Patient data is the hardest case. Start there.
A hospital cannot delete a medical record because a patient withdrew marketing consent, and it cannot treat a nine-year-old the way it treats an adult. Healthcare is where generic consent tooling breaks first, which is exactly why we built for it first.
Built for: Hospitals, clinic chains, diagnostics labs, healthtech platforms, teleconsultation and insurers.
The pressure points, specifically
Withdrawal cannot mean deletion
Medical records carry statutory retention obligations that outlive any consent. A withdrawal has to stop the processing it governs without touching the record the law requires you to keep, and you need to be able to show which is which.
Children are a separate regime
Paediatric care means §9 applies routinely, not exceptionally: verifiable parental consent, no behavioural monitoring, no targeted advertising. A ward full of minors is not an edge case you handle later.
Correction is amendment, not overwrite
When a patient exercises the right to correction against a clinical record, the clinically correct answer is an amendment with an audit trail, not an in-place edit. Tools built for CRM data get this wrong by default.
Consent arrives through many doors
Front desk, kiosk, app, teleconsult, insurer portal, lab partner. Every one of them collects, and every one of them has to write to the same record if the answer to "did this patient consent" is going to be a single one.
The parts that matter here
Consent that outlives the interaction
Every artifact is immutable and hash-chained: each ledger entry hashes its own canonical form together with the entry before it. When a regulator, an auditor or a medico-legal case asks what the patient agreed to and when, the answer is a verifiable record rather than a screenshot.
Verifiable parental consent for minors
A dedicated parental-consent flow for patients under eighteen, with the guardian relationship captured and the §9 restrictions applied to the child record rather than left to policy.
Rights with statutory clocks
Access, correction, erasure and grievance intake with the response clock running from the moment a request lands, fulfilment tracked to completion, and correction handled as an amendment so the clinical history stays intact.
One ledger behind every desk
A hosted consent page for the front desk and kiosks, a server-side API for your HIS or app, and bulk ingestion for the consents you already hold on paper or in a legacy system. Different doors, one record.
Notices in the language the patient reads
Versioned, translated notices across twenty-two Indian languages, with the exact version served pinned to the artifact. A consent taken in Kannada is provable as a consent taken in Kannada.
Healthcare and the DPDP Act
No. The DPDP Act does not override a retention obligation imposed by another law, and medical-record retention requirements continue to apply after a withdrawal. What must stop is the processing that consent was the basis for — marketing, optional analytics, non-essential sharing. Sammati models this explicitly: withdrawal switches off the purposes it governs and leaves records retained under a legal obligation in place, with the distinction recorded rather than assumed.
Anyone under eighteen is a child under the DPDP Act, and processing their data requires verifiable consent from a parent or lawful guardian. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright. For a hospital this is routine rather than exceptional, so the parental-consent flow is a first-class path in Sammati rather than a bolt-on.
The DPDP Act, unlike the older SPDI Rules and unlike GDPR, does not define a separate category of sensitive personal data — the obligations apply uniformly to all digital personal data. In practice health data still attracts heightened scrutiny through the reasonable-security-safeguards duty, sectoral rules, and the likelihood of being classed a Significant Data Fiduciary at volume.
Yes. Sammati runs either as SaaS or entirely inside your own cloud account, from the same codebase under the same licence, so patient data never has to leave the environment your board has already approved.
General information about the DPDP Act, 2023, not legal advice. For a position specific to your organisation, talk to us or read the deep dive: DPDP for Healthcare and Healthtech: Consent, Sensitive Data and Sector Rules.
Find out where you actually stand.
The free self-assessment takes a few minutes and gives you a written position on your own setup, not a generic checklist.