← Back to Case Studies Healthcare / Government

DPDP Act & ISO 27001 Compliance Readiness for a State Health Department

A State Government Health Department

A State Health Department operating a network of district hospitals and primary health centres needed to demonstrate ISO 27001 alignment as a condition of a central funding programme, while also bringing patient record systems into line with the DPDP Act. With no internal information-security function and years of accumulated, partly paper-based patient records, the department needed an independent partner to map where it actually stood before committing to a certification timeline.

The Challenge

Patient data was spread across a legacy hospital management system, standalone spreadsheets maintained at individual facilities, and paper registers that had never been formally digitized. Nobody in the department could say with confidence who had access to what, how long records were retained, or whether breach-notification procedures existed at all. The funding body's deadline was fixed and non-negotiable.

Our Approach

  • Data flow mapping: Traced patient data from intake at each facility through to storage, identifying every system, spreadsheet, and paper register that held personal or health data.
  • Gap analysis: Assessed current controls against both ISO 27001's Annex A controls and the DPDP Act's consent, purpose-limitation, and breach-notification requirements simultaneously, rather than as two separate exercises.
  • Prioritised remediation roadmap: Sequenced fixes by risk and by what the funding body's auditors would actually check first, so the department could show credible progress within the fixed timeline rather than trying to fix everything at once.
  • Policy and consent framework: Drafted data retention, access control, and patient consent documentation the department's own staff could realistically operate and maintain after we left.
The turning point wasn't any single control — it was getting facility staff to see data protection as part of patient care, not paperwork imposed from the state capital.

The Outcome

The department entered its formal ISO 27001 certification audit with a documented control set and passed with no critical non-conformities. Patient consent and access-control procedures were standardised across all facilities in the network, and the department retained an internal point of contact trained to maintain the framework going forward rather than depending on an external party indefinitely. As a pure-play auditor with no security software or hardware to sell, every recommendation in the roadmap was selected purely on what the department's facilities could realistically sustain.

Ready to protect your IT investment?

From RFP writing to compliance audits and project governance — ITPMS delivers unbiased, expert-led IT management.