The shift from paper medical records to Electronic Health Records (EHRs) has been underway in Indian hospitals for over a decade. But the legal framework governing these digital records — what must be captured, how long it must be kept, who can access it, and what happens when it is lost, altered, or destroyed — remains poorly understood by many healthcare providers.

This gap in awareness carries real consequences. Lost records weaken hospitals' defences in negligence litigation. Tampered records attract adverse inferences from courts. Records not produced on patient request breach legal obligations. And hospitals that have not aligned with the Ministry of Health's EHR Standards 2016 and the emerging Ayushman Bharat Digital Mission (ABDM) framework risk being on the wrong side of an increasingly active regulatory environment.

"In my experience as a medico-legal expert, the single most common institutional failure in litigation is inadequate recordkeeping. A complete, contemporaneous, unaltered EHR is both the doctor's best defence and the patient's right. Treating medical records as an administrative burden rather than a legal document is a mistake that courts routinely penalise."
— Dr. Namit Gupta, Senior Medico-Legal Expert, Medico Legal Services, New Delhi

The MoHFW EHR Standards 2016: What They Require

The Ministry of Health and Family Welfare (MoHFW) issued its first EHR Standards in 2013 and revised them in 2016. The 2016 Standards apply to all healthcare establishments — government and private — that maintain electronic health records. They are not merely aspirational guidelines; they are mandatory standards issued under the authority of the Ministry.

The Standards specify:

  • Core EHR components that a compliant record must contain (see below)
  • Technical interoperability requirements (HL7 FHIR-aligned standards for data exchange)
  • Unique patient identification (linked to ABHA/Health ID under the ABDM)
  • Security and access-control requirements
  • Audit trail requirements — who accessed, modified, or deleted a record and when
  • Terminology standards (ICD-10 for diagnoses, SNOMED CT for clinical concepts, LOINC for lab tests)

The importance of terminology standardisation extends beyond technical compliance: a diagnosis coded correctly in ICD-10 is far more useful — and far more legally defensible — than a free-text note that is ambiguous or illegible.

What a Valid EHR Must Contain

A complete EHR under the 2016 Standards includes the following components, all of which have legal relevance in litigation:

Patient Demographic Data

Full name, date of birth, sex, address, contact details, and unique patient identifier (UHID or ABHA). Errors in demographic data — particularly date of birth — can cause problems in linking records to the correct patient in multi-encounter scenarios.

Clinical Notes

History, physical examination findings, provisional and final diagnosis, treatment plan, progress notes. These are the core clinical record. In negligence litigation, courts examine whether the clinical note is contemporaneous (written close in time to the encounter), complete, and internally consistent.

Prescriptions

Drug name (generic where possible), dose, route, frequency, duration, prescribing doctor's name and registration number. Under the NMC Code of Medical Ethics, prescriptions must be legible — electronic prescriptions that are properly generated from an EHR system satisfy this requirement.

Laboratory Results and Imaging Reports

All investigation results, including their reference ranges and the requesting clinician's notation of whether results were reviewed and acted upon. A critical value — a dangerously abnormal lab result — that appears in the system but is not acknowledged in a clinical note is a serious medico-legal risk.

Consent Records

Records of informed consent for procedures, anaesthesia, and blood transfusions. Digital consent forms with timestamped patient signatures (via e-sign or biometric authentication) are legally valid under the Information Technology Act, 2000 and the DPDP Act framework.

Discharge Summary

A complete discharge summary — diagnosis, procedures performed, complications, medications at discharge, follow-up instructions — is both a clinical and legal document. Incomplete discharge summaries are among the most common deficiencies cited by consumer forums in medical negligence cases.

Referral Records

Letters of referral and correspondence with other treating physicians. These establish the chain of clinical responsibility and are relevant when multiple providers are implicated in an adverse outcome.

Minimum Retention Periods for Electronic Health Records

There is no single national retention period for medical records in India. Instead, a patchwork of central and state rules creates different obligations depending on where the hospital is located and what type of record is in question.

Rule / Jurisdiction Minimum Retention Notes
Clinical Establishments Act Rules 2012 (Central) 3 years Applies to centrally-notified states and UTs
Maharashtra Medical Council 7 years Recommended practice for Maharashtra hospitals
Karnataka Private Medical Establishments 5 years Under Karnataka state rules
Minor patients (all India — prudent practice) Until age 18 + 3 years To cover limitation period for minors on majority
ICU / High-risk surgical records (prudent practice) 10 years Many leading hospitals adopt this standard

As a matter of prudent practice, hospitals should adopt the longest applicable period as their baseline. Given that the Consumer Protection Act 2019 allows a complaint to be filed within 2 years of the cause of action (extendable on application), records relevant to a clinical episode should be retained for at least 2 years beyond the treatment date — and considerably longer where there is a known dispute or claim.

Electronic Records as Legal Evidence: The IT Act and Its Requirements

Under the Indian Evidence Act 1872 (and the Bharatiya Sakshya Adhiniyam 2023, which replaced it), electronic records are admissible as documentary evidence. Section 65B of the Evidence Act — mirrored in the new law — creates a specific procedure for admissibility of computer-generated records:

  • A certificate must be signed by a responsible official of the organisation
  • The certificate must state that the document was produced by a computer used regularly in the organisation's business
  • The computer was operating properly during the relevant period
  • The information in the output was derived from information supplied to the computer in the ordinary course of business

Without a proper Section 65B certificate (or equivalent under BSA 2023), the admissibility of the EHR printout can be challenged by the opposing party. Hospitals involved in litigation must ensure their legal counsel is aware of this requirement and that a designated official can produce the certificate.

Liability for Lost or Tampered Electronic Records

The Adverse Inference Doctrine

When a hospital cannot produce medical records in response to a court order or tribunal direction — whether because the records were not maintained, were deleted, or were "lost" — courts draw an adverse inference under the principle that a party who destroys evidence likely did so because the evidence would have harmed their case. The National Consumer Disputes Redressal Commission (NCDRC) has applied this principle extensively in medical negligence cases.

The practical consequence is stark: a hospital that cannot produce an ICU chart, anaesthesia record, or operative note may find that the court treats its absence as corroboration of the patient's account of what happened. A strong expert witness for the hospital cannot overcome records that do not exist.

Spoliation of Evidence

Deliberate destruction or alteration of medical records after a hospital becomes aware of a claim or potential claim is not just a litigation disadvantage — it may amount to contempt of court or obstruction of justice. There have been cases before Indian consumer forums where hospitals were awarded no benefit of the doubt precisely because their records were found to be inconsistent, backdated, or otherwise manipulated.

Alteration of EHRs

Electronic records are in principle more traceable than paper: a proper audit trail in an EHR system records every access, every edit, and every deletion with a timestamp and the identity of the user. Tampering with a paper file is easier to conceal; altering an EHR without leaving a trace requires either disabling the audit trail (itself a red flag) or exploiting a system vulnerability. Courts and expert witnesses can examine metadata and audit logs — hospitals that have manipulated EHRs have been exposed this way.

Patient Access to EHRs: The Legal Framework

Patients have a right to access their own medical records. This right is grounded in:

  • The NMC Code of Medical Ethics Regulations, which require doctors to provide copies of records on patient request
  • Consumer law — a patient who paid for treatment is a consumer and is entitled to the documentation produced in the course of that service
  • The DPDP Act 2023 — which creates a statutory right to access personal data held by a Data Fiduciary
  • The Right to Information Act (for government hospitals) — applicable to institutional records, though the scope of patient records access under RTI has been subject to case-by-case adjudication

A hospital that refuses to provide records without a legitimate reason — such as an ongoing legal dispute where the hospital has been advised by counsel — risks a consumer complaint and a direction to produce. The fee for photocopies or digital copies must be reasonable; inflated charges for records are themselves a form of denial.

ABDM and the Ayushman Bharat Health Account (ABHA)

The Ayushman Bharat Digital Mission, launched in 2021 by the Government of India, aims to create a unified digital health ecosystem for India. Its central element is the Ayushman Bharat Health Account (ABHA) — a 14-digit health identification number that a patient can use to link health records from multiple providers into a single, patient-controlled digital health locker.

Key points for doctors and hospitals:

  • ABHA registration is currently voluntary for patients — no patient can be coerced into obtaining one
  • Hospitals empanelled under PM-JAY and other government schemes are being progressively integrated with the ABDM infrastructure
  • Once integrated, doctors must understand that patients can consent to share their ABHA-linked records with other providers — the hospital does not "own" those records
  • The Health Information Exchange and Consent Manager (HIE-CM) framework governs how consent is granted and revoked for sharing records across the network
  • Hospitals that participate in ABDM must comply with the ABDM Health Data Management Policy, which aligns with the DPDP Act obligations

Cybersecurity Obligations for EHR Systems

Hospitals that suffer a cybersecurity breach affecting patient data have obligations under multiple frameworks:

  • CERT-In Directions (April 2022): All organisations, including healthcare providers, must report cybersecurity incidents to the Indian Computer Emergency Response Team within 6 hours of detection. Ransomware attacks, data breaches, and unauthorised access to patient systems must all be reported.
  • DPDP Act 2023: A personal data breach must also be notified to the Data Protection Board and to affected patients (timeline to be specified by Rules)
  • IT Act 2000: Failure to implement reasonable security practices under Section 43A of the IT Act can expose a hospital to civil liability to affected patients

Practical Checklist for Hospital EHR Compliance

  • Backup protocols: Automated daily backups of all EHR data, with off-site or cloud backup; monthly restoration tests to verify backup integrity
  • Audit trails: Enable and preserve immutable audit logs of all EHR access and modifications; audit logs should themselves be protected from deletion or alteration
  • Access controls: Role-based access — clinical staff see only the records they need; administrative staff cannot access clinical notes; a log of all access attempts (including failed attempts) is maintained
  • Staff training: All staff who touch patient records — from junior doctors to registration clerks — should be trained on documentation standards, the legal significance of records, and what to do if they suspect tampering
  • Retention schedules: Build a documented data retention schedule mapped to applicable rules; implement an automated deletion or anonymisation process for records that have passed their retention period
  • Section 65B readiness: Designate a responsible official who can issue Section 65B certificates when required for litigation; ensure that official understands the technical requirements
  • Incident response plan: A written plan for responding to a data breach or ransomware attack — covering notification to CERT-In, the Data Protection Board, patients, and the hospital's insurer

Conclusion

Electronic health records are both a clinical tool and a legal document. The gap between their importance and the attention most hospitals pay to their legal dimensions is closing — driven by more active consumer forums, the DPDP Act's new obligations, and the ABDM's drive toward a nationwide health data infrastructure. Hospitals that invest in EHR compliance now will be better protected in litigation, better prepared for regulatory scrutiny, and better positioned to participate in India's evolving digital health ecosystem.

If you are a hospital setting up an EHR system, a doctor facing a records-related dispute, or a patient who has been denied access to your own records, contact our medico-legal team for expert advice.