OneCity
COMPLIANCE

Role-Based Access Control in Hospital ERP: What DPDP Rules 2025 Actually Require

Rule 6 of the DPDP Rules 2025 requires access control and one-year audit logging. Most hospital software runs on shared logins that can't meet it.

Short answer: The DPDP Rules 2025 (notified 13 November 2025) require role-based access control and at least one year of audit-log retention as part of "reasonable security safeguards" under Rule 6. Most hospital software in India today runs on shared department logins, which cannot produce the audit trail the Rule requires.

Walk into most tier-2/3 hospital front desks and the login screen shows one account: "reception," password taped to the monitor, used by whoever is on shift. It works, in the sense that registrations get entered. It fails a very specific test that's now written into law: if something goes wrong with that account, there is no way to say which of six people typing on it that week actually did it.

ROLE-BASED ACCESS, BY DEPARTMENT Front Desk Registration only Billing Clerk Billing + GST Nurse / Doctor Clinical record Admin Full audit view OneCity ERP

What the DPDP Rules 2025 actually say about access control

The Digital Personal Data Protection Rules, 2025 were notified in the Gazette on 13 November 2025, giving operational effect to the Digital Personal Data Protection Act, 2023. Rule 6, covering security safeguards, requires data fiduciaries, which includes hospitals processing patient data, to implement encryption or masking of personal data, strict access control over the computer resources used to process it, and logging with monitoring sufficient to detect unauthorised access. Multiple independent legal and compliance sources publishing after the notification consistently cite a minimum one-year retention period for these logs, tied to the same Rule.

Not every provision of the Rules is in force yet. A block of provisions, including Rule 4, phases in over the following year, and the bulk of the substantive rules, including 6 and 7, come into force eighteen months after the Gazette notification, which multiple compliance guides place around May 2027. That gap is a runway, not a reason to wait: building role-based access into a hospital's systems and workflows takes longer than flipping a setting, and retrofitting it under enforcement pressure is a worse position than building it now.

Why a shared login defeats the entire requirement

Rule 6's logging requirement exists to answer one question after an incident: who accessed what, and when. A shared "reception" or "nursing station" login makes that question unanswerable, regardless of how good the underlying software's logging feature is. The system can log that "reception" opened a patient record at 3:14 PM; it cannot say which of the three people who used that terminal that shift actually did it. This is the single most common gap between what hospital software is technically capable of and what's actually configured on the ground, and it's usually a training and discipline gap, not a software one.

What role-based access actually looks like, department by department

RoleCan seeCannot see / do
Front desk / registrationDemographics, appointment scheduling, insurance/ABHA linkageClinical notes, billing rates, payroll
Billing clerkCharges, GST invoice generation, payment statusClinical diagnosis detail beyond billing codes
Nurse (ward-assigned)Assigned patients' vitals, medication administration recordPatients outside their assigned ward, payroll, billing
Treating doctorFull clinical record for their own patientsPatients under another doctor unless referred or covering
Pharmacy staffPrescriptions, stock, dispensing logFull clinical history beyond the prescription
AdministratorFull audit log, user management, configurationNothing structurally, but every action is itself logged

The administrator row matters as much as any other: an admin account with unrestricted access and no logging on its own actions is a bigger risk than any single clinical role, since it's the account most likely to be used, or misused, to cover something up.

Building this into a hospital ERP's day-to-day reality

Access control that only exists in a policy document, while every terminal actually logs in as "admin" because it's faster, satisfies nothing. A few practical steps that make role-based access survive contact with a busy shift:

  1. One login per person, tied to their actual role, set up during onboarding, not retrofitted later. This is also where implementation and data migration matters: user accounts should be provisioned as part of go-live, not added ad hoc after.
  2. Roles scoped to what the job needs, not what's convenient to grant. A front-desk account that can also see billing rates because "it was easier to set up that way" is exactly the kind of scope creep Rule 6 is aimed at.
  3. Ward or department-level scoping for clinical staff, not blanket hospital-wide access, since a nurse assigned to one ward has no legitimate need to browse records from another.
  4. Logging that's actually reviewed, not just collected. A log nobody looks at until after an incident answers the audit question too late to prevent anything.
  5. A documented policy that matches the actual configuration, since a Data Protection Board review after a breach checks both, and a mismatch between the two is worse than either alone.

Where this connects to the rest of a hospital's DPDP posture

Access control doesn't stand alone. It's one of several safeguards under Rule 6 sitting alongside encryption and breach-response timelines, covered in more depth in our hospital ERP data security and CERT-In compliance guide, and it depends on the same underlying principle running through the hospital's broader DPDP Act compliance: data collected and accessed for a specific purpose should stay scoped to that purpose, for that role, not spread across every account with a login.

A caveat worth stating plainly

Not every source describing the DPDP Rules 2025 agrees on exact enforcement dates for every provision, and the phased commencement schedule is genuinely complex, with different rules taking effect at different points after the November 2025 notification. What's consistent across every source checked for this piece is Rule 6's substance: access control and one-year log retention as baseline security safeguards. The exact enforcement date matters less than the direction, which is unambiguous, and hospitals waiting for the enforcement date to arrive before building this are choosing the more expensive path.

How to test whether access control actually works, not just exists

A configuration screen showing roles and permissions proves the feature exists, not that it's being used correctly. A more honest test: pick five random staff logins across different shifts and ask what each one can see. If two nurses on different wards share a login, or if the billing clerk's account can open a full clinical note unrelated to any invoice, the system is configured but the access control isn't actually functioning as intended. This kind of spot-check takes under an hour and surfaces the gap between paper policy and real practice faster than any audit document review.

Common mistakes hospitals make when setting this up

Sources

Digital Personal Data Protection Rules, 2025, Gazette Notification G.S.R. 846(E), 13 November 2025, Ministry of Electronics and Information Technology (meity.gov.in). Digital Personal Data Protection Act, 2023, Section 8 (meity.gov.in).

Frequently asked questions

What does Rule 6 of the DPDP Rules 2025 require for access control?

Rule 6 requires reasonable security safeguards including encryption or masking, strict access control over systems holding personal data, and logs and monitoring to detect unauthorised access, with audit logs retained for at least one year.

When do the DPDP Rules 2025 security provisions become enforceable?

The Rules were notified on 13 November 2025. Most substantive provisions, including Rule 6 security safeguards, take effect 18 months after notification, placing enforceability around mid-2027, though hospitals are advised to implement controls well before that date.

Does role-based access control mean every staff member needs a different login?

Yes. Shared logins make it impossible to produce a meaningful audit trail, which defeats the purpose of the logging requirement under Rule 6. Each staff member needs an individual account mapped to a role.

What roles typically exist in a hospital ERP?

Common roles include front-desk registration, billing clerk, nursing staff, treating doctor, pharmacy staff, lab technician, and administrator, each scoped to only the data and functions their job requires.

Is a written access-control policy required, or just the technical controls?

Both. A Data Protection Board review after a breach will look at whether documented policy and actual system configuration matched at the time of the incident, not just whether technical controls existed somewhere.

Related reading

See role-based access mapped to your hospital's departments.

Talk to OneCity