📞 Call Now 💬 WhatsApp 📋 Report
⚖️
SIRI Law LLP
● Typically replies within 30 min
👋 Hi! How can SIRI Law LLP help you today?

We offer expert legal and cybersecurity advisory. Tap below for a confidential chat.
SIRI Law · Now
💬  Start Chat on WhatsApp
Healthcare Technology Law in India | SaMD, ABDM, Telemedicine — SIRI Law LLP
Healthcare Technology Lawyers · Hyderabad, India

Healthcare technology law in India — where clinical risk, data privacy, and software regulation all apply at once.

SIRI Law LLP advises healthtech companies, hospitals, telemedicine platforms, and medical device software makers on CDSCO SaMD classification, ABDM and ABHA integration, telemedicine compliance, and DPDP Act health-data obligations — with cyber risk assessed alongside every regulatory question.

4CDSCO risk classes for medical device software — Class A to D
840M+ABHA digital health IDs issued as of early 2026 (approximate)
₹250 CrMaximum DPDP penalty for security safeguard failures
2Disciplines under one privilege: health law + cyber advisory
The healthtech regulatory clock
Live tracking · scroll to see every relevant development
Standing
MAR 2020
Telemedicine Practice Guidelines issued by the Board of Governors, now under the NMC — still the core framework for RMPs using digital consultation.
Draft
21 OCT 2025
CDSCO releases its Draft Guidance Document on Medical Device Software — the first comprehensive clarification of how existing rules apply to SaMD.
Formalised
2026
CDSCO formalises the four-tier Class A–D risk classification for AI diagnostic, treatment, and monitoring software, requiring licensing before marketing.
Innovation
2026
Algorithm Change Protocol introduced for AI/ML-based SaMD, allowing iterative model updates without constant re-licensing.
Growing
Ongoing
ABDM integration increasingly mandatory for AB-PMJAY empanelled providers, with several hundred million ABHA IDs already issued nationally.
Standing
Ongoing
DPDP Act obligations apply in full to health data processing, layered with the ABDM Health Data Management Policy's own privacy-by-design mandate.

Why healthtech carries a heavier compliance load

Three regulators, not one — and they don't always talk to each other.

A fintech company's compliance conversation usually starts and ends with one or two regulators. A healthtech company's doesn't. Depending on what your product actually does, you may simultaneously answer to CDSCO for medical device classification, the National Medical Commission for how licensed practitioners can use your platform, and the Data Protection Board for how you handle patient data — three regulatory bodies with three different mandates, applied to the same feature.

The sharpest edge right now sits with CDSCO's Software as a Medical Device framework. Following an October 2025 draft guidance document, CDSCO has formalised a four-tier risk classification — Class A through D — for standalone software that independently performs a medical function: AI-based imaging tools, diagnostic apps, remote monitoring platforms, and clinical decision support systems all fall inside this scope. Classification is determined by intended use and clinical impact, not by whether the underlying technology is AI or conventional rules-based logic — a distinction many product teams get backwards, assuming AI specifically triggers scrutiny when in fact the clinical function does.

Wording changes can shift your classification
Even minor changes in labelling, promotional materials, or instructions for use can move a product from a lower to a higher risk class if they suggest diagnostic or life-supporting functionality — meaning a marketing team's copy edit can create a regulatory event the legal and product teams never see coming.

Layered on top of SaMD classification is the Ayushman Bharat Digital Mission. ABDM integration — ABHA ID verification, consent-based health record sharing through the Unified Health Interface — is not universally mandatory today, but it is increasingly required for providers connected to government schemes and is fast becoming a practical expectation for interoperability across the sector. And underneath both sits the DPDP Act, which applies to health data processing without a special statutory carve-out, but whose consent and security expectations are read more strictly in practice given the sensitivity of the data — reinforced independently by the ABDM Health Data Management Policy's own privacy-by-design mandate for ecosystem participants.

SIRI Law LLP healthcare technology advisory session

Classification determines everything

The device class sets your application form, documentation depth, review timeline, and level of CDSCO scrutiny.

CDSCO's four-tier framework

Software as a Medical Device — Class A through D

Risk-based classification under the Medical Devices Rules 2017, broadly aligned with international frameworks such as the EU MDR and US FDA approaches to software as a medical device.

A
Low risk

Retrospective data analysis software with no direct role in real-time clinical decisions.

B
Low to moderate

Real-time patient monitoring and diagnostic support software.

C
Moderate to high

Software playing a role in managing or diagnosing serious conditions, subject to rigorous CDSCO-level review.

D
High risk

Software directly diagnosing or guiding treatment in critical, life-threatening scenarios — for example, AI-based cancer detection.

Class A and B applications route through the state licensing authority; Class C and D route through the Central Licensing Authority via the CDSCO Medical Device Online Portal. CE Mark or FDA clearance can support a technical dossier but never substitutes for independent CDSCO licensing. Source: CDSCO Draft Guidance Document on Medical Device Software, 21 October 2025, and subsequent 2026 formalisation.

What we cover

Healthcare technology legal services across the full compliance lifecycle

From product classification through data governance and breach response — every regulatory touchpoint a healthtech company, hospital, or medical device maker actually encounters.

01 / DEVICE CLASSIFICATION

SaMD Classification & Licensing

Determination of whether your software qualifies as SaMD or SiMD, Class A–D risk assessment, CDSCO licence application support, and QMS documentation aligned to ISO 13485.

  • SaMD/SiMD determination and Class A–D assessment
  • CDSCO licence application support (MD5/MD9/MD15)
  • Algorithm Change Protocol structuring for AI/ML tools
  • ISO 13485 QMS documentation review
02 / INTEROPERABILITY

ABDM & ABHA Integration Advisory

Legal assessment of ABDM integration obligations, ABHA ID verification flows, consent-based record-sharing architecture, and Unified Health Interface participation requirements.

  • ABDM integration obligation assessment
  • Consent-based record-sharing architecture
  • ABDM Health Data Management Policy compliance
  • UHI participation and interoperability advisory
03 / TELEMEDICINE

Telemedicine Regulatory Compliance

Compliance with the Telemedicine Practice Guidelines for registered medical practitioners — patient identification, consent architecture, prescribing rules, and record-keeping obligations.

  • RMP consent and identification flow review
  • Prescribing rules and List O/A/B compliance
  • Platform terms of service and liability allocation
  • ABHA-linked identity verification structuring
04 / DATA GOVERNANCE

Health Data DPDP Compliance

DPDP Act implementation specific to health data processing — consent architecture, purpose limitation, and security safeguards calibrated to the sensitivity of clinical information.

  • Health-data-specific consent architecture
  • Purpose limitation and retention policy design
  • DPIA execution for high-risk health processing
  • ABDM privacy-by-design alignment
05 / BREACH RESPONSE

Health Data Breach Response

Immediate legal response to health data breaches — CERT-In notification, Data Protection Board filing, patient notification strategy, and forensic evidence preservation under privilege.

  • CERT-In 6-hour notification support
  • Patient notification strategy and drafting
  • Regulatory investigation defence
  • Privileged forensic coordination
06 / COMMERCIAL

Medical Device Software Agreements

Licensing agreements, vendor DPAs, clinical validation data-sharing terms, and IP ownership structuring for medical device software and health platform transactions.

  • Software licensing and OEM agreements
  • Clinical validation data-sharing terms
  • IP ownership and algorithm ownership clauses
  • US-facing HIPAA exposure assessment

Evidence, not guesswork

Which regulator actually governs which part of your product

Most healthtech compliance confusion comes from not knowing which authority governs which feature. Here's the practical map.

Product feature Governing authority Core obligation
AI diagnostic or monitoring software CDSCO SaMD classification (Class A–D) and licensing before marketing
Doctor-patient teleconsultation National Medical Commission Telemedicine Practice Guidelines — consent, identification, prescribing rules
Health record storage and sharing ABDM / National Health Authority Consent-based access, ABDM Health Data Management Policy
Patient personal data generally Data Protection Board of India DPDP Act consent, purpose limitation, breach notification
Cybersecurity incidents CERT-In 6-hour mandatory notification from awareness
US-facing patient or partner data US Department of Health and Human Services HIPAA, if applicable — assessed separately from DPDP

Sources: CDSCO Draft Guidance Document on Medical Device Software (Oct 2025) and 2026 formalisation; Telemedicine Practice Guidelines 2020 (NMC); ABDM Health Data Management Policy; DPDP Act 2023 and Rules 2025. Figures and framework status current as of publication — verify against the latest CDSCO and NMC notifications before relying on a specific classification.

What the numbers actually mean

Four figures that frame the stakes in healthtech compliance

₹250 Cr
DPDP penalty exposure

Maximum per-instance penalty for security safeguard failures — a real risk given how frequently healthcare is targeted for breaches.

4
SaMD risk classes

Class A through D — misclassifying your product's risk tier can delay market entry or trigger post-launch enforcement.

840M+
ABHA IDs issued

Approximate figure as of early 2026 — a scale that makes ABDM interoperability a practical necessity even where not strictly mandated.

6 hrs
CERT-In notification window

From awareness of a breach — identical to every other sector, but with far higher stakes given the sensitivity of health data.

How we work

From product review to a defensible compliance posture

01

Product classification review

We assess your product's intended use and clinical function to determine SaMD/SiMD status and likely CDSCO risk class before you build or file anything.

Weeks 1–2
02

Regulatory mapping

A clear map of which authorities govern which features — CDSCO, NMC, ABDM, and DPDP — with obligations ranked by regulatory and commercial priority.

Weeks 2–3
03

Documentation & filing

CDSCO licence application support, consent architecture drafting, ABDM integration documentation, and DPDP compliance implementation.

Engagement-specific
04

Ongoing counsel

Standing advisory as CDSCO guidance, ABDM requirements, and DPDP enforcement evolve — so your classification and compliance posture don't go stale.

Ongoing

Why SIRI

Healthcare law backed by cybersecurity intelligence

Health data breaches are simultaneously a regulatory event and a security event. SIRI is the only practice in India where your health law counsel and your penetration testers work from the same office.

SIRI Law LLP healthcare technology team
01 — Classification

SaMD classification fluency

We track CDSCO's evolving Class A–D framework closely, including the Algorithm Change Protocol for AI/ML tools — so your product classification is defensible from first filing, not corrected after a rejection.

02 — Integration

Legal + technical data governance

Consent architecture and ABDM integration are reviewed by attorneys who understand the underlying data flows, not just the regulatory text — closing the gap between policy and actual system behaviour.

03 — Privilege

Privilege on technical findings

Health data audits and breach investigations are conducted under privilege — findings generally cannot be subpoenaed by the Data Protection Board or CDSCO in a regulatory investigation.

04 — Cross-border

HIPAA exposure assessed separately

For healthtech companies with US-facing operations, we assess HIPAA exposure independently of DPDP compliance — the two frameworks are not interchangeable, and treating them as one is a common and costly assumption.

Who we work with

Across the healthcare technology stack

From an early-stage diagnostic AI startup to an established hospital network's digital infrastructure — the compliance shape differs, the underlying regulators don't.

AI diagnostic & imaging startups Telemedicine platforms Hospitals & clinic networks Medical device software makers Remote patient monitoring Health insurance & TPAs Pharmacy & e-pharmacy platforms Diagnostic labs & pathology networks

Frequently asked

Healthcare technology law, answered directly

Does our AI diagnostic tool need CDSCO approval?

Likely yes, if it independently performs a medical function such as analysing medical images or supporting a diagnosis. Under CDSCO's Software as a Medical Device framework, standalone software of this kind is classified into four risk-based classes, A through D, based on its intended use and clinical impact. Classification is determined by what the software is validated to do, not by its underlying technical architecture — an AI tool and a simpler rules-based tool performing the same clinical function can fall into the same class.

Is ABDM integration mandatory for our platform?

Not universally, but it is increasingly mandatory for providers connected to government schemes such as AB-PMJAY empanelled hospitals, and strongly encouraged across the sector more broadly. With several hundred million ABHA health IDs already issued, ABDM integration is becoming a practical expectation for interoperability even where it is not yet a strict legal requirement for a given platform type.

How does the DPDP Act treat health data differently from other personal data?

The DPDP Act does not currently create a separate statutory category with heightened obligations purely for health data in the way GDPR treats special category data, but health data's sensitivity in practice drives stricter consent, security, and breach-notification expectations from both the Data Protection Board and sector-specific frameworks like the ABDM Health Data Management Policy, which independently mandates security and privacy by design for participants in the ABDM ecosystem.

Do we need HIPAA compliance if we only operate in India?

Only if you process data for US-based patients, US covered entities, or US business associates as part of your operations. Indian healthtech companies serving purely domestic patients are governed by the DPDP Act and sector rules, not HIPAA — but any company with a US-facing product line, US clinical partners, or US data processing agreements should assess HIPAA exposure separately rather than assuming DPDP compliance covers it.

What happens if a wording change shifts our product's risk classification?

It can trigger a genuine reclassification event. Even minor changes to labelling, promotional materials, or instructions for use can move a product from a lower to a higher risk class if the new language suggests diagnostic or life-supporting functionality — meaning marketing copy, app store descriptions, and onboarding flows all carry real regulatory weight and should be reviewed alongside the underlying software, not treated as a separate workstream.

What does a healthtech engagement with SIRI typically include?

A product classification review to establish SaMD status and likely risk class, a regulatory map across CDSCO, NMC, ABDM, and DPDP, and documentation support for whichever filings and consent architecture your specific product requires — with cyber risk assessment built into the same engagement rather than run as a separate, uncoordinated exercise.

Ready when you are

Build your healthtech product on a defensible regulatory foundation.

Book a confidential consultation with SIRI Law LLP. We will review your product, map your obligations across CDSCO, NMC, ABDM, and DPDP, and propose a clear compliance plan.

or call +91 79819 12046 — Mon–Sat, 9 AM – 7 PM IST

Visit or contact us

SIRI Law LLP — Hyderabad, India

Registered officeHITEC City, Madhapur, Hyderabad, Telangana 500081, India
Telephone+91 79819 12046
Emailinfo@sirilawllp.com
Other officesNew Delhi, India · Austin, Texas, USA · Online worldwide
HoursMon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7
© SIRI Law LLP · Hyderabad, Telangana

This page is provided for general informational purposes and does not constitute legal advice. References to CDSCO's SaMD classification framework, ABDM figures, and DPDP obligations reflect publicly available information as of publication and remain subject to regulatory clarification; verify current status before relying on any specific classification or figure. No lawyer-client relationship is formed by viewing this page. SIRI Law LLP is a registered law firm under the Limited Liability Partnership Act 2008, practising under the Advocates Act 1961; complaints regarding professional conduct may be directed to the Bar Council of Telangana.

Scroll to Top