Telemedicine Guidelines
Everything Indian healthcare professionals need to know about telemedicine law, the Telemedicine Practice Guidelines 2020, data privacy under the DPDP Act 2023, and online prescriptions.
Telemedicine the delivery of healthcare services over digital communication platforms expanded dramatically during the COVID-19 pandemic in India and has since become a permanent
feature of the healthcare delivery landscape. The Government of India formally recognised and regulated telemedicine through the Telemedicine Practice Guidelines 2020, issued jointly
by the Board of Governors in Supersession of the Medical Council of India (the interim body that preceded the NMC) and the Ministry of Health and Family Welfare.
For healthcare professionals, understanding telemedicine law India means understanding both the permissions and the limitations of this evolving framework.
The Telemedicine Practice Guidelines, 2020
The Telemedicine Practice Guidelines (TPG) 2020 are appended to the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations 2002 as Amendment Regulation 3.8.1. They apply to all registered medical practitioners under the NMC Act and provide a legal basis for remote consultations with patients.
The Guidelines address the following key areas:
Eligible practitioners: Only registered medical practitioners can provide telemedicine consultation. AYUSH practitioners are covered by their respective telemedicine guidelines issued by the AYUSH Ministry.
Patient consent: Before the first telemedicine consultation, explicit consent must be obtained from the patient. This may be verbal, written, or electronic (including clicking an 'I agree' button on a platform).
Technology platforms: The consultation may take place over any platform video, audio, or text-based provided appropriate security is maintained. eSanjeevani is the government's official telemedicine platform.
First consultation: A doctor may undertake telemedicine consultations as a first consultation. There is no requirement for a prior in-person meeting before a telemedicine consultation can occur.
Referred patients: Where a specialist is consulted via telemedicine following a referral from another doctor, the referring doctor's clinical information may supplement the specialist's assessment.
Key Requirement
The Telemedicine Practice Guidelines require practitioners to identify themselves to patients including their full name, registration number, and qualification at the beginning of each telemedicine consultation. Patients must similarly be identified before clinical advice is given. Anonymous consultations are not compliant.
Prescription Rules in Telemedicine Practice
One of the most practically significant aspects of the TPG 2020 concerns what medicines may be prescribed via telemedicine. The Guidelines create three categories:
List O (Over the counter): Medicines that can be prescribed via any mode of telemedicine video, audio, or text/chat.
List A: Medicines that can be prescribed via telemedicine following a video consultation. This list includes many commonly prescribed drugs for chronic conditions.
List B: Medicines that can only be prescribed during or following an in-person consultation. These include Schedule X drugs (controlled substances, narcotics, and psychotropic drugs under the Drugs and Cosmetics Act) and certain other high-risk drugs specified in List B.
Crucially, the Guidelines prohibit prescribing Schedule X substances including opioids, benzodiazepines, and other controlled substances via telemedicine. Violating this provision constitutes professional misconduct and exposes the practitioner to regulatory action.
E-prescriptions issued via telemedicine must include the doctor's name, qualification, registration number, contact details, date, and patient details. A digital signature or the equivalent electronic authentication is recommended.
eSanjeevani India's National Telemedicine Platform
eSanjeevani is the Government of India's national telemedicine service, operated under the National Health Mission. It operates in two modes:
eSanjeevani AB-HWC: A doctor-to-doctor consultation platform enabling Ayushman Bharat Health and Wellness Centres to connect with specialists at identified Hub hospitals.
eSanjeevani OPD: A patient-to-doctor platform enabling direct teleconsultation between patients and registered doctors.
eSanjeevani provides a ready-to-use, government-approved platform for practitioners who wish to offer telemedicine services without setting up proprietary infrastructure. Consultations conducted through eSanjeevani are presumptively compliant with the TPG 2020.
Data Privacy in Digital Health: The DPDP Act, 2023
The Digital Personal Data Protection (DPDP) Act, 2023 is India's comprehensive data privacy legislation. While it is being implemented in phases (with rules yet to be notified as of the time of writing), its implications for healthcare providers are significant.
Under the DPDP Act:
Patient health data constitutes 'personal data' and likely 'sensitive personal data' under the forthcoming DPDP Rules, which will attract heightened protection requirements.
Hospitals, clinics, and telemedicine platforms that process patient data are 'data fiduciaries' with obligations to process data only for specified, lawful purposes with patient consent.
Patients have rights including the right to access information about their data, the right to correct inaccurate data, the right to erasure (with certain exceptions for healthcare records), and the right to grievance redress.
In the event of a personal data breach, data fiduciaries must notify the Data Protection Board of India and affected individuals as prescribed.
Significant data fiduciaries (a category that will be specified by rules) will face enhanced obligations including the appointment of a Data Protection Officer and conducting Data Protection Impact Assessments.
Telemedicine practitioners using third-party platforms must conduct due diligence on the platform's data security and privacy compliance. Sharing patient data with third parties including marketing analytics companies without explicit patient consent would violate the DPDP Act.
Practical Tip
Review your telemedicine platform's privacy policy and data processing terms. Ensure your patient consent forms include clear information about how their data is collected, stored, shared, and protected. Update your website privacy policy to reflect DPDP compliance. Consider appointing an internal data protection lead even before the law mandates it.
Liability in Telemedicine Key Risk Areas
Telemedicine creates several distinct liability risks that do not arise (or arise differently) in face-to-face practice:
- Diagnostic limitations: Inability to physically examine the patient means that some diagnoses cannot be reliably made remotely. Practitioners must be alert to cases where in-person examination is necessary and direct the patient accordingly.
- Patient identity verification: Prescribing medicines without verifying the patient's identity creates fraud and liability risks.
- Record-keeping: Telemedicine consultations must be documented in the medical record just as in-person consultations are. Failure to maintain records of the consultation is a common compliance gap.
- Cross-state and international consultations: Providing consultations to patients in different states or countries raises questions about which regulatory framework applies. Indian registered practitioners may consult patients in India via telemedicine; providing consultations to patients abroad may engage the host country's medical licensing laws.
- Data breaches: A breach of patient data from a telemedicine platform can create liability under the DPDP Act and reputational damage for the practitioner.
Setting up a telemedicine practice? Our medico-legal experts can help you build a compliant, legally sound telemedicine framework from patient consent templates to data privacy policies. Contact us today.