DPDP-Safe Patient Communication: AI-Drafted Copy for Indian Clinics

Why patient communication is the new compliance surface
ost Indian clinics treat patient communication as an operational task. The DPDP Act 2023 reframed it as a compliance surface. Every message a clinic sends a patient now sits inside a consent scope: did this patient agree to appointment reminders, lab-result delivery, marketing updates, or research participation? A message that crosses scope — for example, a lab-result reminder doubled as a wellness package promotion — is a DPDP violation regardless of how well-intentioned. The clinic does not have to mean harm to attract a penalty.
Consent-aware drafting: the four message classes
We sort every clinic outbound message into four DPDP-aligned classes. Each class draws on a different consent record, uses a different tone, and triggers a different audit log. The classes:
- Operational — appointment reminders, prescription pickups, lab-result availability (requires operational consent, neutral tone)
- Care-continuity — chronic-condition check-ins, post-procedure follow-ups (requires care-continuity consent, warm tone, doctor signature)
- Wellness — preventive screening reminders, health-tip distribution (requires wellness consent, educational tone, opt-out link)
- Research — anonymised cohort participation requests (requires explicit research consent, formal tone, IEC reference)
Why PHI redaction happens at draft, not at send
Most clinics that adopt AI assistance redact Protected Health Information at the send-time hand-off. That is too late. The patient record has already been parsed by the language model — name, phone, address, Aadhaar reference, diagnosis text — by the time the clinic strips fields out of the final message. A DPDP-aware content workflow redacts before the model sees the record: only the speciality, the appointment type, and a non-identifying token reach the model. The model produces a placeholder draft; the clinic re-inserts the patient's name on the local side before send. The model never holds identifiable PHI.
Speciality-specific templates that do not feel like templates
A diabetologist's follow-up message reads differently from a paediatrician's annual-checkup nudge. A psychiatrist's session reminder is more cautious than a dentist's six-month cleaning prompt. Templates that ignore these speciality differences read as templates — patients open them, recognise the shape, and treat them as marketing. Templates that bake in speciality voice read as personal communication. AI-assisted drafting can produce 8-12 speciality-tuned variants in a morning; what humans cannot do is write 12 versions of the same message at the same quality bar.
The 90-second doctor review loop
Every AI-drafted message that contains a clinical reference — a follow-up window, a medication reminder, a screening recommendation — needs a doctor's review before send. The review does not have to take 10 minutes. The structured review loop we use: doctor reads the draft, checks four bullet points (consent scope, clinical accuracy, tone, PHI absent), edits or approves in under 90 seconds. A clinic of four doctors that sends 800 messages a week spends roughly 20 doctor-hours on review — and the review cost is what stands between the practice and a DPDP-triggered shutdown.
A DPDP-safe message is not one that avoids PHI. It is one whose consent scope, clinical accuracy, and audit log all agree with each other.
Internal DPDP healthcare review, 2025