7 mins

DPDP 72 Hours vs CERT-In 6 Hours: Managing Dual Clocks for Healthcare Breaches

Manage the overlapping incident reporting timelines under the DPDP Rules, 2025 and CERT-In mandates. General Counsels in healthcare must update vendor SLAs to handle dual legal liability.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

A single security incident affecting digital patient records triggers a 6-hour cyber reporting window to CERT-In and a 72-hour personal data breach notification window under the DPDP Rules, 2025. HealthTech platforms face dual clocks for the exact same server intrusion. The Data Protection Board requires a detailed breach report within 72 hours. Simultaneously, the Digital Personal Data Protection Act, 2023 commands fiduciaries to notify affected Data Principals without delay. CERT-In demands technical indicators of compromise within 6 hours. Managing one incident across two strict timelines forces legal teams to gather automated evidence before outside counsel drafts a response. The Board evaluates compliance under Section 33. Section 33(2)(e) directs the Board to review the timeliness and effectiveness of mitigation efforts when calculating penalties. Failing to reconcile a rushed 6-hour technical filing with a detailed 72-hour DPDP filing creates permanent liability records.

What to Keep vs What to Build for Breach Governance

Legal teams often rely on manual playbooks and external law firms to draft incident reports. Manual governance creates massive litigation risk when the 6-hour and 72-hour clocks start ticking simultaneously. You must keep the legal review process in-house. Internal review protects privilege and determines the exact scope of liability. You need runtime enforcement tools to automatically detect compromised patient data fields. These systems generate the specific technical logs CERT-In and the DPB require. ComplyDP maps patient data flows in 24 hours. The platform separates cyber security forensics from the personal data liability assessment. This division lets your legal team focus on regulator engagement. The software establishes the technical evidence trail in the background. If your technical team spends three days querying databases to see which patient files leaked, you will miss both regulatory deadlines. You fail the CERT-In mandate by 66 hours. You leave external counsel with zero hours to draft the DPDP submission.

Allocating Liability Across the Dual Reporting Framework

The dual reporting framework demands precision in your processor contracts. The Data Protection Board evaluates the nature, gravity, and duration of the breach under Section 33(2)(a). Fines for reporting failures reach 200 crore rupees. HealthTech platforms operating at scale attract Significant Data Fiduciary scrutiny due to the high volume of health data processed. Filing an inaccurate 6-hour CERT-In report contradicts the detailed 72-hour DPB filing. This contradiction damages your defensibility during a regulatory inquiry. General Counsels must draft specific indemnities and tight Service Level Agreements into every processor contract. A standard 24-hour vendor notification SLA leaves the internal legal team exposed to a CERT-In violation. The processor must notify the fiduciary within 2 hours of a suspected breach. This tight window gives the fiduciary 4 hours to verify the anomaly and submit the CERT-In report. Cross-border data flows add another layer of complexity. Section 16(1) allows the Central Government to restrict the transfer of personal data outside India. Your incident response tools and vendor logs must reside in permitted jurisdictions to avoid secondary compliance failures during a live breach investigation.

Acceptance Tests a Procurement Team Can Run

Healthcare procurement teams evaluating incident response tools must run specific acceptance tests to measure defensibility.

1. Simulate a ransomware attack on a clinic management system. The tool must isolate the compromised databases and identify the affected digital personal data within 3 hours.

2. Require the platform to log exactly when a third-party processor detects an anomaly. The system must record the exact minute the processor notifies your internal legal desk.

3. Validate the export formats. The software must generate a raw technical indicator export for CERT-In and a separate categorized personal data breach report for the DPB.

4. Test the historical audit trail. The Board reviews the repetitive nature of the breach under Section 33(2)(c). The system must prove this incident is an isolated event rather than a recurring vulnerability.

If the proposed solution requires a week of manual database queries by an IT vendor to answer these basic questions, it fails the baseline regulatory requirements. Fiduciaries cannot wait for manual forensic reports when the law demands immediate notifications.

Common Mistake: Treating Withdrawal as Global Delete

A frequent error during post-breach remediation involves confusing consent withdrawal with mandatory deletion. Patients often panic upon receiving a breach intimation. They revoke consent for processing to stop further data exposure. Legal teams sometimes execute a global delete command across all health systems to minimize perceived exposure. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Revoking consent stops marketing communications and elective data sharing immediately. The hospital must still retain specific clinical records, prescriptions, and billing data to comply with medical council regulations and tax laws. Your compliance architecture must isolate elective processing from mandatory legal retention. Deleting a medical history due to a DPDP consent withdrawal creates separate liabilities under healthcare delivery standards. The breach notification must clearly explain to the Data Principal what data was affected. The notice must specify the exact remediation steps taken. The fiduciary must not destroy statutory records under the guise of honoring a privacy request.

Managing the Enforcement Timeline

You have exactly 221 days until the hard compliance deadline of 13 May 2027. Section 1(2) gives the Central Government power to appoint different commencement dates for different provisions. The penalty framework takes effect immediately upon enforcement. Relying on outside counsel to manually draft incident reports during a live breach exhausts the 6-hour CERT-In window immediately. Doctors and clinics cannot use complex banking software to manage these workflows. Healthcare decision makers need automated data mapping and breach identification systems tailored to patient data flows. Test your internal workflows against the DPDP Rules, 2025 reporting templates today. A live incident forces the issue without warning. Evaluate your readiness and map your patient data flows at https://www.complydp.com/audit-preview.

Sources

Frequently asked questions

What triggers the DPDP 72-hour breach reporting clock?

Identifying a personal data breach under the DPDP Rules, 2025 starts the clock. The fiduciary must notify the Data Protection Board within 72 hours and inform affected Data Principals without delay.

How does the CERT-In 6-hour rule overlap with the DPDP Act?

CERT-In mandates reporting cyber security incidents within 6 hours of identification. A single server hack triggers both the CERT-In cyber deadline and the DPDP personal data deadline, requiring coordinated legal review.

Can our external legal counsel handle both reporting windows?

Relying solely on outside counsel often delays the initial response past the 6-hour CERT-In window. General Counsels need automated data mapping tools to provide lawyers with immediate facts to draft the filings.

Are HealthTech platforms automatically Significant Data Fiduciaries?

Designation depends on data volume and risk parameters defined by the Central Government. Healthcare platforms handling large patient datasets attract SDF classification, bringing stricter audit requirements.

What penalties apply for missing the DPDP reporting deadline?

Under Section 33 of the DPDP Act, 2023, the Board evaluates timeliness and mitigation effectiveness. Fines for failing to report a personal data breach to the Board or the Data Principal reach 200 crore rupees.