Hemostasis Today

July, 2026
July 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
Sujeet Katiyar: You Share Patient Data with Your TPA. Where Is the Contract?
Jul 28, 2026, 08:27

Sujeet Katiyar: You Share Patient Data with Your TPA. Where Is the Contract?

Sujeet Katiyar, Principal Consultant in Healthcare Data Privacy, AI Governance, and Regulatory Advisory at KGS Consulting, shared a post on LinkedIn:

”Your hospital empanels with a TPA for cashless insurance processing.

Every day, your billing team sends discharge summaries, diagnosis codes, and treatment plans to that TPA.

The relationship has worked smoothly for years.

Ask your billing head one question: where is the Data Processing Agreement governing exactly what the TPA can do with that data?

In most Indian hospitals, the answer is silence — followed by someone going to check, and not finding one.

There is an empanelment agreement. There is a service-level understanding. There may even be a commercial contract covering payment terms.

But a specific, DPDP-compliant Data Processing Agreement governing the TPA’s handling of patient data?

In the overwhelming majority of cases, it does not exist.

And under the Digital Personal Data Protection Act, 2023, that absence is not a paperwork gap.

It is an active, ongoing compliance failure with every single data transfer.

Why the TPA Relationship Is Legally Different From What You Assume

Most hospitals think of their TPA as a trusted partner handling an administrative function — insurance claims processing — on their behalf.

That is operationally accurate. It is also legally significant in a way most hospitals have never considered.

Under DPDP, your hospital is the Data Fiduciary. You determine the purpose and means of processing your patients’ data.

Your TPA is a Data Processor. It processes data strictly on your instructions, for the purpose you authorise.

Section 8(2) of the DPDP Act requires that any processing carried out by a Data Processor on behalf of a Data Fiduciary be governed by a valid contract.

This is not a suggestion. It is a precondition for lawful data sharing.

Without that contract, every discharge summary, every diagnosis code, every treatment plan your hospital transmits to the TPA is being shared without a valid legal mechanism governing its use.

What a Genuine Data Processing Agreement Must Actually Cover
A commercial empanelment contract that mentions ‘confidentiality’ in a single clause does not meet this standard.

A compliant Data Processing Agreement must specifically address:

The precise categories of patient data the TPA is authorised to receive and process — not a general reference to ‘claims-related information’

The exact purpose for which that data may be used — cashless claim adjudication, for example, and nothing beyond that without separate authorisation

The security standards the TPA must maintain — encryption, access controls, and breach detection capability appropriate to health data

The TPA’s obligation to notify your hospital immediately upon discovering any security incident, so that your 72-hour breach notification clock to the Data Protection Board can be managed

Restrictions on the TPA engaging any further sub-processor — a fraud analytics vendor, a cloud storage provider — without your hospital’s specific, documented approval

Data retention and deletion obligations, specifying how long the TPA may hold patient data and the process for deletion once the claim is settled or your hospital instructs it

The TPA’s obligation to assist your hospital in responding to patient rights requests — access, correction, or erasure — where that patient’s data sits within the TPA’s systems

If your current agreement with your TPA does not address each of these points explicitly, you do not have a DPDP-compliant Data Processing Agreement.

You have a commercial contract that happens to involve patient data — which is a fundamentally different, and fundamentally inadequate, legal position.

The Liability You Cannot Delegate

This is the point most hospital administrators misunderstand most seriously.

If your TPA suffers a data breach — its systems are compromised, an employee misuses access, a sub-processor it engaged without telling you exposes data — your hospital does not escape liability because ‘it was the TPA’s fault.’

Under DPDP, the Data Fiduciary remains accountable for ensuring its Data Processors meet appropriate standards.

You selected the TPA. You continued sharing data without a compliant contract. You failed to govern the relationship.

The Data Protection Board will examine the adequacy of your due diligence and contractual governance — not simply whose system was technically breached.

What the United States Has Already Learned About This Exact Failure

This is not a hypothetical risk. It has already been tested under HIPAA, and the outcome is instructive.

North Memorial Health Care of Minnesota agreed to pay USD 1.55 million to settle charges that it violated HIPAA by disclosing protected health information to its business associate,

Accretive Health, without first executing a Business Associate Agreement — the HIPAA equivalent of a Data Processing Agreement.

The breach itself involved an unencrypted, password-protected laptop, belonging to an Accretive employee, that was stolen — exposing the health information of approximately 9,500 individuals.

It was the business associate’s laptop that was lost. Not the covered entity’s.

And yet North Memorial — the hospital system — paid the USD 1.55 million penalty.

Because the foundational failure was not the stolen laptop. It was sharing patient data with a business associate without first establishing the contractual governance the law requires.

This is precisely the structure of risk facing Indian hospitals with their TPAs today: a vendor relationship operating without the foundational contract, where any downstream incident — regardless of whose system it occurs on — becomes the hospital’s liability.

Missing Business Associate Agreements remain, even now, among the most consistently cited findings in US healthcare enforcement actions, alongside lapses in routine access reviews — a pattern that has persisted for nearly a decade of HIPAA enforcement.

What You Must Do Before 13 May 2027

Begin with an honest inventory.

List every TPA, every insurer, every third-party vendor that receives patient data from your hospital in any form.

For each one, determine whether a genuine Data Processing Agreement — meeting the standards outlined above — currently exists.

In most hospitals, this exercise alone will reveal a significant gap between the number of vendor relationships and the number of compliant contracts governing them.

For every gap identified, the agreement must be drafted, negotiated, and executed before that vendor relationship continues to operate.

This is not solely a legal exercise. It requires understanding exactly what data flows to each vendor, for what purpose, and under what technical safeguards — information that often does not exist in a single place within most hospitals today.

The Question to Ask Your Billing Head This Week

Do not wait for an external audit to discover this gap.

Ask the question yourself, this week: for every TPA we work with, do we have a signed, DPDP-compliant Data Processing Agreement on file?

If the answer is ‘I am not sure’ or ‘let me check’ — you have already identified your hospital’s most immediate compliance exposure.

The penalty for unlawful data sharing under DPDP reaches Rs. 250 crore.

The cost of drafting and executing proper agreements with your existing TPA partners is a fraction of that — and it is work that can begin today, not after enforcement begins.

About the Author

Sujeet Katiyar is a healthcare compliance, data protection, and technology governance professional with more than 27 years of experience across healthcare, digital health, and regulatory frameworks.

With a multidisciplinary background in engineering, law, and healthcare technology, he advises hospitals, health-tech companies, insurers, and healthcare platforms on implementing the Digital Personal Data Protection Act (DPDP Act 2023) and building robust privacy governance frameworks.

Through his work at KGS Consulting, Sujeet Katiyar helps healthcare organizations translate complex legal requirements into practical operational compliance.

His expertise spans healthcare regulations, data protection frameworks, digital health systems, and AI governance, positioning him as one of India’s leading experts at the intersection of healthcare, law, and technology.

Organizations seeking end-to-end DPDP compliance solutions for healthcare and health-tech ecosystems can reach out to Sujeet Katiyar for strategic advisory, implementation frameworks, and regulatory readiness programs.”

Stay updated with Hemostasis Today.