administrators or of everyone — the sign-in enforces the choice rather than the screen suggesting it.
DPDP s.8(5)
Do you look, on a schedule, at who still holds powerful access?MedAppz gives you the desk
Access is granted in a hurry and removed never. The leaver who still has a login is the classic breach.A review campaign lists every powerful grant with the privileges it actually carried on the day the campaign opened, and each line is attested with a signed note or challenged. Revoking one takes two people.
DPDP s.8(5)
Are government identifiers stored in a form a stolen database would not hand over?MedAppz does this
An Aadhaar number in a spreadsheet is the highest-value row a clinic holds.Aadhaar and ABHA numbers are stored as a keyed hash plus the last four digits — never in full — so a record can still be matched and reconciled without the number being readable.
DPDP s.8(5)
When somebody leaves, is their access ended the same day — including on the phone in their pocket?MedAppz gives you the desk
This is a process, not a feature, and it is the one that gets skipped in a busy week.Every user can see their live sessions and end one, and an administrator can end them for somebody else. Deciding it has to happen on the last working day is yours.
DPDP s.8(5)
When something goes wrong
The obligation that starts on the worst day, when nobody has time to invent a process.
Is there a written process for a data breach — who is told, by whom, and in what order?Yours to do
The Act requires intimation to the Board and to every affected person. Both are hard to do quickly without a document.MedAppz keeps its own incident-response playbook and a published address for reporting a security concern, and would tell you about anything affecting your data. The notice to your patients and to the Board is the clinic’s, because the clinic is the one they gave their data to.For a compliance reviewer: The breach clock and the form come from the Rules and from the CERT-In directions, and they are different clocks. Confirm both with a reviewer before you need them.
DPDP s.8(6)
Could you actually reach every affected patient — do you hold a current number for them?MedAppz gives you the desk
The obligation is to tell the people affected. A dead phone number is not an excuse anybody accepts.Contact details sit on the patient record and the messaging engine can send to a list. Nothing in the product knows whether a number is still the patient’s.
DPDP s.8(6)
Everyone else who touches it
A processor’s mistake is still your obligation, and the list is always longer than a clinic expects.
Do you know every company that touches your patients’ data, and what each one receives?MedAppz gives you the desk
Your software vendor, its hosting, its messaging providers, your accountant, your billing agency. Most clinics can name two of them.MedAppz publishes its own sub-processor table — who, what they receive, and which region — on the trust centre, and keeps it as a list rather than a sentence. Yours will have rows this list does not.
DPDP s.8
Do you know which of your data leaves India, and have you decided that on purpose?MedAppz gives you the desk
Transfer outside India is restricted by notification, and “our vendor uses an American service” is the usual way it happens without anybody choosing.Some optional features send data outside India — AI drafting, transcription, video visits and message delivery. They are named one by one in the sub-processor table with the region each sits in, so the decision is yours to make rather than yours to discover.For a compliance reviewer: Which transfers are restricted depends on Government notification. Take the sub-processor table to a reviewer rather than reading a country column as approval.
DPDP s.16
Is there a written contract with each of them covering what they may do with the data?Yours to do
A processor without a contract is a transfer with nothing behind it.MedAppz publishes its own terms and a processing addendum in the legal centre, readable without an account. The contracts with everybody else you use are yours to hold.
DPDP s.8
If you are bigger than you think
One line, because getting it wrong is expensive and most clinics never check.
Have you checked whether you are a Significant Data Fiduciary — and if so, appointed a Data Protection Officer in India, run an impact assessment and an audit?Yours to do
The extra duties are substantial, and a hospital chain is a more plausible candidate than a single clinic.Nothing in the product decides this for you, and MedAppz does not claim to make you compliant with it. The audit trail and the access reviews are evidence an auditor can use; the appointment and the assessment are acts of the organisation.For a compliance reviewer: Whether a class of fiduciary is notified as significant is a Government decision. This line exists so a reviewer is asked the question, not so this page can answer it.
DPDP s.10
What this does not do
This is not legal advice and it is not a certification. It is a working list, written from the Act’s own structure and from what this product does; the section references have not yet been signed off by a named compliance reviewer, and the lines flagged below are the ones to take to one first.
Get the scored report, with your gaps written out
Everything above stays free and open — this page works without giving us anything. Tell us who you are and the printable version opens right here, on this page, with no email to wait for.