Critically evaluate the privacy and consent-management architecture of India's digital health ecosystem.
Q. Critically evaluate the privacy and consent-management architecture of India's digital health ecosystem. (15 marks, 250 words)
India's digital health ecosystem, anchored by the Ayushman Bharat Digital Mission (ABDM) with over 90 crore ABHA accounts, is built on a consent-driven design [1]. Yet handling sensitive health data of near-billion citizens makes its privacy architecture both a strength and a fault-line, demanding critical scrutiny.
Strengths of the architecture - Federated, consent-first design: The Health Information Exchange & Consent Manager (HIE-CM) ensures records are shared only with explicit, purpose-specific citizen consent, not centrally pooled [1]. - Interoperability with control: The 14-digit ABHA lets citizens link, access and withdraw access to records, embedding data minimisation [1]. - Legal backing: The DPDP Act, 2023 mandates prior notice, consent withdrawal, breach reporting and a Data Protection Board, giving statutory teeth [3]. - Security safeguards: NHA has notified cyber-security measures and audits under ABDM [2].
Weaknesses and concerns - Consent fatigue & literacy gap: Meaningful consent is doubtful when many rural, low-literacy users cannot grasp data-sharing implications. - Government-wide exemptions: The DPDP Act exempts state processing for "national security" and research, diluting protection [3]. - Enforcement lag: The Data Protection Board's independence and the absence of a health-specific data law raise oversight gaps [3]. - Breach risk: Concentrated digital records expand the attack surface despite safeguards [2].
The architecture is globally progressive in intent but under-secured in practice. Strengthening the Board's autonomy, phasing in health-data rules, and localised consent literacy—aligned with SDG-3 and the Puttaswamy privacy verdict—can make trust the foundation of digital health.
(~250 words)
Sources: 1. Ayushman Bharat Digital Mission Crosses 90 Crore ABHA Accounts, PIB (2026) — ABHA consent-based architecture, HIE-CM, 14-digit ID 2. Steps taken for cyber security under ABDM, PIB — security safeguards and audits 3. The Digital Personal Data Protection Act, 2023 — PRS Legislative Research — consent, breach reporting, Data Protection Board, government exemptions