Name an accountable owner
Significant Data Fiduciaries must appoint an India-based Data Protection Officer who reports directly to the hospital Board.
Consent & Compliance Platform
Certinal makes DPDP compliance an operating standard for healthcare, not a project - every patient consent captured, signed, purpose-tagged, and audit-ready for the Data Protection Board, NABH surveys, and ABDM.
Under the DPDP Act, health data is sensitive personal data and the penalties are not symbolic. A single leaked record, an unlogged consent, or a missed breach notice can put a hospital in front of the Data Protection Board of India - with fines assessed per instance.
Before the Board asks - who owns DPDP?
Significant Data Fiduciaries must appoint an India-based Data Protection Officer who reports directly to the hospital Board.
Access, correction, and erasure across the EHR, LIS, billing, and every vendor holding a patient's records - captured and evidenced on time.
Purpose-tagged consent, DPIAs, and independent audit records kept ready as a by-product of everyday care.
Reduction in patient check-in wait times, with 100% automated, audit-ready consent logs across 70+ hospitals and 10,000+ beds.
One of Asia's largest healthcare networksWeekly documents signed directly in Epic, eliminating $210K+ in annual administrative cost across 30+ locations.
Independent primary-care networkOf patients sign consent forms digitally, saving 4 hours of staff effort a day for 1.1M+ patients served annually.
Leading Southeast Asia hospitalCompliance, mapped in
Enforceable agreements and protected health data, mapped to the Indian laws, healthcare standards, and security certifications regulated enterprises are held to.
Every patient consent timestamped, versioned, and exportable as proof on demand.
Section 5 (IT Act) electronic signatures for medical records, prescriptions, and consent forms - admissible in Indian courts.
DPDP Section 6, built in
Purpose-based capture, granular notice, and Data Principal rights for sensitive health data - consent that stands up to the Data Protection Board and NABH surveys.
Enforcement clock Live
EnforcementMay 13, 2027
The window is closing
The law is not theoretical anymore. The work runs in sequence - map the data, serve fresh notices, then stand up consent and rights.
May 13, 2027Enforcement deadline
Enforcement May 13, 2027
The Digital Personal Data Protection Act is enacted by Parliament as India's data protection law for every Data Fiduciary.
The transition begins - months, not years, to build the consent, rights, and breach workflows the Act expects.
Audits and scrutiny begin, with fines of up to ₹250 crore assessed per instance against the hospital as Data Fiduciary.
The window is closing
Compliant patient consent captured wherever care happens - intake, admission, procedures, and remote care.
Clear, purpose-specific notices and granular consent across web, mobile, and offline touchpoints - timestamped and withdrawable.

The Certinal consent platform is typically deployed in around 7 days, so compliant capture starts almost immediately.
From large hospital networks to diagnostics and telehealth, Certinal captures compliant consent across every setting.

Access, correction, and erasure requests captured in one place and routed with SLA tracking across every system.
Intake, admission, and procedure consent with the audit trails regulated care demands.
Test authorizations, sample-collection consent, and report release, signed on any device.
Remote consent for teleconsults, ABHA-linked and DPDP-ready from day one.
When the Board, a NABH surveyor, or the Data Protection Board asks, the evidence is on hand - not a project to assemble.
Independent data audits, DPIAs for high-risk processing, and purpose-tagged consent - versioned where the processing happens.
Patient-consent records structured so external auditors can verify without archaeology.

Trigger consent and signing from your EHR, HIS, or patient portal, then get every signed record synced straight back.
Free API access: embed consent capture into any clinical workflow, on every plan.
Every patient consent captured, signed, purpose-tagged, and audit-ready - for the Data Protection Board, NABH surveys, and ABDM.

Consent, end to end
Certinal keeps every patient consent, rights request, and audit artefact in one place - so compliance is a by-product of everyday care, not a scramble before an audit.
Proof
Patient intake, admission, and procedure consent captured digitally with the audit trails regulated care demands.
Signed directly inside the systems clinicians already use, across 30+ locations.
Consent for 1.1M+ patients a year, digital, purpose-tagged, and defensible.
Test authorizations, sample-collection consent, and report release, signed anywhere.
Certinal healthcare customers, 2026 · results vary by deployment and workflow.
70+
Hospitals on a single network
10000+
Beds served across facilities
1M+
Patients served annually
7000+
Weekly documents signed in Epic
93%
Patients signing digitally
7 days
Typical time to go live
Recognition & certifications

Named a Leader in the IDC MarketScape for Worldwide eSignature Software

Featured in the Gartner Market Guide for Electronic Signature

Recognized in Gartner Peer Insights Voice of the Customer

Rated by verified enterprise reviewers on Gartner Peer Insights

Consent built for DPDP Section 6 and sensitive health data

Electronic signatures admissible in Indian courts

Consent documentation aligned with NABH patient-rights standards

Consent for ABHA-linked records and Health Information Exchange

Certified information-security controls, annual surveillance audits

Independently audited controls over patient personal data

Aligned informed consent and investigator sign-off for trials
Built for regulated care
Protected health data, mapped to the Indian laws, healthcare standards, and security certifications regulated enterprises are held to.
DPDP Section 6 capture, purpose tagging, and Data Principal rights - audit-ready for the Data Protection Board, NABH surveys, and ABDM.
ISO 27001 certified and SOC 2 Type II audited controls over how patient personal data is stored, processed, and transmitted.
Guides, research, and playbooks on DPDP, patient consent, and secure e-signature - from the Certinal team.
Learn what digital patient intake is, why it matters, and how to implement it. A complete guide for clinic managers and healthcare IT leads. Get…
Patient Intake & Digital FormsLearn how digital patient pre-registration reduces no-shows by 20–30%, improves revenue cycle outcomes, and streamlines intake. See the data and get started.
Patient Intake & Digital FormsStreamline your practice with digital patient intake form. Access free, specialty-specific templates designed for HIPAA compliance and better care.
Patient Intake & Digital FormsLearn how the DPDP Act and DPDP Rules 2025 mandate multilingual consent and why language-compliant consent is critical for compliance.
ComplianceWhat does ‘specified purpose’ mean under the DPDP Act The phrase “specified purpose” may sound straightforward, but under the Digital Personal Data Protection (DPDP) Act…
ComplianceA privacy notice is more than just a formality - it is the foundation of transparency between an organization and the individuals whose data it…
ComplianceLearn what data minimization under the DPDP Act means, with legal rules, real-world examples, compliance risks, penalties, and implementation steps.
ComplianceLearn what a Consent Manager is under India’s DPDP Act, why it matters, how it works, and when organizations must comply.
ComplianceUnderstand the difference between Data Fiduciary vs Data Processor under India’s DPDP Act, their responsibilities, liabilities, and compliance timelines
Compliance
See how Certinal's DPDP Consent & Compliance Platform can transform the way your organisation manages consent and privacy.