



Indian healthcare is undergoing a rapid digital transformation. Hospital management systems (HMS), electronic medical records (EMR), telemedicine platforms, and connected medical devices are generating and processing more patient data than ever before. This digital acceleration brings a parallel challenge: ensuring that sensitive personal data — medical records, diagnostic images, lab results, insurance information — is protected in compliance with the Digital Personal Data Protection (DPDP) Act 2023.
This guide covers the specific cybersecurity measures that Indian hospitals and healthcare providers need to implement for DPDP compliance, with practical architectures that work within the constraints of existing medical infrastructure.
As data fiduciaries under the DPDP Act, hospitals and healthcare providers must:
Notably, the DPDP Act designates health data as “sensitive personal data,” which triggers higher standards for consent, security, and breach notification. The penalty for non-compliance can extend to ₹250 crore.
Healthcare networks face unique security challenges that make standard enterprise security approaches insufficient:
Goal: Know what’s on your network and isolate it appropriately.
Passive discovery: Use passive network monitoring (SPAN ports, NetFlow, or FortiGate’s traffic logging) to identify every device on the hospital network without active scanning. Medical devices can crash under active scanning. Document each device: IP, MAC, vendor, operating system, function, and connected services.
Network segmentation: Create isolation zones based on function and risk level:
Fortinet approach: FortiGate firewall with inter-VLAN rules and FortiNAC for 802.1X device authentication on managed switches. FortiGate’s application control identifies DICOM and HL7 traffic and can enforce policies even on unauthenticated devices.
DPDP compliance outcome: Reasonable security safeguards demonstrated through network segmentation and least-privilege access controls.
Goal: Know who and what is accessing patient data.
802.1X deployment: Implement 802.1X on all managed switches. Every device authenticates before getting network access. Medical devices that can’t do 802.1X get MAC authentication bypass (MAB) with registered MAC addresses only — unregistered MACs are dropped into a quarantine VLAN with minimal access.
Role-based access: Integrate FortiAuthenticator with the hospital’s Active Directory. Doctors get access to the EMR and PACS. Lab technicians get access to the LIS only. Administrative staff get access to HMS only. No admin gets access to systems they don’t need for their role.
Multi-factor authentication (MFA): Deploy MFA for all remote access, all administrator accounts, and any access to systems containing sensitive personal data. FortiAuthenticator supports TOTP, SMS, and push notification MFA.
Session logging: Log every access event — who accessed what system, from which device, at what time, and what data they viewed or modified. FortiGate logging plus FortiAnalyzer provides a searchable, compliant audit trail.
DPDP compliance outcome: Access controls and audit trails demonstrate that patient data is accessed only by authorised personnel, with full accountability for every access.
Goal: Detect and respond to security incidents affecting patient data.
Baseline behaviour: Medical devices have predictable traffic patterns. A CT scanner sends images to the PACS server after each scan. An infusion pump sends status updates every 30 seconds. A lab analyser sends HL7 messages when results are ready. Establish baselines for normal behaviour — the SIEM detects deviations.
Anomaly detection: Configure alerts for: medical devices communicating with unfamiliar IPs, sending data at unusual times, attempting internet access, or showing sudden traffic volume changes. These are indicators of compromise that traditional security tools miss.
Log retention: Maintain 180 days of logs from all critical systems (FortiGate, FortiAnalyzer, Windows Event Logs from domain controllers, EMR/PACS audit logs). This satisfies both CERT-In requirements and DPDP data protection obligations.
Incident response: A documented IR plan tailored for healthcare — with specific procedures for preserving clinical continuity during an incident, isolating affected systems without disrupting patient care, and reporting breaches to the Data Protection Board within 72 hours.
DPDP compliance outcome: 72-hour breach notification capability, evidence of monitoring, and documented incident response procedures.
Goal: Ensure that third-party vendors don’t become a backdoor into patient data.
Vendor access controls: Medical device vendors often need remote access for maintenance. Use ZTNA (see Day 6) for time-bound, application-specific vendor access. No permanent VPN accounts. No vendor access to any system beyond the specific device they’re maintaining.
Vendor security assessments: Request security documentation from all medical device and EMR vendors. Understand their vulnerability management practices, patching cycles, and breach notification procedures. Include security requirements in procurement contracts.
Patching agreements: Work with medical device manufacturers to establish patching windows and validation procedures. Document when patches can’t be applied and the compensating controls in place.
DPDP compliance outcome: Supply chain risk management demonstrating that third-party access is controlled and monitored.
We’ve helped Indian hospitals from 50 beds to 1000+ beds implement DPDP-compliant cybersecurity architectures. Our approach is phased, practical, and designed to work within the constraints of existing medical infrastructure — including the unpatchable devices that every hospital has.
Contact our healthcare cybersecurity team for a compliance gap assessment. We’ll audit your current network architecture, identify DPDP compliance gaps, and deliver a phased remediation plan with budget estimates.
P J Networks has been securing Indian healthcare institutions since 2001. We specialise in medical device network security, DPDP compliance, and Fortinet-based hospital security architecture.