A common question for Indian healthtech founders: does HIPAA apply to us at all? The answer is not about where you are based. It is about whose health data you handle.
TL;DR
HIPAA is a US law that follows US health data, not a rule about company location. An Indian health startup needs HIPAA if it handles US protected health information or sells to US healthcare customers who require it. If you serve only Indian users, HIPAA does not apply, DPDP does.
Many Indian healthtechs targeting the US market need both: HIPAA for US buyers and DPDP for Indian users. Because both rest on the same security core, you can satisfy each without running two separate programs.
On this page
The short answer
HIPAA is a United States law, and it applies based on the data you handle, not the country you operate from. So being an Indian company does not automatically put you under HIPAA, nor does it exempt you. If your startup handles the protected health information of US individuals, or sells to US healthcare organisations that must comply, HIPAA applies to you. If you serve only users in India, HIPAA does not apply, but India’s own DPDP Act does.
The deciding question
Cut through the confusion with a single question about your customers and data.
It really is that clean. HIPAA is triggered by contact with US health data or US healthcare buyers, not by your registration address. Answer the question honestly and you know whether HIPAA is in scope.
When HIPAA applies to an Indian startup
In practice, HIPAA becomes relevant to an Indian healthtech in a few common situations.
| Situation | Does HIPAA apply? |
|---|---|
| Selling software to US hospitals or clinics | Yes, typically as a business associate |
| Processing US patients’ health data | Yes, you handle US PHI |
| Building for US healthcare customers | Yes, they will require it of you |
| Serving only Indian users | No, DPDP applies instead |
HIPAA and DPDP together
For Indian healthtechs selling into the US, the realistic picture is not HIPAA instead of DPDP, but both. DPDP governs the personal data of your Indian users, HIPAA governs the US health data you handle for US customers. They differ on consent, rights, and paperwork, but they share the same security foundation, encryption, access control, and logging, so meeting both is far less work than it sounds.
The lean-team path for Indian healthtech
Whether you need HIPAA alone, DPDP alone, or both, the underlying work is the same security controls and the evidence that proves them. For an Indian startup targeting global customers, doing that once and mapping it everywhere is what keeps compliance from becoming a barrier to expansion.
Sell to the US and serve India, from one platform.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Meet HIPAA for US buyers and DPDP for Indian users from one security core, with shared evidence. No security team required.
Frequently asked questions
Do Indian health startups need HIPAA?
Only if they handle US protected health information or sell to US healthcare customers who require it. HIPAA follows US health data, not company location. An Indian startup serving only Indian users does not need HIPAA, but must comply with India’s DPDP Act.
Does HIPAA apply to companies outside the US?
Yes, when they handle US PHI or act as a business associate to a US covered entity. HIPAA is triggered by contact with US health data, so a non-US company serving US healthcare customers must comply regardless of where it is based.
How does an Indian startup become subject to HIPAA?
Most commonly through US customers. When a US covered entity uses your product to handle PHI, you become its business associate, must meet HIPAA’s safeguards, and sign a BAA. Processing US patients’ health data directly also brings you into scope.
If I serve only Indian users, do I need HIPAA?
No. HIPAA is a US law tied to US health data. If your users are only in India, HIPAA does not apply, but the DPDP Act does, and it sets its own requirements for consent, rights, and protection of personal data.
Do Indian healthtechs need both HIPAA and DPDP?
Often yes, if they sell to the US while serving Indian users. DPDP covers Indian users’ personal data and HIPAA covers US health data. The two share the same security core, so meeting both is far less work than running two separate programs.
Is complying with DPDP enough for US customers?
No. DPDP and HIPAA are different regimes. Strong DPDP compliance builds much of the shared security foundation, but US healthcare customers will still require HIPAA compliance and a signed BAA specifically. You need to meet HIPAA’s requirements too.

