Doctors and clinics: how to keep patient records safe on a PC (DPDP Act guide)
A clinic's computer holds some of the most private information there is: diagnoses, prescriptions, lab reports, scans and phone numbers. Patients rarely think about where it's kept, until something goes wrong. Here's how a small clinic, a doctor's practice or a diagnostic centre can protect patient records on an ordinary Windows PC.
What the rules expect
- Medical records: the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002, which the NMC currently applies, require physicians to keep indoor patients' records for 3 years from the start of treatment, and to provide records within 72 hours when a patient or a legal authority asks.
- DPDP Act, 2023: health data is digital personal data, and clinics and hospitals that process it are data fiduciaries. The Act has no special health-data category, so the general duties apply in full.
- DPDP Rules, 2025, Rule 6: security safeguards including encryption, obfuscation, masking or virtual tokens; access controls; access logs kept for one year; and backups so records survive a compromise. Rule 6 takes effect around 13 May 2027.
Set it up on the clinic PC
- Download Clavis Encrypt and install it on the clinic PC. It needs no internet connection to work, and no administrator rights.
- Create a vault with a strong password known only to the doctor or practice owner, and store the one-time recovery key safely away from the PC.
- Encrypt existing patient folders. Clavis Pro encrypts whole folders; Free encrypts files one at a time.
- Make the folder where your scanner, ECG machine or lab software saves files a watch folder, so every new report is encrypted automatically.
- Open a record by double-clicking the
.encfile; it opens in its usual program. With Pro's Open, changes are saved and the file re-locked when you close it. - Back up regularly to an external drive. Encrypted files stay encrypted in the backup; Clavis Premium also makes one-file vault backups.
Everyday practices that prevent most leaks
- Separate Windows accounts for the doctor and the front desk, so staff only see what they need.
- Don't send reports over unprotected email or WhatsApp. Encrypt them first, or share through a secure channel. See encrypting files before emailing.
- Lock the screen when you step away. Clavis locks itself when Windows locks or the PC sleeps.
- Before sending the PC for repair, make sure patient files are encrypted, or remove the drive.
- Turn on full-disk encryption (BitLocker or Device encryption) too, for a stolen PC.
Which tool fits a small clinic?
| Need | Clinic software (EMR/HMS) | Clavis Encrypt |
|---|---|---|
| Appointments, billing, prescriptions | Yes | No (not an EMR) |
| Protects scans, PDFs and reports saved as files | Depends on the product | Yes, any file type |
| Works without internet | Varies | Yes |
| Keeps data on your own PC | Often cloud-hosted | Yes |
| Cost | Monthly fees are common | Free for files; Pro one-time $19 |
Clavis Encrypt doesn't replace clinic-management software; it protects the files around it: scanned reports, exported PDFs, referral letters and anything saved to disk.
Questions
How can a small clinic keep patient records secure on a computer?
Encrypt patient files on the PC, give each person a separate Windows login, keep an encrypted backup on an external drive, and avoid sending reports over unprotected email or WhatsApp. A file-encryption app such as Clavis Encrypt seals each file with AES-256-GCM, works offline, and can encrypt new reports automatically.
Does the DPDP Act apply to doctors and clinics?
Yes. Patient information is digital personal data, and clinics that process it are data fiduciaries under the DPDP Act, 2023. The DPDP Rules, 2025 (Rule 6) set security safeguards including encryption, access controls, logs and backups, taking effect around May 2027.
How long must doctors keep medical records in India?
The Indian Medical Council Regulations, 2002, applied by the NMC, require records of indoor patients to be kept for 3 years from the start of treatment, and copies to be provided within 72 hours on request. Other laws or your state may require longer, so check with your association or a lawyer.
Is it safe to send lab reports on WhatsApp?
WhatsApp messages are end-to-end encrypted in transit, but copies stay on both phones and in any chat backups, and they're easy to forward to the wrong person. Encrypt sensitive reports first, or use a channel built for medical records.
Will encrypted patient files open in my usual programs?
Yes. Double-click the encrypted file in Clavis Encrypt and it opens in the program it normally opens in, whether that's a PDF viewer, an image viewer or Word.
Sources
- National Medical Commission — Code of Medical Ethics Regulations, 2002
- DPDP Rules, 2025 — Rule 6, reasonable security safeguards (text)
- AMLegals — health data and the DPDP Act, a practical guide
- Clavis Encrypt — security design
This guide explains general practice, not legal advice. Laws and rules change; check the current text or ask a lawyer for your situation.