Medblaze Book a demo
The layered policy architecture for healthcare AI in India: NITI Aayog and SAHI for policy, BODH for validation, ABDM for digital infrastructure, NABH Digital Health for institutional maturity, the DPDP Act for data protection, and CDSCO and ICMR for sector regulation.

The New Regulatory Landscape for AI in Indian Healthcare

India is moving from “can AI be used in healthcare?” to “how can AI be scaled safely, responsibly and economically?” This article examines the emerging policy and governance architecture around healthcare AI, including NITI Aayog, SAHI, BODH, ABDM, NABH Digital Health, the DPDP Act and the proposed DISHA framework, alongside international parallels.

1. India is moving towards an AI-enabled healthcare system

Artificial Intelligence in healthcare has crossed an important inflection point in India. The conversation is no longer limited to whether AI can read an X-ray, predict deterioration, automate documentation or assist clinicians with decision-making. AI is increasingly becoming part of the operating fabric of healthcare, from diagnostics and clinical decision support to hospital operations, patient engagement, drug discovery and public-health surveillance.

NITI Aayog identified healthcare as a priority sector for AI in its National Strategy for Artificial Intelligence and subsequently developed a Responsible AI for All framework. The emphasis has progressively shifted from AI capability to safety, fairness, privacy, transparency, accountability and risk-based governance.

The strategic question for hospitals is therefore no longer simply “should we adopt AI?” It is “how do we create the governance, data and clinical infrastructure that allows us to adopt AI safely and at scale?”

2. The policy architecture is beginning to take shape

India’s healthcare AI regulatory landscape is not represented by one single “AI Act”. Instead, it is emerging as a layered ecosystem of laws, standards, policies, sectoral regulations and institutional governance mechanisms.

The layered policy architecture for healthcare AI in India: policy and strategy through NITI Aayog and SAHI, validation through BODH, digital infrastructure through ABDM, institutional maturity through NABH Digital Health, data protection through the DPDP Act, and sector regulation through CDSCO and ICMR.

At the policy level are NITI Aayog’s Responsible AI principles and SAHI. At the validation layer is BODH. ABDM provides digital-health infrastructure and interoperability; NABH Digital Health drives institutional digital maturity; the DPDP Act and Rules establish the core personal-data protection framework; ICMR guidance informs ethical AI use in biomedical research; and CDSCO’s medical-device framework can apply to AI-enabled medical devices.

The result is a move toward governance across the AI lifecycle: problem definition, data stewardship, validation, deployment, monitoring and accountability.

3. SAHI: India’s shift from AI experimentation to AI governance

The Strategy for Artificial Intelligence in Healthcare for India (SAHI), launched in February 2026, is a national guidance framework for safe, ethical, evidence-based and inclusive adoption of AI across India’s healthcare system.

Its significance is less about creating a prescriptive “AI law” and more about establishing a governance philosophy around healthcare AI. SAHI provides strategic direction around governance, data stewardship, validation, deployment and monitoring, while supporting states and institutions in responsible adoption.

For hospitals, this implies a shift from technology-led pilots, build, demonstrate, pilot, convince, to a more disciplined model: problem, evidence, validation, governance, deployment, monitoring and scale.

4. BODH: solving the AI validation problem

One of the biggest challenges in healthcare AI is not developing an algorithm. It is proving that the algorithm works in the real world.

BODH, the Benchmarking Open Data Platform for Health AI, was developed by IIT Kanpur in collaboration with the National Health Authority. It provides a privacy-preserving mechanism for systematic evaluation of AI models using diverse, anonymised real-world health datasets.

The platform is designed to assess performance, robustness, bias and generalisability before deployment at population scale. This points toward a future in which hospitals and AI developers increasingly ask, “how does this model perform against representative Indian data?” rather than relying solely on a vendor’s headline accuracy.

5. ABDM is creating the infrastructure AI needs

AI needs data, but it needs structured, interoperable, longitudinal and appropriately governed data, not simply large quantities of data.

The Ayushman Bharat Digital Mission provides digital-health infrastructure around identifiers, registries, interoperability and consent-based health-information exchange. This creates the digital plumbing needed for more meaningful secondary uses of healthcare data, including AI.

A hospital with fragmented records, PDFs and disconnected systems will find it difficult to extract reliable AI value. An interoperable, longitudinal digital record creates a substantially stronger foundation for prediction, clinical decision support, population health and operational intelligence.

ABDM is therefore more than a digital-health programme. It is potentially part of India’s AI infrastructure.

6. NABH Digital Health: from digitisation to digital maturity

NABH Digital Health standards reinforce the relationship between digital maturity and AI readiness. The focus moves beyond simply having an HIS or EMR toward the way technology supports clinical workflows, information management, patient safety, digital operations and continuity of care.

Digital maturity enables data maturity. Data maturity enables AI readiness.

An AI-ready hospital therefore needs more than AI applications. It needs digitised workflows, interoperable data, strong data governance, clinical governance and AI governance.

7. Healthcare startups are an important engine of adoption

Government policy creates the rails, but startups increasingly build the trains.

India has developed a strong health-AI ecosystem spanning radiology, pathology, cardiology, screening, remote monitoring and healthcare operations. Examples include Qure.ai, Niramai and Tricog, among others.

Qure.ai has developed AI applications across areas including chest X-ray interpretation, tuberculosis, lung cancer and stroke. Such examples illustrate how Indian startups can translate AI research into clinical applications at scale.

The emerging ecosystem creates a powerful model: government provides infrastructure and policy; startups provide innovation; hospitals provide clinical environments; clinicians provide validation; and patients provide the ultimate measure of value.

8. But who owns and controls the data?

A hospital’s data is enormously valuable. It can potentially improve clinical pathways, identify deterioration, reduce readmissions, improve infection control, optimise resources, support research and develop AI models.

But value does not equal unrestricted access.

The DPDP Act establishes a framework around personal-data processing, including the roles of Data Principals and Data Fiduciaries, consent and lawful processing, security safeguards and rights of individuals. The practical question for hospitals is therefore: what is the purpose for which patient data is being processed?

Clinical care, AI research, product development and commercial analytics are not automatically the same purpose. That distinction needs to be reflected in governance, contracts, access controls and data-use policies.

9. What hospitals should prepare for under DPDP

Hospitals should begin building a practical data-governance capability around eight areas:

  1. Data inventory. Know what patient data exists, where it is stored, who accesses it and which vendors process it.
  2. Purpose mapping. Document why each significant data use occurs.
  3. Consent management. Capture, record and manage consent where consent is the applicable basis.
  4. Vendor governance. Define permitted use, security, retention, deletion, secondary use, model training, sub-processors, audit and exit requirements.
  5. Data minimisation. Send only the data required for the use case.
  6. Access control. Use role- and need-based access.
  7. Auditability. Maintain traceability of access and processing.
  8. Incident management. Establish a defined response process for data breaches and AI-related incidents.

10. What happened to DISHA?

The Digital Information Security in Healthcare Act (DISHA) is an important part of India’s digital-health policy history. DISHA was proposed as healthcare-specific legislation dealing with collection, storage, transmission and use of digital health information, including privacy, confidentiality and security.

DISHA did not become enacted legislation. The Ministry of Health subsequently indicated that the proposal was being considered for subsumption into the broader data-protection framework being developed by MeitY.

Hospitals should therefore not treat DISHA as an operative statute today. However, the problems DISHA attempted to address remain highly relevant: confidentiality, patient control, secure exchange, authorised access and accountability.

11. India, the NHS and the USA: different models, converging principles

The UK and US provide useful comparisons.

In the NHS, GDPR operates alongside healthcare-specific information-governance arrangements. NHS guidance recommends involving information-governance leaders, the Data Protection Officer and Caldicott Guardian when implementing or sharing data for AI.

In the United States, HIPAA provides a foundational privacy and security framework for protected health information, while healthcare AI may additionally interact with FDA medical-device regulation, clinical standards, contractual requirements and emerging AI governance frameworks.

India is developing a different but increasingly coherent architecture: DPDP, ABDM, SAHI, BODH, NABH, healthcare regulation and institutional governance.

The frameworks differ, but the strategic principle is similar: patient data should not become an uncontrolled raw material for AI. It should become a governed strategic asset.

12. The opportunity: turning patient data into a strategic asset

The objective is not to restrict data use. It is to make responsible use more valuable.

Hospitals can move from data to insights, prediction, intervention and learning. Examples include predicting medication-related harm rather than simply reporting errors; identifying infection patterns earlier; predicting clinical deterioration; identifying patients at risk of dissatisfaction during the care journey; forecasting demand and optimising capacity; and continuously monitoring quality and accreditation risks.

The opportunity is to move from “data to reports” toward “data to intelligence to intervention”. That is where AI can fundamentally change hospital management.

13. Hospitals need three governance systems

Three governance systems a hospital needs around AI: clinical governance asking whether the AI is clinically safe and useful, data governance asking whether the right data is used in the right way, and AI governance asking whether to deploy and how to keep it safe afterwards.

Clinical governance asks: is the AI clinically safe and useful? It should cover clinical ownership, intended use, validation, workflow integration, human oversight, escalation, patient safety and adverse-event monitoring.

Data governance asks: are we using the right data in the right way? It should cover stewardship, quality, purpose limitation, consent, access, lineage, retention, anonymisation or pseudonymisation, vendor access, secondary use, cybersecurity and breach management.

AI governance asks: should we deploy this AI, and how do we keep it safe after deployment? It should cover an AI inventory, risk classification, validation, bias testing, explainability, cybersecurity, human oversight, model drift, performance monitoring, incident management, vendor accountability and periodic reassessment.

The key principle is that AI governance cannot stop at procurement. Validation is not a one-time event.

14. How hospitals should conduct an AI pilot

The traditional technology-pilot model, vendor demo, IT approval, pilot, deployment, is increasingly inadequate. A better model is:

  1. Define the clinical or operational problem.
  2. Classify the potential risk and harm if the system is wrong.
  3. Define the data required, source systems, quality, purpose, access and retention.
  4. Validate the model, including Indian-population relevance, false positives, false negatives and uncertainty.
  5. Establish human oversight and clinical accountability.
  6. Run the pilot with predefined KPIs covering outcomes, safety, turnaround time, adoption, false positives, false negatives, patient experience and cost.
  7. Monitor after deployment for drift, workflow changes and adverse events.

The pilot should be governed as a clinical or operational programme, not simply an IT project.

15. The strategic implication for hospital leaders

The winners in healthcare AI will not necessarily be hospitals that buy the largest number of AI tools. They will be hospitals that build the strongest AI operating model.

That operating model has five foundations: digital maturity, data maturity, clinical maturity, governance maturity and change maturity.

The future hospital CIO will increasingly become a steward of clinical data, digital transformation and AI risk. Quality leaders will need to ask whether AI processes are reliable, safe, equitable, auditable and evidence-based.

16. The CEO agenda: five questions every hospital should ask now

  1. What are our highest-value AI use cases?
  2. Are we digitally and data ready?
  3. What is our AI governance model, and who owns the risk?
  4. Are our vendor contracts AI-ready, including provisions for secondary use, model training, security, retention and liability?
  5. Can we run an AI pilot like a clinical programme rather than an IT project?

The answers will determine whether a hospital merely experiments with AI or develops the capability to scale it responsibly.

Conclusion: the regulatory landscape should make scale possible

India’s healthcare AI journey is entering its second phase. The first phase was about possibility: can AI detect disease, read images, predict deterioration or automate documentation? The second phase is about scale: can these systems work reliably across hospitals and diverse Indian populations while protecting patient rights and maintaining clinical accountability?

The emergence of SAHI and BODH, alongside ABDM, NABH Digital Health and the DPDP framework, suggests that India is building an architecture for responsible AI adoption.

The future is not AI replacing healthcare professionals, nor healthcare professionals resisting AI. It is healthcare professionals, governed data, validated AI and accountable institutions.

The strategic imperative for Indian hospitals is clear: do not wait for AI regulation to tell you how to govern AI. Build the governance capability now, because hospitals that learn to deploy AI responsibly will be best positioned to scale it.

Selected reference points

  • NITI Aayog: National Strategy for Artificial Intelligence and Responsible AI for All.
  • Ministry of Health and Family Welfare: SAHI and BODH launch, 17 February 2026.
  • Ministry of Health and Family Welfare: update on Secure AI in Health Initiative, 10 March 2026.
  • India Code: Digital Personal Data Protection Act, 2023.
  • MeitY: Digital Personal Data Protection Rules, 2025.
  • ABDM: Ayushman Bharat Digital Mission.
  • NABH: Digital Health Accreditation Programme and Digital Health Standards.
  • NHS England: artificial intelligence and information-governance guidance.
  • U.S. HHS and HealthIT.gov: AI and healthcare information-governance resources.

Disclaimer: this article is a strategic and educational perspective, not legal advice. Specific implementations should be reviewed against the DPDP Act and Rules, applicable healthcare regulations, contracts, professional requirements and the facts of the use case.

Talk to our team about AI governance for hospital quality →