ABDM and ABHA for private clinics: what it means in practice
2026-09-22 · MedSlay
India's Ayushman Bharat Digital Mission (ABDM) is building a national digital health ecosystem: a health account for every patient, registries of verified doctors and facilities, and consent-based exchange of records between them. For a private clinic the practical question is narrower — what do you actually have to do, what do you get for it, and what can wait?
This is an orientation for practising doctors, not regulatory advice. ABDM is actively evolving; check the current official documentation for the requirements that apply to you.
The pieces, in plain terms
- ABHA number. A 14-digit health account the patient creates, using Aadhaar or a mobile number. It identifies them across facilities without your clinic holding their identity documents.
- ABHA address. A handle that reads like an email (name@abdm). Records are linked and shared through it, and it is separate from the number.
- Health Professional Registry (HPR). The national register of verified practitioners — your qualifications and registration on a record others can verify.
- Health Facility Registry (HFR). The same for clinics and hospitals, including single-doctor practices.
- Consent manager. The mechanism through which a patient approves, time-limits and revokes access to their records. Nothing moves without them saying yes.
Two roles decide what your software must be able to do. A Health Information Provider is a facility whose system can publish records — prescriptions, reports, discharge summaries — against a patient's ABHA. A Health Information User is one that can request records from elsewhere, with consent. Most clinics want to be both, eventually.
What a clinic actually does
- Register yourself on the HPR and your clinic on the HFR. This is the foundation for everything else, and it is worth doing early — it is your verified identity in the ecosystem.
- Offer ABHA creation or verification at the front desk. Most patients either already have one or can create one in a couple of minutes.
- Link records to the ABHA as you create them. This is where software decides whether the scheme is useful or a burden: linking should be part of finishing a consultation, not a second round of data entry someone does later.
- Handle consent properly. Requests for a patient's history from elsewhere go through the consent manager, and your staff should understand that a refusal is normal, final, and not a problem to work around.
What you get out of it
- A real history at the first visit. With consent, a new patient's past prescriptions and reports can reach you instead of being reconstructed from memory and a plastic bag of papers.
- Less repeated paperwork. Identity and demographics arrive with the ABHA rather than being re-typed and re-spelled at every visit.
- Faster OPD registration. Scan-and-share flows let a patient share their ABHA at the desk and get a token without standing in a registration queue.
- Verifiable credibility. An HPR and HFR presence is increasingly what patients, partners and insurers expect to be able to check.
What to be careful about
- Consent is not paperwork to route around. Access is per-request, time-bound and revocable. Treating it casually is both a regulatory problem and a trust problem, and trust is the harder one to repair.
- ABHA does not replace your own records. You remain responsible for what you store and how you protect it; DPDP obligations do not lapse because a record is also linked to an ABHA.
- Patients may decline, and that is allowed. ABHA is voluntary. Your workflow must work for a patient without one, and having an ABHA must never become a condition of being treated.
- The specification moves. Integration is a moving target, and requirements and incentive schemes have changed over time. Prefer software that tracks the standard over a one-off integration you will maintain yourself.
Where MedSlay stands
MedSlay is built to be DPDP compliant today — granular, independently revocable patient consents at booking, role-based access for doctors and assistants, encrypted sensitive data and activity logs — which is the same discipline ABDM's consent model expects.
ABHA/ABDM compliance is in progress, not complete, and we would rather say so than imply otherwise. What is already in place is the groundwork that makes it worth doing: structured consultations, prescriptions as proper documents, and patient records complete enough to be shared rather than reassembled. If ABDM readiness matters to your practice, say so when you book a demo at medslay.com/book-demo — it helps us prioritise.