Estimated reading time: 5 minutes
Part of Selling AI to Indian Hospitals, a field guide.
If you sell AI into Indian healthcare, there is one sentence that quietly ends deals: “we’re HIPAA compliant.” HIPAA is an American law. It has no force in an Indian hospital, and leading with it tells a hospital’s IT head that you have not done your homework. The law that actually governs patient data here is the Digital Personal Data Protection Act, 2023 (DPDP), and the questions a hospital will ask you flow directly from it.
At BeyondChats we build AI that talks to patients and prospective patients, so these are the questions we prepare for before any conversation with a hospital’s technology or compliance team. If you are building anything that touches patient data in India, here are the five that decide whether you get past the first IT call.
The five, in one line each:
- Who is the data fiduciary, and who stays liable?
- Where does the patient data physically live?
- Is there a Data Processing Agreement (DPA)?
- Who can access the data, and is it logged?
- What is your deletion and consent story?
1. Who is the data fiduciary, and who stays liable?
Under DPDP the hospital is almost always the data fiduciary: it decides why and how patient data is processed, and it carries the legal responsibility for that data. You, the vendor, are the data processor acting on its instructions. The critical point that trips up both sides: the hospital cannot outsource its liability by outsourcing the data. If you mishandle it, the hospital is still answerable to the patient and the regulator. That is exactly why their questions get sharp: your risk is their risk.
2. Where does the data physically live?
“Where does patient data reside?” is usually the first concrete question, and the wrong answer is a hand-wave about “the cloud.” Health information is treated as sensitive, and DPDP allows the government to restrict transfers of personal data to certain countries. A meaningful share of healthcare AI in India, by some 2025 estimates well over half, is deployed on-premise or in-country precisely for this reason. Have a crisp answer: which region, which provider, and whether an on-prem or India-hosted option exists for buyers who need it. “We can host it in India” is often the difference between a pilot and a polite no.
3. Is there a Data Processing Agreement?
A serious hospital will expect a Data Processing Agreement (DPA) with every vendor that touches patient data, defining what you may process, for what purpose, for how long, and what happens on termination. If you don’t have a template DPA ready, you look like a security risk. If you do, you look like a partner who has been through this before. Bring it to the table; don’t wait to be asked.
4. Who can access the data, and is it logged?
Access control and audit logging are not nice-to-haves; they are what a compliance team checks. Expect: role-based access, a record of who saw what and when, encryption in transit and at rest, and a clear answer on whether your own engineers can see raw patient data (the best answer is “no, not by default”). If a breach ever happens, the audit trail is what protects both of you, so treat it as a selling point, not a checkbox.
5. What is your deletion and consent story?
DPDP gives people rights over their data, including the right to have it erased. A hospital will want to know how consent is captured for the processing you do, and how a patient’s data is deleted on request or when the contract ends. Vague answers here read as “we’ve never thought about this.” A one-page note on consent capture and a documented deletion process does more for trust than any slide about your model.
The runway is shorter than it looks
DPDP’s rules are being phased in, with compliance timelines widely expected to bite through 2026 and into 2027. Hospitals know this, which is why data questions are moving earlier in the buying conversation, not later. The vendors who win are the ones who treat compliance as part of the product, answered before it’s asked, rather than a legal afterthought bolted on at contract stage.
None of this is legal advice: talk to a real DPDP practitioner before you sign anything. But if you can answer these five questions clearly and calmly, you’ll clear the bar that stops most AI vendors at the door of an Indian hospital.
This is part of what I’m writing about here: selling and building AI for Indian healthcare, in public. If that’s your world too, here’s why I started writing, and the monthly letter below is where the numbers and the messier lessons go.
Next in the field guide: Who actually signs?, reading the buying committee, the owner-doctor and the tender portal. Or see all the guides.
Get the monthly letter
Building BeyondChats in public: the numbers, the decisions, and what broke. One email a month. No spam, unsubscribe anytime.