Home / Insights / Compliant by design

Compliance shouldn't be a document
you produce at audit time.

ABDM, DPDP, NMC and GST are not a report your team assembles before an assessment. They are rules that belong in the data model — enforced the moment a record is written.

Ospia Insights · Compliance

Most hospital systems treat compliance as a layer added on top: a module, a report, a pre-audit scramble where someone reconciles what actually happened against what should have. It works, in the sense that a fire drill works. But it means the hospital is only ever compliant in retrospect.

In India, that gap has become expensive. Compliance here is structural, not optional, and four requirements touch nearly every record a hospital creates.

The four that touch every record

ABDM defines how health data is identified and moves between systems. DPDP defines how personal data is protected, consented and retained. NMC requirements shape what a medical record must contain and how it's attributed. And GST touches every bill you raise. Each is usually bolted on per project — and each bolt-on is a place where reality and the record can drift apart.

The system must enforce these continuously — not produce a document at audit time.

What "by design" actually changes

Compliant-by-design means the rule is part of how the record is written, not a check that runs afterward. Consent state gates access before data is read. A bill cannot be finalised in a GST-invalid state. An entry that NMC requires to be attributed to a named clinician cannot be saved anonymously. The system doesn't warn you later — it refuses to create non-compliant data in the first place.

The consequence is quiet but large: "can we prove it?" stops being a project and becomes a query. Because every action publishes an event and every event is kept permanently, "show me the consent that was in force when this data was accessed on that date" is answerable in seconds, months later — not reconstructed from memory and paper.

Why this matters more as AI enters operations

The moment software starts acting — an agent submitting a claim, flagging a record, routing data — compliance-as-afterthought stops being tenable. Every AI action has to run through the same permission-checked, consent-gated, audited path a person would. That's only possible if compliance lives in the data model rather than in a report. Governance and compliance are the same discipline seen from two angles, and both have to be foundational.

Build the regulation into how data is written, and the answer to "are we audit-ready?" is always, on any day, yes.

See it on your own numbers. An executive demonstration takes forty-five minutes, with the architecture open, using synthetic data shaped like yours. Write to hello@ospia.in.

Primary sources

This resource is grounded in the following official standards, laws and regulator guidance. Links were checked on 22 August 2026.

Questions buyers ask

Straight answers

What does "compliant by design" actually mean?

The regulation is built into the data model and enforced when data is written — not added per project or checked before an audit. The system refuses to record data in a non-compliant state, so you stay audit-ready continuously.

Which regulations should Indian hospital software enforce?

At minimum ABDM (identity and data exchange), DPDP (personal-data protection and consent), NMC requirements shaping the medical record, and GST on every bill. Ospia enforces all four at write-time.

How is this different from a compliance module?

A module is software staff operate and can bypass, usually reconciled after the fact. By-design makes the rule part of how the record is written, so non-compliant data can't be created — and proof is a query, not a fire drill.

Related reading

Keep going

Revenue

The revenue your hospital is quietly losing — and how to stop it.

Uncaptured charges and rejected claims are a preventable leak.

Read the article →
Category

You don't need a new HMS. You need to stop buying HMS.

The three taxes baked into how hospitals buy software.

Read the article →

Next step

See compliance enforced, not asserted

Forty-five minutes, on your numbers, with the architecture open. Synthetic data, zero real patients.

Book your hospital simulation More insights

synthetic data · zero real patients
self-hosted or managed cloud
one database per hospital