top of page

Regulatory Issues in Telemedicine Platform Models

  • 19 minutes ago
  • 8 min read

Introduction : Telemedicine practices have seen an enormous increase in their implementation in India in recent times. Virtual consultations gained traction during the COVID -19 pandemic, and have since continued to be an essential part of the healthcare framework. Today, many telemedicine platforms do not just connect patients with duly registered practitioners but allow users to conduct online consultations, receive e-prescriptions, maintain medical records, and book appointments, thereby increasing access to medical services, especially for patients in remote geographical locations.


The Telemedicine Practice Guidelines, 2020, were introduced to regulate telemedicine in India. However, they mainly focus on the responsibilities of registered medical practitioners and say little about telemedicine platforms. As these platforms have taken on a much larger role, their regulation extends beyond the Guidelines and draws on a mixture of medical ethics, healthcare law, consumer protection law, data protection law, and intermediary liability law, each applicable to a different facet of platform operation. This blog examines the application of these laws to platform-based telemedicine, focusing first on licensing and doctor onboarding, then on patient consent, prescriptions, cross-border consultations, platform liability, data governance, and advertising. It also outlines practical compliance measures for telemedicine platforms and concludes with a compliance matrix summarising the key legal obligations.


Legal Provisions


In India, there is no unified legislation which governs telemedicine. Its legal framework is instead a compilation of regulations on medical ethics, healthcare law, data protection law, intermediary liability principles, and consumer protection norms, each addressing a different facet of telemedicine practice and platform operation.


The Telemedicine Practice Guidelines, 2020, issued by the Board of Governors in supersession of the Medical Council of India on 25 March 2020, serve as the foundation of this framework. The Guidelines were not introduced as a standalone law but were instead incorporated as Appendix 5 to the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002. They prescribe standards governing teleconsultation, including patient identification, securing consent, modes of consultation, maintenance of medical records, and issuing of prescriptions.


Eligibility for teleconsultations is governed by the National Medical Commission Act, 2019, which replaced the Indian Medical Council Act, 1956. Section 31 provides for the National Register of registered medical practitioners, while Section 34 bars any individual not registered in the State or National Register from practising medicine, subject to limited statutory exceptions.These provisions determine who is lawfully permitted to offer telemedicine services in India.


The Drugs and Cosmetics Rules, 1945, read with the prescription matrix of the Telemedicine Practice Guidelines, classify the medicines that may be prescribed during teleconsultation according to the mode of consultation, while prohibiting the prescription of Schedule X drugs and any narcotic or psychotropic substance regulated under the Narcotic Drugs and Psychotropic Substances Act, 1985.


Professional ethics continue to form an important part of the regulatory framework. Regulation 6.1.1 of the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002 prohibits physicians from soliciting patients through advertisements or publicity, restriction the Telemedicine Practice Guidelines reiterate in the telemedicine context.


Given the considerable amount of patient data collected and processed by telemedicine platforms, compliance with the Digital Personal Data Protection Act, 2023 is essential. The Act requires that consent for processing personal data be free, specific, informed, unconditional, and limited to the stated purpose. Section 79 of the Information Technology Act, 2000 grants intermediaries conditional safe-harbour protection, subject to compliance with prescribed due diligence norms. In addition, the Consumer Protection Act, 2019 defines “service” broadly, and the Supreme Court has held that medical services rendered for consideration fall within this definition, exposing medical practitioners and, depending on their role, telemedicine platforms to potential consumer claims.


In sum, the provisions discussed above set the parameters of telemedicine operation. While they define the obligations of registered medical practitioners in considerable detail, the obligations of telemedicine platforms continue to be shaped by broader principles of healthcare regulation, data protection, consumer protection, and intermediary liability law.


Legal Analysis


A. Licensing and Doctor Onboarding


The legitimacy of any telemedicine consultation begins with the eligibility of the physician providing it. This follows from Section 34 of the National Medical Commission Act, 2019, which permits only registered practitioners to conduct telemedicine. While the licensing framework governing registered practitioners is well defined, the process by which platforms onboard doctors is considerably less clear.


The Telemedicine Practice Guidelines require platforms to ensure that onboarded doctors hold the necessary licences to practise, but do not specify the nature of the due diligence procedure to be followed. Platforms are therefore left to determine their own onboarding standards. In practice, this means that while onboarding standards may vary across platforms, all telemedicine activity remains subject to the underlying requirements relating to patient safety and quality of service.


B. Consent and E-Prescriptions


Consent in telemedicine involves two distinct obligations. While the Telemedicine Practice Guidelines require the practitioner to establish the patient's identity and obtain consent for the consultation, the Digital Personal Data Protection Act, 2023 separately governs the platform's collection of the patient's personal data. These obligations arise under different legal frameworks and are owed by different parties, with no coordinated mechanism bringing them together.


The position is comparatively clearer for online prescriptions. The Telemedicine Practice Guidelines classify medicines according to the mode of consultation and prohibit the prescription of Schedule X drugs and narcotic or psychotropic substances under the NDPS Act, 1985. Being rule-based rather than judgment-based, these restrictions are more clearly defined and easier to comply with in practice than the consent and identity-verification requirements discussed above.


C. Platform Liability and Data Governance


The growing influence of telemedicine platforms raises important questions about the extent of their legal accountability. Section 79 of the Information Technology Act, 2000 grants intermediaries conditional immunity, provided they comply with the due diligence process defined under the Act. Modern telemedicine platforms, however, perform functions well beyond merely connecting doctors with patients, including verifying practitioners, maintaining records, and processing payments.


As platform functions grow in scope, the line between a passive intermediary and an active participant becomes less distinct, a distinction courts have applied rigorously outside the healthcare context wherever intermediaries take on functions beyond mere transmission. This is particularly significant for data governance, since platforms typically collect and process patient information before a consultation even begins, making compliance with the Digital Personal Data Protection Act, 2023 a core operational responsibility rather than an incidental one.


D. Cross-Border Consultations and Advertising


Cross-border telemedicine remains one of the least developed areas of the regulatory framework. Although the National Medical Commission Act, 2019 contains a limited provision permitting foreign-registered practitioners to practise within India, it offers little clarity on issues such as applicable law, jurisdiction, professional liability, and data protection where patients, doctors, and platforms operate across different countries, leaving significant compliance challenges for telemedicine service providers.


A similar asymmetry exists in relation to advertising. While the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002 and the Telemedicine Practice Guidelines prohibit physicians from soliciting patients through advertisements, these provisions do not extend to platform-level advertising that does not name a specific doctor. As telemedicine platforms increasingly market services under their own brand, the regulatory position governing such advertising remains unsettled.


Case Laws


Deepa Sanjeev Pawaskar & Anr. v. State of Maharashtra, 2018 SCC OnLine Bom 1841


This case arose from the death of a patient following post-operative complications, where treatment advice had been given by the doctor over the phone without the patient being examined physically. The Bombay High Court refused anticipatory bail to the doctors, holding that medical advice given without an adequate clinical assessment could amount to criminal negligence. Although the Supreme Court subsequently granted anticipatory bail on appeal, the case is widely regarded as one of the factors that prompted the introduction of the Telemedicine Practice Guidelines, 2020, and demonstrates that teleconsultation does not dilute the standard of care expected of a registered medical practitioner.


Indian Medical Association v. V.P. Shantha & Ors., (1995) 6 SCC 651


In this landmark decision, the Supreme Court held that medical services rendered for consideration fall within the definition of “service” under the Consumer Protection Act, thereby establishing the rights of patients as consumers entitled to claim remedies for deficiency in service. The ruling remains significant and applicable to telemedicine, as it affirms the potential liability of paid online consultations under consumer law.


Christian Louboutin SAS v. Nakul Bajaj & Ors., 2018 SCC OnLine Del 12215


While this case dealt with trademark infringement, it offers a useful framework for understanding intermediary liability. The Delhi High Court held that an e-commerce platform may lose the safe-harbour protection under Section 79 of the Information Technology Act, 2000 where it moves beyond the role of a passive intermediary and takes on a more active role by curating listings, verifying sellers, or facilitating transactions. While not directly applicable to healthcare, the reasoning is relevant by analogy to telemedicine platforms that verify doctors, curate services, and facilitate consultations.


Practical Implications


The issues addressed above are not merely theoretical but have a significant operational impact on telemedicine platforms. Today's telemedicine platforms do much more than facilitate consultations; they verify the legitimacy of doctors, process sensitive patient data, maintain health records, and enable online prescriptions. Regulatory compliance should accordingly be viewed as an ongoing governance function rather than a one-time legal requirement.


This is evident from recent developments. The eSanjeevani initiative, India's largest telemedicine platform, has onboarded more than 2,30,000 registered medical practitioners, underscoring the need for robust verification and onboarding mechanisms at scale. Similarly, the ransomware incident reportedly affecting Apollo Hospitals, whose Apollo 24/7 platform offers teleconsultation services, in late 2024 highlighted the growing importance of strong data protection and cybersecurity practices for digital health platforms.


Accordingly, telemedicine platforms should:


  • Independently verify the registration and credentials of every practitioner before onboarding.

  • Maintain separate records for patient identification, medical consent, and consent for processing personal data.

  • Configure systems to enforce the prescription categories prescribed under the Telemedicine Practice Guidelines.

  • Periodically review platform functions, such as doctor curation and algorithmic recommendations, to ensure continued compliance with intermediary due diligence requirements.

  • Implement appropriate technical safeguards for the secure collection, storage, and processing of patient data.

  • Establish internal protocols for cross-border consultations and subject platform-level advertising to legal review.


By adopting these measures, telemedicine platforms can strengthen regulatory compliance, reduce legal and operational risk, and build greater trust in digital healthcare services.


Conclusion


The growth of telemedicine has made digital platforms an integral part of healthcare delivery in India. While the existing legal framework provides a clear foundation for regulating teleconsultations and the conduct of registered medical practitioners, it is considerably less certain when it comes to the role and responsibilities of the platforms facilitating these services.


As discussed, the current framework draws on medical ethics, consumer protection, data protection, and intermediary liability law to regulate different aspects of telemedicine. Although this approach addresses several important issues, questions relating to platform onboarding, data governance, intermediary liability, and cross-border consultations continue to lack a dedicated regulatory framework.


As telemedicine continues to expand, there is a need for clearer platform-specific standards that complement the existing regulation of medical practitioners. Until then, telemedicine platforms will need to rely on robust internal compliance measures and careful adherence to the existing legal framework to minimise risk while continuing to deliver accessible and reliable healthcare services.


Author: Harshita Lalwani in case of any queries please contact/write back to us via email to content@khuranaandkhurana.com or at  Khurana & Khurana, Advocates and IP Attorney.


Endnotes


  1. Telemedicine Practice Guidelines, 2020 (Board of Governors, in supersession of the Medical Council of India, 25 March 2020), Appendix 5 to the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002.

  2. National Medical Commission Act, 2019, ss. 31, 34.

  3. Drugs and Cosmetics Rules, 1945; Narcotic Drugs and Psychotropic Substances Act, 1985.

  4. Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002, reg. 6.1.1.

  5. Digital Personal Data Protection Act, 2023, ss. 4–6.

  6. Information Technology Act, 2000, s. 79.

  7. Consumer Protection Act, 2019, s. 2(42); Indian Medical Association v. V.P. Shantha & Ors., (1995) 6 SCC 651.

  8. Deepa Sanjeev Pawaskar & Anr. v. State of Maharashtra, 2018 SCC OnLine Bom 1841.

  9. Indian Medical Association v. V.P. Shantha & Ors., (1995) 6 SCC 651.

  10. Christian Louboutin SAS v. Nakul Bajaj & Ors., 2018 SCC OnLine Del 12215.


Comments


bottom of page