Contributed By JSA
Overview
“Digital healthcare”, in common parlance, is an umbrella term for the use of technology in order to deliver healthcare, support clinical decisions, maintain health records, monitor patients and improve access to healthcare for the citizens of India. While there is no definition under applicable healthcare laws for digital healthcare, aspects of digital healthcare are principally addressed through the current regulatory framework, which includes:
Rather than regulating digital healthcare as a standalone sector, India regulates individual digital healthcare activities in accordance with their underlying function. Taken together, these frameworks recognise several forms of digital healthcare, including telemedicine, electronic health records, mobile health (mHealth) applications, remote patient consultations, consent-based health information exchange and software-enabled clinical services.
Telemedicine and Telehealth
Telemedicine represents the most common and established form of digital healthcare in India and is principally regulated through the Telemedicine Guidelines. These guidelines form part of the professional conduct framework applicable to registered medical practitioners (RMPs) in the country.
The Telemedicine Guidelines permit RMPs to provide remote clinical consultations using audio-video or text-based communication for first and follow-up consultations, review diagnostic reports and dispense post-treatment care. Along with the overarching application, the Telemedicine Guidelines also recognise specialty-specific applications including tele-radiology – transmission of X-rays, computed tomography (CT), magnetic resonance imaging (MRI), positron emission tomography (PET)/CT scans and ultrasound images – tele-pathology (the secure transfer of image-rich pathology data) and tele-ophthalmology (remote screening, diagnosis and monitoring of eye diseases).
Telehealth is similarly regulated through the Telemedicine Guidelines and is used in the industry to describe a broader range of technology-enabled healthcare services, including medical care, patient/ healthcare provider education, counselling, wellness support, preventive healthcare, rehabilitation and public health initiatives and non-clinical services (eg, health education webinars, administrative co-ordination, provider training), in addition to remote clinical care.
mHealth
Mobile health, commonly referred to in India as mHealth, refers to health services that are delivered through mobile applications, SMS and related channels. mHealth can include services such as the booking of medical appointments, wellness tracking (through external wearable devices or a mobile phone), medication reminders, tools to boost patient engagement, symptom checking and mental health support services.
The government of India has also implemented its own mHealth framework through the establishment of the Aarogya Setu 2.0 software, which was first introduced in 2020 as an application geared towards responding to the COVID-19 pandemic but now operates at a much wider scale to store personal health records and health services.
Relaunched in 2025, Aarogya Setu 2.0 now enables the creation and management of Ayushman Bharat Health Account (ABHA) accounts, consent-based health record sharing, artificial intelligence (AI)-powered health insights, integration of wearable devices, hospital payments, medication reminders, family health management and ambulance services, along with further health-related and medical services. This showcases the evolution of digital health applications available to the public, transitioning from a single-purpose tool into a broader healthcare access platform.
Electronic Records and Remote Monitoring
The electronic health records of patients stored and monitored in India include information such as medical history, prescription information, diagnostic reports from doctors, discharge summaries and immunisation records. India’s framework is supported by the EHRS, with the ABDM now seeking to create a landscape of interoperability of such data within the health ecosystem, along with creating records that are longitudinal, for everyone in the country.
Personal health records are patient-focused and intend to allow citizens to access, manage and share their health information through consent-based systems. Remote patient monitoring increasingly relies on wearable devices, connected sensors and mobile applications capable of collecting physiological data outside conventional clinical settings. Where such products are intended by their manufacturer to diagnose, monitor, prevent or treat disease, they may fall within the regulatory scope of the MD Rules.
India’s healthcare system has undergone a quiet but considerable digital transformation over the past few years, and the numbers tell a striking story. Digital technology is now embedded across most segments of India’s healthcare ecosystem, and its use extends beyond teleconsultation to services such as patient registration, electronic health records, diagnosis, pharmacy services, public health programmes and even the processing of claims. This is carried out primarily through the following government-backed programmes.
At the centre of this shift is the ABDM, the government’s flagship effort to wire the entire healthcare ecosystem into a single, interoperable network. The idea is straightforward: give every citizen a unique identity digitally – ie, an ABHA, to connect doctors, hospitals, clinics, pharmacies, laboratories and insurers on a common digital platform. As of May 2026, over 900 million ABHA accounts have been created, and more than 1 billion health records have been linked to them. To put that in perspective, both numbers have roughly doubled since February 2025.
The Indian government’s eSanjeevani platform has facilitated over 470 million teleconsultations through more than 234,000 registered healthcare facilities, with 57% of beneficiaries being women and roughly 14% being senior citizens. What makes eSanjeevani particularly notable is its integration of an AI-powered clinical decision support system, which has assisted doctors across more than 282 million online consultations between April 2023 and November 2025.
AI has made considerable inroads into the detection of diseases. Sector-specific AI software includes:
Market Adoption
The adoption of digital healthcare has accelerated significantly over the past few years, although implementation remains uneven across different regions, healthcare providers and specialties. Large hospital networks, medical insurance companies and health-tech companies are rapidly moving towards adopting companywide digital workflows, while smaller healthcare providers continue to rely primarily on paper-based systems/records.
With initiatives continually being introduced by the Indian government, digital healthcare is definitely a priority in India. Recent initiatives such as Aarogya Setu 2.0, the National Drug Registry (which standardises medicine-related information across the healthcare ecosystem through the uniform coding of drugs) and the e-Sushrut Clinic application (a plug-and-play clinic management solution, aiding healthcare providers by digitising their workflows, maintaining electronic health records and seamlessly integrating with the ABDM framework) are not standalone products, but building blocks of a thriving connected ecosystem intended to make healthcare delivery more efficient, accessible and transparent.
The private sector has also played a significant role in mainstreaming digital healthcare. Large multi-specialty hospital groups such as Apollo Hospitals, Fortis Healthcare and Max Healthcare have expanded their digital health capabilities, while digital-first healthcare platforms such as Practo, Tata 1mg and PharmEasy have integrated teleconsultations, diagnostics and pharmacy services into unified digital platforms.
The benefits of digital healthcare extend beyond improving patient access to healthcare services. Digital technologies increasingly support continuity of care, clinical decision-making, operational efficiency and public health planning. While adoption continues to vary across healthcare providers, digital health has become an important component of healthcare delivery, particularly for outpatient care, chronic disease management and preventive healthcare.
Benefits to Patients
For patients, the most tangible benefit of digital healthcare is access, particularly for those in remote, rural and underserved parts of the country, where eSanjeevani has made specialist consultations accessible, with patients not being required to travel long distances. The impact extends beyond telemedicine: a community-based cross-sectional survey using THULSI (a mobile screening toolkit) showed that simple, mobile-based screenings can enable local healthcare providers to detect previously unrecognised chronic conditions in urban slum populations – conditions that might otherwise have gone undiagnosed until they became more acute. Moreover, telemedicine reduces indirect costs for patients associated with healthcare, including travel, accommodation and waiting times, making the overall experience much more affordable and non-disruptive to everyday life.
Digital healthcare has also changed the manner in which routine healthcare is accessed by urban households. Patients in metropolitan centres and Tier I/Tier II cities are increasingly using digital health platforms for primary consultations, follow-up care, prescription renewals and chronic disease management, enabling families, working professionals, caregivers and senior citizens to obtain timely medical advice without disrupting their daily routines. As a result, digital healthcare is increasingly viewed not merely as a solution to geographical barriers, but as a convenient mode of healthcare delivery in its own right.
Benefits to Healthcare Providers
For healthcare providers, digital tools help improve storage of and access to medical records, clinical decision-making, follow-up care and co-ordination. AI-based support tools are also being integrated into public health and medicine programmes to provide support for screening, diagnostics and remote care. At the same time, implementation requires significant investment in technology infrastructure, cybersecurity, interoperability, staff training and ongoing regulatory compliance.
Benefits for the Healthcare Ecosystem
Beyond individual patients and healthcare providers, digital healthcare also supports broader system-level efficiencies. It facilitates information sharing between hospitals, laboratories, pharmacies and insurers, while digital claims processing and standardised health records have the potential to reduce administrative inefficiencies and improve continuity of care across different healthcare settings.
Indian law does not have a single statutory definition of “digital healthcare” or “digital health”. The expression is instead understood via an umbrella of policies, sectoral regulations/ laws, government programmes and technical standards, each addressing a different aspect of the digital health landscape.
The Telemedicine Guidelines, for instance, define “telemedicine” by reference to healthcare delivery and, more specifically, a direct clinical service delivered by an RMP, where distance is a pertinent factor and technologies relating to information/communication are used to exchange valid information – an understanding that maps closely to that of the definition of telemedicine of the World Health Organization (WHO).
Similarly, “Telehealth” is defined under the Telemedicine Guidelines using a definition adopted from the New England Journal of Medicine: “The delivery and facilitation of health and health-related services including medical care, provider and patient education, health information services, and self-care via telecommunications and digital communication technologies”.
The ABDM approaches digital healthcare from the lens of infrastructure, framing it around a national, interoperable ecosystem designed to support universal health coverage – an approach that is aligned with the WHO’s Global Strategy on Digital Health 2020–25. India’s technical standards are also directly drawn from international frameworks, which have been adopted by the EHRS. Hence, while the regulatory framework in India does not have a specific definition for “digital healthcare” or “digital health”, it is adopting globally recognised standards and localising them for digital healthcare operability in the country.
Telemedicine Guidelines
These guidelines set out how RMPs may consult patients remotely, covering permissible modes of communication (audio, video, text), patient identification and consent requirements, categories of drugs that can and cannot be prescribed digitally, documentation obligations, and what platforms need to ensure to support consultations that are compliant with the guidelines. In practical terms, the Telemedicine Guidelines constitute the rulebook that essentially governs the doctor-patient relationship once it moves online and becomes digital.
The DPDP Act and the DPDP Rules, 2025
The Act and the Rules are central to the processing of healthcare data and records. The law imposes clear obligations around notice, consent, purpose limitation, security safeguards, breach notifications, grievance redressal and data erasure. It is important to note that the DPDP Act and its rules are being implemented in phases, and for most healthcare organisations, the core compliance deadline falls in May 2027, which means that the compliance pathway has already begun.
IT Act
The IT Act is the foundational statute that regulates all aspects of information technology. It provides legal recognition of electronic records and digital signatures, which underpins every digital healthcare transaction. It also supplies the intermediary liability and safe harbour framework, which governs how online health platforms are governed when they host or transmit third-party content. The Indian Computer Emergency Response Team (CERT-In) has cyber incident reporting requirements for prescribed entities, which have to report certain incidents within a period of six hours from the incident taking place or from gaining knowledge of an incident that has taken place, and these requirements operate under this statute.
MD Rules
Medical devices are regulated under the MD Rules, which deal with the regulation of digital tools that cross into the clinical sphere. Any software, including standalone software, may fall within the medical device framework if it is meant to be used for the diagnosis, prevention, monitoring, treatment or alleviation of a disease or disorder. This is particularly pertinent for AI-enabled tools such as diagnostics, clinical decision-support tools, imaging software and remote monitoring devices.
Other Relevant Frameworks
A number of other laws and policies interact with the digital health ecosystem. These include:
The approach of the Indian government and policymakers has mostly been based on a technology-neutral, adaptive regulatory approach as opposed to solely relying on primary legislation, using expert committees, technical standards, pilot programmes and sector-specific guidance in order to keep pace with a sector that evolves faster than most legislative processes can follow – especially with the ever-growing expansion and development of AI.
A key feature of this approach is public consultation before any regulatory change. By way of an example, before the DPDP Rules were put into force, nationwide consultation and stakeholder input was received by the Indian government; there were approximately 7,000 inputs with respect to the draft rules before they were finalised. The Central Drugs Standard Control Organisation (CDSCO) has followed a similar pathway with its draft guidance on medical device software, whereby they have made the draft document available for stakeholder comments, rather than issuing binding rules without any public or industry input.
The result is a regulatory framework that moves through phases. First, the technology is observed, followed by wide consultation, after which guidance is issued and then refined through feedback before legislative formalisation. While this framework is not always time-efficient, and in some instances the consultation and regulation cycle has taken much longer than anticipated, the underlying approach and logic are effective. In a sector where technology is still maturing and evolving, premature regulation can result in more harm than good, as opposed to well-timed, thoroughly consulted rules and regulations that support the scope of a broader industry buy-in, with fewer unintended consequences.
Technical standards do not operate in the background in India; rather, they are at the centre of digital health, making interoperability possible.
The EHRS, notified by the Ministry of Health and Family Welfare, established a uniform system for how health records should be coded, structured and exchanged. The National Resource Center for electronic heath record supports these standards and works with internationally recognised systems, such as the Systematized Nomenclature of Medicine – Clinical Terms (SNOMED CT) for clinical terminology, Logical Observation Identifiers Names and Codes (LOINC) for laboratory observations, Digital Imaging and Communications in Medicine (DICOM) for diagnostic imaging, Health Level Seven International (HL7) for messaging and the WHO’s classifications for disease coding. Thus, India is not laying down its own independent technical language from scratch; rather, it is localising and adapting global standards to serve healthcare needs within the country.
The ABDM further builds on these standards by defining the minimum conformity requirements for accessing and exchanging health data across ecosystems, supported by technical standards to ensure that the exchange and interpretation of health data can be carried out between different systems. This is demonstrated through its Fast Healthcare Interoperability Resources implementation guide. Practically, this means that whenever a hospital/ pharmacy/insurer or health tech application/ software integrates with the ABDM, it must follow a common data structure, ensuring interoperability, cross-usage and access across different record systems.
In 2026, the Indian government has further expanded on this structure, with the launch of common LOINC codes for India and the Bharath Health Terminology Service in June 2026, signalling a specific push towards deeper semantic operability, ensuring that a clinical term carries the same meaning whenever it appears. Combined with the Drug Registry, these moves are attempting to build a common, shared vocabulary for digital healthcare in India.
Software as a Medical Device (SaMD)
Under the MD Rules, software may be regulated as a medical device where its intended purpose is for medical uses such as the diagnosis, prevention, monitoring, treatment or alleviation of disease or injury. This extends to standalone software, namely software that performs a medical function independent of any specific hardware device. An AI tool that analyses chest X-rays, a mobile application that screens for diabetic retinopathy and a platform that performs automated cell counts from digital pathology slides may all fall within the SaMD framework.
Additionally, in October 2025, the CDSCO issued draft guidance on SaMD, which provided further clarity, distinguishing between a SaMD embedded into hardware and a standalone SaMD, along with applying a risk-based classification by creating different classes depending on the clinical significance of the information the software provides and the seriousness of the health condition involved.
The guidance draws a distinction between two categories: software “as” a medical device and software “in” a medical device (software that is embedded in/is not separable from a physical, hardware-based medical device).
Wellness, Wearable Hardware and Remote Monitoring
The regulatory position differs significantly for products positioned within the general wellness and fitness segment. As discussed in the foregoing, the applicability of the MD Rules depends principally upon the intended purpose of the software or device rather than the technology itself. A smartwatch that tracks your steps, sleeping patterns and heartrate for general fitness purposes does not automatically become a regulated medical device. In this scenario, the “intended use” test under the MD Rules determines whether a product falls into the medical device framework or not. The qualifying factor is whether a tool/wearable device is being used for diagnosing, monitoring, preventing or treating any disease.
That said, wearables and internet of things (IoT) products are not unregulated. They continuously collect sensitive health related data, which brings them within the scope of the DPDP Act, along with the CERT-In directions in relation to timely reporting of any cybersecurity breach. Certain wearable devices may also be subject to product-specific regulatory requirements, including applicable Bureau of Indian Standards certification requirements.
Cybersecurity and Data Protection
Cybersecurity and data protection obligations applicable to digital healthcare businesses arise under multiple legal and regulatory frameworks, including the DPDP Act and the rules thereunder, the IT Act and the rules thereunder, the CERT-In Directions and, where applicable, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
For healthcare companies, this is not a single compliance exercise. It is a layered set of obligations that deals with access controls, breach response, vendor management, consent architecture, data retention policies and grievance mechanisms for patients.
AI and Machine Learning
While machine learning and AI are not yet governed under a specific statute/regulation in India, they are partially regulated in accordance with the Indian Council of Medical Research Ethical Guidelines for Application of Artificial Intelligence in Biomedical Research and Healthcare, 2023, which sets out ethical principles for the integration of AI into healthcare. More specifically, the Strategy for AI in Healthcare for India (SAHI) and Benchmarking Open Data Platform for Health AI (BODH) initiatives announced by the Indian government during the India AI Impact Summit in 2026 mark the Indian government’s policy direction, positioning these initiatives as constituents of a governance framework, and national pathway for the ethical and responsible use of AI in healthcare – with a specific emphasis on safety, accountability, transparency and inclusion.
In practice, AI tools used in healthcare will also need to navigate the medical devices framework if they qualify under the definition of SaMD, the DPDP Act with respect to the patient data they process, and CERT-In requirements with respect to cybersecurity. Thus, regulation of AI is not absent, but rather distributed across multiple frameworks, with a growing trend towards specificity.
Environmental, Social and Governance (ESG) Matters
ESG matters are not regulated as a separate digital health category. They apply to digital health companies in the same way they apply to any Indian company: through the general corporate sustainability framework.
The (Indian) Companies Act, 2013, prescribes corporate social responsibility obligations for qualifying companies, while SEBI’s Business Responsibility and Sustainability Reporting framework imposes ESG-related disclosure requirements on specified listed entities.
Telehealth
Clinical telehealth services provided by RMPs are principally governed by the Telemedicine Guidelines, which prescribe requirements relating to patient identification, consent, modes of consultation, maintenance of medical records and prescription of medicines. More broadly, telehealth platforms are also subject to the legal and regulatory requirements applicable to their underlying activities, including data protection laws.
Strengths of the Digital Healthcare Framework
India’s digital healthcare framework has evolved significantly in recent years. Until this decade, the regulatory landscape of healthcare was sparse and uncertain. Today, telemedicine is regulated under specific conduct guidance, health data is protected under a comprehensive data protection statute with operational rules, the ABDM has been set up to provide national digital healthcare infrastructure, and the CDSCO continues to refine the regulatory framework applicable to SaMD, amongst other things.
Rather than attempting to force each digital health issue into a statute, the Indian government has enacted specialised frameworks to address specific risks. This means that if one aspect of the systems needs updating, it can be revised without reopening the entire regulatory architecture. Equally important is the framework that encourages participation from both the public and private sectors.
Gaps in Legislation and Possible Reforms
Notwithstanding these developments, the current framework continues to present practical regulatory challenges. A digital health business operating across telemedicine, wearables, diagnostics, e-pharmacy, AI, health record-keeping, etc, may need to navigate a multilayered legal framework for its operations, which may appear less as a modular system and more as a compliance maze. Presently, there is no primary compliance pathway, no unified regulator/body and no common redressal mechanism that ties it all together.
In addition, certain areas of digital healthcare continue to evolve through policy initiatives and draft guidance, rather than settled legislation. These include the regulation of e-pharmacies, governance of AI in healthcare, treatment of wellness products and connected wearables, cross-border digital health services, and operational alignment between the DPDP framework and the consent architecture under the ABDM.
Accordingly, while India’s digital healthcare framework has matured considerably, the next phase of regulatory development is likely to focus less on introducing new legislation and more on improving harmonisation, interoperability and implementation across existing frameworks.
There is no single digital healthcare regulation body in India, and that is not by accident; the sector sits at the intersection of health policy, data governance, cybersecurity, professional ethics, etc, and these different sectors are overseen by different bodies. The regulators are as follows.
Various aspects of digital healthcare fall within the remit of non-healthcare regulators, but primarily in relation to data protection and cybersecurity:
Enforcement in the digital healthcare sector is fragmented and depends on the nature of the underlying activity, with different regulators exercising jurisdiction over different sectors. In practice, regulatory scrutiny has been most visible in relation to professional misconduct, medical devices and cybersecurity.
Data Protection and Cybersecurity
For digital healthcare businesses, regulatory enforcement is increasingly focused on the manner in which patient information is collected, processed, stored and shared. Hospitals, telemedicine platforms, e-pharmacies and other digital health businesses processing health-related personal data are required to comply with the DPDP Act and the rules framed thereunder, with the Data Protection Board empowered to inquire into instances of non-compliance and impose monetary penalties. Given the volume and sensitivity of patient information handled by such businesses, data protection and cybersecurity are expected to remain key enforcement priorities.
Healthcare organisations are also required to comply with applicable CERT-In directions relating to cybersecurity incidents. Given the operational dependence of digital healthcare businesses on technology systems, cybersecurity incidents are likely to attract heightened regulatory scrutiny.
Professional Conduct and Ethical Guidelines
An RMP/doctor who provides healthcare digitally is subject to exactly the same professional conduct standards as those who provide healthcare in person. Any violation in respect of prescribing restricted drugs remotely, incorrectly identifying a patient, confidentiality or documentation adequacy may lead to disciplinary proceedings before the relevant state medical council or the National Medical Commission. Penalties/ sanctions start from just a warning, but go up to suspension and even cancellation of registration.
Consumer Protection
A patient who is dissatisfied or aggrieved by the platforms providing digital healthcare may seek compensation by filing a complaint before the District or National Consumer Disputes Redressal Commission, depending on the pecuniary jurisdiction.
The Consumer Protection Act specifically covers online transactions and e-commerce providers. This means that digital health platforms are open to consumer complaints and cannot avoid responsibility simply because the services were delivered online or through an application. Remedies for individuals include compensation for deficiency in service, directions to discontinue unfair trade practices and, in cases of false advertisement, penalties for the endorser of the product(s) and the advertiser. Further, if health-tech companies make false claims about the efficacy of drugs/products, the Central Consumer Protection Authority has the power to carry out an investigation against them and take suo motu cognisance against any unfair trade practices.
Medical Devices and Drug Regulation
If any company markets an unlicensed diagnostic software/ application, sells prescription drugs online without proper licences or distributes unregistered medical devices, it faces possible show-cause notices, licence suspension, product seizure and even criminal prosecution under the Drugs Act. It is pertinent to note that the CDSCO has already issued show-cause notices to companies that were engaged in the sale of unauthorised drugs.
India’s digital healthcare framework has matured considerably, with building blocks that are very much real – and growing. In the span of a few years, India has achieved guidance on telemedicine, comprehensive data protection laws, clarification regarding medical devices and a national digital health infrastructure – and it is also committed to the governance of AI in medicine.
That being said, while there are varied and extension legislative frameworks for different digital healthcare sectors, there is no umbrella organisation or act overseeing or regulating violations. Hence, a challenge remains in relation to the absence of a single piece of legislation connecting all of the sectoral laws.
Overlaps
Companies operating in different sectors have to comply with individual regulations and statutes, with separate and independent regulatory bodies. Not only does this cover regulations in relation to digital healthcare, but also data management and consumer protection.
Overlaps further compound this issue. By way of illustration, a data breach involving a teleconsultation company could trigger obligations under the DPDP Act, CERT-In, the Telemedicine Guidelines and the Consumer Protection Act. The issue, then, for companies is not which sector they have obligations that have to be met, but rather which sector to address first without falling short in the others.
Enforcement Still in Development
AI with respect to health, e-pharmacy and wellness devices operate in a different sector. While they are not unregulated, enforcement is not as rigorous as in the sectors mentioned previously. This gap arises because the frameworks are new, without many precedents, and the regulators are in the process of developing a strong and robust institutional framework.
Further, there are sectors where the market has simply evolved beyond the regulations already in place. E-pharmacy rules have been pending since 2018. Clinical governance surrounding AI still exists as a policy framework, rather than binding law. The wellness-to-medical device boundary is blurred when fitness trackers add clinical diagnostic features through software updates. The DPDP Act’s consent framework is yet to be formalised with the ABDM’s consent-based record sharing system.
That being said, given the deadline of May 2027 for the implementation of compliance now made mandatory by the DPDP Act and the rules thereunder, along with the CDSCO’s guideline on software as medical devices reaching finalisation, this gap is unlikely to persist much longer.
The legal risks associated with digital healthcare arise less from the absence of regulation and more from the increasing convergence of healthcare, technology and data governance. Unlike traditional healthcare delivery, digital healthcare frequently involves multiple stakeholders, including healthcare providers, platform operators, software developers, medical device manufacturers, cloud service providers and data processors, each subject to different legal and regulatory obligations. This often makes compliance and allocation of responsibility significantly more complex.
Non-Compliance With Regulations
One of the principal legal risks is ensuring compliance across multiple regulatory frameworks that may apply simultaneously to the same business. Depending on the nature of the services offered, a digital healthcare business may be required to comply with a plethora of regulations. Businesses developing software, connected devices or AI-enabled healthcare solutions also face the additional challenge of determining whether their products fall within existing categories of medical devices or other healthcare regulatory frameworks, particularly as technology continues to evolve. Further, E-pharmacy companies face a unique compliance risk as the final rules governing e-pharmacies are yet to be notified, leaving them exposed to enforcement under existing drug laws without any clear framework that can be followed.
Enforcement by Regulatory Authorities
The fragmented regulatory framework also means that a single incident may attract scrutiny from more than one regulator. For instance, a data breach affecting a telemedicine platform may trigger obligations under the DPDP framework, the applicable CERT-In Directions, professional conduct requirements and consumer protection laws. As a result, businesses are often required to manage parallel reporting obligations and regulatory processes arising from the same event.
Liability
Digital healthcare also changes the manner in which liability arises. Unlike traditional healthcare models, responsibility may be shared across multiple participants involved in the delivery of digital health services, including healthcare providers, RMPs, platform operators, software developers, medical device manufacturers and third-party service providers.
While contractual arrangements may allocate responsibility between these parties, they do not displace statutory obligations or limit liabilities arising under applicable law. In practice, disputes often turn on questions of regulatory compliance, the role performed by each participant and whether reasonable standards of care and diligence were maintained. Here, failure can attract liability under the DPDP Act, the Consumer Protection Act and/or the Bhartiya Nyaya Sanhita, 2023, amongst other pieces of legislation.
Accordingly, the principal legal challenge posed by digital healthcare is not that it creates entirely new categories of legal risk, but that it requires businesses to navigate overlapping regulatory obligations while carefully allocating responsibility across an increasingly interconnected healthcare ecosystem.
Statutory Remedies
Legal exposures arising out of any breach can be addressed through multiple routes. A patient who receives substandard care on a digital platform can file consumer complaints under the Consumer Protection Act for deficiency in service, misleading representations, fraud, unfair trade practices, defective goods or services, etc. Remedies available under the Act include monetary compensation, refunds, directions to discontinue trade practices and penalties for incorrect/ misleading advertisements.
Medical negligence in relation to digital consultation is also actionable through multiple routes. Civil liability for medical negligence can be pursued through consumer forums or civil courts. In cases involving death caused by negligence, criminal liability can arise under the Bharti Nyaya Sanhita, 2023, carrying a penalty of imprisonment that may be extended to five years, along with a monetary fine. In situations of negligence of a gross or reckless nature, more serious provisions under the Indian Penal Code, 1860, may also be applicable.
Any data breach triggers the DPDP Act framework, including through complaints to the Data Protection Board of India. This results in a mandatory breach notice to the affected individuals and potential monetary penalties, if so decided by the board. Cybersecurity breaches/attacks trigger CERT-In reporting and co-operation requirements for intermediaries, and any issue related to the use of medical devices will lead to action/prosecution under the Drugs Act and the MD Rules. The key point is that these legal enforcement mechanisms do not operate in parallel, but as alternative remedies under applicable law.
Contractual/Professional Liability
On the contractual side, digital healthcare relationships/usage is usually governed by commercial agreements, which specifically allocate responsibility in relation to clinical workflows, data security, the performance/efficacy of software, intellectual property, indemnities, patient consent and regulation-based compliance.
When something goes wrong (a vendor system data leak, a platform failing to meet commitments, an AI tool underperforming with respect to its contractual obligations, etc), the first avenue of redress is the contractual relationship between the relevant parties, which is enforceable through civil courts or under arbitration clauses as agreed between the parties in the contract.
Professional liability operates separately. An RMP/doctor continues to be professionally accountable with respect to their judgement, documentation, consent and referral, irrespective of whether the consultation took place remotely. If any patient suffers harm due to the negligence of an RMP/doctor during a teleconsultation, the professional ethics principles under the Telemedicine Guidelines apply as they would if the consultation was done in person.
Regulatory Compliance
There is no single legal defence available against the risks associated with digital healthcare. In practice, the strongest defence against regulatory action is demonstrating compliance with the legal framework applicable to the particular product or service. Depending on the nature of the business, this may include ensuring that the necessary licences and approvals have been obtained, products and services have been appropriately classified, applicable professional standards have been followed, and reasonable technical and organisational measures have been implemented to meet data protection and cybersecurity requirements.
Regulatory Enforcement
Given the fragmented regulatory landscape, businesses are often required to respond to parallel regulatory proceedings arising from the same incident. Maintaining appropriate records, internal compliance processes and documented decision-making often place businesses in a stronger position when responding to regulatory scrutiny or investigations.
Liability
Liability in digital healthcare frequently extends beyond the treating RMP/healthcare professional. Depending on the circumstances, claims may also involve hospitals, platform operators, software developers, medical device manufacturers, cloud service providers and other third-party vendors. While contractual arrangements cannot exclude statutory obligations or professional responsibilities, they remain important in allocating responsibilities and commercial risk between the parties and in determining the obligations of each participant.
Clinical and Operational Governance
Where claims arise from the provision of healthcare services, healthcare professionals may defend their actions by demonstrating compliance with applicable professional standards, including the Telemedicine Guidelines, where relevant, and that reasonable clinical judgement was exercised in the circumstances. Similarly, organisations are generally better placed to respond to regulatory action where they can demonstrate robust internal governance, appropriate vendor oversight, documented compliance processes and effective incident response mechanisms.
Recent years have seen increased regulatory activity in digital healthcare. The developments fall into four major areas:
AI
AI has moved from the edge of policy discussions to the centre of the Indian government’s policy development. The launch of SAHI and the BODH at the AI Summit in 2026 was not just a symbolic gesture, but rather a signal of a greater focus on safety, benchmarking, bias, privacy and accountability in relation to the use of AI in the digital healthcare space (without hampering growth or advancement and avoiding reliance on self-regulation or an after-the-event enforcement mechanism).
Data Governance
There has been considerable development with respect to data governance. Most notably, the DPDP Act’s rules, published in 2025, have provided an operational mechanism for India’s personal data framework, along with introducing a phased compliance timeline for organisations/providers who process personal data.
The compliance deadline of May 2027 for the healthcare sector is strict enough to make it meaningful, but also lenient enough to let an industry that processes patient data in extraordinary volumes, with sensitivity and velocity, adapt without organisational chaos. The 18-month period from notification is not an invitation to delay but rather a finite window in which consent architecture, breach protocols, retention policies and vendor controls need to move from paper commitments to working systems.
For businesses in this sector that have waited for clarity on consent management, data retention, cross-border transfer of information and breach responses, the Act and its Rules provide clarity, along with a specified pathway for compliance.
Infrastructure
It is in the infrastructure sector where the ambition for development is most visible. With interoperability in focus, recent developments such as the Aarogya Setu 2.0 service, the Drug Registry, BHTS and NHCX reflect a clear shift in the Indian government’s thought process in relation to digital health – ie, moving from standalone applications to connected public infrastructure, along with standardised specifications in accordance with international standards. The infrastructure framework is no longer about building individual tools but rather building guardrails on which the entire system functions.
E-Pharmacy
While draft rules aiming to regulate e-pharmacies were introduced by the Indian government in 2018, e-pharmacy remains largely a grey area. While the Indian government has provided further guidance in relation to registration, inspection, sale procedures, monitoring, complaint redressal and advertisement limits as part of the proposed framework, it still has not been formalised into a statute/regulation. Essentially, the e-pharmacy sector still operates on legacy drug laws, regulations and judicial orders, while the market is scaling rapidly.
Private Sector-Related Activity
The pace of development in digital healthcare is not only being driven by the Indian government – India’s private sector has also been an active participant in developing the landscape and, in many instances, has moved ahead of formal regulation. Large hospital conglomerates such as Max Healthcare Apollo Hospitals and Fortis Healthcare have built their own telemedicine platforms and integrated their data systems with the ABDM. Legacy diagnostic companies like Dr Lal Pathlabs and SRL have also adopted heath record sharing and personal information storage practices compliant with the ABDM.
More notably, there has been an influx of health technology start-ups such as Practo, Tata 1mg and MFine that have made telemedicine, e-pharmacy, remote monitoring and AI-supported diagnostics available for millions of users. That said, while large private companies are investing heavily in compliance and interoperability, smaller companies and entry-level start-ups still lack the resources to keep pace with the regulatory environment, which becomes more demanding with every financial quarter.
International Digital Heath Ambitions
India’s digital heath development ambitions are not just domestic. The India-UK Health and Life Sciences Partnership, renewed in January 2025 as a five-year binding memorandum of understanding, deals with digital health innovation, disease surveillance, telemedicine and cybersecurity.
On a multilateral level, India has also used its 2023 G20 Presidency to launch its Global Initiative on Digital Health, along with the WHO. Further, under its 2026 BRICS chairmanship, digital healthcare has also been identified as a priority area. India is also an active member of the Global Digital Health Partnership, a network of countries focused on greater interoperability and cybersecurity implementation in digital healthcare. What can be understood from the foregoing is that India is not only focusing on building its own infrastructure for digital health, but is also actively positioning itself as a strong international player in digital healthcare from the Global South.
Recent Reforms
Announcement of SAHI and the BODH
The Indian government announced the launch of SAHI and the BODH at the AI Impact Summit in 2026, with a focus on implementing AI in the digital healthcare sector.
SAHI is a national guidance framework for the safe, inclusive, ethical and evidence-based adoption of AI in healthcare – not a binding regulation, but rather a clear and precise policy compass that signals how the government expects AI in the healthcare sector to be developed, deployed and monitored.
The BODH compliments SAHI by providing a privacy preservation model, supported by a benchmarking platform for evaluating AI models in comparison to real-world health data before deployment on a mass scale. Together, these policies reflect India’s push to get ahead of AI integration in healthcare, rather than play catch-up later, actively showcasing a solution-based approach and understanding the shortcomings of previous regulation frameworks.
Notification of the DPDP Rules, 2025
In furtherance of the DPDP Act, notified in 2023, the most significant reform in recent times has been the notification of the DPDP Rules, which operationalise the DPDP Act and establish a citizen- and individual-centric framework for responsible use of digital personal data in India. Once fully implemented, these rules will be incredibly important for digital healthcare with respect to the large-scale processing of patient data across app-based platforms, hospitals, data managers, data storers, etc. For businesses that process and store patient data, this reform underpins and changes day-to-day operations.
Incoming Reform
CDSCO’s draft guidance on medical device software
CDSCO released draft guidance on SaMD in October 2025 (currently awaiting finalisation), which is the most anticipated development. It is expected to provide clarification with respect to SaMD and AI-enabled healthcare tools and services, as showcased in the draft policy. The market has been eagerly awaiting clarity in relation to such software, and the draft is expected to strongly shape the investment and product strategy for medical devices across India’s healthcare sector.
What Comes Next
The direction that India intends to take in the future is clear – increase interoperability and innovate in a standardised and accountable manner. As discussed herein, this is being supported by the building of infrastructure and governance frameworks to support such development and adoption of digital healthcare.
The challenge will be whether these frameworks and regulations can keep pace with the infrastructure that is meant to govern them. In this respect, privacy obligations will need to align with the ABDM’s consent framework, AI validation standards will have to match the speed at which AI is expanding, e-pharmacy will have to be regulated under binding law, and liability rules will have to be in line with an ever-evolving world where clinical decisions will be increasingly assisted and carried out by software.
Hence, India’s digital healthcare story over the next few years will come to be defined not by the frameworks and regulations that exist on paper, but by whether they converge in practice, address sectoral gaps and provide consistent support to a sector that is scaling faster than any other part of the economy.
Sandstone Crest
Opposite Park Plaza Hotel
Sushant Lok – I, Gurugram
National Capital Region 122009
India
+91 124 439 0632
+91 124 439 0617
gurugram@jsalaw.com www.jsalaw.com