
When a hospital hires an agency, one of the first questions is “what data do you need?”. The honest answer is: less than you might think—and almost never patient medical information.
Here is how to share the right data safely.
What an agency typically needs
- Website analytics: visits, pages viewed, where visitors come from.
- Google Business Profile insights: calls, direction requests, website clicks per branch.
- Ad accounts: if you run paid campaigns.
- Enquiry counts by stage: how many requests came in, were contacted, booked and attended—as numbers, not names.
- Approved information: services, doctors, timings, fees and photos you have permission to use.
What an agency does not need
- Patient names linked to conditions or treatments.
- Medical records, reports or prescriptions.
- Full patient contact lists for marketing, unless patients have explicitly agreed.
Tip: If an agency asks for a full patient database “to run campaigns”, ask why, and check consent first. Most useful reporting works with anonymous totals.

Keep ownership with the hospital
- Create analytics, ad and social accounts in the hospital’s name, using a hospital email.
- Add the agency as a user with the least access they need.
- Remove access as soon as the engagement ends.
- Keep a simple access register: who has access to what, and since when.
This protects you if you change agencies and prevents your history from disappearing.
Handle enquiry data carefully
Enquiry forms and WhatsApp messages contain personal data. Collect only what you need to reply, store it securely, set a deletion period, and tell people how their information is used. India’s Digital Personal Data Protection Act makes consent and purpose limitation central, so involve your privacy owner.
Make reporting honest
Good agencies separate three things: activity (posts, pages, ads), enquiries (requests received and handled), and outcomes (attended appointments recorded by the hospital). They also explain what they cannot measure—for example, a patient who saw an ad and later walked in.
Data-sharing checklist
- All accounts owned by the hospital.
- Role-based access for the agency, recorded in a register.
- Anonymous enquiry and appointment counts, not patient records.
- Clear consent for any marketing messages.
- A deletion period for enquiry data.
- Access removed when the engagement ends.
Our commitments include keeping every account and file in your name. The reputation guide covers how to handle feedback data responsibly.
Sources and further reading
- WhatsApp Business: Business messaging policy
- Google Search Central: Creating helpful, reliable, people-first content
Frequently asked questions
Does a marketing agency need patient data?
Usually not. Anonymous counts of enquiries, bookings and attended appointments are enough for reporting. Patient medical information should never be shared for marketing.
Who should own a hospital’s marketing accounts?
The hospital. Accounts should be created in the hospital’s name, with agencies given role-based access that is removed when the work ends.
How long should a hospital keep enquiry form data?
Only as long as needed to respond and follow up, based on a deletion period set by your privacy owner and applicable law. Record the period and apply it consistently.
Want this checked for your hospital?
Clear healthcare information. Better enquiry handling. A more dependable appointment experience. Start with diagnose the problem from ₹7,500, or take the free two-minute brand check.
