How ready is your clinic for the DPDP Act?
Answer a short set of questions about how your clinic collects, stores, shares and deletes patient data. The score tells you where you stand and which obligations still need an owner. Not legal advice.
- Your answers only
- No sign-up
- Not legal advice
Your DPDP readiness score.
Answer each question about how the clinic actually works today, not how it should. The questions cover the obligations the Digital Personal Data Protection Act 2023 places on a clinic as a data fiduciary. The score updates as you go.
- The score is a self-assessment from your own answers; it is not a legal opinion and does not certify compliance
- Questions cover consent at registration, what the patient is told, retention and deletion, staff access, sharing with labs and third parties, breach handling, and where data is stored
- Each question is weighted the same; the score is the share of questions where your current practice meets the obligation
- Rules and timelines under the Act are still being notified; check the current rules or ask counsel before relying on the result
- Do you record patient consent for storing and using their health data?
- Can a patient ask what data you hold about them and get an answer?
- Is there a written retention period for patient records?
- Is access to records limited by role (reception vs doctor vs owner)?
- Is every view and edit of a record logged with who and when?
- Is patient data encrypted at rest and in transit?
- Do you know where (which country/region) the data is hosted?
- Is there a process to report a data breach within the required timeline?
- Do your vendors (software, labs, messaging) have data-processing agreements with you?
- Is there a named person responsible for data protection at the clinic?
Your score and next steps appear here.
One point per obligation you already meet.
The DPDP Act 2023 treats a clinic as a data fiduciary for the personal data it holds about patients. The tool lists the obligations that apply to an outpatient clinic, asks whether your clinic meets each one today, and reports the share you meet as a score out of a hundred. Nothing is weighted higher than anything else, because the tool doesn't know your clinic's risk.
The questions are about practice, not paperwork. Whether a patient is told at registration what their data is used for. Whether consent is recorded somewhere you could show later. Whether a leaving staff member's access is removed the same day. Whether the lab you send samples to has agreed in writing how it handles the data. Whether you know where your EMR vendor stores the records.
The result is a starting list, not a certificate. Each question you answer no to is an obligation that needs an owner, whether that is the clinic, your software, or both. The trust pages describe which of these Saaro handles in the product and which remain the clinic's responsibility.
- Score = obligations met ÷ obligations asked, shown out of a hundred
- Every obligation counts once; there is no hidden weighting
- Answers are not stored and no contact details are requested
- This is not legal advice; confirm with counsel and the current notified rules
The obligations the software can carry for you.
Consent in the record
Consent is recorded against the patient's record at registration, with what was agreed and when, so it can be shown later rather than reconstructed.
Learn moreRole-based access and audit trail
Reception sees the calendar, doctors see the chart, owners see the reports. Every view, edit and share is logged against a user and a reason.
Learn moreData hosted in India
Records are stored in the Mumbai region, encrypted at rest and in transit, so the question of where your patient data lives has a plain answer.
Learn more
Walk through your score with someone who built the controls.
Twenty minutes. We show consent, access and the audit trail on a real record, and tell you honestly what stays with the clinic.
Your questions answered.
The things clinics ask first.
No. It is a self-assessment based on your own answers, written to help you see which obligations need attention. Confirm your position with counsel and against the rules as currently notified.
No software can do that on its own. Saaro carries the parts that live in the product: consent recording, role-based access, audit trail and data hosted in India. Notices to patients, staff training and your agreements with labs remain the clinic's responsibility.
No. The score is calculated in your browser, nothing is saved, and you don't need to enter an email or phone number.
Keep reading.
- FeaturesPatient recordsA record built from every visit, not a spreadsheet row. Prescriptions, reports, notes and follow-ups sit in one timeline, linked to the patient's ABHA if they have one.
- SolutionsMulti-doctor clinicFor clinics with 2–5 doctors under one roof. Every doctor keeps their own templates and their own collections report, and every patient has one record that all of them can see.
- TrustDPDP complianceConsent, notice, retention, erasure, breach reporting and grievance handling are obligations on the clinic. Here is what each one means for an OPD, and which parts the product does for you.
- TrustSecurityPatient data is encrypted in transit and at rest, seen only by the roles that need it, logged every time it is touched, and backed up so it can be restored. Here is the detail behind each of those claims.
- ResourcesDPDP checklist for clinicsSeven parts, each with concrete items you can assign to a person and a date. Written for clinic owners and practice managers, not lawyers.
