Draft Health Data Management Policy: Towards Ensuring Data Privacy

  • 29 Aug 2020

  • The National Health Authority (NHA) has released the Draft Health Data Management Policy in the public domain.
  • The policy is part of the National Digital Health Mission (NDHM) announced on the occasion of the 74th Independence Day of India, by Prime Minister Narendra Modi.
  • The vision of NDHM is to create a national digital health ecosystem which enables timely and efficient access to inclusive, affordable, and safe healthcare to all citizens. NDHM aims to significantly improve the efficiency, effectiveness, and transparency of health services in India.

Objective of this Draft Policy

  • The main objective of this draft policy is to provide adequate guidance and to set out a framework for handling sensitive personal data of individuals participating in the mission in accordance with all applicable laws and international standards.

What are the Major Provisions?

  • Data Privacy:
  • The policy stipulates that any agency or personnel that have access to personal medical data of people enrolling in the NDHM will have to formulate and implement a personal data breach management mechanism and this will be publicly displayed.
  • Any instance of unauthorised or accidental disclosure or sharing of personal data that compromises its confidentiality and integrity should have to be reported promptly to the NHA and other relevant authorities.
  • The persons responsible for such a breach will be liable to punished according to the provisions of the applicable law.
  • Health ID:As per the draft policy, anybody enrolled for the health mission will get a Health ID free of cost and they will have complete control over their individual personal data.
  • Provision of Taking Back Consent: People are free to take back the consent already given in order to restrict any sharing of personal data linked to the ID.
  • Frameworks of Consent: It also defines the set of frameworks of consent for the collection and processing of health data by healthcare practitioners and other entities.
  • Data Interoperability and Data Sharing: It also puts forward relevant standards to meet data interoperability and data sharing.