Every Indian household accumulates a medical archive whether it intends to or not. A discharge summary from a 2019 appendectomy, three years of your father’s lipid panels, an MRI on a CD nobody owns a drive for, and four hundred photographs of prescriptions buried in a phone gallery between wedding pictures. It works until the night it has to work: an admission at 2 a.m., a cashless request the TPA is querying, a specialist asking what your mother’s creatinine was doing eighteen months ago.
This is a records-management and privacy guide, not medical advice. We do not interpret results or suggest treatments — ask a registered practitioner. What we can do is make sure that practitioner has the full picture in under a minute.
The three places your records already live in India
ABHA and the ABDM network
The Ayushman Bharat Digital Mission runs the national health data plumbing. An ABHA number is your identifier on it; hospitals and labs registered as Health Information Providers can link records to it, and anyone wanting to pull them becomes a Health Information User who must ask your consent first.
Two design decisions are widely misunderstood. ABDM is federated: its Health Data Management Policy requires electronic medical records to stay stored at the facility that created them, not pooled into one central government database. What moves across the network is a pointer and, on your consent, a copy. And participation is voluntary — the policy states no individual may be denied access to a health facility merely for not having created an ABHA.
So ABHA is an excellent index and a poor archive. If a hospital closes, leaves the network, or never digitised your 2017 admission, it has nothing to show.
DigiLocker as a health locker
DigiLocker has worked as a Personal Health Records app since the government extended it in 2022. You can link an ABHA account, pull records from ABDM-registered hospitals and labs, upload records you already hold, and share selected records with ABDM-registered professionals. Vaccination records, prescriptions, lab reports and discharge summaries are all in scope. It does one thing private cloud storage cannot: documents issued into it by an authorised issuer are the authentic article, not a photograph of one. Treat it as a second location, not your only one.
Hospital and diagnostic-lab portals
Large hospital chains and pathology labs almost all issue reports as downloadable PDFs through a patient portal or SMS link. Download the PDF the day it lands: retention is set by each provider’s own policy and varies from months to a few years, and no national rule guarantees a lab keeps your 2021 report retrievable in 2029. Take the PDF rather than screenshotting the page — it carries reference ranges, accreditation details, the pathologist’s name and the report number, all of which an insurer or consultant looks for.
A folder tree you can build this weekend
Create one top-level folder, Family-Health, with a subfolder per person. Inside each, use exactly six subfolders:
- 01-Identity-and-Insurance — policies, health cards, ABHA number, TPA details
- 02-Reports — every lab, imaging and pathology report
- 03-Prescriptions — prescriptions and doctor’s notes
- 04-Admissions — discharge summaries, operative notes, final bills
- 05-Claims — one subfolder per claim
- 06-Baseline — the one-page summary below, vaccination record, device cards
Name files so the sort order does the work
Use one convention and never deviate: YYYY-MM-DD_Person_DocType_Provider_Detail.pdf. So 2026-03-14_Asha_Report_Metropolis_LipidProfile.pdf, or 2025-11-02_Ramesh_Discharge_ApolloChennai_Angioplasty.pdf.
Dates first in ISO order means every folder sorts chronologically in every file manager, with no metadata and no app dependency. Person second means a flat search on one name pulls that person’s whole history. Use the date on the document, not the date you scanned it. Never use spaces or Indian date order — 14-03-2026 sorts catastrophically. Keep the tree in one place; a system split across two cloud accounts and a laptop desktop is not a system.
What to scan, and what to leave in the drawer
Do not scan everything. Scan discharge summaries, operative notes, imaging reports (the written report, not the films), lab reports as far back as you have them, chronic-medication prescriptions, immunisation records, insurance policies with the schedule of benefits, and anything documenting an allergy or adverse drug reaction. Skip till receipts unless they belong to an open claim, skip appointment slips, skip duplicates.
Use a document scanner app rather than the camera — Adobe Scan, Microsoft Lens, or the scan function inside most phones’ notes and files apps. They deskew, flatten shadows, and output a multi-page PDF with searchable text, turning a five-page discharge summary into one findable file. Set output to PDF, not JPEG.
What to keep permanently, and what expires
Keeping everything forever is expensive in attention, not storage. Some documents never lose value; others are noise within a year.
| Document type | Why it matters later | How long to keep it | Where it belongs |
|---|---|---|---|
| Discharge summary, operative notes | Every future doctor and insurer asks for it | Permanently | Store plus offline backup |
| Imaging reports | Comparison against a prior scan is the diagnostic value | Permanently | Store |
| Allergy and adverse drug reaction records | Safety-critical; what an emergency team needs first | Permanently | Store plus printed card |
| Immunisation records | School and college admission, travel, employer onboarding | Permanently | DigiLocker plus store |
| Chronic panels (thyroid, HbA1c, lipids, renal) | The trend over years is the point, not one reading | Permanently while the condition lasts | Store |
| One-off tests for a resolved illness | Rarely revisited once the episode closed | 2 to 3 years | Store |
| Hospital final bill, itemised breakup | Claim substantiation, later disputes, top-up claims | Until settled, then with that year’s tax records | Claims folder |
| Insurance policy schedule and terms | Defines cover; proves continuity on portability | Every year held, plus renewals | Store |
| Implant, pacemaker or device cards | Model and serial number needed for MRI safety, recalls | Permanently | Store plus wallet copy |
Prune the expiring categories one Sunday each January. Ten minutes a year keeps the archive searchable.
Three people, three different problems
You and your spouse. Each should hold the other’s records. Do not build the household’s system inside one person’s account.
Children. The immunisation record and growth chart get asked for repeatedly for two decades. India’s data protection framework requires verifiable parental consent to process a child’s personal data, and the same logic should govern your conduct: a child’s medical history is not yours to forward to family groups or hand to an app. Build the folder knowing it transfers to them at eighteen.
Elderly parents. Here the effort concentrates and records are most often paper. Build a one-page baseline summary for each parent — current diagnoses, every medication with dose, known allergies, treating doctors with numbers, blood group, policy number and TPA helpline, ABHA number — and keep a printed copy in the wallet and one inside a kitchen cupboard door. Involve them in the setup; managing a parent’s records without telling them leaves them unable to answer a doctor when you are not in the room.
Who you are actually handing this data to
The Digital Personal Data Protection Act, 2023 requires consent to be free, specific, informed, unconditional and unambiguous, and withdrawable at any time — with withdrawal as easy as giving consent was. It obliges data fiduciaries to apply reasonable security safeguards, notify you and the Data Protection Board of a breach, and erase your data once the purpose is served or consent is withdrawn, unless a law requires retention. It gives you rights of access, correction and erasure. Notably it treats personal data as one broad category rather than carving out a separate tier for health data. The DPDP Rules, 2025 were notified on 14 November 2025, operationalising consent notices, consent managers and breach handling on a phased runway.
What ABDM consent grants, and how to pull it back
When a hospital, insurer or app asks for records over ABDM, you are not granting a permanent read. The request is scoped: it names the requester, the purpose, the data categories, the date range, and a validity period. Approving it lets that entity fetch records matching that scope, for that window.
You revoke it in the same PHR app where you granted it — the ABHA app or DigiLocker — under the consent or approvals section. Revocation stops future fetches. It does not un-fetch what was already pulled, which is why the scope of the original request matters far more than the ability to revoke. Read the date range before approving; a request for your lifetime history to settle one claim is one to decline and query. Review active consents twice a year and revoke grants for apps you no longer use.
Why the photo gallery is the wrong home
Prescriptions in your camera roll are a privacy problem, not a tidiness one. Gallery photos sync to an account already logged into a dozen other apps, get indexed by face and text recognition, and get swept into shared albums and auto-generated memories. Every photo-editing, collage or cleanup app you granted photo permission can read them — and photo access is among the most casually granted permissions on any phone. A prescription carries a name, an age, a doctor, a diagnosis by implication, often a phone number. Move medical documents into a dedicated store and delete the camera-roll originals.
Encryption at rest, without the jargon
Encrypted at rest means the file is unreadable on its disk without a key. What matters is who holds that key. Mainstream cloud drives hold it themselves, so the provider — and anyone who compels or breaches it — can read your files. End-to-end encrypted storage means only you hold it.
Either use an end-to-end encrypted provider for the Family-Health folder, or keep your existing cloud drive and put the folder inside a container encrypted on your own machine first; Cryptomator and VeraCrypt both do this, free and open source. Either way add an offline backup — an encrypted external drive updated twice a year, stored outside the house it backs up. Cloud accounts get locked out, and a lockout during an admission is exactly when you need the file. Protect the account with a unique password from a password manager and two-factor authentication via an authenticator app, not SMS.
If you cannot unlock your own phone
The failure nobody plans for: the person who built the archive is the one in the ICU, and everything sits behind a biometric lock. Solve it deliberately, without emailing anyone a password.
- The paper layer. The one-page baseline summary in the wallet, plus the phone’s built-in medical ID — both iPhone and Android expose emergency information and contacts from the lock screen without unlocking. Fill it in for everyone. This is the layer that actually gets used at 2 a.m.
- Password manager emergency access. Most reputable password managers offer a trusted-contact feature: you nominate someone, they request access, and after a waiting period you set, access opens unless you decline first. Time-delayed, revocable, no password shared in plain text. Set it up and tell them it exists.
- The platform layer. Apple’s Legacy Contact and Google’s Inactive Account Manager let you designate who can reach account data under defined conditions.
There is a statutory hook too: the DPDP Act, 2023 gives you the right to nominate another individual to exercise your rights under the Act on your death or incapacity. That is a right over data held by companies, not a key to your phone — but name the same person you trusted with emergency access.
Building the file your insurer will ask for
Claims are delayed on documentation far more often than on medical grounds. IRDAI’s policyholder guidance describes the reimbursement route as submitting the claim form, discharge summary, prescriptions and bills, after informing the insurer as the policy requires. In practice, insurers and TPAs ask for a consistent bundle.
The recurring items: signed claim form; policy copy or health card; photo ID; discharge summary; the itemised final bill with payment receipts (not the estimate, not a summary bill); pharmacy bills matched to in-hospital prescriptions; diagnostic reports with receipts; the doctor’s advice for admission; and bank details with a cancelled cheque. For an accident, a police report or MLC is usually requested; for planned cashless treatment, pre-authorisation goes in before admission.
Two habits do most of the work. Ask the billing desk for the itemised breakup at discharge rather than chasing it a month later, and scan every original before you courier it — a submitted original that goes missing is yours to reconstruct. Keep one folder per claim under 05-Claims with everything sent and every response received, including query letters; if a claim is disputed, that folder is your case. Requirements vary by insurer, so check your policy wording.
Questions families ask us
Is an ABHA number compulsory?
No. ABDM’s Health Data Management Policy states participation is voluntary and that no one may be denied access to a health facility for not having an ABHA.
Does creating an ABHA upload my old records to the government?
No. ABDM is federated by design; the policy requires records to stay at the facility that created them. Linking makes existing records discoverable and shareable with your consent. It does not pool your history centrally, nor digitise what was never digitised.
Can I withdraw consent after records have already been pulled?
You can withdraw going forward, and the DPDP Act, 2023 requires withdrawal to be as easy as consent was, with erasure once the purpose is served, unless a law requires retention. What withdrawal cannot do is recall a copy already delivered — so scope the request tightly at approval time.
What about a parent who does not use a smartphone?
Hold their archive in your encrypted store with their agreement, and keep their printed one-page summary current in their wallet. If they want an ABHA, help them create it themselves and make sure they know what a genuine consent request looks like — people who do not are easiest to defraud with a fake one.
Sources we checked
- Ayushman Bharat Digital Mission
- DigiLocker and the PIB release on DigiLocker health records and ABHA linking
- The Digital Personal Data Protection Act, 2023 (MeitY, full text)
- DPDP Rules, 2025 notified — Government of India briefing
- IRDAI policyholder guidance on health insurance claims
How we research and correct our guides is set out in our editorial standards, and you can read about the team on our about page. Rules and features change; verify anything time-sensitive against the sources above.

