Hospitals (10–500 beds)
Multi-specialty, super-speciality or single-specialty. CE Act plus CDSCO plus biomedical waste plus fire NOC plus TPA empanelment plus pharmacy plus statutory audit — all under one roof.
DPDP patient data, CDSCO licences, Clinical Establishments Act, NABL, lab vendor DPAs, insurance TPA reconciliation, GST exemption mapping for Indian hospitals, clinics, diagnostic labs and health-tech. Named DPO + CA, one retainer.
Indian healthcare operates under the most layered regulatory stack of any sector. Clinical Establishments Act (centre + state variants), CDSCO drug licences, NABL for diagnostic labs, biomedical waste rules, PCPNDT for radiology, blood bank licences, insurance TPA empanelment, pharmacy registration, nursing council — plus GST, Income Tax, labour laws, POSH, and now DPDP for patient data at the strictest sensitivity tier.
Patient health data under DPDP Act 2023 is sensitive personal data — the strictest tier. Explicit written consent, breach reporting within hours, Virtual DPO mandatory for Significant Data Fiduciaries, data residency restrictions for international health-tech platforms. The margin for error is zero.
Insurance TPA reconciliation is the other operational nightmare. Star Health, Bajaj Allianz, HDFC Ergo, ICICI Lombard, government schemes (Ayushman Bharat, ESIS, CGHS) — each with their own claim format, rejection codes, re-submission windows. A hospital typically carries 20–40% of claims in TPA write-off that proper reconciliation would recover.
Cosmoura runs the full healthcare back-office as one retainer. Named DPO plus named CA on your account. DPDP for patient data, CDSCO / Clinical Establishments Act / NABL licence renewals, TPA reconciliation, pharmacy inventory accounting, GST exemption mapping — all on one calendar. Decipher Consultancy Services (our sister concern) builds the automation for consent capture, TPA reconciliation and licence tracking.
Trigger moment: You just received a DPDP data-breach notice, a CDSCO renewal reminder, a TPA rejection worth lakhs that nobody has time to re-submit, and a labour inspector asking about biomedical waste staff training — all in the same week. For a 50-bed hospital, this is a quiet week.
Who this is for
The retainer is tuned to your stage. If you do not fit cleanly, we scope a custom pack.
Multi-specialty, super-speciality or single-specialty. CE Act plus CDSCO plus biomedical waste plus fire NOC plus TPA empanelment plus pharmacy plus statutory audit — all under one roof.
Chain or single-location. NABL for labs, CDSCO for radiology, DPDP for patient data, GST on diagnostic services, pharmacy integration, insurance TPA for cashless. Lower regulatory burden than hospitals but same compliance surface.
DPDP children-data for paediatric platforms, cross-border data flows, EU + UK GDPR for international users, consumer protection rules for e-health, data interoperability standards (ABDM), consent architecture for tele-consult.
What this industry faces
Health data is sensitive personal data under DPDP — strictest tier. Explicit consent, strict purpose limitation, mandatory breach reporting, Virtual DPO required for larger entities, data residency for international flows.
Registration, categorisation, minimum standards. Rules vary by state (Karnataka, Tamil Nadu, Rajasthan, West Bengal have state-specific CE Acts; others follow central Act). We maintain the register and track renewal deadlines.
Drug licences (Form 20B / 21B), pharmacy registration, NABL accreditation for labs, blood bank licences, PCPNDT for radiology. Renewal calendars plus inspection prep plus pre-inspection document packs.
TPA reconciliation (Star, Bajaj, HDFC Ergo, government schemes), rejection management, GST treatment of health services vs. cosmetic / wellness services (treated differently), ITC on medical equipment and consumables.
Pre-built packs
Each pack pulls from the right pillars. Pick one or bundle all four.
Hero · Compliance
Patient consent flows for admissions, teleconsultation and research. Health data map. HIPAA-adjacent controls for international patients. Breach response playbook. Lab, imaging, pharmacy and TPA vendor DPAs.
Clinical
Clinical Establishments Act registration (centre or state), CDSCO drug licences, NABL coordination for diagnostic labs, PCPNDT for radiology, blood bank licence, biomedical waste licence, pre-inspection prep.
Finance
TPA reconciliation across 10+ TPAs, rejection management with re-submission, GST on medical services (exempt / taxable / mixed-supply matrix), pharmacy and consumables inventory accounting, OT equipment depreciation.
Secretarial
Multi-entity ROC filings (hospital + pharmacy + diagnostic company often separate entities), doctor ESOP schemes for consultant retention, cap-table hygiene for health-tech, M&A and PE deal support for consolidation.
How we onboard
Most new healthcare clients come to us mid-mess. Clean-up is a one-time cost; everything else is monthly cadence.
Week 1
We audit your clinical licence status, DPDP posture across patient touchpoints, TPA empanelment list and reconciliation gaps, and GST treatment matrix. Written report with ranked remediation list.
Week 2–4
Patient consent library deployed. Vendor DPAs renegotiated with lab, imaging and TPA. TPA re-submission campaign run on last 6 months of rejections to recover written-off claims. Clinical licence gaps filed where overdue.
Week 4
12-month compliance + finance calendar handed over. Named DPO plus CA plus (where applicable) CS assigned. Monthly cadence agreed with your medical superintendent and finance head.
Ongoing
Monthly TPA reconciliation, monthly compliance calendar, quarterly POSH training, annual licence renewals in the renewal window, annual DPDP posture report to board. All on calendar.
How we compare
Honest comparison on cost, coverage and the parts most firms quietly skip.
| Generic CA firm | Self-run team | Cosmoura retainer | |
|---|---|---|---|
| DPDP patient-data compliance | Not offered | Rarely built | Full consent + DPO on retainer |
| TPA reconciliation | In-house billing only | 20–40% write-off | Automated · write-off down 20–40% |
| CE Act + CDSCO + NABL | Separate licence agents | Internal admin burden | In-house, calendar-driven |
| Multi-entity ROC | Per-entity billing | In-house CS or none | Consolidated handling |
| Doctor ESOP + cap table | Separate CS | Rarely done well | In-house, included |
| Monthly cost (full stack) | ₹10–20L/yr across vendors | ₹20–40L/yr fully loaded | ₹4–10L/yr fixed retainer |
| Breach response | Not offered | In-house panic | 6-hour window · on-call support |
What's included
FAQ
All four. Each has a tuned pack. Hospitals get the full CE Act + CDSCO + TPA pack. Diagnostic labs add NABL. Clinics get the lightweight registration + inventory pack. Health-tech gets DPDP + consumer protection + data interoperability.
Health data is sensitive personal data — the strictest tier under the Act. Explicit written consent, breach reporting within hours, Virtual DPO mandatory for Significant Data Fiduciaries (SDFs). We prepare you for SDF classification if your scale warrants it.
Yes. We integrate with your HIS (hospital information system), pull daily TPA submissions, track rejections, raise re-submission requests and reconcile payments monthly. Reduces TPA write-offs by 20–40% typically. Covers Star, Bajaj Allianz, HDFC Ergo, ICICI Lombard, Max Bupa, government schemes.
Consolidated books with location-wise P&L. Compliance tracked per location for CE Act, CDSCO, NABL, fire NOC. Centralised for ROC, GST, income tax and DPDP.
Yes. Empanelment application support, ongoing claim processing and reconciliation, scheme-specific documentation, audit coordination with scheme auditors. Government scheme claims typically settle 60–90 days — we track and chase.
Yes. Form F maintenance, Form H quarterly reporting, premises registration, machine registration, operator training records. One of the most inspected compliance areas in Indian radiology.
Yes. Classical options under Section 62(1)(b) or SAR (Stock Appreciation Rights) depending on your preference. We draft the scheme, run board approvals, maintain the grant register, and handle Section 194R TDS implications on exercise.
Our Virtual DPO is on-call. On breach detection: 1-hour internal assessment, 6-hour CERT-In report, 72-hour affected-data-subject notification (Act default). Plus crisis communication draft for your medical director and PR team. Tabletop exercises run quarterly.
Ready to run cleaner?
Free 30-minute discovery call. We map your current compliance + finance posture, then come back with a sequenced plan.