Can Hospitals Share Patient Data with Third Parties?

Share & spread the love

Key Takeaways

  • Hospitals in India cannot freely share a patient’s medical information with third parties. Medical records, diagnoses, test reports, prescriptions and other health information are confidential and should generally be disclosed only for a lawful and legitimate purpose.
  • Patient consent is an important basis for sharing medical information with outside parties. However, consent is not required in every case. Disclosure may also be permitted where it is necessary for treatment, required by law, ordered by a court or justified by a serious and identified public safety concern.
  • Hospitals may share relevant information with doctors, diagnostic laboratories and other healthcare professionals involved in treatment. Such disclosure should ordinarily remain limited to information necessary for providing healthcare.
  • Employers, relatives, marketing companies and other private parties do not automatically acquire a right to access a patient’s complete medical records merely because they request them.
  • Mental health records and HIV-related information receive additional statutory protection under the Mental Healthcare Act, 2017 and the Human Immunodeficiency Virus and Acquired Immune Deficiency Syndrome (Prevention and Control) Act, 2017.
  • Digital medical information is also subject to data protection and information security requirements. Health conditions and medical records have traditionally been treated as sensitive personal data under India’s information technology framework.
  • The Digital Personal Data Protection Act, 2023 introduces a wider framework for digital personal data. However, as of August 2026, several major provisions governing consent, processing and data fiduciary obligations are still awaiting commencement under the phased implementation notified in November 2025.

What Is Patient Data?

Patient data is information relating to an individual that is collected, generated, received or maintained in connection with healthcare.

It includes much more than a hospital registration form. Information generated during consultation, testing, diagnosis, treatment and hospitalisation can form part of a patient’s medical data.

LawBhoomi
Add LawBhoomi as your preferred source on Google.
Add Now →

Common examples include:

  • personal details such as name, age, address and contact information;
  • symptoms and previous medical history;
  • diagnosis and treatment records;
  • prescriptions and medicine details;
  • blood tests, pathology reports and other investigation results;
  • X-rays, scans and other diagnostic images;
  • surgical and hospitalisation records;
  • mental health information;
  • reproductive and sexual health information;
  • biometric information;
  • insurance and billing records; and
  • electronic health records maintained by hospitals and digital healthcare systems.

Medical information is particularly sensitive because its disclosure may affect an individual’s privacy, dignity, employment, insurance, personal relationships and social life.

For this reason, patient confidentiality forms an important part of healthcare law and medical ethics in India.

Can Hospitals Share Patient Data with Third Parties?

Yes, hospitals can share patient data with third parties in India, but only in legally permissible circumstances.

LawBhoomi
Explore the latest legal opportunities for law students and lawyers.
Explore Opportunities →

A hospital does not obtain an unrestricted right over medical information simply because it collected or created that information during treatment.

As a general principle, identifiable patient information should remain confidential unless there is a proper basis for disclosure.

Patient data may commonly be shared where:

  • the patient has authorised the disclosure;
  • sharing is necessary for diagnosis or treatment;
  • information is required for processing a legitimate insurance claim;
  • a statute requires the hospital to report particular information;
  • a court or competent authority requires production of records;
  • information must be reported to public health authorities;
  • disclosure is necessary because of a serious and identified risk; or
  • another specific legal exception applies.

The purpose and extent of disclosure are also important. Even where sharing is permitted, it does not necessarily follow that a third party should receive the patient’s entire medical history.

What Is Medical Confidentiality?

Medical confidentiality means that information disclosed or generated during the doctor-patient relationship should ordinarily remain private.

Patients frequently have to provide highly personal details to doctors so that proper diagnosis and treatment can take place. The healthcare system therefore depends on confidence that such information will not be unnecessarily disclosed.

The Code of Medical Ethics Regulations, 2002 recognises this professional duty. A registered medical practitioner is generally expected not to disclose information learnt during professional attendance except in legally recognised circumstances.

This duty applies not merely to a formal diagnosis. It may extend to information concerning symptoms, medical history, test results and other facts obtained during professional treatment.

LawBhoomi
Learn at your own pace with LawBhoomi's recorded law courses.
View Recorded Courses →

Confidentiality, however, is not absolute.

When Can a Doctor Disclose Confidential Information?

The medical ethics framework recognises important exceptions to the general rule of confidentiality.

When a Court Orders Disclosure

Medical information may be disclosed where a court of law requires production or disclosure of the information.

A doctor or hospital generally cannot refuse to comply with a legally valid court order merely by relying on medical confidentiality.

However, disclosure should remain connected with the scope of the judicial requirement.

When There Is a Serious and Identified Risk

Confidentiality may also give way where there is a serious and identified risk to a particular person or the community.

This exception is narrower than a general concern that something harmful might occur. The risk should be sufficiently serious and identifiable to justify interfering with confidentiality.

When a Disease Must Be Reported

Certain communicable or notifiable diseases may have to be reported to appropriate public health authorities.

The purpose of such reporting is to allow authorities to undertake surveillance, disease-control measures, contact tracing or other public health functions required under law.

LawBhoomi
Find the latest legal internship opportunities, updated daily.
Find Internships →

Is Patient Consent Required before Sharing Medical Records?

Consent is one of the most important grounds for sharing identifiable patient information.

Where a hospital proposes to provide medical information to an unrelated third party, there should ordinarily be clear authority for that disclosure unless another lawful exception applies.

Consent may be relevant when information is shared with:

  • an insurance company;
  • a third-party administrator;
  • another healthcare institution;
  • an authorised representative;
  • an employer for a specific medical purpose;
  • a researcher using identifiable information; or
  • another private organisation.

Consent should also be understood in relation to purpose.

Permission to collect information for treatment does not automatically amount to permission to use the same information for unrelated marketing, advertising, profiling or commercial activities.

Hospitals should therefore consider why information was originally collected and why it is now proposed to be disclosed.

Are Medical Records Sensitive Personal Information?

Medical information has traditionally received heightened protection under India’s information technology framework.

The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 identify categories such as physical and mental health conditions, medical records and history and biometric information as sensitive personal data or information.

This classification is important because organisations handling such information are expected to follow requirements concerning collection, disclosure and reasonable security practices.

Hospitals maintaining electronic databases must therefore consider not only intentional sharing of patient records but also protection against unauthorised access, leaks and cyber incidents.

Can Hospitals Share Patient Data with Other Doctors?

Yes. Relevant medical information can generally be shared with healthcare professionals who are genuinely involved in diagnosis or treatment.

For example, information may need to pass:

  • from a general physician to a specialist;
  • from a hospital to a diagnostic laboratory;
  • from a surgeon to an anaesthetist;
  • between departments of the same hospital;
  • from one hospital to another when a patient is transferred; or
  • between healthcare professionals responsible for continuing care.

Modern medical treatment often requires multidisciplinary care. Confidentiality cannot reasonably prevent doctors involved in the same treatment process from receiving necessary information.

However, healthcare access should still follow a need-based approach. A person working within a hospital should not automatically have unrestricted access to every patient’s complete medical record merely because that person is part of the organisation.

Can Hospitals Share Medical Records with Insurance Companies?

Hospitals frequently share patient information with health insurers and third-party administrators when processing cashless treatment, reimbursement or insurance claims.

Such information may include:

  • diagnosis;
  • date and reason for admission;
  • treatment provided;
  • investigation reports;
  • discharge summaries;
  • medical bills; and
  • documents necessary to establish the validity of the claim.

Sharing information for an insurance claim should remain connected with the insurance purpose.

An insurer does not necessarily become entitled to every medical record ever maintained by a hospital merely because a claim has been submitted.

Disputes concerning health insurance may also raise questions of consumer protection in insurance services, particularly where claims are delayed, rejected or handled unfairly.

Can Hospitals Share Medical Information with Employers?

Employers do not automatically have a right to obtain an employee’s complete medical records directly from a hospital.

Situations may arise where medical information is relevant to employment, such as a fitness examination, workplace injury claim or insurance arrangement. Even in such cases, the purpose and scope of disclosure remain important.

For example, a medical examination may be conducted to establish whether a person is fit to perform particular occupational duties. That does not necessarily justify giving the employer the person’s entire unrelated medical history.

Where confidential medical information is requested by an employer, hospitals should therefore identify the legal basis and scope of the proposed disclosure before releasing it.

Can Hospitals Share Patient Information with Family Members?

Being a family member does not automatically create an unrestricted right to access the medical records of a competent adult patient.

In practice, family members are often involved in healthcare decisions and doctors may communicate important information where the patient has permitted such involvement.

The position may also differ where:

  • the patient is a minor;
  • the patient lacks capacity to make a relevant decision;
  • a lawful representative has been appointed;
  • a nominated representative is recognised under a specific statute; or
  • an emergency requires communication for treatment.

However, a spouse, parent, sibling or other relative should not automatically be treated as legally entitled to every confidential medical detail of an adult patient.

Can Hospitals Share Patient Data for Marketing?

Hospitals should not treat medical databases in the same manner as ordinary commercial customer databases.

Patient details collected for diagnosis, treatment, billing or hospitalisation cannot automatically be used for unrelated commercial purposes.

Practices that may raise serious confidentiality and privacy concerns include:

  • selling patient databases to outside companies;
  • providing identifiable patient information to pharmaceutical businesses;
  • sharing details of particular medical conditions with advertising agencies;
  • allowing unrelated companies to profile patients according to diseases;
  • sending medical information to marketing companies without a lawful basis; and
  • publishing identifiable patient stories, photographs or case details without appropriate permission.

Professional ethics rules also restrict publication of identifiable patient photographs or case reports without permission where the identity of the patient can be made out.

Commercial convenience does not by itself override medical confidentiality.

Can Hospitals Use Anonymised Patient Data?

Properly anonymised information is different from identifiable medical data.

Hospitals, researchers and public authorities may require statistical information for purposes such as medical research, disease surveillance, public health planning and academic analysis.

Examples include information relating to:

  • the number of patients treated for a particular disease;
  • treatment success rates;
  • disease patterns within particular regions;
  • average hospital stay; or
  • demographic trends among patients.

The important question is whether an individual patient can reasonably be identified.

Simply removing the person’s name may not always be enough.

For example, a rare medical condition combined with age, occupation, place of residence and date of hospitalisation might allow a person to be identified even if the name has been deleted.

Anonymisation therefore requires consideration of all information that could reasonably lead back to the individual.

How Is Mental Health Information Protected?

Mental health information receives specific statutory protection under the Mental Healthcare Act, 2017.

Section 23 of the Act recognises the right of a person with mental illness to confidentiality concerning mental health, mental healthcare, treatment and physical healthcare.

Healthcare professionals providing treatment have a corresponding duty to maintain confidentiality.

The Act nevertheless recognises specific situations in which information may be disclosed.

These include circumstances where information needs to be shared:

  • with healthcare professionals for treatment;
  • with a nominated representative where legally necessary;
  • to protect another person from harm or violence;
  • to prevent a threat to life;
  • pursuant to an order of a court or statutory authority; or
  • for public safety and security where the statutory requirements are satisfied.

Importantly, where disclosure is necessary to protect another person from harm, the law adopts a limited approach. Only information necessary for addressing the risk should be disclosed.

This demonstrates an important principle of medical privacy: lawful disclosure does not automatically justify unlimited disclosure.

Is HIV-Related Information Confidential?

Yes. HIV-related information receives separate statutory protection under the Human Immunodeficiency Virus and Acquired Immune Deficiency Syndrome (Prevention and Control) Act, 2017.

The legislation restricts disclosure of a person’s HIV status and other private information connected with HIV.

Disclosure without informed consent is permitted only in particular circumstances recognised by the Act.

These may include certain disclosures:

  • between healthcare providers involved in treatment;
  • required by court orders;
  • necessary in specified legal proceedings; or
  • involving information that cannot reasonably identify the individual.

The Act also contains a specific mechanism under which HIV-positive status may, subject to strict statutory requirements, be communicated to a partner facing a significant risk of transmission.

HIV-related confidentiality is particularly important because unauthorised disclosure can expose individuals to stigma, discrimination and serious social consequences.

What Is the Position under the Digital Personal Data Protection Act, 2023?

The Digital Personal Data Protection Act, 2023 creates a broad legal framework governing digital personal data in India.

Hospitals holding electronic patient information are likely to fall within important parts of this framework once the relevant provisions become operational.

The Act introduces concepts including:

  • Data Principals;
  • Data Fiduciaries;
  • consent;
  • legitimate uses;
  • obligations concerning processing;
  • protection of personal data;
  • rights relating to personal data; and
  • consequences for non-compliance.

However, the implementation position requires attention.

On 13 November 2025, the Central Government notified the phased commencement of the Act. Certain institutional and preliminary provisions came into force immediately, while many important substantive provisions were scheduled to commence 18 months later.

Therefore, as of August 2026, it would be inaccurate to state that all substantive provisions of the DPDP Act relating to hospital data processing are already fully operational.

The Digital Personal Data Protection Rules, 2025 have similarly been notified with phased commencement arrangements.

Until the relevant provisions become effective, existing information technology requirements, medical confidentiality duties and sector-specific laws remain particularly important.

What Security Measures Should Hospitals Follow?

Patient confidentiality involves more than preventing deliberate disclosure. Hospitals must also protect information against unauthorised access, theft, accidental exposure and cyber incidents.

Reasonable safeguards may include:

  • restricting access to records according to professional responsibilities;
  • using secure hospital information systems;
  • implementing authentication and access controls;
  • securely transmitting medical records;
  • maintaining appropriate records of access;
  • preventing staff from accessing files without a legitimate healthcare or administrative purpose;
  • protecting physical records from unauthorised inspection; and
  • requiring third-party service providers to maintain suitable confidentiality and security safeguards.

A hospital may therefore face concerns even where information was not deliberately sold or handed over to an outside party. Poor security allowing unauthorised disclosure can itself have serious legal consequences.

What Can Happen If a Hospital Wrongfully Shares Patient Data?

Unauthorised disclosure of patient information can lead to different legal consequences depending on the circumstances.

Potential issues may include:

The available remedy depends on the nature of the violation.

For example, a complaint concerning a doctor’s professional conduct may have to be considered by the appropriate medical regulatory authority. A dispute involving paid healthcare services may involve consumer law issues. Other cases may require proceedings before a statutory authority or court.

Patient data disputes may also arise together with allegations of medical negligence and consumer rights in healthcare, particularly where improper handling of medical information forms part of a broader deficiency in hospital services.

The nature of the information, the identity of the recipient, the existence of consent, the purpose of disclosure and any resulting harm are therefore important in determining legal responsibility.

Is Patient Confidentiality an Absolute Right?

No. Patient confidentiality is strongly protected, but it is not absolute.

Indian law recognises circumstances where competing legal and public interests can justify disclosure.

A hospital may therefore be required to disclose information despite the absence of patient consent where, for example:

  • disclosure is ordered by a court;
  • reporting is mandatory under a statute;
  • an authorised government agency lawfully requires information;
  • a notifiable disease must be reported;
  • disclosure is necessary for continuing healthcare; or
  • a serious identified threat creates a recognised exception.

The existence of an exception does not mean that confidentiality disappears altogether.

A proportionate approach should ordinarily be followed. Information that is unnecessary for the lawful purpose should not be disclosed merely because some disclosure has become permissible.

Conclusion

Hospitals in India can share patient data with third parties, but they cannot do so freely or without a lawful basis. Medical records contain some of the most private information concerning an individual and are protected through professional confidentiality obligations, information technology rules and special healthcare legislation.

Patient consent is an important basis for disclosure, particularly where medical information is being provided to insurers, private organisations, representatives or parties outside the immediate healthcare relationship. At the same time, consent is not required in every circumstance. Hospitals may disclose information where it is necessary for treatment, required by legislation, ordered by a court, connected with public health reporting or justified by a serious and identified risk.

Family members and employers do not automatically acquire a right to obtain complete medical records. Similarly, patient databases should not be treated as unrestricted commercial resources for advertisers, pharmaceutical businesses or marketing agencies.

Special protection applies to particularly sensitive categories such as mental health information and HIV-related information. Hospitals must also protect digital and physical records against unauthorised access and accidental disclosure.

The Digital Personal Data Protection Act, 2023 will become increasingly important to the handling of electronic patient information as its substantive provisions come into force. As of August 2026, however, its implementation remains phased.

The central legal principle is therefore clear: patient information must ordinarily remain confidential, and any disclosure should have a legitimate legal or medical basis and remain limited to what is genuinely necessary for that purpose.


Attention all law students and lawyers!

Are you tired of missing out on internship, job opportunities and law notes?

Well, fear no more! With 2+ lakhs students already on board, you don't want to be left behind. Be a part of the biggest legal community around!

Join our WhatsApp Groups (Click Here) and Telegram Channel (Click Here) and get instant notifications.

Aishwarya Agrawal
Aishwarya Agrawal

Aishwarya is a gold medalist from Hidayatullah National Law University (2015-2020). She has worked at prestigious organisations, including Shardul Amarchand Mangaldas and the Office of Kapil Sibal.

Articles: 6390

Leave a Reply

Your email address will not be published. Required fields are marked *