Rule 6 of the DPDP Rules 2025 requires access control and one-year audit logging. Most hospital software runs on shared logins that can't meet it.
Walk into most tier-2/3 hospital front desks and the login screen shows one account: "reception," password taped to the monitor, used by whoever is on shift. It works, in the sense that registrations get entered. It fails a very specific test that's now written into law: if something goes wrong with that account, there is no way to say which of six people typing on it that week actually did it.
The Digital Personal Data Protection Rules, 2025 were notified in the Gazette on 13 November 2025, giving operational effect to the Digital Personal Data Protection Act, 2023. Rule 6, covering security safeguards, requires data fiduciaries, which includes hospitals processing patient data, to implement encryption or masking of personal data, strict access control over the computer resources used to process it, and logging with monitoring sufficient to detect unauthorised access. Multiple independent legal and compliance sources publishing after the notification consistently cite a minimum one-year retention period for these logs, tied to the same Rule.
Not every provision of the Rules is in force yet. A block of provisions, including Rule 4, phases in over the following year, and the bulk of the substantive rules, including 6 and 7, come into force eighteen months after the Gazette notification, which multiple compliance guides place around May 2027. That gap is a runway, not a reason to wait: building role-based access into a hospital's systems and workflows takes longer than flipping a setting, and retrofitting it under enforcement pressure is a worse position than building it now.
Rule 6's logging requirement exists to answer one question after an incident: who accessed what, and when. A shared "reception" or "nursing station" login makes that question unanswerable, regardless of how good the underlying software's logging feature is. The system can log that "reception" opened a patient record at 3:14 PM; it cannot say which of the three people who used that terminal that shift actually did it. This is the single most common gap between what hospital software is technically capable of and what's actually configured on the ground, and it's usually a training and discipline gap, not a software one.
| Role | Can see | Cannot see / do |
|---|---|---|
| Front desk / registration | Demographics, appointment scheduling, insurance/ABHA linkage | Clinical notes, billing rates, payroll |
| Billing clerk | Charges, GST invoice generation, payment status | Clinical diagnosis detail beyond billing codes |
| Nurse (ward-assigned) | Assigned patients' vitals, medication administration record | Patients outside their assigned ward, payroll, billing |
| Treating doctor | Full clinical record for their own patients | Patients under another doctor unless referred or covering |
| Pharmacy staff | Prescriptions, stock, dispensing log | Full clinical history beyond the prescription |
| Administrator | Full audit log, user management, configuration | Nothing structurally, but every action is itself logged |
The administrator row matters as much as any other: an admin account with unrestricted access and no logging on its own actions is a bigger risk than any single clinical role, since it's the account most likely to be used, or misused, to cover something up.
Access control that only exists in a policy document, while every terminal actually logs in as "admin" because it's faster, satisfies nothing. A few practical steps that make role-based access survive contact with a busy shift:
Access control doesn't stand alone. It's one of several safeguards under Rule 6 sitting alongside encryption and breach-response timelines, covered in more depth in our hospital ERP data security and CERT-In compliance guide, and it depends on the same underlying principle running through the hospital's broader DPDP Act compliance: data collected and accessed for a specific purpose should stay scoped to that purpose, for that role, not spread across every account with a login.
Not every source describing the DPDP Rules 2025 agrees on exact enforcement dates for every provision, and the phased commencement schedule is genuinely complex, with different rules taking effect at different points after the November 2025 notification. What's consistent across every source checked for this piece is Rule 6's substance: access control and one-year log retention as baseline security safeguards. The exact enforcement date matters less than the direction, which is unambiguous, and hospitals waiting for the enforcement date to arrive before building this are choosing the more expensive path.
A configuration screen showing roles and permissions proves the feature exists, not that it's being used correctly. A more honest test: pick five random staff logins across different shifts and ask what each one can see. If two nurses on different wards share a login, or if the billing clerk's account can open a full clinical note unrelated to any invoice, the system is configured but the access control isn't actually functioning as intended. This kind of spot-check takes under an hour and surfaces the gap between paper policy and real practice faster than any audit document review.
Digital Personal Data Protection Rules, 2025, Gazette Notification G.S.R. 846(E), 13 November 2025, Ministry of Electronics and Information Technology (meity.gov.in). Digital Personal Data Protection Act, 2023, Section 8 (meity.gov.in).
Rule 6 requires reasonable security safeguards including encryption or masking, strict access control over systems holding personal data, and logs and monitoring to detect unauthorised access, with audit logs retained for at least one year.
The Rules were notified on 13 November 2025. Most substantive provisions, including Rule 6 security safeguards, take effect 18 months after notification, placing enforceability around mid-2027, though hospitals are advised to implement controls well before that date.
Yes. Shared logins make it impossible to produce a meaningful audit trail, which defeats the purpose of the logging requirement under Rule 6. Each staff member needs an individual account mapped to a role.
Common roles include front-desk registration, billing clerk, nursing staff, treating doctor, pharmacy staff, lab technician, and administrator, each scoped to only the data and functions their job requires.
Both. A Data Protection Board review after a breach will look at whether documented policy and actual system configuration matched at the time of the incident, not just whether technical controls existed somewhere.
See role-based access mapped to your hospital's departments.
Talk to OneCity