Doctors and clinics: how to keep patient records safe on a PC (DPDP Act guide)

A clinic's computer holds some of the most private information there is: diagnoses, prescriptions, lab reports, scans and phone numbers. Patients rarely think about where it's kept, until something goes wrong. Here's how a small clinic, a doctor's practice or a diagnostic centre can protect patient records on an ordinary Windows PC.

Short answer: keep patient files encrypted on the clinic PC, keep an encrypted backup, and give each person their own login. A file-encryption app such as Clavis Encrypt seals each report or record with AES-256-GCM, works offline, and can automatically encrypt every new scan or report saved into a folder. Under India's DPDP Act, clinics are data fiduciaries, and the DPDP Rules, 2025 name encryption and backups among the required security safeguards.

What the rules expect

  • Medical records: the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002, which the NMC currently applies, require physicians to keep indoor patients' records for 3 years from the start of treatment, and to provide records within 72 hours when a patient or a legal authority asks.
  • DPDP Act, 2023: health data is digital personal data, and clinics and hospitals that process it are data fiduciaries. The Act has no special health-data category, so the general duties apply in full.
  • DPDP Rules, 2025, Rule 6: security safeguards including encryption, obfuscation, masking or virtual tokens; access controls; access logs kept for one year; and backups so records survive a compromise. Rule 6 takes effect around 13 May 2027.

Set it up on the clinic PC

  1. Download Clavis Encrypt and install it on the clinic PC. It needs no internet connection to work, and no administrator rights.
  2. Create a vault with a strong password known only to the doctor or practice owner, and store the one-time recovery key safely away from the PC.
  3. Encrypt existing patient folders. Clavis Pro encrypts whole folders; Free encrypts files one at a time.
  4. Make the folder where your scanner, ECG machine or lab software saves files a watch folder, so every new report is encrypted automatically.
  5. Open a record by double-clicking the .enc file; it opens in its usual program. With Pro's Open, changes are saved and the file re-locked when you close it.
  6. Back up regularly to an external drive. Encrypted files stay encrypted in the backup; Clavis Premium also makes one-file vault backups.

Everyday practices that prevent most leaks

  • Separate Windows accounts for the doctor and the front desk, so staff only see what they need.
  • Don't send reports over unprotected email or WhatsApp. Encrypt them first, or share through a secure channel. See encrypting files before emailing.
  • Lock the screen when you step away. Clavis locks itself when Windows locks or the PC sleeps.
  • Before sending the PC for repair, make sure patient files are encrypted, or remove the drive.
  • Turn on full-disk encryption (BitLocker or Device encryption) too, for a stolen PC.

Which tool fits a small clinic?

NeedClinic software (EMR/HMS)Clavis Encrypt
Appointments, billing, prescriptionsYesNo (not an EMR)
Protects scans, PDFs and reports saved as filesDepends on the productYes, any file type
Works without internetVariesYes
Keeps data on your own PCOften cloud-hostedYes
CostMonthly fees are commonFree for files; Pro one-time $19

Clavis Encrypt doesn't replace clinic-management software; it protects the files around it: scanned reports, exported PDFs, referral letters and anything saved to disk.

Questions

How can a small clinic keep patient records secure on a computer?

Encrypt patient files on the PC, give each person a separate Windows login, keep an encrypted backup on an external drive, and avoid sending reports over unprotected email or WhatsApp. A file-encryption app such as Clavis Encrypt seals each file with AES-256-GCM, works offline, and can encrypt new reports automatically.

Does the DPDP Act apply to doctors and clinics?

Yes. Patient information is digital personal data, and clinics that process it are data fiduciaries under the DPDP Act, 2023. The DPDP Rules, 2025 (Rule 6) set security safeguards including encryption, access controls, logs and backups, taking effect around May 2027.

How long must doctors keep medical records in India?

The Indian Medical Council Regulations, 2002, applied by the NMC, require records of indoor patients to be kept for 3 years from the start of treatment, and copies to be provided within 72 hours on request. Other laws or your state may require longer, so check with your association or a lawyer.

Is it safe to send lab reports on WhatsApp?

WhatsApp messages are end-to-end encrypted in transit, but copies stay on both phones and in any chat backups, and they're easy to forward to the wrong person. Encrypt sensitive reports first, or use a channel built for medical records.

Will encrypted patient files open in my usual programs?

Yes. Double-click the encrypted file in Clavis Encrypt and it opens in the program it normally opens in, whether that's a PDF viewer, an image viewer or Word.

Sources

This guide explains general practice, not legal advice. Laws and rules change; check the current text or ask a lawyer for your situation.

Try Clavis Encrypt — free