How do I keep patient data private on WhatsApp at my clinic?
Updated 8 min readFacts checked
Keep patient data private on WhatsApp by getting clear consent before messaging, sending reports and photos only to a confirmed number, and turning on end-to-end encrypted chat backup, which WhatsApp does not enable by default. The DPDP Act 2023 and Rules 2025 also require a plain notice, security safeguards, and prompt breach reporting. General information, not legal advice.
Key takeaways
- A patient's WhatsApp chat, phone number, report or photo is personal data under the DPDP Act, the same as a paper file, and needs consent, notice and a real purpose.
- A clinic's WhatsApp Business Platform (API) number works differently from a personal chat: Meta's own documentation says its Cloud API decrypts an incoming message before forwarding it to the business.
- WhatsApp's end-to-end encrypted chat backup is off by default. A staff phone's ordinary Google Drive or iCloud backup is not end-to-end encrypted unless someone turns that setting on.
- Verifiable parental consent is generally required to process a child's data, but a government backgrounder on the DPDP Rules states this does not apply to essential services such as healthcare.
- A data breach must be reported to affected patients and the Data Protection Board without delay, with a detailed report to the Board within 72 hours. This is general information, not legal advice.
On this page
"WhatsApp is end-to-end encrypted" gets repeated on almost every clinic-marketing page. It is true for a personal chat. It is not the whole story once your clinic's WhatsApp number is a business account, and it says nothing about what happens to a report after a patient receives it. Here is what the DPDP Act, DPDP Rules and WhatsApp's own documentation actually say, in plain words.
Does the DPDP Act cover patient chats on WhatsApp?
Yes. The Digital Personal Data Protection Act, 2023 (DPDP Act) applies to any digital data about a person who can be identified from it, and a WhatsApp chat qualifies the same way a paper file does. A phone number saved against a patient's name, a message thread, a report, or a photo of a scan all count.
Before you process that data for a purpose, such as booking an appointment, you generally need the patient's consent and a plain-language notice telling them what you are collecting and why. Consent has a specific meaning under the Act: it must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and it can be withdrawn as easily as it was given.
What do purpose limitation and security safeguards require?
Purpose limitation means a yes for one reason is not automatically a yes for another. A patient who agrees to be messaged about their appointment has not agreed to receive offers later; that needs its own consent.
None of this needs new software. A shared clinic phone with no screen lock, a WhatsApp Web session left open on the reception computer, or a habit of forwarding a patient's report to "whoever is free" all fall short of this, regardless of how good the clinic's intentions are.
What happens if patient data on WhatsApp is breached?
A lost staff phone, a hacked WhatsApp Web session, or a report sent to the wrong number all count as a personal data breach under section 8(6) of the Act. Two clocks start the moment your clinic finds out.
Step 1: Tell affected patients, without delay
Rule 7
What happened, the likely effect on them, what you are doing about it, and who to contact.Step 2: Tell the Data Protection Board, without delay
A first, short notice of what is known so far: nature, extent and timing.Step 3: Send the Board a detailed report
Rule 7
Within 72 hours of becoming aware: cause, mitigation steps, and a summary of who was told.Step 4: Fix the cause and keep records
Access logs, what changed, and what stops it happening again.
Do I need parental consent for a child patient's WhatsApp chat?
Generally, yes. The Act defines a child as anyone who has not completed 18 years, and section 9 requires a clinic to obtain verifiable consent from a parent or lawful guardian before processing that child's personal data, including a WhatsApp chat about their treatment. Tracking or targeted advertising directed at children is not allowed at all.
[Clinic name]
Business account
- [Clinic name]: Hello [Parent's name], this is [Clinic name]. [Child's name]'s report from today is ready. Should we send it to this number?4:40 pm
- Patient: Yes, please send it here, I am their mother4:52 pm
- [Clinic name]: Sending now. We will only send future updates about [Child's name] to this confirmed number.4:53 pm
Is a WhatsApp chat with my clinic actually end-to-end encrypted?
It depends on which WhatsApp your clinic runs. A one-to-one chat on the free consumer app is end-to-end encrypted using the Signal Protocol: WhatsApp says only the sender's and recipient's own devices hold the keys, and Meta cannot read the content. A clinic's number on the WhatsApp Business Platform (the paid API most chatbots and AI receptionists run on) works differently.
| What happens to a message | Chat with a friend or family member | A clinic's WhatsApp Business Platform number |
|---|---|---|
| Who holds the encryption keys | Only the two people's own devices | The patient's device and Meta's Cloud API, acting for the business |
| Is the message decrypted before it reaches its final destination? | No | Yes, Meta's Cloud API decrypts it, then forwards it to the business |
| How long is the message kept on Meta's servers? | Not applicable, delivered directly | Up to 30 days, to run retransmission and delivery |
| Once received, whose privacy practices apply? | Not applicable | The business's own, per WhatsApp's Help Center |
Sources: WhatsApp Help Center: About end-to-end encryption (checked 17 Sep 2026); Meta for Developers: Data Privacy & Security (WhatsApp Business Platform) (checked 17 Sep 2026).Cloud API messages are still encrypted in transit and at rest on Meta's servers. The difference from a personal chat is that a business's messages pass through a point where Meta's own system holds the decryption keys, not just the two people talking.
What about staff phones, backups, reports and photos?
- Chat backups are not encrypted by default. WhatsApp's own end-to-end encrypted backup for Google Drive or iCloud has to be turned on in Settings; it is off by default. An ordinary backup of a staff phone is not end-to-end encrypted unless someone did this.
- Send reports and photos only to a confirmed number, after the patient has said yes to receiving them that way, not to whichever number happens to be saved.
- Do not forward a patient's chat or photo to a colleague "for a second opinion" without asking first. WhatsApp's policy explicitly bars sharing one customer's chat information with another.
- Lock the phone, log out of WhatsApp Web on shared reception computers, and agree who tells whom first if a device goes missing.
A WhatsApp privacy checklist for the front desk
None of the items below need new software, only a few minutes and a decision to actually do them.
Before WhatsApp becomes routine at your clinic
Every staff phone used for clinic WhatsApp has end-to-end encrypted backup turned on.
Reports and photos go only to the number a patient (or their parent or guardian) confirmed.
No chat or photo is forwarded to a colleague without the patient's separate consent.
Consent for a child patient is confirmed with a parent or guardian for anything beyond urgent care.
Healthcare has a possible carve-out; confirm your exact case with a lawyer.
Staff phones are locked, and nobody leaves WhatsApp Web open on a shared computer.
Someone at the clinic knows the Data Protection Board must be told about a breach without delay.
Want to see what Medslots costs?
₹4,999 a month per clinic, everything included. No setup fee and no contract.
Common questions
Is it safe to send a patient's report or photo on WhatsApp?
Only after the patient has confirmed the number and said yes to receiving it that way. WhatsApp's own Business Messaging Policy also tells businesses not to use WhatsApp for telemedicine or to send health-related information where local rules require systems built for heightened confidentiality. General information, not legal advice.
Does WhatsApp's end-to-end encryption protect a chat with my clinic?
A personal-to-personal chat is end-to-end encrypted using the Signal Protocol, and Meta says it cannot read the content. A clinic's WhatsApp Business Platform (API) number works differently: Meta's own documentation states its Cloud API decrypts an incoming message before forwarding it to the business, so the encryption guarantee is not identical. Checked 17 Sep 2026.
Are WhatsApp chat backups encrypted?
Not by default. An ordinary WhatsApp backup to Google Drive or iCloud is not end-to-end encrypted unless someone turns on 'End-to-end encrypted backup' in Settings, per WhatsApp's own Help Center. A staff phone backing up chats without this setting on is a common, avoidable gap.
Do I need a parent's consent to message a child patient on WhatsApp?
Generally yes: the DPDP Act defines a child as under 18 and requires verifiable parental or guardian consent before processing a child's personal data. A Press Information Bureau backgrounder on the DPDP Rules states this consent is not required when the processing relates to essential services such as healthcare. Not legal advice; confirm with a lawyer for your clinic's exact situation.
What must a clinic do if patient data on WhatsApp is breached?
Tell affected patients and the Data Protection Board without delay under section 8(6) of the DPDP Act, then send the Board a detailed report within 72 hours under Rule 7. Failing to notify a breach can draw a penalty of up to ₹200 crore, decided case by case, whatever the clinic's size.
Can staff forward a patient's WhatsApp chat to a colleague?
WhatsApp's Business Messaging Policy says a business may not forward or otherwise share information from a customer chat with any other customer, and data obtained through a chat should not be used beyond what is reasonably necessary to support messaging that person. Treat an internal forward the same way: a new purpose needs its own reason and, generally, consent.
Facts checked against the sources listed on this page.
Sources
- 1.Indian Kanoon: The Digital Personal Data Protection Act, 2023 (full text) (checked 17 Sep 2026)
- 2.Press Information Bureau: DPDP Rules, 2025 Notified (backgrounder) (checked 17 Sep 2026)
- 3.DPDPA.com: Digital Personal Data Protection Rules, 2025, Rule 6 (checked 17 Sep 2026)
- 4.DPDPA.com: Digital Personal Data Protection Rules, 2025, Rule 7 (checked 17 Sep 2026)
- 5.DPDPA.com: Digital Personal Data Protection Rules, 2025, Rule 10 (checked 17 Sep 2026)
- 6.King Stubb & Kasiva: Penalties and adjudication under India's DPDP Act, 2023 (checked 17 Sep 2026)
- 7.Meta for Developers: Data Privacy & Security (WhatsApp Business Platform) (checked 17 Sep 2026)
- 8.WhatsApp Help Center: About end-to-end encryption (checked 17 Sep 2026)
- 9.WhatsApp Help Center: About end-to-end encrypted backup (checked 17 Sep 2026)
- 10.WhatsApp for Business: WhatsApp Business Messaging Policy (checked 17 Sep 2026)
Update log
- : published.