Skip to content
🏥 Industry pack · Hospitals · Clinics · Labs

Patient data. Clinical compliance.
Treated with respect.

DPDP patient data, CDSCO licences, Clinical Establishments Act, NABL, lab vendor DPAs, insurance TPA reconciliation, GST exemption mapping for Indian hospitals, clinics, diagnostic labs and health-tech. Named DPO + CA, one retainer.

DPDPPatient-data compliant
CDSCOLicense renewals tracked
5 daysTPA reconciliation cycle
48hQuery SLA

Indian healthcare operates under the most layered regulatory stack of any sector. Clinical Establishments Act (centre + state variants), CDSCO drug licences, NABL for diagnostic labs, biomedical waste rules, PCPNDT for radiology, blood bank licences, insurance TPA empanelment, pharmacy registration, nursing council — plus GST, Income Tax, labour laws, POSH, and now DPDP for patient data at the strictest sensitivity tier.

Patient health data under DPDP Act 2023 is sensitive personal data — the strictest tier. Explicit written consent, breach reporting within hours, Virtual DPO mandatory for Significant Data Fiduciaries, data residency restrictions for international health-tech platforms. The margin for error is zero.

Insurance TPA reconciliation is the other operational nightmare. Star Health, Bajaj Allianz, HDFC Ergo, ICICI Lombard, government schemes (Ayushman Bharat, ESIS, CGHS) — each with their own claim format, rejection codes, re-submission windows. A hospital typically carries 20–40% of claims in TPA write-off that proper reconciliation would recover.

Cosmoura runs the full healthcare back-office as one retainer. Named DPO plus named CA on your account. DPDP for patient data, CDSCO / Clinical Establishments Act / NABL licence renewals, TPA reconciliation, pharmacy inventory accounting, GST exemption mapping — all on one calendar. Decipher Consultancy Services (our sister concern) builds the automation for consent capture, TPA reconciliation and licence tracking.

Trigger moment: You just received a DPDP data-breach notice, a CDSCO renewal reminder, a TPA rejection worth lakhs that nobody has time to re-submit, and a labour inspector asking about biomedical waste staff training — all in the same week. For a 50-bed hospital, this is a quiet week.

Three profiles we build the pack around.

The retainer is tuned to your stage. If you do not fit cleanly, we scope a custom pack.

01

Hospitals (10–500 beds)

Multi-specialty, super-speciality or single-specialty. CE Act plus CDSCO plus biomedical waste plus fire NOC plus TPA empanelment plus pharmacy plus statutory audit — all under one roof.

02

Clinics + diagnostic labs

Chain or single-location. NABL for labs, CDSCO for radiology, DPDP for patient data, GST on diagnostic services, pharmacy integration, insurance TPA for cashless. Lower regulatory burden than hospitals but same compliance surface.

03

Health-tech + telemedicine

DPDP children-data for paediatric platforms, cross-border data flows, EU + UK GDPR for international users, consumer protection rules for e-health, data interoperability standards (ABDM), consent architecture for tele-consult.

Four regulatory realities we solve for.

DPDP + patient health records

Health data is sensitive personal data under DPDP — strictest tier. Explicit consent, strict purpose limitation, mandatory breach reporting, Virtual DPO required for larger entities, data residency for international flows.

Clinical Establishments Act + state rules

Registration, categorisation, minimum standards. Rules vary by state (Karnataka, Tamil Nadu, Rajasthan, West Bengal have state-specific CE Acts; others follow central Act). We maintain the register and track renewal deadlines.

CDSCO + drug licences + lab accreditation

Drug licences (Form 20B / 21B), pharmacy registration, NABL accreditation for labs, blood bank licences, PCPNDT for radiology. Renewal calendars plus inspection prep plus pre-inspection document packs.

Insurance TPA + GST on health services

TPA reconciliation (Star, Bajaj, HDFC Ergo, government schemes), rejection management, GST treatment of health services vs. cosmetic / wellness services (treated differently), ITC on medical equipment and consumables.

The retainer, mapped to Healthcare.

Each pack pulls from the right pillars. Pick one or bundle all four.

Hero · Compliance

DPDP patient data pack

Compliance & Risk

Patient consent flows for admissions, teleconsultation and research. Health data map. HIPAA-adjacent controls for international patients. Breach response playbook. Lab, imaging, pharmacy and TPA vendor DPAs.

  • Patient consent architecture (admissions + tele + research)
  • Health-data map + ROPA
  • HIPAA-adjacent controls for international patients
  • Vendor DPAs (lab + imaging + pharmacy + TPA)
DPDP-compliant · breach-response ready Explore →

Clinical

CE Act + licence pack

Compliance & Risk

Clinical Establishments Act registration (centre or state), CDSCO drug licences, NABL coordination for diagnostic labs, PCPNDT for radiology, blood bank licence, biomedical waste licence, pre-inspection prep.

  • CE Act registration + state variants
  • CDSCO Form 20B / 21B + pharmacy licence
  • NABL + PCPNDT coordination
  • Biomedical waste + blood bank licences
All clinical licences · zero gap Explore →

Finance

Healthcare finance pack

Finance & Accounting

TPA reconciliation across 10+ TPAs, rejection management with re-submission, GST on medical services (exempt / taxable / mixed-supply matrix), pharmacy and consumables inventory accounting, OT equipment depreciation.

  • TPA reconciliation + rejection management
  • GST treatment matrix (exempt / taxable / mixed)
  • Pharmacy + consumables inventory
  • OT equipment depreciation + capex planning
TPA write-off down 20–40% · clean books Explore →

Secretarial

Hospital group ROC + ESOP

Secretarial & Corporate

Multi-entity ROC filings (hospital + pharmacy + diagnostic company often separate entities), doctor ESOP schemes for consultant retention, cap-table hygiene for health-tech, M&A and PE deal support for consolidation.

  • Multi-entity ROC filings
  • Doctor ESOP schemes for consultants
  • Cap-table hygiene for health-tech
  • M&A + PE deal support
Governance that PE investors will fund Explore →

Four weeks to a clean back-office.

Most new healthcare clients come to us mid-mess. Clean-up is a one-time cost; everything else is monthly cadence.

01

Licence + DPDP + TPA audit

Week 1

We audit your clinical licence status, DPDP posture across patient touchpoints, TPA empanelment list and reconciliation gaps, and GST treatment matrix. Written report with ranked remediation list.

  • Clinical licence status check
  • DPDP posture audit
  • TPA + GST gap check
02

DPDP + TPA cleanup

Week 2–4

Patient consent library deployed. Vendor DPAs renegotiated with lab, imaging and TPA. TPA re-submission campaign run on last 6 months of rejections to recover written-off claims. Clinical licence gaps filed where overdue.

  • Patient consent live
  • Vendor DPAs renegotiated
  • TPA re-submission campaign
03

Calendar + handover

Week 4

12-month compliance + finance calendar handed over. Named DPO plus CA plus (where applicable) CS assigned. Monthly cadence agreed with your medical superintendent and finance head.

  • 12-month calendar handed over
  • Named DPO + CA assigned
  • Dedicated WhatsApp with hospital team
04

Live + monthly cadence

Ongoing

Monthly TPA reconciliation, monthly compliance calendar, quarterly POSH training, annual licence renewals in the renewal window, annual DPDP posture report to board. All on calendar.

  • Monthly TPA + compliance cadence
  • Quarterly POSH + staff training
  • Annual licence + audit cycle

Generic CA firm. Self-run team. Cosmoura.

Honest comparison on cost, coverage and the parts most firms quietly skip.

Generic CA firm Self-run team Cosmoura retainer
DPDP patient-data compliance Not offered Rarely built Full consent + DPO on retainer
TPA reconciliation In-house billing only 20–40% write-off Automated · write-off down 20–40%
CE Act + CDSCO + NABL Separate licence agents Internal admin burden In-house, calendar-driven
Multi-entity ROC Per-entity billing In-house CS or none Consolidated handling
Doctor ESOP + cap table Separate CS Rarely done well In-house, included
Monthly cost (full stack) ₹10–20L/yr across vendors ₹20–40L/yr fully loaded ₹4–10L/yr fixed retainer
Breach response Not offered In-house panic 6-hour window · on-call support

Eight things we handle, every month.

Named DPO + CA on your account
DPDP patient consent + vendor DPA library
CDSCO, CE Act, NABL renewal calendar
TPA reconciliation with rejection management
Pharmacy + consumables inventory accounting
GST treatment matrix (exempt vs. taxable vs. mixed-supply)
Breach response playbook + CERT-In reporting
Dedicated channel with 48-hour SLA

Questions healthcare teams ask us.

01 Do you work with hospitals, clinics, diagnostic labs and health-tech platforms? +

All four. Each has a tuned pack. Hospitals get the full CE Act + CDSCO + TPA pack. Diagnostic labs add NABL. Clinics get the lightweight registration + inventory pack. Health-tech gets DPDP + consumer protection + data interoperability.

02 How does DPDP treat patient health data differently from other data? +

Health data is sensitive personal data — the strictest tier under the Act. Explicit written consent, breach reporting within hours, Virtual DPO mandatory for Significant Data Fiduciaries (SDFs). We prepare you for SDF classification if your scale warrants it.

03 Can you handle insurance TPA reconciliation across Star, Bajaj, HDFC Ergo and government schemes? +

Yes. We integrate with your HIS (hospital information system), pull daily TPA submissions, track rejections, raise re-submission requests and reconcile payments monthly. Reduces TPA write-offs by 20–40% typically. Covers Star, Bajaj Allianz, HDFC Ergo, ICICI Lombard, Max Bupa, government schemes.

04 What about multi-location hospitals and consolidated reporting? +

Consolidated books with location-wise P&L. Compliance tracked per location for CE Act, CDSCO, NABL, fire NOC. Centralised for ROC, GST, income tax and DPDP.

05 Do you support government scheme empanelment like Ayushman Bharat, ESIS, CGHS? +

Yes. Empanelment application support, ongoing claim processing and reconciliation, scheme-specific documentation, audit coordination with scheme auditors. Government scheme claims typically settle 60–90 days — we track and chase.

06 What about PCPNDT compliance for radiology / ultrasound units? +

Yes. Form F maintenance, Form H quarterly reporting, premises registration, machine registration, operator training records. One of the most inspected compliance areas in Indian radiology.

07 Can you handle doctor ESOP schemes for consultant retention? +

Yes. Classical options under Section 62(1)(b) or SAR (Stock Appreciation Rights) depending on your preference. We draft the scheme, run board approvals, maintain the grant register, and handle Section 194R TDS implications on exercise.

08 What does breach-response actually look like for a hospital? +

Our Virtual DPO is on-call. On breach detection: 1-hour internal assessment, 6-hour CERT-In report, 72-hour affected-data-subject notification (Act default). Plus crisis communication draft for your medical director and PR team. Tabletop exercises run quarterly.

A retainer built for healthcare.
Live in two weeks.

Free 30-minute discovery call. We map your current compliance + finance posture, then come back with a sequenced plan.