🏥
The Scenario

A large Indian health insurer operates a cashless network with 400 hospitals. On admission, hospitals collect patient data (diagnosis, treatment, vitals, Aadhaar-linked biometrics). For pre-auth and claims, hospitals transmit this data to the insurer's TPA. The TPA processes claims and stores health records. The insurer also uses anonymised health data for actuarial modelling.

Q 2.1

Health data is sensitive personal data. What additional obligations does this trigger?

The DPDP Rules 2025 empower MeitY to specify categories requiring higher protection, and health/biometric data falls squarely in this bucket. IRDAI's data governance circular independently requires enhanced security standards for health records.

For the hospital (primary Fiduciary): its consent notice must specifically mention transmission to the insurer/TPA for claims processing. In emergency admissions, §7(d) "vital interests" basis may apply — but only for the immediate treatment purpose, not ongoing insurance processing.

For the insurer: processing health data requires a DPIA (not just PIA) given sensitivity, scale, and automated decisioning. The DPIA must document risk mitigations, data minimisation measures, and access controls specific to health records.

🚫 Common Violation Using health records from claims for underwriting future policy renewals (premium loading, exclusions) without fresh consent — purpose limitation violation. Claims processing consent ≠ actuarial profiling consent.
Q 2.2

Is the TPA a Data Processor or Data Fiduciary? This determines breach liability.

This is a fact-specific determination — the most consequential structural question in health insurance data governance.

Figure — TPA Role Decision Tree
IS THE TPA A DATA PROCESSOR OR FIDUCIARY? — DECISION TREE Does TPA independently determine processing purpose or format? NO DATA PROCESSOR Insurer = primary Fiduciary Insurer bears breach liability YES CO-FIDUCIARY Both independently liable Separate ROPA required TPA Signals That Push Toward Co-Fiduciary • Uses claims data for own analytics products • Offers data to other insurer clients • Determines own retention beyond insurer requirements • Designs own database schema independently
⚠️ Liability Implication If the TPA is a Processor, the insurer bears primary liability for a TPA-side breach. If co-Fiduciary, both entities are independently liable. Insurers must audit TPA contracts immediately — most pre-DPDP agreements do not address this distinction.
Q 2.3

Can the insurer use anonymised claims data for actuarial modelling without consent?

● CONDITIONALLY PERMITTED — HIGH SCRUTINY

True anonymisation — where re-identification is not reasonably possible — places the output outside DPDP scope. However, pseudonymisation is not anonymisation. If a linkage key exists that could re-identify records, the data remains personal data.

The insurer must document its anonymisation methodology and have it independently reviewed. Original consent notice should also mention "statistical/actuarial research on anonymised data" for transparency even if technically exempt.

Mapping your TPA agreements to DPDP? We can help.

Request a demo →