Your HIS Vendor Will Not Save You On The 13th Of November 2026

Pull-out your hospital's HIS contract and search it for the phrase 'Consent Manager'.
For most, it won't be there. Not because your legal team missed a clause, but because the concept didn't formally exist when most hospital information system contracts were signed. As of mid-2026, the government portal for registration hasn't opened and due to this, no organisation has been able to register itself as a 'Consent Manager' under the DPDP Act. The framework that goes live on the 13th of November 2026 is the registration mechanism itself, not a finished network your hospital simply plugs into.
Your vendor contract has two boundaries it was never built to reach. One is brand new, while the other never really did its job.
I'm Boudhhayan Duttaa, founder of Batti Jalao, an AI-led healthcare marketing growth consultancy based in Guwahati. We build content and marketing systems such as BattiLynk AI, BattiSense and custom agentic AI, across relevant healthcare sub-segments. This piece is about what a typical HIS vendor agreement actually covers under the DPDP Act and the two specific places it doesn't reach.
What A HIS Vendor Contract Actually Covers
A hospital information system agreement is written around a specific, familiar relationship where the hospital is the 'Data Fiduciary', the party that decides why patient data is collected and how it's used, while the vendor is the 'Data Processor', the party that handles it on instruction. A reasonably current contract will have a data-processing clause, security-standard commitments and a breach-notification timeline. That much, most hospitals already have, even if nobody's re-read it since signing.
What it will not have, in almost every contract signed before this year, is any language about 'Consent Managers' at all.
Consent Manager Registration, In Plain Terms
Section 6 of the DPDP Act creates a specific role, that of a 'Consent Manager'. It's a registered, independent intermediary a patient can use to view and control his/her consents across multiple organisations from one dashboard, not just at your hospital, but anywhere she might've given consent to. Crucially, a 'Consent Manager' is not your vendor and it's accountable to the patient, not to you. The statute treats it more like an agent acting on a patient's behalf than a service you contract for.
The rollout runs in three dates, not one. The DPDP Rules were notified on the 13th of November 2025. The 'Consent Manager' registration framework, the mechanism that lets an organisation apply to become one, goes operational a year later, which is on the 13th of November 2026.
Full substantive obligations across the Act, including the consent mechanisms this eventually feeds into, come into force by the 13th of May 2027. A 'Consent Manager' needs a minimum net worth of ₹2 crore to register and operating as one without registering afterward carries a penalty of up to ₹50 crore per instance. None of this says that your hospital must become one. Adopting the 'Consent Manager' framework at all is optional under the Act. What isn't optional is being ready to interoperate with one once a patient starts using it and that's precisely the capability most HIS contracts were never written to include.
The Mix-Up Almost Every Hospital Makes
If your hospital already uses a cookie-consent banner or a consent-management platform bought from any third-party vendor, know that it's not a DPDP 'Consent Manager'. A consent-management platform is a website-level tool you configure and control. A 'Consent Manager' is a registered, independent statutory entity the patient chooses and controls, sitting entirely outside your relationship with any vendor. The two solve adjacent problems with almost identical names, which is exactly how a genuine compliance gap ends-up quietly reclassified as 'Already Handled' on an internal checklist.
The Vendor Risk Memo
This is the practical fix and it doesn't require renegotiating your entire contract to get it. A vendor risk memo is a short, internal document, one page is usually enough, that states plainly what your current HIS agreement actually commits your vendor to on four specific points including data-processing scope, security safeguards, breach-notification timing and consent-revocation handling.
Then, mention a fifth line, 'Consent Manager' interoperability, not yet addressed. Writing that gap down, in one sentence, in a document your compliance lead actually keeps, is worth more than assuming it's covered because the contract sounds thorough.
The Marketing-Surface Boundary
Here's the boundary that was never the vendor's job to begin with. A HIS or EMR contract governs clinical and administrative data inside your core system. It says nothing about your website's booking form, your WhatsApp broadcast list or a tracking pixel on your fertility clinic's landing page, because those usually sit with a completely different vendor or with an internal team running ad accounts directly, outside the HIS relationship entirely.
That means a hospital can have an airtight HIS vendor contract and a completely unaddressed marketing-data exposure at the same time, because the two were never covered by the same document or sometimes by any document at all. A compliance review that only reads the HIS contract has checked exactly one of the two places a hospital's data actually moves.
What This Looks Like on the Hospital Floor
Take a mid-sized hospital chain with a five-year HIS contract signed in 2023, well before any of this was drafted. Its data-processing clause is genuinely solid with encryption at rest, role-based access and a 72-hour breach notification window. A compliance officer reading it would reasonably conclude the hospital is in good shape.
Run that same contract against the five-point memo above and the picture changes. Data-processing scope: Covered, Security safeguards: Covered, Breach notification: Covered. Consent-revocation handling: Partially covered, the system can flag a withdrawal but nothing in the contract says how fast the vendor must act on it. Consent Manager interoperability: Absent entirely, because the clause would have needed to reference a registration framework that, in 2023, was still years from existing.
That's not a failing contract. It's a contract doing exactly what it was written to do, for a set of rules that has since moved past it. The memo's job is to make that gap visible on paper, so it gets addressed on a timeline the hospital controls, rather than discovered during an audit or worse, after a patient complaint.
What To Actually Do Before The 13th Of November
Search your HIS contract for 'Consent Manager' yourself. If it isn't there, you already know what line one of your risk memo says.
Write the vendor risk memo now, even in draft form, covering the five points above. A document that names a gap is worth more than a comfortable assumption that skips it.
Ask explicitly who owns marketing-surface compliance. If the honest answer is 'Nobody', that's the finding, not a reason to leave the memo blank.
Don't wait for the DPBI portal to open before you're ready. Interoperability readiness and the registration framework are two different clocks and the second one starting doesn't mean the first one waits for you.
Does A Smaller Hospital Need To Worry About This Too?
The 'Consent Manager' framework applies regardless of size, because it's built around the patient's choice, not the hospital's scale. A smaller facility is less likely to face a 'Significant Data Fiduciary' audit, but a patient at a ten-bed clinic has exactly the same statutory right to manage her consent through a registered intermediary as one at a 500-bed chain.
Your HIS vendor was never going to cover this, not out of negligence, but because the contract was written for a different problem. Worth finding out now what's actually in writing, before the 13th of November 2026 turns an assumption into a gap someone else discovers first.




