India’s health ID system is a directory and a messenger, not a warehouse of medical files. Your lab report stays on the server of the lab that ran it, and the national system only knows that a record exists and where to ask for it.
Why There is No Central Health Database
There is no central health database because the design deliberately avoids building one. This is what engineers call a federated model, and it keeps data at the point where it was created.
Your prescription sits on your doctor’s system. Your discharge summary sits on the hospital’s. Your scan report sits with the imaging centre.
The national registry holds an index of what exists and where, not the contents. Nobody at the centre has your diagnosis, because it was never sent there.
What Your ABHA Number Actually Is
Your ABHA number is a 14-digit identifier that ties those scattered records to one person. The Ministry of Health and Family Welfare describes it as a number any individual can create free of cost.
It comes with a readable address as well, in the form name@abdm, which works like an email handle for health data. That is what you hand over at a counter.
The number carries no medical information itself. It is the key that lets the system match records across facilities that have never exchanged data before.
Who the Two Sides of a Request Are
A request has two sides, and the specification gives both sides a name. A health information provider is anyone who creates records: a hospital, a clinic, a laboratory or a pharmacy.
A health information user is anyone asking to read them, most often a doctor treating you now. The same hospital can be both, on different days and for different patients.
Holding an abha card makes you the third party in that exchange, and the only one who can approve it.
How the Consent Manager Works
The consent manager is the piece that makes the request reach you instead of going straight to the data. It sits between the party asking and the party holding.
When a doctor asks for your records, the request goes to the consent manager first. The consent manager sends you a notice and waits.
Nothing is fetched while it waits. For example, a hospital asking at 9am for two years of your reports gets nothing at all until you tap approve, and nothing ever if you do not.
What Happens When a Doctor Asks
Here is the sequence, in order, when a doctor asks for your history.
- The hospital’s software sends a request through the national gateway, naming your ABHA address.
- The consent manager receives it and sends you a notification.
- You approve, decline or ignore it, and set what is covered.
- If approved, a signed consent record is issued to both sides.
- The hospital holding your old records checks that record, then releases only what it names.
Every step is logged. There is no path that skips the middle.
What the Consent Record Contains
The consent record is a signed document, not a tick box, and it contains five things. Each one narrows what actually moves.
- The specific records or care episodes covered.
- The categories of information, such as prescriptions or diagnostic reports.
- The date range the request applies to.
- The stated purpose, which is usually treatment.
- A deletion date, after which the recipient must erase what it pulled.
Because it is signed and time-bound, the holding facility can verify it independently. An expired or withdrawn record simply returns nothing on the next attempt.
How a Hospital Gets Connected
A hospital gets connected by building against a public specification and passing staged certification. Developers work in a sandbox first, then move through defined milestones before going live.
Once live, a facility appears on the national health facility list, which is how patients and other systems find it. More than 450 public and private health technology systems had integrated by May 2026.
That is also why coverage is uneven. A large hospital chain can fund the work; a two-doctor clinic often cannot.
Why the Design Limits a Breach
The design limits a breach because there is no single pile of clinical data to steal. Compromising the central registry gets an attacker an index, not a medical history.
That does not make the system safe by itself. Each hospital still holds real records on its own servers, and those are as secure as that hospital made them.
What the architecture does is remove the single catastrophic target. It also means a patient’s cover, whether a state scheme or a policy they buy health insurance through, is handled on a separate track from their clinical history.
Frequently Asked Questions
What is federated architecture in this system?
It means records stay with the facility that created them rather than being copied to a central store. The centre keeps an index of what exists and where.
Who is a health information provider?
Any facility that generates records, such as a hospital, clinic, laboratory or pharmacy. A health information user is whoever requests them, usually a treating doctor.
What identifier links the records together?
The 14-digit ABHA number, along with a readable ABHA address in the form name@abdm.
Can the government read my medical records?
Not through this system. Central servers hold the registry and the consent machinery, and clinical files stay with the facilities that made them.
How does a clinic join the network?
It builds against the public specification, tests in a sandbox, passes staged certification and then registers on the national facility list.
Key Takeaways
- The system routes requests, it does not store records. Clinical data stays with the facility that created it, and the centre keeps only an index.
- The ABHA number is a key, not a file. It carries no medical information and exists to match records across separate systems.
- Consent is a signed, expiring record. It names the records, the categories, the dates, the purpose and a deletion date, and it can be withdrawn.
- There is no single database to breach. That removes the catastrophic target, though each hospital’s own servers still carry real risk.

