Skip to main content

Hospital Software Compliance in India 2026: ABDM, DPDP, NABH & GST

T
Team Healthixio
29/7/20266 min read
Hospital Software Compliance in India 2026: ABDM, DPDP, NABH & GST

A hospital in India running software today is answerable to five different regimes at once: ABDM for digital health records, the DPDP Act for patient data, CERT-In for cyber incidents, NABH for accreditation, and GST for billing — with NHCX arriving for insurance claims.

Most hospitals discover these one crisis at a time: during an NABH assessment, after a GST notice, or when an insurer asks for structured claim data. This checklist puts all of them in one place, with the specific software capability each one requires — so you can evaluate your current system, or a vendor's, against the whole picture.

1. ABDM — Digital Health Records

Governing body: National Health Authority.

ABDM is the one regime where the software vendor, not the hospital, must be certified. A hospital cannot create ABHA IDs or link health records with software that has not cleared the NHA's milestone process.

  • Facility registered on HFR — the Health Facility Registry entry for your hospital. Registration guide.
  • Doctors registered on HPR — individual practitioner registration. Guide.
  • Software certified for M1, M2 and M3 — verify the milestone status directly rather than accepting an "ABDM ready" claim. What the milestones mean.
  • ABHA creation and verification at registration, including Scan and Share for OPD.
  • Consent capture and health record linking — records linked only with recorded patient consent.

Ask your vendor: which milestones have you cleared, and can you show me the certification? Full list in the ABDM compliance checklist.

2. DPDP Act — Patient Data Protection

Governing body: Data Protection Board of India.

Under the Digital Personal Data Protection Act, a hospital is a Data Fiduciary processing sensitive personal data. The duties are yours, but almost all of them are discharged through software capabilities:

  • Consent and purpose limitation — collect what you need, for a stated purpose, with notice to the patient.
  • Reasonable security safeguards — encryption in transit and at rest, access control, and backups. Failure to maintain these is itself a penalised breach of duty.
  • Unique logins and role-based access — no shared accounts, and permissions that follow the job role.
  • Breach detection and notification — you must be able to detect a breach, determine its scope, and notify the Board and affected patients.
  • Data principal rights — the ability to give a patient their data, correct it, and erase it where the law allows.
  • Retention limits — a defined policy for how long records are kept, aligned with medical record retention rules.
  • Processor accountability — a written agreement with your software vendor covering how they handle your data.

Ask your vendor: can we enforce unique logins, restrict exports, and produce a per-user access report for any date range? Detail in the DPDP Act guide and how hospital data leaks happen.

3. CERT-In — Cyber Incident Reporting

Governing body: Indian Computer Emergency Response Team.

CERT-In directions apply to organisations across sectors, including healthcare, and impose two obligations that hospitals routinely fail on:

  • Incident reporting within the mandated window — ransomware, data breaches, and unauthorised access must be reported promptly after being noticed.
  • Log retention — system logs must be maintained for the prescribed period and be producible on request.
  • Synchronised system clocks — logs across systems must line up to a common time source, or they are useless as evidence.

Ask your vendor: are audit logs immutable, retained for the required period, and exportable in a form we could hand to an investigator? See audit logs and access control.

4. NABH — Accreditation

Governing body: National Accreditation Board for Hospitals and Healthcare Providers.

NABH does not certify software, but assessors ask for evidence that software either produces or fails to produce:

  • Complete and legible clinical documentation — assessment notes, care plans, progress notes, and discharge summaries.
  • Informed consent records — captured, stored, and retrievable per procedure.
  • Medication management trail — prescription, dispensing, and administration records.
  • Unique patient identification — one UHID per patient, with duplicate prevention at registration.
  • Quality indicators — turnaround times, infection rates, readmissions, and mortality data, produced as reports rather than counted by hand.
  • Incident reporting and corrective action tracking.
  • Medical record retention per NABH and statutory requirements.

Ask your vendor: can the system produce our NABH indicator data as standard reports? See NABH accreditation and hospital software.

5. GST and Financial Compliance

Governing body: GST Council and CBIC.

Healthcare services are largely exempt, which is exactly why hospital GST goes wrong — the taxable items are the ones nobody watches:

  • Correct treatment of exempt vs taxable supplies — pharmacy sales to outsiders, cosmetic procedures, canteen, room categories above prescribed thresholds, and equipment rental each behave differently.
  • GST-compliant invoice format with GSTIN, HSN/SAC codes, and correct tax breakup.
  • E-invoicing where the hospital crosses the applicable turnover threshold.
  • Input tax credit tracking and reversal rules for exempt supplies.
  • TDS on professional fees for consultant doctor payouts.
  • Return-ready reports that reconcile to your billing data without manual rework.

Ask your vendor: does the system handle exempt and taxable supplies on the same bill, and generate return-ready summaries? See hospital billing and GST in India.

6. NHCX — Claims Readiness

Governing body: National Health Authority.

The National Health Claims Exchange standardises how claims move between hospitals, insurers, and TPAs. It is being rolled out progressively rather than switched on everywhere at once, but readiness is now a competitive question:

  • Structured, standards-based claim data rather than scanned documents.
  • Policy and payer details captured at admission, not reconstructed at discharge.
  • Pre-authorisation and query tracking inside the system.
  • Claim status visibility — submitted, queried, approved, settled — for every claim.
  • ABHA linkage connecting the claim to the patient's health account.

Step-by-step preparation in the NHCX integration guide.

The One-Page Vendor Question List

  1. Which ABDM milestones has your software cleared, and can you evidence it?
  2. Can we enforce one login per user and role-based access per module?
  3. Are audit logs immutable, retained, and exportable?
  4. Can we restrict and log bulk data exports?
  5. Is data encrypted at rest and in transit, and where is it hosted?
  6. What is your breach notification process and timeline to us?
  7. Can the system produce NABH indicator reports as standard?
  8. Does billing handle exempt and taxable supplies, e-invoicing, and TDS?
  9. Can we hold scheme, TPA, and cash rates separately against one record?
  10. Can we export our complete data, in a usable format, if we leave?

A vendor who answers these confidently and in writing is a compliance asset. One who deflects is a liability you will discover during an assessment.

Frequently Asked Questions

Is ABDM compliance mandatory for hospitals in India?

ABDM is not uniformly mandatory nationwide, but several states have moved towards requiring it for empanelment and scheme participation, and NHA incentive programmes have rewarded digital record creation. The practical position in 2026 is that ABDM adoption is becoming a condition of doing business with government schemes and insurers rather than an optional upgrade. See is ABDM mandatory for hospitals.

Does the DPDP Act apply to small clinics and nursing homes?

Yes. The Act applies to any entity determining the purpose and means of processing digital personal data, with no exemption based on hospital size. A 15-bed nursing home holding patient records digitally carries the same core duties around consent, security safeguards, and breach notification as a large hospital, though the scale of implementation differs.

Can one hospital management system cover all of these requirements?

Yes, and it should. ABDM certification, access control and audit logs, NABH documentation and indicators, GST-compliant billing, and structured claim data are all software capabilities. Splitting them across separate products creates reconciliation gaps that themselves become compliance failures — the classic example being pharmacy running on separate software, so dispensing records and bills never fully match.

Who is responsible if our software vendor causes a data breach?

The hospital remains the Data Fiduciary and is accountable to patients and the Data Protection Board, regardless of where the failure occurred. That is why a written data processing agreement with your vendor, covering security obligations, breach notification timelines, and audit rights, is not optional paperwork.

Meet Every Requirement on One Platform

Healthixio is built for Indian regulatory reality: ABDM-integrated with ABHA and consent handling, role-based access with complete audit logs and encryption, GST-ready billing with scheme and TPA rate structures, and MIS reporting that produces the indicators assessors ask for. See ABDM integration, the security module, or talk to us on 07513135857.

Tags:#Compliance#ABDM#DPDP Act#NABH#GST