On this page · 14 sections
- The eligibility rule that filters the market
- Gate 1: where the vendor actually sits on the ABDM ladder
- Gate 2: FHIR R4 as a data model, not an export format
- Gate 3: DPDP readiness with a real date attached
- Gate 4: whether the build is a medical device
- Gate 5: claims, because that is where the payback sits
- Gate 6: accreditation scoring, not just accreditation
- Gate 7: teleconsultation scope
- India-specific considerations
- What eCorpIT builds in this space
- A short scoring sheet
- FAQ
- How eCorpIT can help
- References
Summary. NABH will not certify a hospital information system or EMR product unless the vendor holds a valid ABDM M3 compliance certificate and has at least 3 deployments in operational hospitals in India. That eligibility rule, published on the NABH programme page, removes most of the market before anyone quotes a price. Two other dated constraints sit alongside it. The Digital Personal Data Protection Rules were notified on 14 November 2025 with an eighteen-month phased compliance period, and the maximum penalty for failing to keep reasonable security safeguards is ₹250 crore. NABH's 6th edition hospital accreditation standards took effect on 1 January 2025 and raised the weight of digital records. Under the Digital Health Incentive Scheme, a hospital earns ₹500 per claim or 10% of the claim amount, whichever is lower, for each insurance claim routed through NHCX. Choose a healthcare software development company against those four numbers, not against a portfolio deck.
The eligibility rule that filters the market
Most vendor comparisons in Indian healthcare start with team size and end with hourly rates. The regulator has already written a harder filter.
NABH runs a certification programme for HIS and EMR products, separate from hospital accreditation. Its published eligibility line is short: any HIS/EMR product with a minimum of three deployments in operational hospitals in India, along with a valid ABDM M3 compliance certificate, is eligible to apply. The certification runs for two years. NABH describes it as a programme that "provides a quality benchmark for solution providers" (NABH).
Read that as a buyer and it does two useful things. It sets a floor on real deployment experience, and it forces the vendor through the full Ayushman Bharat Digital Mission integration ladder, because M3 cannot be reached without M1 and M2 first.
The published certification fees are third-party costs your vendor carries, not yours, but they tell you how seriously a vendor treats the programme.
| NABH HIS/EMR certification level | Fee for 2 years (HIS or EMR) | Fee for 2 years (both HIS and EMR) |
|---|---|---|
| Basic | ₹50,000 | ₹75,000 |
| Advanced | ₹1,00,000 | ₹1,50,000 |
| GST | 18% extra | 18% extra |
| Validity | 2 years | 2 years |
| Prerequisite | ABDM M3 certificate | ABDM M3 certificate |
The current standard document is version 12.1, dated 14 September 2024 (NABH standard PDF). A draft 2nd edition was circulated in September 2025 (draft PDF), so a vendor certified against 12.1 will face a re-read of its own product within the next cycle. Ask what they have budgeted for that.
Gate 1: where the vendor actually sits on the ABDM ladder
ABDM certifies health IT systems in sequential milestones, and the sequence matters more than the labels. The Press Information Bureau, describing an NHA and IRDAI workshop, states plainly that M1 integration "enables a software to create and verify Ayushman Bharat Health Account (ABHA)" and that M1 is an essential step to complete NHCX integration (PIB).
The ABDM sandbox developer forum publishes reference recordings of M1, M2 and M3 flows implemented on a live HMIS, contributed by an integrating partner (ABDM developer forum). Those recordings are the cheapest due-diligence artefact available to you: watch them, then ask the vendor to demonstrate the same three flows on their own build.
| ABDM milestone | What the software does | What it unlocks for the hospital |
|---|---|---|
| M1 | Creates and verifies ABHA, links patient identity | NHCX onboarding becomes possible |
| M2 | Acts as a Health Information Provider, shares records on consent | Records discoverable across the network |
| M3 | Acts as a Health Information User, fetches external records | NABH HIS/EMR certification eligibility |
| NHCX | Submits claims to the health claims exchange | Digital Health Incentive Scheme payouts |
A vendor at M1 is not a vendor at M3. The gap between them is consent-artefact handling and encrypted FHIR bundle exchange, and it is months of work, not a configuration flag.
Gate 2: FHIR R4 as a data model, not an export format
Plenty of Indian HIS products claim FHIR support and mean a nightly export job. ABDM record exchange is built on HL7 FHIR R4: the National Resource Centre for EHR Standards publishes the FHIR Implementation Guide for ABDM, currently version 6.5.0, which defines the minimum conformance requirements for exchanging health records in the Indian context (NRCeS). Records stay at the originating facility and move only against explicit, time-bound, revocable patient consent.
The engineering consequence is specific. If clinical data lives in a bespoke relational schema and FHIR is a translation layer bolted on at the edge, every new care-context type becomes a mapping project. Ask to see the resource-level model. Ask which FHIR resources are first-class in the database and which are synthesised on request. The answer predicts your change costs for the next five years far better than the team's headcount does.
The real cost is usually the mapping, not the code.
Gate 3: DPDP readiness with a real date attached
The Government of India notified the Digital Personal Data Protection Rules, 2025 on 14 November 2025, giving full effect to the DPDP Act, 2023 (PIB explainer). The consultation drew 6,915 inputs. The Rules set an eighteen-month phased compliance period, which places the outer deadline in mid-2027 (India Briefing).
The penalty schedule is where healthcare buyers should focus, because the categories are commonly mixed up in vendor decks.
| Failure under the DPDP Act, 2023 | Maximum penalty | Who it lands on |
|---|---|---|
| Failure to maintain reasonable security safeguards | ₹250 crore | Data Fiduciary |
| Not notifying the Board or affected individuals of a breach | ₹200 crore | Data Fiduciary |
| Breach of obligations relating to children's data | ₹200 crore | Data Fiduciary |
| Any other violation of the Act or Rules | ₹50 crore | Data Fiduciary |
| Appeal route against Board decisions | TDSAT | Data Fiduciary |
Three operational requirements from the Rules translate directly into software work. Data Fiduciaries must respond to access, correction, update and erasure requests within a maximum of ninety days. Breach notification must reach affected individuals in plain language, covering what happened, the likely impact and the remedial steps. Consent Managers must be companies incorporated in India. The Rules also carve out a healthcare exception: verifiable parental consent for a child's data is required unless the processing relates to essential services such as healthcare, education or real-time safety.
A hospital remains the Data Fiduciary. The software vendor is usually the Data Processor. No contract moves the ₹250 crore exposure off the hospital, so the useful question is not whether the vendor claims compliance but whether the product gives you the evidence trail to demonstrate yours.
Gate 4: whether the build is a medical device
This is the gate that surprises Indian buyers most often. Software that performs a medical purpose on its own, without being part of a hardware device, can be regulated as Software as a Medical Device under the Medical Devices Rules, 2017, administered by CDSCO. Standalone clinical decision support, AI image analysis and software that interprets patient data are the usual candidates (Morulaa).
CDSCO has issued draft guidance on medical device software introducing a risk-based Class A to Class D classification aligned with international practice, driven by the significance of the information the software provides and the seriousness of the clinical situation it addresses (Cyril Amarchand Mangaldas). It is draft guidance, not settled law, which is exactly why the scoping conversation belongs at the start of a build rather than at user acceptance testing.
Get this wrong and a feature you treated as a dashboard becomes a licensable device midway through delivery. Our note on clinical AI deployment under CDSCO and DPDP sets out how that scoping call is made in practice.
Gate 5: claims, because that is where the payback sits
NHCX is the digital health claims platform built by the National Health Authority with IRDAI. IRDAI issued a circular in June 2023 advising all insurers and providers to onboard (PIB). By the November 2023 accelerator workshop, 12 insurance companies had completed NHCX integration, including Aditya Birla Health Insurance, Star Health, Bajaj Allianz, HDFC Ergo, ICICI Lombard and Tata AIG.
The commercial hook is the Digital Health Incentive Scheme, running since January 2023: for every insurance claim transaction through NHCX, a hospital receives ₹500 per claim or 10% of the claim amount, whichever is lower (NHA DHIS). At 2,000 claims a month that is a measurable line item, and it is the clearest way to put an ABDM integration programme on a payback footing rather than a compliance footing.
Gate 6: accreditation scoring, not just accreditation
NABH's 6th edition hospital accreditation standards took effect on 1 January 2025, with all new accreditation applications assessed under them from that date; already-accredited hospitals continue under the 5th edition until their next assessment. The 6th edition gives more weight to digital health technology and electronic medical records (Digital Health News).
Note the wording carefully, because vendor marketing routinely overstates it. Digital records are weighted in scoring; they are not an absolute pass or fail. A vendor telling you the 6th edition "mandates" a particular product is selling, not advising. Our detailed walkthrough of ABDM HIP integration for hospitals covers the sequencing between accreditation cycles and integration milestones.
Gate 7: teleconsultation scope
If the brief includes teleconsultation, the governing document is the Telemedicine Practice Guidelines issued in March 2020 by the Board of Governors in supersession of the Medical Council of India, now under the National Medical Commission. Only Registered Medical Practitioners enrolled with the NMC or a state medical council may provide teleconsultations, and consultation may be by video, audio or text depending on case suitability (International Bar Association).
Product decisions follow from that: practitioner-registry verification at onboarding, mode selection recorded per consultation, and prescription handling that matches the mode used. A telemedicine app development company that cannot describe those three controls has not read the guidelines.
India-specific considerations
Three patterns repeat across Indian hospital groups and diagnostics chains.
The first is registry sequencing. Facility registration in the Health Facility Registry produces the HFR ID that everything else hangs from, and clinician records belong in the Health Professional Registry. Starting integration work before those registrations are clean creates rework.
The second is the empanelment driver. Digital readiness matters commercially because state and central insurance empanelment paths, including AB-PMJAY, run through the same digital rails as NHCX claims. That is usually a stronger internal business case than accreditation scoring.
The third is language and terminology. FHIR R4 exchange assumes coded clinical terminology. Free-text diagnosis fields in a legacy HIS will pass a demo and fail an interoperability audit.
What eCorpIT builds in this space
eCorpIT is a Gurugram-based technology company founded in 2021, CMMI Level 5 assessed, MSME certified and ISO 27001:2022 certified, working with senior-led engineering teams across web, mobile and data platforms. In healthcare we build hospital and clinic systems, ABDM integration layers, FHIR R4 data models, patient-facing applications, and the consent and audit plumbing that sits under both.
We design applications aligned with DPDP requirements and aligned with ABDM implementation guidance. We do not describe ourselves as DPDP compliant, because compliance is a property of your organisation and its processing, not of a codebase.
Our delivery shape is a short paid discovery that produces a milestone map against ABDM M1 to M3 and a regulatory scoping call on whether any component is likely to fall under the Medical Devices Rules, 2017, followed by either a fixed-scope milestone build or a dedicated senior team on a rolling engagement. Which one fits depends on how much of the target state is already decided when we start. Related reading: healthcare AI deployment under CDSCO and DPDP and our engineering notes on the DPDP Act for Indian product teams.
A short scoring sheet
Run every shortlisted healthcare software development company through these seven, in this order, before you compare commercials.
- Highest ABDM milestone actually certified, with evidence.
- NABH HIS/EMR certification status, or a dated plan to reach the three-deployment and M3 eligibility bar.
- FHIR R4 as a native data model, demonstrated at resource level.
- DPDP evidence trail: ninety-day request handling, breach notification content, audit logs.
- Medical Devices Rules scoping opinion for every analytic or decision-support feature.
- NHCX claim path and the DHIS payback arithmetic on your claim volume.
- Telemedicine controls, if teleconsultation is in scope.
A vendor who answers all seven with specifics is a shorter list than you expect.
FAQ
How eCorpIT can help
eCorpIT builds hospital, clinic and diagnostics software with ABDM integration, FHIR R4 data models and the consent and audit layers that regulators and accreditors ask to see. We start with a paid discovery that produces a milestone map and a Medical Devices Rules scoping opinion, so the regulatory questions are answered before code is written rather than during acceptance testing. Engagements run either as fixed-scope milestone builds or as a dedicated senior team, depending on how much of the target state is settled. Tell us what you are building at /contact-us/ and we will tell you which milestone you actually need first.
References
Last updated: 18 August 2026.