The medical devices sector in India is an essential and integral constituent of the Indian healthcare sector, particularly for the prevention, diagnosis, treatment, and management of all medical conditions, diseases, illnesses, and disabilities. The terms MedTech and medical devices are used interchangeably. While the medical devices industry is often understood to be limited to physical products, the broader MedTech industry also encompasses digital solutions such as telemedicine platforms, home diagnostic devices, AI-enabled software for disease detection embedded within products, and specialised medical equipment, including ocular implants.
In India, the medical devices industry is regulated by the Central Drugs Standard Control Organisation (CDSCO), which also regulates the pharmaceutical industry. Unlike in other countries where drugs/pharmaceutical products are regulated separately from medical devices, in India, medical devices are regulated under the Drugs and Cosmetics Act, 1940 (Act) and more specifically Medical Device Rules, 2017. Medical devices in India are defined as ‘drugs’ under Section 3(b) of the Act.
The Indian MedTech market will expand to about $12 billion by 2030, according to an EY report. Due to changing lifestyles and technology, medical devices are no longer simple, standalone equipment. They now have operating systems and are connected to networks and other devices. Earlier, monitoring heart rate was done by standalone ECG machines in hospitals and nursing homes.
Today, IoT devices such as the Apple Watch monitor heart rate efficiently. Due to the growth in technology and shift in nature of medical devices from freestanding to Internet of Things (IoT), health data (categorised as ‘personal data’ under India’s data privacy law) generation and processing volume have increased exponentially. The digitisation of healthcare has given caregivers the power to access, analyse, manage, and share patient data, helping to transform care and lower costs. But millions of connected medical devices, systems, and networks make hospital and patient data highly vulnerable to cyber-attacks, and consequently, data privacy issues also emerge. As the medical devices are connected to networks and transmit data, the threat of cyberattacks looms large.
As per a report of Philips, EMR systems are increasingly connecting to hospital networks and are constantly feeding EMR systems with patient physiological data. The multitude of vendors, legacy networks, and devices in any given hospital provides attractive access points for bad actors to extract volumes of valuable patient data. Moreover, currently, the medical devices sector is 70-80 per cent dependent on imports.
DPDPA in the MedTech sector
In this regard, it’s important to examine the privacy compliance imposed by the Digital Personal Data Protection Act, 2023. This is because the DPDPA has a fine of up to Rs 250 crore. The DPDPA requires significant efforts by the MedTech sector for compliance, like, for instance:
As per the Central government notification dated November 14, 2025, all entities, including the MedTech manufacturers and operators, will need to be compliant with the DPDPA by May 14, 2027.
Adopting voluntary standards
There are several voluntary standards that are available; the adoption of which by the MedTech manufacturer or the hospital that is operating the MedTech device can lead to heightened security. Some of these standards are –
Targeting structured DPDPA
The MedTech industry is becoming increasingly connected. Software, medical devices, and health data are now constantly exchanged across multiple stakeholders in the ecosystem.
With the Digital Personal Data Protection Act, 2023, being enforced from November 14, 2025, and compliance timelines extending till May,14 2027, participants across the MedTech sector must prepare for compliance. This includes manufacturers, hospitals, software providers, platform operators, and white-labelling entities.
Given the volume and sensitivity of health-related personal data involved, undertaking a structured DPDPA implementation exercise is essential for the sector.
S Chandrasekhar, MD & CEO, K&S Digiprotect Services
(with inputs from Aman Varma, Senior Manager – Legal and Regulatory Affairs, K&S Digiprotect Services)