API Accountability In India’s Health Data Interoperability Ecosystem: A Doctrinal Legal Analysis Of The ABDM Framework
- IJLLR Journal
- 13 minutes ago
- 1 min read
Manika Sharma, NLU Jodhpur
ABSTRACT
The Ayushman Bharat Digital Mission (‘ABDM’) by India has created an ecosystem involving hospitals, laboratories, insurance providers, and third- party apps using the health data exchange protocol based on Application Programming Interface (‘API’) and the Fast Healthcare Interoperable Resources (FHIR) standards. However, even though there is a robust mechanism to facilitate the interoperability of health data, the legal rules governing the attribution of accountability concerning such data exchanges via APIs is still far from clear. This article conducts a doctrinal analysis of accountability in API-based data exchanges in the context of ABDM using the right to privacy as derived from Justice K.S. Puttaswamy v. Union of India, the Digital Personal Data Protection Act 2023 (DPDP Act), Information Technology Act 2000 (IT Act), and the Consumer Protection Act 2019 (CPA). Specifically, it shows that the lack of a functional distinction between the categories of 'data fiduciary' and 'data processor' recognized in the DPDP Act leads to a classificatory deficit in respect of 'API intermediaries,' which controls conditions of transfer but not its purposes. The article proposes a ‘layered API accountability’ framework recognizing the API intermediary as a new legal category, deriving three operational principles: proportional liability, purpose-bound granular consent, and mandatory security-by-design anchored to ISO 27799:2025 and the NIST Cybersecurity Framework.
Keywords: API accountability; health data interoperability; ABDM; DPDP Act 2023; API intermediary.
