OneCity
COMPLIANCE

Medical Records Retention Rules for Indian Hospitals: How Long to Keep What

Three years is the number everyone quotes and almost nobody applies correctly. Here is the full statutory map — every record class, the rule it sits under, the event that starts its clock — and what the DPDP Rules 2025 add on top.

There is no single medical records retention period in India. The Code of Medical Ethics sets three years for indoor patient records, but blood bank registers run five years, biomedical waste records five years, PC-PNDT records two years or until proceedings end, and staff radiation dose records for decades. A hospital has to hold every record class for the longest clock that touches it.

Why "three years" is the most misquoted number in Indian hospital compliance

Ask ten hospital administrators in Karnataka how long they must keep patient files and nine will say three years. They are quoting Regulation 1.3.1 of the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002, which requires every physician to maintain the medical records of indoor patients for three years from the date of commencement of treatment, in the standard proforma at Appendix 3. Regulation 1.3.2 adds that when a patient, an authorised attendant or a legal authority asks for those records, the request must be acknowledged and the documents issued within 72 hours. Regulation 7.2 makes failure on either count professional misconduct.

All of that is correct. It is also incomplete in three ways that cost hospitals money.

First, the clause covers indoor patients — admitted cases. It says nothing about OPD notes, and hospitals that run high-volume outpatient departments often assume this means OPD paper can be discarded freely. It cannot, because other laws and other liabilities reach the same encounter. Second, the clock runs from the commencement of treatment, not from discharge. For a patient admitted for eleven months, the file is already eleven months into its three years on the day they go home. Third, and most importantly, three years is the floor set by one instrument. It has never been the ceiling.

There is a live regulatory question sitting on top of this. The National Medical Commission notified its Registered Medical Practitioner (Professional Conduct) Regulations, 2023 on 2 August 2023 and then held them in abeyance by an amendment notification dated 23 August 2023, simultaneously adopting the 2002 Regulations as its own with immediate effect. As of this writing the NMC's own rules listing still shows the abeyance amendment and no replacement notification. The 2002 text therefore governs — but a hospital writing a records policy today should re-check the NMC site before signing it off, because a fresh conduct regulation would reset this section. We flag it rather than pretending the position is permanently settled.

The full text of the 2002 Code of Medical Ethics is published by the NMC and is worth reading in the original before anyone drafts policy from a summary.

The retention map: what each law actually demands

A mid-sized hospital in a tier-2 city typically operates under half a dozen record-keeping statutes at once, and none of them were drafted with reference to the others. The table below is the working map. Every period in it is drawn from the governing instrument named beside it, not from industry rule of thumb.

Record classGoverning instrumentMinimum retention
Indoor (inpatient) case recordsMCI Code of Ethics 2002, Reg. 1.3.13 years from commencement of treatment
Copies to patient or legal authorityMCI Code of Ethics 2002, Reg. 1.3.2Issued within 72 hours of request
Register of medical certificatesMCI Code of Ethics 2002, Reg. 1.3.3No period stated — treat as indefinite
Blood bank records and registersDrugs and Cosmetics Rules 1945, Rule 122P with Schedule F Parts XII-B and XII-C5 years from date of manufacture
Biomedical waste generation, treatment and disposal recordsBio-Medical Waste Management Rules 2016, Rule 145 years
PC-PNDT Form F, consent forms, sonographic platesPC-PNDT Rules 1996, Rule 92 years, or until final disposal of proceedings, whichever is later
Occupational radiation dose records for staffAtomic Energy (Radiation Protection) Rules 2004, as applied through AERB personnel monitoring requirementsUntil the worker attains or would have attained 75, or at least 30 years after the exposure work ends, whichever is later
Books of account (companies)Companies Act 2013, s. 128(5)8 financial years immediately preceding
Books and supporting documents (income tax)Rule 6F(5), Income-tax Rules 19626 years from the end of the relevant assessment year
Processing logs and traffic data for personal dataDPDP Rules 2025, Rule 6(1)(e)1 year minimum

Two entries need a caveat rather than a confident figure. The income tax line refers to the 1961 framework; the Income-tax Act, 2025 came into force on 1 April 2026 and renumbered the statute from 819 sections to 536, and sources disagree on whether the accompanying rules are cited as the Income-tax Rules, 2025 or 2026. The six-year practice has not changed, but the provision reference has, so a finance team should confirm the current numbering with its auditor rather than copying "Rule 6F" into a policy document unchecked. The radiation entry is drawn from AERB's personnel monitoring guidance implementing the 2004 Rules; the exact wording — 75 years of age, or not less than 30 years after termination of the work involving occupational exposure, whichever is later — is set out in AERB's published personnel monitoring document.

ONE PATIENT EPISODE, SIX DIFFERENT CLOCKS PC-PNDT Form F 2 yrs, or till proceedings end Indoor case record 3 yrs from start of treatment Blood bank register 5 yrs Biomedical waste log 5 yrs Company books of account 8 fin. yrs Staff radiation dose record until age 75, or 30 yrs after the work ends 0 2 3 5 8 years retained OneCity ERP

Read that chart as one admission, not six. A woman admitted for an obstetric emergency who receives a transfusion, a sonography and a chest X-ray generates records governed by four separate retention regimes inside a single episode of care. If the hospital purges the whole file at three years, it has breached the blood bank rule and possibly the PC-PNDT rule in the same action.

The rule that actually governs: the longest clock wins

The operating principle is simple to state and awkward to implement. Retention attaches to the record type, not to the patient, and not to the file. Where two instruments touch the same document, the longer period applies. Where a document is evidence in a proceeding, it survives every schedule until the proceeding ends.

This is where paper systems quietly fail. A physical MRD stores by admission number, so the only practical unit of destruction is the whole folder. Staff either keep everything forever, which fills the room and makes the 72-hour retrieval duty impossible to meet, or they weed by year, which destroys the five-year and eight-year classes along with the three-year ones. Neither outcome is defensible in front of an assessor or a consumer commission.

Digital systems solve this only if they are set up to. A record has to carry its own retention metadata from the moment it is created: what class it belongs to, which event starts its clock, and whether anything is holding it. That is a configuration decision, not a feature that appears by default, and it is one of the questions worth asking during any hospital ERP implementation or migration rather than after go-live.

Limitation periods, not retention rules, set the real floor

The statutes above tell a hospital the minimum it must keep. They say nothing about how long it will actually need the record. That number comes from litigation exposure.

Section 69 of the Consumer Protection Act, 2019 bars a District, State or National Commission from admitting a complaint filed more than two years after the cause of action arose. But sub-section (2) lets a Commission entertain a late complaint where the complainant shows sufficient cause, provided the Commission records its reasons for condoning the delay. Condonation is not rare. A claim arising from a 2020 admission can land in 2027, and it will be decided on the documents the hospital can produce.

Civil claims outside the consumer framework carry their own limitation periods, and in cases involving minors the clock behaves differently again, since a person under legal disability may generally sue after the disability ends. A paediatric admission is therefore an exposure that can outlive a three-year retention schedule by more than a decade.

The practical test. Consumer commissions routinely draw an adverse view where a hospital cannot produce the case sheet to rebut an allegation. Destroying a record on the last legal day of a three-year schedule is compliant and, in a contested claim, close to indefensible. Retention floors are not risk ceilings.

This is the reason most well-run private hospitals we work with in Bengaluru and across Karnataka set internal periods well above statutory minimums — commonly eight to ten years for adult inpatient records, and until majority plus a margin for paediatric cases. The cost of that is storage, which for digital records is now trivial compared with the cost of losing one contested claim. If storage economics are the objection, that is a conversation about architecture, and it is covered in more detail in our note on hospital data security, backup and CERT-In compliance.

Medico-legal cases break every schedule

Assault, poisoning, road traffic accidents, burns, suspected suicide, custodial injury — the MLC register and its supporting documents sit outside ordinary retention thinking, because the associated criminal proceeding can run for years and the record is evidence.

We could not identify a single central rule fixing an MLC retention period for hospitals. State health department circulars and individual hospital policies vary, and several states direct permanent retention of the MLC register itself while treating the clinical file separately. Anyone writing policy should obtain their own state's current directive rather than adopting a figure from a national template — and we say that plainly because the alternative is a hospital confidently destroying evidence on a schedule that never applied to it.

The PC-PNDT drafting is the model worth copying internally even where it does not strictly apply: keep for the stated period or until final disposal of any legal proceeding, whichever is later. Written into an ERP as a legal-hold flag, that single sentence prevents most catastrophic deletions.

What DPDP changes: you now have to justify keeping data too

Until recently, Indian hospital records policy was a one-directional problem — keep enough, for long enough. The Digital Personal Data Protection Act, 2023 adds pressure from the other side. Section 8(7) requires a data fiduciary to erase personal data once the specified purpose is no longer being served, unless retention is necessary for compliance with any law in force.

The Digital Personal Data Protection Rules, 2025 were notified in the Gazette on 13 November 2025 (G.S.R. 846(E)) with a staggered commencement. Definitional and Board-procedure provisions took effect immediately; the substantive obligations phase in over eighteen months, which places the main compliance date around May 2027. Commentary varies slightly on the exact phasing of less-central provisions, and at least one analysis dates the final phase to 13 May 2027 — close enough for planning, not close enough to put in a board paper without checking the Gazette text.

Two features matter for hospitals specifically:

The net effect is that a hospital now needs a documented legal basis for every retention period it applies, and an audit trail proving that access to retained data was controlled. Neither is achievable with a shared login and a shelf. We have written separately about the access side of this in our piece on role-based access control under the DPDP Rules, and about the identity layer in ABDM and ABHA integration, where consent artefacts create yet another record class with its own lifecycle.

Destruction is a compliance event, not an absence of one

Hospitals prepare carefully for keeping records and casually for getting rid of them. Assessors and litigators look at both.

A defensible destruction produces its own paperwork: a list of what was destroyed identified by record class and date range, the retention rule relied on, the name and designation of the officer who authorised it, the method used, the date, and a witness signature. That certificate is the hospital's evidence that the record is gone lawfully rather than conveniently. Without it, absence looks like concealment.

Digital destruction is harder than paper destruction, and this catches people out. Deleting a row from the live database does not remove it from last night's backup, the offsite replica, the reporting warehouse or the departing vendor's export. A retention policy that stops at the application layer is a policy that has not actually been implemented. The same logic applies to biomedical waste documentation, where the disposal record has its own five-year life independent of the clinical file — a point we cover in our page on biomedical waste management software. The CPCB publishes the consolidated 2016 Rules for anyone who wants the primary text.

RETENTION LIFECYCLE INSIDE THE ERP Classify record type tagged at creation Start clock trigger event, not file date Legal hold blocks purge if flagged Review MRD officer approves list Destroy + log certificate, immutable entry OneCity ERP

What accreditation assessors actually check

Records retention comes up in accreditation as a documentation question and a demonstration question. Hospitals prepare for the first and get caught by the second.

1

A written policy that names periods and their legal basis

Not "records are retained as per statutory requirements." A table: record class, period, the rule it comes from, the event that starts the clock.

2

Evidence of authorised destruction

Destruction certificates for the last cycle, signed, with the authorising officer named. A policy with no destruction history usually means nothing was ever destroyed, which is its own finding.

3

A live retrieval test

An assessor picks an admission from two years ago and asks for the file. The 72-hour statutory duty is the outer limit for patient requests; an assessor expects minutes. This single test exposes more MRD weakness than any document review.

4

Access control and audit trail on retained records

Who opened which record, when. Old records are the ones most likely to be accessed without a clinical reason, and the least likely to be monitored.

5

Legal hold handling

Show a case currently under litigation and demonstrate that its records are excluded from the purge queue by system control, not by someone remembering.

Hospitals working toward accreditation will find the retention policy sits inside the wider information management requirements — see our page on NABH accreditation software for how the documentation set fits together. State registration adds a further layer in Karnataka, covered in our note on KPME registration and hospital software.

Configuring retention in a hospital ERP

The gap between a written policy and an enforced one is configuration. Five things have to be true in the system.

Every record carries a class tag at creation. Lab report, transfusion record, Form F, MLC, biomedical waste manifest, consent artefact, invoice. If classification happens later, it will not happen.

The clock start event is stored, not inferred. This is the detail most implementations get wrong. Commencement of treatment, date of manufacture for a blood component, date of test, date the exposure work ended for a radiation worker — these are different fields on different tables. Using the file creation timestamp as a proxy produces schedules that are wrong by months in both directions.

Legal hold is a system flag that overrides everything. Set at case level, it removes every associated record from every purge queue until it is cleared, and clearing it is itself a logged, authorised action.

Purge is proposed, never automatic. The system generates a candidate list; a named officer reviews and approves; destruction is executed; a certificate is produced and stored permanently. The certificate outlives the record.

Backups honour the same schedule. If your retention policy says a class is destroyed at five years and your backup rotation keeps full images for seven, you have not destroyed anything. This is also the moment to check what happens if you change vendors, because export completeness and format determine whether a schedule survives a migration at all — the reason we wrote about vendor lock-in and data ownership in the first place.

Groups running more than one facility have an additional problem: the same record class can sit under different state directives in different locations, and consolidated reporting has to respect the strictest of them. That is handled at the tenancy layer, not with a spreadsheet, and it is one of the design points behind multi-location hospital ERP for chains and groups.

Where tier-2 and tier-3 hospitals usually lose this

The failures repeat. In rough order of how often we find them:

None of these are exotic. All of them are cheap to fix before an incident and expensive after one. If you are choosing a system now rather than repairing one, our guidance on choosing a hospital ERP for tier-2 and tier-3 hospitals covers the questions worth asking a vendor about record lifecycle before you sign.

Frequently asked questions

How long must an Indian hospital keep medical records?

There is no single answer. Indoor patient records must be kept for at least three years from the commencement of treatment under Regulation 1.3.1 of the 2002 Code of Medical Ethics. Blood bank records run five years, biomedical waste records five years, PC-PNDT records two years or until proceedings conclude, and staff radiation dose records for decades. Each record class follows its own rule, and where two rules overlap the longer one applies.

Does the three-year rule apply to OPD records as well?

Regulation 1.3.1 refers specifically to indoor patients. It does not set a period for outpatient records. That does not make OPD notes disposable, because limitation periods for consumer complaints and civil claims still reach outpatient encounters, and other statutes may apply to individual documents generated during an OPD visit. Most hospitals apply the same period to OPD records as a matter of policy.

When does the retention clock start — admission or discharge?

Under Regulation 1.3.1 it starts at the commencement of treatment, not at discharge. For long admissions this matters. Other rules use different trigger events: the date of manufacture for blood components, the date of the test for PC-PNDT records, and the end of exposure work for radiation dose records.

Can a hospital destroy records after the statutory minimum has passed?

Legally yes, if no proceeding is pending and no longer period applies. Commercially it is often unwise. A consumer complaint can be admitted beyond the two-year limitation period under Section 69(2) of the Consumer Protection Act, 2019 where the Commission condones the delay, and a hospital that cannot produce the case sheet is defending a claim without its primary evidence. Many hospitals set internal periods of eight to ten years for this reason.

How long should medico-legal case records be kept?

We could not find a single central rule fixing this for hospitals, and state directives vary. Several states require the MLC register to be retained permanently. The safe construction is to keep MLC records until final disposal of any related proceeding, and to obtain the current directive from your own state health department rather than relying on a national figure.

Does the DPDP Act require hospitals to delete patient records after three years?

No. The three-year deletion timeline in the Third Schedule of the DPDP Rules, 2025 applies to specified large e-commerce entities, social media intermediaries and online gaming intermediaries above stated user thresholds. Hospitals are not in that list. Section 8(7) of the Act requires erasure once the purpose is served, but retention required by law overrides it, and the retention rules described above are exactly that kind of law.

What does a hospital need to prove it destroyed records properly?

A destruction certificate identifying the record class and date range, the retention rule relied on, the authorising officer's name and designation, the method of destruction, the date, and a witness signature. Keep the certificate permanently. For digital records, also confirm the deletion propagated to backups, replicas and any reporting copies.

Do electronic records satisfy the retention requirement?

Yes, and Regulation 1.3.4 of the 2002 Code positively encourages computerisation for quick retrieval. What matters is that the electronic record is complete, retrievable within the required time, access-controlled, and covered by backups that themselves respect the retention schedule.

Related reading

Need a records policy your MRD can actually run, enforced by the system rather than by memory?

Book a demo