By: CA Anil
K. Jain
Chartered Accountant | Economist | Policy Researcher | Author
President – Ahimsa Foundation India
Email: CAINDIA@HOTMAIL.COM
Chapter Synopsis
This chapter examines the
critical cybersecurity challenges facing Indian hospitals, where digital
transformation has created vast vulnerabilities that threaten patient safety.
Hospitals are uniquely difficult to secure due to connected legacy medical devices
(often unpatched), 24/7 operations that cannot tolerate downtime, high-value
patient data, complex fluid workforces, and the constant tension between
accessibility for emergency care and security controls.
The threat landscape is dominated
by ransomware—exemplified by the 2022 AIIMS Delhi attack that crippled the
nation's premier hospital for two weeks, forcing manual operations and
postponing surgeries. Other threats include data breaches (medical records
worth more than credit cards on dark web), phishing and business email
compromise, medical device hacking, DDoS attacks, and insider threats.
The legal framework imposes
stringent obligations: the DPDP Act, 2023 designates hospitals as
Data Fiduciaries requiring reasonable security safeguards, breach notification
to patients and the Data Protection Board, and verifiable parental consent for
children's data—with penalties up to ₹250 crore. The IT Act,
2000 (including cyber terrorism under Section 66F for CII
hospitals), CERT-In Directions (six-hour incident reporting, 180-day
log retention), and NCIIPC guidelines apply to Critical Information
Infrastructure hospitals.
Core security measures include
network segmentation (isolating clinical, IT, and guest zones), multi-factor
authentication on all remote access, medical device inventory and vendor
security management, data encryption with offline 3-2-1 backups, staff phishing
training, 24/7 Security Operations Centres, and tested incident response plans
with manual fallback procedures for clinical operations.
The
chapter concludes that cybersecurity in healthcare is a patient safety
imperative—as essential as hand hygiene and surgical sterility—requiring
board-level leadership, sustained investment, and cultural transformation
across the sector.
1.
Introduction
A
hospital is a place of healing, but in the digital age, it is also a vast,
complex information system. Every patient admitted generates a stream of data:
personal identification, medical history, diagnostic images, laboratory
results, prescriptions, billing information, and discharge summaries. This data
flows through an intricate network of interconnected devices—MRI machines,
ventilators, infusion pumps, patient monitors, electronic health record
systems, and billing platforms. The hospital information system (HIS) that
integrates these functions is the nervous system of the modern healthcare
enterprise. If that nervous system is paralysed by a cyber attack, the
consequences are measured not in rupees but in human lives.
The
cyber threat to Indian hospitals is not hypothetical. On 23 November 2022, the
All India Institute of Medical Sciences (AIIMS), Delhi—the nation's premier
healthcare institution and a declared Critical Information
Infrastructure—suffered a ransomware attack that crippled its hospital
information system for over two weeks. Patient registrations reverted to paper,
laboratory reports were handwritten and hand-delivered, and surgeries were
postponed. The attack was a national wake-up call. It exposed the profound
vulnerability of India's healthcare sector, where the pace of digital
transformation has far outstripped the investment in cybersecurity. AIIMS was
not an isolated incident. Hospitals across the country—large corporate chains,
state medical colleges, and small nursing homes—have been targeted by
ransomware, data theft, and phishing. Each successful attack disrupts care,
erodes patient trust, and, in the worst cases, can contribute to patient harm
or death.
Cybersecurity
for hospitals is therefore not a technical specialty; it is a patient safety
imperative. This chapter examines the unique cybersecurity challenges of the
Indian healthcare sector, maps the threat landscape, analyses the legal and
regulatory framework, and sets out the practical measures that hospitals must
implement to protect their patients, their data, and their operations.
Quotation:
"When a hospital's systems are encrypted by
ransomware, the hostage is not just data. The hostage is the patient waiting
for a diagnosis, the surgeon who cannot access the scan, and the family praying
for a loved one. Cyber security in healthcare is a matter of life and
death." — Dr. Sanjay Bahl, Director General, CERT-In, in a 2023 address on
healthcare cyber security.
2.
The Unique Cyber Security Challenges of Hospitals
Hospitals
face a confluence of challenges that make them uniquely vulnerable to cyber
attack.
A.
Connected Medical Devices: Modern
hospitals are filled with network-connected medical devices—infusion pumps,
ventilators, MRI and CT scanners, patient monitors, and picture archiving and
communication systems (PACS). Many of these devices run on legacy operating
systems (such as Windows XP or embedded Linux) that cannot be easily patched or
updated. A vulnerability in a single device can provide an attacker with a
foothold into the wider hospital network. Aggressive security controls cannot
compromise the safety and functionality of these devices; a security patch that
crashes a ventilator is worse than the vulnerability it fixes.
B.
Legacy Systems and Underinvestment: Many
Indian government hospitals operate on outdated hospital management systems
that are no longer supported. Upgrading these systems requires budget,
downtime, and technical expertise that are often unavailable. Private
hospitals, while more modern, may still run legacy software in critical
departments like radiology or pathology.
C.
24/7 Operations and the Inability to
Tolerate Downtime: A bank can afford to shut down its
internet banking for a few hours for maintenance. A hospital cannot shut down
its emergency room. The need for continuous, uninterrupted operation makes
routine maintenance, patching, and system upgrades exceptionally difficult.
Security measures that might disrupt clinical workflow—such as a multi-factor
authentication prompt during an emergency—face fierce resistance from clinical
staff.
D.
High-Value Data: Hospital
patient data is a rich trove for criminals. A complete medical record contains
name, address, date of birth, Aadhaar number, insurance details, financial
information, and clinical history. On the dark web, a medical record is worth
significantly more than a stolen credit card number because it can be used for
a wider range of fraud—identity theft, insurance fraud, extortion, and
obtaining prescription drugs.
E.
Complex, Fluid Workforce: A
large hospital employs not only doctors and nurses but also administrative
staff, technicians, interns, visiting consultants, medical students, and
third-party service providers (catering, laundry, security). The workforce is
large, diverse, and transient. Managing identity and access for this constantly
changing population is a monumental challenge.
F.
Balancing Accessibility with
Security: Clinical work requires rapid, frictionless
access to patient data. A doctor in an emergency needs to pull up a patient's
history in seconds. Security controls that slow down this access—complex
passwords, frequent re-authentication—are often bypassed in the interest of
patient care, creating vulnerabilities.
G.
Supply Chain Dependencies: Hospitals
depend on a vast supply chain of pharmaceutical suppliers, equipment vendors,
insurance companies, and IT service providers. A breach at any of these can
cascade into the hospital.
Example:
In 2021, a private multi-specialty hospital in Mumbai
discovered that the MRI scanner in its radiology department had been infected
with malware. The scanner, running on an unsupported Windows 7 operating
system, had been connected to the hospital's network without the knowledge of
the IT department, by the equipment vendor for "remote diagnostics."
The malware had been quietly exfiltrating patient scan data to a server in
Eastern Europe for over six months. The hospital was unaware until a cybersecurity
audit flagged the anomaly.
Quotation:
"The hospital is the hardest environment to
secure. You cannot take a critical care unit offline for a patch. You cannot
ask a surgeon in the middle of an operation to re-authenticate. Security must
work around the mission, not against it." — Dr. Lopa Mudraa Basu, Global
CISO, in a 2023 healthcare security roundtable.
3.
The Cyber Threat Landscape for Hospitals
Indian
hospitals face a spectrum of threats, with ransomware being the most severe.
A.
Ransomware: This
is the dominant threat. The AIIMS attack of 2022 was the most prominent, but it
was not the first or the last. In 2020, a corporate hospital chain in western
India was hit by ransomware; the attackers demanded Bitcoin worth ₹2 crore. In
2021, a COVID-19 designated hospital in Maharashtra had its patient records
encrypted, disrupting vaccination certificate issuance during the peak of the
pandemic. Ransomware groups increasingly target healthcare because hospitals
are more likely to pay: the cost of downtime is measured in patient suffering,
and the pressure to restore operations quickly is immense.
B.
Data Breaches and Theft of Patient
Data: Medical data is a prime target for identity
thieves. In 2023, a diagnostic laboratory chain in Bengaluru suffered a breach
that exposed the pathology reports of over 100,000 patients, including HIV
status and other sensitive health information. The data was found for sale on a
dark web marketplace. The breach was caused by a misconfigured cloud storage
bucket that was accessible without a password.
C.
Phishing and Business Email
Compromise: Hospital staff are overwhelmed,
working long hours, and often lack cybersecurity awareness. Phishing emails
offering COVID-19 guidelines, claiming to be from the Indian Council of Medical
Research, or impersonating the hospital administration are highly effective. A
single click can compromise the entire network. In 2022, the finance department
of a Delhi hospital transferred ₹45 lakh to a fraudster's account after
receiving a spoofed email that appeared to be from the medical director,
instructing payment for a "procurement of emergency ventilators."
D.
Medical Device Hacking: While
less common than ransomware, the potential for medical device hacking is
terrifying. Researchers have demonstrated the ability to remotely alter the
dosage on an infusion pump, disable a pacemaker, or manipulate a patient
monitor. In India, no such attack has been publicly confirmed, but the
vulnerability exists in unpatched, network-connected devices across the
country's hospitals.
E.
DDoS Attacks on Hospital Portals: Distributed
Denial of Service attacks have been used to overwhelm hospital websites and
patient portals, preventing patients from booking appointments or accessing
test results. While not as destructive as ransomware, DDoS can cause
significant disruption and reputational damage.
F.
Insider Threats: The
healthcare employee who accesses celebrity patient records out of curiosity,
the billing clerk who sells patient data to insurance fraudsters, or the
disgruntled technician who deletes critical files—insiders pose a persistent
risk. In 2019, an employee at a prominent Delhi hospital was found to have
accessed the medical records of a film actor and leaked them to a tabloid for
money. The employee was arrested under the IT Act, but the damage to the
hospital's reputation was done.
Case Study:
The AIIMS Ransomware Attack (2022). On 23
November 2022, the AIIMS Delhi hospital information system became inaccessible.
Screens displayed a ransom note. The attackers, believed to be affiliated with
the BlackCat/ALPHV ransomware group, had encrypted critical servers. The
hospital reverted to manual mode. For over two weeks, patient registration,
appointment scheduling, diagnostic reporting, and discharge processes were done
on paper. The impact cascaded: laboratory results were delayed, surgeries
postponed, and patients from across the country who depended on AIIMS for
complex referrals were stranded. The Delhi Police registered an FIR under
Section 66F of the IT Act (cyber terrorism) and Section 385 IPC (extortion).
The investigation revealed that the initial entry point was likely a phishing
email that harvested VPN credentials of a hospital employee. The attackers
moved laterally across the flat, unsegmented network, exfiltrated an estimated
1.3 TB of patient data, and then deployed the ransomware. AIIMS had backups,
but they were on a network-attached storage device that was also encrypted. The
hospital did not pay the ransom. The incident exposed severe gaps: lack of
network segmentation, weak credential management, absence of multi-factor
authentication on VPN access, and a disaster recovery plan that did not account
for encrypted backups. The Ministry of Health and Family Welfare subsequently
issued directives to all central government hospitals mandating cyber security
audits, offline backups, and incident response plans.
Quotation:
"The AIIMS attack was not an IT failure. It was a
patient safety failure. For two weeks, the nation's premier hospital was forced
into the pre-digital era. The lesson is brutal and clear: cyber security in
healthcare is not a support function; it is a core clinical governance
issue." — Dr. Randeep Guleria, former Director, AIIMS Delhi, in a 2023
interview.
4.
Legal and Regulatory Framework for Hospital Cyber Security
Hospitals
in India are subject to a growing and increasingly stringent set of cyber
security obligations.
A. Information
Technology Act, 2000:
i.
Section 43A: A body corporate that
handles sensitive personal data (health data is explicitly included in the SPDI
Rules) and is negligent in implementing reasonable security practices is liable
for damages.
ii.
Section 66: Hacking and unauthorised
access.
iii.
Section 66F: Cyber terrorism. The
AIIMS attack was booked under this section because the hospital is a declared
Critical Information Infrastructure (CII) and the attack disrupted an essential
service, threatening public health and safety.
iv.
Section 72: Breach of confidentiality
by a person with lawful access. An employee who leaks patient data can be
prosecuted.
v.
Section 70B: Mandates incident
reporting to CERT-In.
B. Digital
Personal Data Protection Act, 2023 (DPDP Act):
i.
Health data—information about the physical
or mental health of an individual—is among the most sensitive categories of
personal data. Hospitals that determine the purpose and means of processing
patient data are Data Fiduciaries.
ii.
Consent (Sections 5-6): The hospital
must provide clear notice to the patient and obtain free, informed, and
specific consent for the processing of personal data, including health data.
iii.
Reasonable Security Safeguards (Section
8(5)): The hospital must implement reasonable security safeguards to
prevent a personal data breach. Given the sensitivity of health data, the
standard of care is high. Compliance with ISO 27001, NABH digital health
standards, or the IT (Reasonable Security Practices) Rules is expected.
iv.
Breach Notification (Section
8(6)): In the event of a personal data breach involving patient data, the
hospital must notify the Data Protection Board and each affected patient. The
penalty for failure to notify can be up to ₹200 crore.
v.
Penalties (Schedule): Failure to
implement reasonable security safeguards can attract a penalty of up to ₹250
crore.
C. CERT-In
Directions, 2022:
·
Hospitals that are body corporates are
subject to the mandatory incident reporting (within six hours), 180-day log
retention, and ICT asset register requirements.
D. NCIIPC
Guidelines:
·
Hospitals designated as Critical
Information Infrastructure (such as AIIMS Delhi) must comply with the NCIIPC's
guidelines for CII protection, which mandate specific security controls,
audits, and incident reporting.
E. Ministry
of Health and Family Welfare (MoHFW):
i.
Following the AIIMS attack, the MoHFW
issued a directive to all central government hospitals and institutions
mandating: periodic cyber security audits by CERT-In empanelled auditors;
implementation of offline, immutable backups; network segmentation;
multi-factor authentication; and the development of cyber incident response
plans.
ii.
The Clinical Establishments
(Registration and Regulation) Act, 2010, and its state-level counterparts,
impose a general duty of care on hospitals to maintain patient safety and
confidentiality. Cyber security is increasingly interpreted as part of this
duty.
iii.
The National Accreditation Board for
Hospitals and Healthcare Providers (NABH) standards, while voluntary,
include requirements for information security management, data protection, and
business continuity that are consistent with ISO 27001.
F. Medical
Council of India (MCI) / National Medical Commission (NMC) Code of Ethics:
·
The code requires physicians to maintain
the confidentiality of patient information. A breach caused by a physician's
negligent cybersecurity practices (e.g., accessing patient data on an unsecured
public Wi-Fi network) could constitute professional misconduct.
Quotation:
"A hospital's duty to its patient is not limited
to the quality of the surgery or the accuracy of the diagnosis. It extends to
the security of the data that the hospital collects about the patient. In the
digital age, data protection is part of the Hippocratic Oath." — Justice
B.N. Srikrishna, in a 2023 lecture on data protection and healthcare.
5.
Key Cyber Security Measures for Hospitals
The
security of a hospital must be built on a foundation of layered, resilient
controls, adapted to the clinical environment.
A. Network
Segmentation: This is the most critical
architectural control. The hospital network must be segmented into isolated
zones:
i.
Clinical Zone: Medical devices,
patient monitors, operating room systems.
ii.
IT Zone: Hospital information system,
electronic health records, billing, email.
iii.
Guest Zone: Wi-Fi for patients and
visitors.
iv.
Operational Technology Zone: Building
management systems, HVAC, power.
Traffic between zones is strictly controlled by firewalls. A breach in the
guest Wi-Fi must not reach the clinical zone. The AIIMS attack spread laterally
because the network was flat. Segmentation would have contained it.
B. Medical
Device Security: The hospital must maintain an
accurate inventory of all connected medical devices, including make, model,
operating system, network connection, and patching status. Devices that cannot
be patched must be isolated on a dedicated VLAN with restricted access. Default
passwords on devices must be changed. Vendors must be contractually obligated
to disclose vulnerabilities and provide security updates. Remote access by
vendors must be strictly controlled, time-limited, and monitored.
C. Multi-Factor
Authentication (MFA): MFA must be enforced on all remote
access (VPN), email, and access to critical systems (HIS, EHR). The AIIMS
attack leveraged compromised VPN credentials. MFA would have stopped the
attacker even with the stolen password.
D. Access
Control and Least Privilege: Clinicians, nurses,
administrative staff, and students must have role-based access to only the data
and systems necessary for their work. Access to sensitive patient data (HIV
status, psychiatric records, celebrity patients) must be further restricted and
logged. Accounts must be deactivated immediately upon employee separation.
E. Data
Encryption and Backup: All patient data at rest (on
servers, in databases) and in transit (across the network) must be encrypted.
Backups must follow the 3-2-1 rule, and at least one copy must be entirely
offline (air-gapped) and immutable, so that ransomware cannot reach it. Backups
must be tested regularly. A backup that has never been restored is a theory,
not a protection.
F. Phishing
Protection and Staff Training: Hospital staff must
receive regular, practical cybersecurity awareness training, tailored to the
clinical environment. Training must cover phishing identification, password
hygiene, safe handling of patient data, and reporting procedures. Simulated
phishing exercises should be conducted. A culture where staff feel safe
reporting a click without fear of punishment is essential.
G. Security
Operations Centre (SOC) and Monitoring: Large hospitals and
hospital chains should operate or outsource a 24/7 SOC that monitors network
traffic, analyses logs, and detects anomalies in real time. Smaller hospitals
can pool resources through regional healthcare SOCs.
H. Incident
Response and Business Continuity for Clinical Operations: The
hospital must have a documented and tested cyber incident response plan that
addresses the unique challenges of a clinical environment. The plan must
answer:
i.
How does the emergency department function
if the HIS is down?
ii.
How are laboratory results communicated if
the digital system is unavailable?
iii.
How are critical care patients monitored
if the central monitoring system is compromised?
iv.
The plan must include manual fallback
procedures, paper forms, and clear communication protocols. It must be
rehearsed through regular drills.
I. Physical
Security of IT Assets: Server rooms must be physically
secured with access control and surveillance. Workstations in public areas must
be locked down. The risk of a visitor plugging a malicious USB drive into an
unattended nursing station computer is real.
J. Supply
Chain Risk Management: The hospital must assess the
cyber security posture of critical vendors—HIS providers, medical device
manufacturers, cloud service providers, insurance portals. Contracts must
include security requirements, audit rights, and breach notification obligations.
The compromise of a vendor must not become the compromise of the hospital.
Example:
Following the 2022 AIIMS incident, a large corporate
hospital chain in South India implemented a comprehensive cyber security
overhaul. The network was segmented into clinical, IT, and guest zones. All VPN
access was protected with MFA. An isolated, offline backup system was
established. A dedicated CISO was appointed, reporting directly to the Chief
Operating Officer. The hospital's cyber incident response plan was tested
through a simulated ransomware drill, revealing gaps in communication between
the IT and clinical teams, which were subsequently addressed.
Quotation:
"In a hospital, cybersecurity is not about
protecting computers; it is about protecting patients. Every control must be
evaluated through the lens of patient safety. A security measure that endangers
a patient is a failed security measure." — Dr. Triveni Singh, former SP
Cyber Crime, in a 2023 workshop for hospital administrators.
6.
Data Protection and Patient Privacy Under the DPDP Act
The
DPDP Act has profound implications for hospital data handling:
A.
Health Data as Personal Data: The
Act defines "personal data" broadly. Health data—diagnosis, treatment
history, medication, genetic information—is clearly within its scope. The
hospital is a Data Fiduciary.
B.
Consent for Treatment vs. Consent for
Data Processing: The consent form that a patient
signs for a surgical procedure is not the same as consent under the DPDP Act.
The hospital must provide a separate, clear notice about the data it collects,
the purpose of processing (treatment, billing, legal compliance), and the
patient's rights. This is a significant operational challenge, particularly in
high-volume outpatient departments.
C.
Processing of Children's Data: When
the patient is a child, the hospital must obtain verifiable consent from the
parent or guardian. This applies to pediatric wards, neonatal care, and school
health programmes.
D.
Data Retention and Erasure: The
hospital cannot retain patient data indefinitely. The DPDP Act requires that
data be erased when the purpose is complete, unless retention is required by
law. The Medical Council of India's regulations require the retention of
patient records for a specified period (typically three years from the last
consultation for outpatients, longer for inpatients and medico-legal cases).
The hospital must have a clear data retention and disposal policy.
E.
Data Breach Response: In
the event of a breach of patient data, the hospital must notify the Data
Protection Board and each affected patient. The notification must explain the
nature of the breach, the data affected, and the steps the patient can take to
protect themselves. This is a new and challenging obligation for Indian
hospitals.
Quotation:
"A patient shares her deepest secrets with her
doctor. The DPDP Act ensures that this trust is honoured not just by the
individual physician, but by the entire hospital system. Data protection is the
institutional expression of medical confidentiality." — Dr. Karnika Seth,
Cyber Law Expert, in a 2023 healthcare law seminar.
7.
Emerging Threats and Future Directions
A.
Telemedicine and Remote Patient
Monitoring: The rapid expansion of telemedicine,
accelerated by the COVID-19 pandemic and the Telemedicine Practice Guidelines,
2020, creates new vulnerabilities. Video consultations, remote monitoring
devices, and home-based care generate data that flows outside the hospital's
secure perimeter. Securing these channels is an urgent priority.
B.
AI in Healthcare: AI
is being used for diagnostic imaging, drug discovery, and personalised
treatment plans. AI systems require vast datasets to train, and these datasets
are attractive targets. Moreover, AI models themselves can be
attacked—adversarial inputs can cause a diagnostic AI to miss a tumour.
Securing the AI pipeline is a new frontier.
C.
Medical Device Regulation: The
Central Drugs Standard Control Organisation (CDSCO) is developing regulations
for medical device cybersecurity, requiring manufacturers to build security
into devices from the design stage. This is a critical long-term measure.
D.
National Digital Health Mission
(NDHM) / Ayushman Bharat Digital Mission (ABDM): The
ABDM aims to create a national digital health ecosystem, with unique health
IDs, electronic health records, and a health data exchange. This massive
integration of health data across public and private providers will create
unprecedented cybersecurity challenges. A breach in the ABDM infrastructure
could expose the health data of hundreds of millions of citizens. The
cybersecurity of the ABDM must be a national priority.
Conclusion
The
hospital of the twenty-first century is a marvel of technology. It can diagnose
a disease from a genome sequence, monitor a patient's vitals from a thousand
miles away, and share a CT scan with a specialist across the globe in seconds.
But this technological marvel is built on a fragile digital foundation. The
AIIMS ransomware attack was not an anomaly; it was a harbinger. It exposed the
reality that India's healthcare sector, for all its clinical excellence, has
not invested commensurately in the cyber security that its digital
transformation demands. The cost of this neglect is not counted in rupees
alone. It is counted in postponed surgeries, delayed diagnoses, breached
confidentiality, and the slow erosion of the trust that is the bedrock of the
doctor-patient relationship.
The
path forward is clear. It requires leadership from the Ministry of Health, the
state governments, and hospital boards. It requires investment—not merely in
technology, but in people: training clinicians and administrators, hiring and
retaining skilled cyber security professionals in a competitive market, and
building a culture of security that permeates every ward and every department.
It requires regulation with teeth: mandatory audits, enforced standards, and
accountability for breaches. Most of all, it requires a fundamental recognition
that cyber security is not a support service for healthcare; it is an integral
part of patient safety, as essential as hand hygiene and surgical sterility. A
hospital that neglects its cyber defences is a hospital that has failed its
patients.
Quotation:
"The Hippocratic Oath says: 'First, do no harm.'
In the digital age, that oath extends to the data that surrounds the patient. A
hospital that allows a cyber attack to compromise patient care has done harm.
The duty to secure the digital hospital is as sacred as the duty to heal."
— Dr. Devi Shetty, Chairman, Narayana Health, in a 2024 address on the future
of healthcare.
Chapter References
1.
Information Technology Act, 2000, Sections
43A, 66, 66F, 70B, 72.
2.
Digital Personal Data Protection Act,
2023, Sections 5, 6, 8, 9, 12, Schedule.
3.
CERT-In, Directions on Information
Security Practices, Procedures, Prevention and Response to Cyber Threats, April
2022.
4.
CERT-In, Advisory on Ransomware
Targeting Healthcare Sector, December 2022.
5.
Ministry of Health and Family
Welfare, Directive on Cyber Security for Central Government Hospitals and
AIIMS, January 2023.
6.
NCIIPC, Guidelines for Protection of
Critical Information Infrastructure, 2021.
7.
National Accreditation Board for Hospitals
and Healthcare Providers (NABH), Digital Health Standards, 2022.
8.
Clinical Establishments (Registration and
Regulation) Act, 2010.
9.
Medical Council of India, Code of
Ethics Regulations, 2002 (as amended).
10. National
Medical Commission Act, 2019.
11. Telemedicine
Practice Guidelines, 2020 (MoHFW).
12. Ayushman
Bharat Digital Mission, National Digital Health Blueprint, 2022.
13. Delhi
Police, Investigation Report on AIIMS Ransomware Attack, 2023.
14. NIST, HIPAA
Security Rule Crosswalk to NIST Cybersecurity Framework.
15. ISO 27799:2016, Health Informatics — Information Security Management in Health using ISO/IEC 27002.