Electronic Health Records & Patient Confidentiality in India: An Evaluative Assessment of the Developing Legal structure
- sonalimukhia2002
- 8 hours ago
- 19 min read
Author: Sneha Rawat, Uttaranchal University
ABSTRACT
The electronic healthcare records have completely changed the healthcare services by providing safe storage, administration and exchange of patient information through digital platforms. Although digital transformation has significantly improved efficiency, but it has also created concerns related to abuse of privacy, patient data security or unauthorised use of patient information along with many other cyber threats. With the increase in digitalisation of healthcare data, a need for an effective regulatory framework in order to ensure the protection of privacy is felt. This paper analyses the statutory realm administering the electronic health records and patient confidentiality in India with its emphasis on Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, Article 21 of the Indian Constitution, and relevant judicial decisions. The study adopts a library based research methodology by examining statutes, case laws, policy documents, and scholarly works. It even compares India's regulatory system with the global standards. The research paper ends by recognizing current legal gaps and suggesting improvements to strengthen patient confidentiality and secure effective protection of digital health information in India.
KEYWORDS
Electronic Health Records, Patient Confidentiality, Digital Personal, Data Protection Act, 2023, Health Data Privacy, Right to Privacy, Ayushman Bharat Digital Mission
INTRODUCTION
The evolution of information and communication technology has altered the health care department by assisting the digital administration of medical information among the most important advancement is the implementation of Electronic Health Record which assists healthcare providers to create, manage, store and exchange patient data in a digital format. Unlike the past manual data, electronic health records supply thorough and immediate availability to a patient’s medical records including their diagnosis, prescriptions, reports, scans, treatment plans and medical suggestions. By securing effective access to precise health data electronic health records provide supports in advance medical decision making, reduction of medical errors, improved health care services and persistent medical care. In India, the government has vigorously supported the digitalization of health care with the help of Ayushman Bharat Digital Mission and the Electronic Health Record Standard for India, targeting to create a patient-centric digital health environment.
Even though the transformation towards digitalization of health care provides many benefits, it also gives rise to many legal and ethical problems relating to the privacy, confidentiality and security of patient’s health information. Medical records encompasses very vulnerable private data and any illicit use, alteration and conduct can violate the privacy of a patient and may lead to many cyber crimes such as identity theft , financial loss , discrimination and may further lead to loss of trust on the healthcare department. As hospitals, laboratories, insurance companies etc rely heavily on electronic health records for administering patient’s data protecting the confidentiality of the information has always been a non-negotiable part of any responsible healthcare system.
The importance of patient privacy expands beyond professional ethics and forms an essential element of the Right to Privacy in India. In the caselaw of Justice K.S. Puttaswamy v. Union of India according to Article 21 of the Indian Constitution, the Indian Supreme Court accepted the right to privacy as a primary right. In addition to statutory advancement such as the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 regulates management, storage, exchange and safeguarding personal information in the digital domain. However, the fast growth of electronic health system continues to create various legal challenges related to cyber security, international data sharing, data breaches, consent and organisational accountability.
Contrary to this setting this research paper evaluates the statutory frameworks administering the Electronic Health Records and Patient Confidentiality in India. It evaluates the statutory and constitutional design to protect health care data while analysing their efficiency in answering the advancing technological problems. The study also compares India’s legal frameworks with International recognised standards and provides suggestions to strengthen patient confidentiality while offering support to the growth of digitalisation of healthcare.
LITERATURE REVIEW
The escalating implementation of electronic health records has attracted extensive education and policy attention due to their scope to improve healthcare services while at the same time raising concerns related to privacy. Existing literature widely evaluates the technological, statutory and ethical aspect of electronic health system, emphasising the necessity to creativity with security of personal rights.
Many scholars have acknowledged that electronic health record improve the effectiveness and the quality of healthcare by ensuring smooth availability of patient information, improving clinical observations and facilitating continuous care. In the India scenario Sunil Kumar Srivastava assert that productive implementation of electronic health records requires robust regulatory infrastructure and efficient legal safeguards. In addition, he highlights the technological growth alone cannot provide the success of digital healthcare unless it is accompanied by regulatory and organisational frameworks.
State policy documents had also emphasised the significance of uniformity in attaining an integrated health environment. The Ministry of Family Welfare with the help of Electronic Health Record Standards for India, 2016 suggests uniform standards for the accumulation, storage, exchange, security of health data to ensure compatibility across healthcare institutions .These standards recognises that digital health records must be encouraged by proper privacy and security measures to maintain public confidence.
The literature on patient confidentiality persistently recognises privacy as a basic component of doctor-patient relations. Scholars argue that confidentiality supports patient to disclose authentic medical information without fear of misuse. Nevertheless, digitalisation has widened the number of agencies capable of using patient information, hence increasing the risk of unauthorised publication, cyber attacks, identity theft and exploitation and vulnerable medical information. As a result researchers promote stronger legal safeguards and efficient measures to preserve patient confidence in digital healthcare system.
The acknowledgement of privacy as a basic right has significantly affected academic debates on health data protection in India. Many people view the caselaw of Justice K.S. Puttaswamy V. Union of India as a watershed in the advancement of data privacy jurisprudence. Legal researchers have detected that the judgment created a constitutional pillar for safeguarding personal information, including sensitive health data, and emphasised the necessity of a comprehensive data security layout. The implementation of the Digital Personal Data Protection Act, 2023 has therefore represents a significant statutory development. However, experts have also pointed out that certain issues, such as duty of care obligations for personal data, exemptions, cross-border data exchange, and enactment processes, require more clarity, specifically in relation to healthcare institutions
International scholarship provides valuable findings into the regulation of electronic health data .The Health Insurance Portability and Accountability Act in the United States has been thoroughly studied for its comprehensive framework governing the privacy and security of health data, while the European Union's General Data Protection Regulation is recognised as one of the most rigorous data protection models globally. Researchers note that both frameworks focus on informed consent, accountability, transparency, and strong penalties for non-compliance. These international practices provide useful guidance for strengthening India's legal framework governing Electronic Health Records and patient confidentiality.
Although considerable literature exists on digital healthcare, medical ethics, data privacy, and health information systems, much of the current research evaluates these subjects independently. Constrained scholarly attention has been given to analysing the relation between Electronic Health Records, the Digital Personal Data Protection Act, 2023, the Ayushman Bharat Digital Mission, constitutional privacy rights, and judicial developments within a single comprehensive legal framework. Furthermore, the evolving nature of digital healthcare requires continuous assessment of new legal and technological challenges.
Accordingly, the current research targets to bridge this gap by undertaking a comprehensive legal evaluation of Electronic Health Records and patient confidentiality in India. It vitally examines the existing constitutional, statutory, and regulatory framework while comparing international jurisdictions to evaluate the efficiency of current legal frameworks and recommend reforms for protecting sensitive health information.
METHODOLOGY
The current study uses library-based methodology which is many based on the evaluation of secondary sources of information. The library based methodology is a widely accepted method in legal research as it systematically studies and interprets the judicial decisions, academic literature, legal policies and existing statutory frameworks. Since the present study aims to evaluate the legal framework governing the electronic health records and patient confidentiality in India it is correct to use the statutory sources to achieve the goal of this research.
The research is a deep study of the primary sources such as the Constitution of India, the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, the Electronic Health Record Standards for India, 2016, and government policies relating to digital healthcare. Judicial decisions pronounced by the Supreme Court of India especially related to right to privacy have also been analysed to get a better understanding of the evolving nature of digitalisation of healthcare.
Further several secondary sources have been referred to such as books, journals, articles, research papers, expert suggestions and international publications related to electronic health records, confidentiality and digitalised healthcare data. A comparative evaluation has also been made with the international frameworks such as Health Insurance Portability and Accountability Act of the United States and the General Data Protection Regulation of the European Union.
The extent of the study is restrained to the regulatory and legal aspect of electronic health records and the confidentiality of patient .The study is to identify current legal challenges, evaluate the efficiency of the current framework, and suggest recommendations for strengthening the protection of sensitive health information in India's constantly changing digital healthcare ecosystem.
MEANING AND EVOLUTION OF EHRs
The electronic health records contain detailed information related to a patient's medical history, the treatment, allergies, scans, medication and any other medical information. Unlike the past paper based records, electronic health records enables the professionals to update patient data immediately hence facilitating efficient diagnosis, continuous care and informed decision making. Electronic healthcare records are not created merely to replace the paper based records but to efficiently share data among authorised personals more conveniently while maintaining patient confidentiality.
The concept of maintaining medical records has been a part of health sector since a very long time however the rapid growth of technology and communication during the 20th century has transformed healthcare. Hospital databases started as fragmented systems lacking system compatibility. With time, technological advancements assisted in developing electronic health records connecting hospitals, laboratories, insurance companies, etc. through a secure network. These advancements significantly improved healthcare administration by reducing paperwork, minimising duplication , enhancing coordination among healthcare providers, and promoting evidence-based medical practice.
Acknowledging the importance of digital healthcare many countries introduced legal frameworks to govern the storage, management supply and exchange of electronic health records. The United States implemented the Health Insurance Portability and Accountability Act while the European Union adopted the General Data Protection Regulation both of which offers detailed safeguards for protecting sensitive health data. These international developments have influenced global debates regarding patient privacy, cybersecurity, and responsible health information management.
In India, the transformation towards the digital age in healthcare has significantly increased over the last decade. The Ministry of Health and Family Welfare introduced the Electronic Health Record Standards for India, 2016, with the aim of fostering uniformity and compatibility among healthcare organisations. Subsequently, the Government launched the Ayushman Bharat Digital Mission to establish an integrated digital health environment that enables individuals to make digital health identities and securely access healthcare services across the country. These steps reflect India's commitment to improving healthcare reach while adopting technological innovation.
In spite of these advancements, the increasing digitisation of health data has also exposed patients and healthcare institutions to new legal and technological problems. Electronic records are vulnerable to cyberattacks, unauthorised access, identity theft, and disclosure of confidential medical data .As healthcare data has become one of the most important categories of private information, the need for efficient legal safeguards has become increasingly important. The evolution of Electronic Health Records has been accompanied by a growing emphasis on data protection, consent, confidentiality, accountability, and cybersecurity, making these issues central to healthcare law and policy.
SIGNIFICANCE OF PATIENT CONFIDENTIALITY
Patient confidentiality is one of the basic rules of medical ethics and healthcare. It refers to the duty of medical professionals to protect personal and medical data provided by patients during their treatment. The principle is based on trust so that patients can disclose their information to professionals without the fear of their information getting into the hands of unauthorised persons. A confidential doctor-patient relation not only assists in treatment but also helps in maintaining the autonomy and privacy of an individual.
The duty to maintain confidentiality has long been a part of the healthcare system through professional standards. Medical professionals frequently get access to information related to the physical health, mental health, genetic characteristics and lifestyle information of an individual. Exposing such information without any legal authority and the consent of the patient’s confidentiality is regarded as ethical duty as well as a legal responsibility.
In the Indian legal setting patient’s privacy derived support from the Right to Life and personal liberty under Article 21 of the Constitution of India. The Indian Supreme Court had decoded this provision to involve right to privacy acknowledging that privacy is an essential part of individual autonomy and dignity. The landmark judgement in Justice K.S Puttaswamy V. Union of India confirms that personal information including medical information deserves protection from unlawful interference. This decision has affected the emergence of data protection laws in India.
The significance of privacy has become even more essential with the rapid adoption of electronic health records unlike previous paper record digital information can be assessed transferred copied or exchanged within seconds across multiple institutions, while such access improves the quality of medical care it also increases the risk of cyberattacks, disclosure and misuse of sensitive information. These problems emphasise the need for robust technical measures, consent mechanisms, access controls and accountability to make sure that patient information remains safe.
In addition, maintaining confidentiality is important for maintaining public confidence in healthcare system. Patients who fear that their personal information may get leaked are less likely to disclose complete and accurate information, ultimately affecting treatment and diagnosis and public health. Hence, an efficient legal framework must maintain a balance between facilitating exchange of information and protecting the privacy of an individual.
LEGAL FRAMEWORKS GOVERNING EHRs IN INDIA
The legal framework governing electronic health records has evolved in response to the increased digitalisation of healthcare and the growing need to protect sensitive information. Even though India currently does not have a single legislation exclusively regulating electronic health records, several constitutional provisions, statutory enactments, judicial judgements and governmental policies govern the storage, management and exchange of electronic health records. The existing legal framework aims to seek a balance between technological developments and patient privacy and data security.
Constitutional Protection
The Constitution of India provides the foundation for protecting patient privacy under Article 21 which ensures the right to life and personal liberty. Over the years, the Indian Supreme Court has interpreted Article 21 to include Right to Privacy, recognising that dignity and information privacy are the basic aspect of a meaningful life.
In Justice K.S. Puttaswamy V. Union of India the Supreme Court held that privacy is a fundamental right under Article 21.The Court recognised informational privacy as a part of right to privacy and observed that individuals must have control over the collection, storage and exchange of their personal information. Since medical records contain highly vulnerable information the principle laid down in Puttaswamy provides constitutional protection to electronic health records.
Information Technology Act, 2000
Before the enactment of specialised data protection legislation, the Information Technology Act, 2000 served as the primary framework governing electronic records and cybersecurity. The Act imposes obligations on organisations handling sensitive information to adopt security practices and procedures. The Information Technology Rules, 2011 recognised medical records and health information as sensitive data requiring to maintain appropriate security measures.
Although, the IT Act was an important step towards digital data protection, scholars observed it was not specifically designed to regulate modern digital healthcare environment, it lacked provisions relating to patient rights, accountability and large scale health information governance.
Digital Personal Data Protection Act, 2023
An important advancement in India’s data protection regime is the enactment of the Digital Personal Protection Act, 2023. The act provides a comprehensive legal layout regulating the processing of digital personal data and imposes obligations for institutions responsible for collecting and processing such information.
Although the act does not have specific provisions related to health data, it still regulates medical data as it constitutes personal data. The act requires data administrators to process personal data legally for specified purposes and based on consent. It also guarantees certain rights to individuals including right to access information related to their personal data, seek correction and obtain grievance redressal.
Electronic Health Record Standards for India , 2016
Recognising the need for uniformity in the administration of digital health information the Ministry of Health and Family Welfare issued the Electronic Health Record Standards for India, 2016. These standards were introduced to promote compatibility and secure exchange of electronic health information. They provide a mutual framework for creating, maintaining, storing and sharing of electronic health records while making sure that while ensuring that health information remains accurate accessible and protected.
The Electronic Health Record Standards incorporated globally accepted technical standards related to data format, coding system and information exchange protocol. They also focus on confidentiality, consent, authentication and access control mechanisms. By motivating health care institutions to adopt uniform standards by government aims to improve coordination among hospitals, laboratories, pharmacies and other healthcare providers while reducing duplication of medicals records.
However these standards function as regulatory technical guidelines rather than a statutory framework. Their efficiency depends upon implementation by healthcare institutions and compliance with legal provisions governing privacy and data protection.
Ayushman Bharat Digital Mission
The Ayushman Bharat Digital Mission is one of India's most ambitious digital healthcare initiatives. Launched by the Government of India, the Mission aims to create an integrated digital health environment by enabling secure exchange of health information among patients, healthcare professionals, hospitals, laboratories, pharmacies, and insurance providers. The Mission introduces several digital components, including the Ayushman Bharat Health Account, which provides individuals with a unique digital health identity for accessing healthcare services.
One of the striking features of this scheme is that it focuses on patient consent. The framework aims to make sure that health data is shared only with the consent of the individual concerned. Patients retain greater control over their medical records and may authorise or refuse the sharing of specific health information with healthcare providers. This consent-based model reflects internationally recognised principles of informational privacy and individual autonomy.
In spite of its transformative potential, the implementation of the ABDM presents several legal and practical problems. Issues relating to cybersecurity, digital literacy, consent, compatibility among healthcare systems, and accountability for data breaches remain areas of concern. Moreover, the successful functioning of the Mission depends upon strict compliance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and the EHR Standards to ensure that patient confidentiality is protected.
JUDICIAL APPROACH
The Indian judiciary has played an important role in supporting the legal protection of patient confidentiality and informational privacy. Through various landmark decisions, the Supreme Court has recognised that medical information contains sensitive personal data requiring constitutional protection. Judicial interpretation has therefore contributed significantly to the development of privacy jurisprudence even before the enactment of data protection legislation.
The most significant decision in this regard is Justice K.S. Puttaswamy V. Union of India (2017), where a nine-judge Bench of the Supreme Court recognised the right to privacy as a fundamental right under Article 21 of the Constitution of India. The Court observed that informational privacy forms an essential part of individual dignity and autonomy, and that individuals possess a legitimate expectation that their personal information will not be disclosed without lawful justification. The principles laid down in this judgment provide the basis for protecting Electronic Health Records and regulating the processing of sensitive health information.
Another important decision is Mr. X v. Hospital Z (1998), where the Supreme Court examined the balance between patient confidentiality and interest of the public. The Court held that although medical confidentiality is an important legal and ethical obligation, it is not an absolute right. Disclosure may be justified where it is necessary to protect the health and safety of others or where disclosure is authorised by law. The judgment illustrates that patient confidentiality must be balanced against public interests in exceptional circumstances.
CHALLENGES IN PROTECTING ELECTRONIC HEALTH RECORDS
The inculcation of electronic health records has significantly improved the quality of healthcare services but it also poses many technical, legal and ethical challenges. Since these records contain very sensitive information any manipulation may affect the patient's privacy, dignity and his confidence in the health department. Although India has taken important steps towards digital healthcare through the Ayushman Bharat Digital Mission and the Digital Personal Data Protection Act, 2023, several challenges continue to hinder the effective protection of electronic health information.
One of the striking challenges is the risk of cybersecurity attacks. Hospitals and other health institutions have become an important target for cyber criminals as they have personal and financial information of an individual. Incidents involving ransomware attacks, hacking, phishing, and unauthorised access can disturb healthcare services and expose confidential patient data. Many healthcare institutions, specifically smaller hospitals and clinics, continue to face limitations in implementing advanced cybersecurity infrastructure due to a lack of technical resources.
Another important concern is the issue of informed consent. Although the legal framework prioritises patient consent before sharing their data many people are still unaware about how their personal information is shared, stored and exchanged between third parties. In practice, consent forms are often lengthy and technical, making it difficult for patients to fully understand the implications of providing consent. Consequently, meaningful and informed consent remains a challenge in India's digital healthcare ecosystem.
The absence of a comprehensive healthcare-specific data protection framework also presents difficulties. While the Digital Personal Data Protection Act, 2023 provides a framework for the protection of personal data, it does not exclusively regulate Electronic Health Records or prescribe detailed standards for health information management. As a result, healthcare institutions must rely upon multiple statutes, policies, and guidelines, which may create uncertainty regarding compliance and enforcement.
India also faces challenges relating to digital infrastructure and digital literacy. The successful implementation of Electronic Health Records depends upon reliable internet connectivity, trained healthcare personnel, and secure digital systems. In many rural and remote areas, inadequate technological infrastructure and limited awareness regarding digital privacy continue to affect the implementation of electronic health systems.
Finally, ensuring institutional accountability remains a significant challenge. Healthcare providers, hospitals, technology companies, and government agencies all play important roles in handling electronic health information. In the absence of clear accountability mechanisms, determining responsibility for data breaches or unauthorised disclosures may become difficult.
COMPARATIVE ANALYSIS: INDIA, HIPAA and GDPR
The legal framework governing Electronic Health Records in India may be better understood by comparing it with established international data protection regimes. The Health Insurance Portability and Accountability Act of the United States and the General Data Protection Regulation of the European Union are regarded as global benchmarks for protecting health information and personal data.
HIPAA establishes detailed standards governing the privacy, security, and confidentiality of protected health information. It imposes strict obligations upon healthcare providers, insurers, and related entities regarding the collection, use, disclosure, and storage of medical records. The legislation also requires healthcare organisations to implement administrative, physical, and technical safeguards to prevent unauthorised access and provides penalties for non-compliance.
Similarly, the GDPR adopts a comprehensive rights-based approach towards personal data protection. It recognises health information as a special category of personal data requiring protection. The GDPR emphasises principles such as legality, fairness, transparency, data minimisation, accuracy, storage limitation, confidentiality, and accountability. Individuals are granted exclusive rights, including the right to access, correct, erase, and restrict the processing of their personal data.
Compared with these international frameworks, India's legal regime is still not mature enough. The Digital Personal Data Protection Act, 2023 represents a significant step towards strengthening personal data protection; however, India presently lacks detailed healthcare-specific legislation equivalent to HIPAA. While initiatives such as the Electronic Health Record Standards and the Ayushman Bharat Digital Mission provide an important foundation for digital healthcare governance, stronger enforcement mechanisms are necessary to ensure protection of Electronic Health Records.
DISCUSSION
The evaluation undertaken in this research shows that electronic health records have basically transformed healthcare services by improving effectiveness, accessibility and continuous medical care. At the same time, the increase in digitalisation of the health system has created important concerns regarding patient, privacy, cyber security and data governance. The constitutional recognisation of privacy as a fundamental right along with legislative developments, such as the Digital Personal Data Protection Act, 2023 and policy initiatives, including the Ayushman Bharat Digital Mission reflects India’s commitment to creating a strong digital health government.
However, the research also shows that India’s legal framework still remains in progress. The absence of a specific statute exclusively regulating electronic health records creates governance gaps related to consent, management, compatibility, accountability and breach. In addition, technological challenges, inefficient cyber security infrastructure, lack of public awareness and lack of digital literacy continue to affect the efficiency of digital healthcare initiatives.
The comparative analysis with HIPAA and GDPR indicates that India can benefit from adopting clear healthcare, specific standards, strong enforcement, and detailed patient rights relating to health data. While it is not correct to replicate foreign legal structure completely, the best practices can be adopted to suit India’s setting.
Overall, achieving a balance between innovation and privacy remains the main challenge of India’s digital healthcare system. A balanced approach involving legislators, professionals, technology providers, regulatory authorities, and patiennts is required for ensuring that technological progress does not compromise with an individual’ privacy.
RECOMMENDATIONS
In the light of challenges associated with electronic health records, several reforms are required to strengthen confidentiality and ensure a secure management of health information in India. Even though the current legal framework provides a significant foundation, continuous improvements in legislation, institutional practices and technological safeguard are necessary for building public confidence in healthcare systems.
Firstly, India should enact a thorough healthcare-specific data protection framework that regulates the collection storage sharing and exchange of electronic health data. Although, the Digital Personal Data Protection Act, 2023 regulates digital, personal data, healthcare information, possesses unique characteristics that require special legal protection.
Secondly, healthcare organisations should create strong, cybersecurity measures, including to an encryption, authentication, intrusion, detection systems, etc. Regular cybersecurity evaluation would reduce the risk of data breaches is and unauthorised access.
Thirdly, focus should be placed on patient awareness and consent. Healthcare providers must make sure that the consent forms are drafted in a clear and easy manner so that the patients are informed regarding the collection, use and sharing of their personal information. Public awareness programmes can also improve the understanding of digital privacy rights and encourage responsible participation in digital initiatives.
Another important recommendation is improving the skills of healthcare professionals. Doctors, nurses, hospitals, administrator, and other healthcare professionals should receive regular training on data, privacy laws, cyber security, confidentiality obligations, and ethical sharning of electronic health records.
Finally, the government should strengthen regulatory and accountability mechanisms. Collaboration between government agencies, healthcare providers, technological companies and legal experts will further contribute to developing a safe and trustworthy digital healthcare environment.
CONCLUSION
The growth of electronic health records marks an important milestone in the modernisation of India’s healthcare system. Digital health technologies have improved the quality, effectiveness and accessibility of medical services, nevertheless, the increasing reliance on digital health data has also intensified concerns regarding patient confidentiality and cybersecurity.
This research evaluated the legal framework governing electronic health records and patient confidentiality in India by analysing constitutional protection, statutory provisions, government initiatives and judicial pronouncements. The research shows that although India has taken a step forward through recognition of privacy as a fundamental right, the introduction of the Digital Personal Data Protection Act, 2023, and the implementation of the Ayushman Bharat Digital Mission, important legal and practical challenges continue to exist.
The study also concludes that efficient protection of electronic health records requires more than legislative reform. Robust institutional governance, cybersecurity measures, patient, consent, continuous training of healthcare, professionals and increase. Public awareness is also important for safeguarding health information. Comparative evaluation with international legal framework, illustrates the importance of thorough regulatory standards and effective enforcement mechanisms.
In conclusion, the success of India’s Digital healthcare environment depends upon its ability to maintain a balance between technological innovation and the protection of privacy. By strengthening legal safeguards and promoting responsible data governance, India can develop a healthcare system that not only embraces digital transformation but also uphold the constitutional values of dignity and confidentiality. Electronic health records should therefore be viewed not merely as technological tools but also as elements of highly sensitive personal, information, deserving legal protection.
REFERENCES
BOOKS
C.R. Kothari, Research Methodology: Methods and Techniques (2d ed. 2004).
JOURNAL ARTICLES
Sunil Kumar Srivastava, Adoption of Electronic Health Records: A Roadmap for India, 5 Healthcare Informatics Research 1 (2016).
CONSTITUTIONAL AND STATUTORY MATERIALS
A. Constitution
India Const. art. 21.
B. Indian Statutes
Digital Personal Data Protection Act, No. 22 of 2023 (India).
Information Technology Act, No. 21 of 2000 (India).
C. Rules and Regulations
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, G.S.R. 313(E) (India).
JUDICIAL DECISIONS
Justice K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1.
Mr. X v. Hospital Z, (1998) 8 SCC 296.
GOVERNMENT REPORTS, GUIDELINES AND OFFICIAL DOCUMENTS
Ministry of Health & Family Welfare, Government of India, Ayushman Bharat Digital Mission (Official Portal).
Ministry of Health & Family Welfare, Government of India, Electronic Health Record (EHR) Standards for India (2016).
INTERNATIONAL AND FOREIGN LEGISLATION
Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, 110 Stat. 1936 (1996) (U.S.).
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).
INTERNATIONAL ORGANISATIONS AND POLICY DOCUMENTS
Organisation for Economic Co-operation and Development (OECD), Health Data Governance: Privacy, Monitoring and Research (2015).
World Health Organization, Global Strategy on Digital Health 2020–2025 (2021).
World Health Organization, WHO Guideline: Recommendations on Digital Interventions for Health System Strengthening (2019).




Comments