Shadow IT Is Quietly Running India's Hospitals. Here's What That Actually Costs.

Indian hospitals increasingly rely on digital messaging to coordinate patient care. But when clinical communication moves through personal devices and consumer messaging platforms, hospitals can lose visibility and administrative control over where patient information is stored, who can access it and how long it remains available.

For healthcare organisations navigating India's DPDP framework, NABH Digital Health requirements and increasingly sophisticated security expectations from international partners, that governance gap is becoming harder to ignore.

What shadow IT actually looks like inside a hospital

In many healthcare environments, clinical teams may turn to familiar consumer messaging tools when they need to coordinate quickly. A WhatsApp group might be used for an ICU team, OT coordination or shift handover. Patient information, reports or images may then become part of those conversations. This is one form of shadow IT: technology used for organisational work without the knowledge, approval or oversight of the relevant IT and compliance teams.

In healthcare, shadow IT can include:

  • Consumer messaging platforms used for patient handoffs, lab results and radiology images
  • Personal email accounts used to send discharge summaries or referral letters
  • Screenshots of EMR data shared in group chats when approved systems are difficult to access
  • Personal devices retaining clinical conversations outside the hospital's direct administrative control

None of this is malicious. Clinicians are trying to save time and, often, save lives. But every one of these workarounds creates a data trail that the hospital cannot see, cannot audit and cannot secure. Patient information may remain on personal devices or backups outside the hospital's direct administrative control. If a device is lost, so is a slice of the hospital's compliance posture. If a regulator asks who had access to this patient's data and when, there is often no honest answer.

Why this has suddenly become urgent

Indian hospitals have faced this risk for years. What's changed is the regulatory ground underneath them.

The DPDP Act, 2023

India's Digital Personal Data Protection framework establishes obligations around the processing and protection of digital personal data. For hospitals, this makes the governance of patient information across digital systems increasingly important. Clinical communication can involve names, diagnoses, reports, images and other information that may constitute personal data. When that information moves through unmanaged personal devices and consumer applications, hospitals can face greater challenges in maintaining organisational control, access governance, retention practices and visibility over how information is handled.

The DPDP Rules, 2025 and the government's phased commencement timeline are moving the framework from legislation towards implementation, making data governance an increasingly practical operational priority for healthcare organisations.

NABH and NABH Digital Health

The National Accreditation Board for Hospitals and Healthcare Providers has long required documented protocols for patient information handling as part of hospital quality and accreditation frameworks. NABH's Digital Health programmes assess areas including digital infrastructure, cybersecurity, patient data privacy and information management. Shadow IT can create a gap between documented policies and how clinical communication actually takes place in practice.

HIPAA, as the global benchmark

HIPAA-aligned security and privacy controls may be requested by international partners or organisations operating in cross-border healthcare environments. Even hospitals with no direct HIPAA obligation increasingly get asked, in due diligence and partnership conversations, whether their communication infrastructure would hold up against a HIPAA-style audit. HIPAA compliance depends on the covered business associate relationship, contractual arrangements and safeguards.

Put together, DPDP, NABH Digital Health and the HIPAA-aligned expectations from global partners are converging on the same requirement: hospitals need to know where clinical communication lives, who can access it and how it's governed. Shadow IT makes all three questions unanswerable.

Kauvery Hospital: what it looks like to close the gap at scale

Kauvery Hospital Group, one of India's fastest-growing hospital networks, recently deployed a secure clinical communication platform across its entire network: 12 hospitals across 6 locations, supporting over 900 doctors and more than 7,000 clinical staff, with a rollout plan covering more than 12,000 users across 100+ teams over the next three years.

That scale matters, because it shows this isn't a pilot program or a single department experiment. It's a network-wide decision to replace the consumer apps with a governed system, built for the reality of how Indian hospitals actually communicate: distributed teams, multiple facilities, doctors moving between locations and a constant stream of time-sensitive clinical information.

Why NetSfere is the answer, not another platform to manage

The instinct when a hospital hears "get off WhatsApp" is often to worry about adding friction for already-overworked clinical staff. NetSfere was built around the opposite goal: give clinicians something that feels as fast as the apps they already use, while giving hospital IT and compliance teams the control that those platforms can never offer.

Built for regulated environments

NetSfere uses ML-KEM 1024, aligned with NIST FIPS 203, for encryption, and is architected on zero-knowledge principles, meaning the platform itself cannot read message content. It also holds FedRAMP Ready status, reflecting the level of security rigour typically demanded in government and highly regulated environments, a bar most consumer apps were never built to meet.

Centralized administration

Every message and file attachment can be archived through NetSfere Vault, providing organisations with a centrally managed record of communications for governance and compliance purposes. That's the difference between having a policy and being able to prove compliance, which is exactly the distinction NABH Digital Health assessments and DPDP breach investigations look for.

Enterprise-controlled communication

Unlike consumer messaging apps, where clinical information may reside on personal devices or consumer backups outside the hospital's direct administrative control, NetSfere provides an enterprise-controlled environment for organisational communication, giving IT teams greater visibility and governance over how communications are managed.

The real choice hospitals are making

The question facing Indian hospital groups right now isn't whether clinical staff will keep messaging each other about patients. They will, because that's how modern care coordination works. The real question is whether that communication happens inside a system the hospital can govern, audit and defend, or inside a patchwork of personal apps that no compliance officer can fully see into.

Kauvery's network-wide deployment is an early signal of where the rest of the sector is headed. As DPDP enforcement matures, as NABH Digital Health becomes a more common benchmark and as global partners keep asking HIPAA-shaped questions, hospitals that haven't closed their shadow IT gap will find it increasingly hard to answer them.

NetSfere helps healthcare organisations bring clinical communication into a secure, enterprise-controlled environment, designed for the demands of modern healthcare.

Ready to close the shadow IT gap? Talk to NetSfere.


Frequently Asked Questions

Shadow IT in healthcare refers to any application, device or communication tool used to handle hospital operations or patient data without approval or oversight from IT and compliance teams. In Indian hospitals, the most common form is clinical staff using WhatsApp, personal email or personal phones to coordinate patient care.
Using WhatsApp for patient communication does not automatically establish a violation of the DPDP Act. However, when patient information is shared through unmanaged personal devices and consumer messaging applications, hospitals may face greater challenges in demonstrating appropriate governance, access control, retention and accountability for that data.
NABH Digital Health certification evaluates how a hospital governs digital clinical data in practice, not only whether a written policy exists. That includes demonstrating control over how clinical communication is stored, accessed and audited, which unmanaged consumer messaging apps cannot provide.
Indian hospitals are not directly regulated by HIPAA, but HIPAA-aligned data handling has become a common benchmark that international partners, insurers and medical tourism referrers expect to see, particularly for hospital groups with cross-border patients or partnerships.
NetSfere is built on a zero-knowledge architecture with ML-KEM 1024 encryption aligned to NIST FIPS 203, and holds FedRAMP Ready status. It provides centrally governed administration and communication archiving, while being designed for mobile-first clinical workflows.
NetSfere holds FedRAMP Ready status and uses encryption aligned with NIST FIPS 203 (ML-KEM 1024). Its architecture follows zero-knowledge principles, and NetSfere Vault can archive messages and file attachments for organisational governance and compliance purposes.


Share: Twitter