Healthcare technology law in India — where clinical risk, data privacy, and software regulation all apply at once.
SIRI Law LLP advises healthtech companies, hospitals, telemedicine platforms, and medical device software makers on CDSCO SaMD classification, ABDM and ABHA integration, telemedicine compliance, and DPDP Act health-data obligations — with cyber risk assessed alongside every regulatory question.
Why healthtech carries a heavier compliance load
Three regulators, not one — and they don't always talk to each other.
A fintech company's compliance conversation usually starts and ends with one or two regulators. A healthtech company's doesn't. Depending on what your product actually does, you may simultaneously answer to CDSCO for medical device classification, the National Medical Commission for how licensed practitioners can use your platform, and the Data Protection Board for how you handle patient data — three regulatory bodies with three different mandates, applied to the same feature.
The sharpest edge right now sits with CDSCO's Software as a Medical Device framework. Following an October 2025 draft guidance document, CDSCO has formalised a four-tier risk classification — Class A through D — for standalone software that independently performs a medical function: AI-based imaging tools, diagnostic apps, remote monitoring platforms, and clinical decision support systems all fall inside this scope. Classification is determined by intended use and clinical impact, not by whether the underlying technology is AI or conventional rules-based logic — a distinction many product teams get backwards, assuming AI specifically triggers scrutiny when in fact the clinical function does.
Layered on top of SaMD classification is the Ayushman Bharat Digital Mission. ABDM integration — ABHA ID verification, consent-based health record sharing through the Unified Health Interface — is not universally mandatory today, but it is increasingly required for providers connected to government schemes and is fast becoming a practical expectation for interoperability across the sector. And underneath both sits the DPDP Act, which applies to health data processing without a special statutory carve-out, but whose consent and security expectations are read more strictly in practice given the sensitivity of the data — reinforced independently by the ABDM Health Data Management Policy's own privacy-by-design mandate for ecosystem participants.
Classification determines everything
The device class sets your application form, documentation depth, review timeline, and level of CDSCO scrutiny.
CDSCO's four-tier framework
Software as a Medical Device — Class A through D
Risk-based classification under the Medical Devices Rules 2017, broadly aligned with international frameworks such as the EU MDR and US FDA approaches to software as a medical device.
Retrospective data analysis software with no direct role in real-time clinical decisions.
Real-time patient monitoring and diagnostic support software.
Software playing a role in managing or diagnosing serious conditions, subject to rigorous CDSCO-level review.
Software directly diagnosing or guiding treatment in critical, life-threatening scenarios — for example, AI-based cancer detection.
Class A and B applications route through the state licensing authority; Class C and D route through the Central Licensing Authority via the CDSCO Medical Device Online Portal. CE Mark or FDA clearance can support a technical dossier but never substitutes for independent CDSCO licensing. Source: CDSCO Draft Guidance Document on Medical Device Software, 21 October 2025, and subsequent 2026 formalisation.
What we cover
Healthcare technology legal services across the full compliance lifecycle
From product classification through data governance and breach response — every regulatory touchpoint a healthtech company, hospital, or medical device maker actually encounters.
SaMD Classification & Licensing
Determination of whether your software qualifies as SaMD or SiMD, Class A–D risk assessment, CDSCO licence application support, and QMS documentation aligned to ISO 13485.
- SaMD/SiMD determination and Class A–D assessment
- CDSCO licence application support (MD5/MD9/MD15)
- Algorithm Change Protocol structuring for AI/ML tools
- ISO 13485 QMS documentation review
ABDM & ABHA Integration Advisory
Legal assessment of ABDM integration obligations, ABHA ID verification flows, consent-based record-sharing architecture, and Unified Health Interface participation requirements.
- ABDM integration obligation assessment
- Consent-based record-sharing architecture
- ABDM Health Data Management Policy compliance
- UHI participation and interoperability advisory
Telemedicine Regulatory Compliance
Compliance with the Telemedicine Practice Guidelines for registered medical practitioners — patient identification, consent architecture, prescribing rules, and record-keeping obligations.
- RMP consent and identification flow review
- Prescribing rules and List O/A/B compliance
- Platform terms of service and liability allocation
- ABHA-linked identity verification structuring
Health Data DPDP Compliance
DPDP Act implementation specific to health data processing — consent architecture, purpose limitation, and security safeguards calibrated to the sensitivity of clinical information.
- Health-data-specific consent architecture
- Purpose limitation and retention policy design
- DPIA execution for high-risk health processing
- ABDM privacy-by-design alignment
Health Data Breach Response
Immediate legal response to health data breaches — CERT-In notification, Data Protection Board filing, patient notification strategy, and forensic evidence preservation under privilege.
- CERT-In 6-hour notification support
- Patient notification strategy and drafting
- Regulatory investigation defence
- Privileged forensic coordination
Medical Device Software Agreements
Licensing agreements, vendor DPAs, clinical validation data-sharing terms, and IP ownership structuring for medical device software and health platform transactions.
- Software licensing and OEM agreements
- Clinical validation data-sharing terms
- IP ownership and algorithm ownership clauses
- US-facing HIPAA exposure assessment
Evidence, not guesswork
Which regulator actually governs which part of your product
Most healthtech compliance confusion comes from not knowing which authority governs which feature. Here's the practical map.
| Product feature | Governing authority | Core obligation |
|---|---|---|
| AI diagnostic or monitoring software | CDSCO | SaMD classification (Class A–D) and licensing before marketing |
| Doctor-patient teleconsultation | National Medical Commission | Telemedicine Practice Guidelines — consent, identification, prescribing rules |
| Health record storage and sharing | ABDM / National Health Authority | Consent-based access, ABDM Health Data Management Policy |
| Patient personal data generally | Data Protection Board of India | DPDP Act consent, purpose limitation, breach notification |
| Cybersecurity incidents | CERT-In | 6-hour mandatory notification from awareness |
| US-facing patient or partner data | US Department of Health and Human Services | HIPAA, if applicable — assessed separately from DPDP |
Sources: CDSCO Draft Guidance Document on Medical Device Software (Oct 2025) and 2026 formalisation; Telemedicine Practice Guidelines 2020 (NMC); ABDM Health Data Management Policy; DPDP Act 2023 and Rules 2025. Figures and framework status current as of publication — verify against the latest CDSCO and NMC notifications before relying on a specific classification.
What the numbers actually mean
Four figures that frame the stakes in healthtech compliance
Maximum per-instance penalty for security safeguard failures — a real risk given how frequently healthcare is targeted for breaches.
Class A through D — misclassifying your product's risk tier can delay market entry or trigger post-launch enforcement.
Approximate figure as of early 2026 — a scale that makes ABDM interoperability a practical necessity even where not strictly mandated.
From awareness of a breach — identical to every other sector, but with far higher stakes given the sensitivity of health data.
How we work
From product review to a defensible compliance posture
Product classification review
We assess your product's intended use and clinical function to determine SaMD/SiMD status and likely CDSCO risk class before you build or file anything.
Weeks 1–2Regulatory mapping
A clear map of which authorities govern which features — CDSCO, NMC, ABDM, and DPDP — with obligations ranked by regulatory and commercial priority.
Weeks 2–3Documentation & filing
CDSCO licence application support, consent architecture drafting, ABDM integration documentation, and DPDP compliance implementation.
Engagement-specificOngoing counsel
Standing advisory as CDSCO guidance, ABDM requirements, and DPDP enforcement evolve — so your classification and compliance posture don't go stale.
OngoingWhy SIRI
Healthcare law backed by cybersecurity intelligence
Health data breaches are simultaneously a regulatory event and a security event. SIRI is the only practice in India where your health law counsel and your penetration testers work from the same office.
SaMD classification fluency
We track CDSCO's evolving Class A–D framework closely, including the Algorithm Change Protocol for AI/ML tools — so your product classification is defensible from first filing, not corrected after a rejection.
Legal + technical data governance
Consent architecture and ABDM integration are reviewed by attorneys who understand the underlying data flows, not just the regulatory text — closing the gap between policy and actual system behaviour.
Privilege on technical findings
Health data audits and breach investigations are conducted under privilege — findings generally cannot be subpoenaed by the Data Protection Board or CDSCO in a regulatory investigation.
HIPAA exposure assessed separately
For healthtech companies with US-facing operations, we assess HIPAA exposure independently of DPDP compliance — the two frameworks are not interchangeable, and treating them as one is a common and costly assumption.
Who we work with
Across the healthcare technology stack
From an early-stage diagnostic AI startup to an established hospital network's digital infrastructure — the compliance shape differs, the underlying regulators don't.
Frequently asked
Healthcare technology law, answered directly
Does our AI diagnostic tool need CDSCO approval?
Likely yes, if it independently performs a medical function such as analysing medical images or supporting a diagnosis. Under CDSCO's Software as a Medical Device framework, standalone software of this kind is classified into four risk-based classes, A through D, based on its intended use and clinical impact. Classification is determined by what the software is validated to do, not by its underlying technical architecture — an AI tool and a simpler rules-based tool performing the same clinical function can fall into the same class.
Is ABDM integration mandatory for our platform?
Not universally, but it is increasingly mandatory for providers connected to government schemes such as AB-PMJAY empanelled hospitals, and strongly encouraged across the sector more broadly. With several hundred million ABHA health IDs already issued, ABDM integration is becoming a practical expectation for interoperability even where it is not yet a strict legal requirement for a given platform type.
How does the DPDP Act treat health data differently from other personal data?
The DPDP Act does not currently create a separate statutory category with heightened obligations purely for health data in the way GDPR treats special category data, but health data's sensitivity in practice drives stricter consent, security, and breach-notification expectations from both the Data Protection Board and sector-specific frameworks like the ABDM Health Data Management Policy, which independently mandates security and privacy by design for participants in the ABDM ecosystem.
Do we need HIPAA compliance if we only operate in India?
Only if you process data for US-based patients, US covered entities, or US business associates as part of your operations. Indian healthtech companies serving purely domestic patients are governed by the DPDP Act and sector rules, not HIPAA — but any company with a US-facing product line, US clinical partners, or US data processing agreements should assess HIPAA exposure separately rather than assuming DPDP compliance covers it.
What happens if a wording change shifts our product's risk classification?
It can trigger a genuine reclassification event. Even minor changes to labelling, promotional materials, or instructions for use can move a product from a lower to a higher risk class if the new language suggests diagnostic or life-supporting functionality — meaning marketing copy, app store descriptions, and onboarding flows all carry real regulatory weight and should be reviewed alongside the underlying software, not treated as a separate workstream.
What does a healthtech engagement with SIRI typically include?
A product classification review to establish SaMD status and likely risk class, a regulatory map across CDSCO, NMC, ABDM, and DPDP, and documentation support for whichever filings and consent architecture your specific product requires — with cyber risk assessment built into the same engagement rather than run as a separate, uncoordinated exercise.
Ready when you are
Build your healthtech product on a defensible regulatory foundation.
Book a confidential consultation with SIRI Law LLP. We will review your product, map your obligations across CDSCO, NMC, ABDM, and DPDP, and propose a clear compliance plan.
Related services
Other ways SIRI Law LLP supports healthtech organisations
Data privacy & cybersecurity law
DPDP Act compliance, consent architecture, and breach notification protocols.
AI & emerging technology law
AI governance frameworks, algorithmic liability, and training data provenance.
Cybersecurity testing services
Penetration testing and security validation for patient data systems.
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

