How to Share Medical Records Using Secure Digital QR Codes
A QR code on a clinic reception counter is now a routine sight in Indian hospitals. Scan it, agree to share your records, and OPD registration moves from twenty minutes to two. The mechanism behind it is worth understanding — because 'scan the QR' hides real choices about which records get shared, for how long, and who ends up with a permanent copy.
What the QR code actually does
A QR code at a hospital's registration counter opens a consent request. When you scan it and approve, one of two things happens:
- A demographic scan-and-share sends your name, age, gender and ABHA number to the hospital's system, cutting the OPD registration to a few seconds. No clinical data changes hands.
- A records scan-and-share requests one or more specific record types — lab reports, discharge summaries, prescriptions — from your linked lockers, for a stated duration.
The difference matters. The first is the digital equivalent of handing over a filled admission form. The second is opening your file to a doctor you have not yet met.
Why the consent model is the safety feature
Under ABDM, no data is shared without a matching consent artefact. That artefact names four things — who is asking, what data type they are asking for, how long they want it for, and what purpose — and the record is delivered only against a scope that matches. If the scope is 'lab reports of last 6 months for the OPD consultation', the hospital does not get your discharge summary from 2019.
- Consent field: Requester · What it decides: Which hospital or clinician is asking
- Consent field: Info type · What it decides: Lab reports, prescriptions, discharge summaries, wellness records
- Consent field: Purpose · What it decides: Care, disease-management, self, research (fewer rights)
- Consent field: Time range · What it decides: From-date and to-date of records requested
- Consent field: Duration of access · What it decides: How long the requester may re-fetch what you approved
The impact when it works
The scan-and-share initiative has issued over 9 crore tokens across Indian hospitals and, by the government's own measurement, saved patients ~90 crore minutes in registration queues. An IIHMR study put the OPD wait for participating patients at 2–5 minutes, down from about an hour. Half of India — over 100 crore records — is now linked to a digital account of some form.
What to check before you approve
Two questions are worth pausing on, whichever app is showing the consent screen:
- Is the requester the hospital you are actually at? A misplaced QR code that opens a consent for another provider is a phishing pattern.
- Does the duration make sense? A follow-up consultation may legitimately ask for a week; a permanent grant is almost never right.
Revoking after the visit
A grant does not have to run to its stated expiry. Once the visit is over — and especially once the doctor has downloaded what they need — revoke the consent from the app that issued it. That does not delete anything the hospital has already stored; it stops them fetching anything new.
This is worth a small standing habit: after every visit that involved a consent, open the sharing screen and revoke. A locker where old consents accumulate is one where any hospital in the list can pull fresh reports whenever they like.
References
• MyGov Blog — QR codes for faster hospital registrations
• Digital Health News — over half of India now has digital health records
• DPO India — digital health records, privacy and ABDM
• ABDM Sandbox — health facility QR scan flow
• Jharkhand State News — 100 crore health records accessible via ABHA
Free for 90 days, no card needed. After that, keeping the record costs ₹349 for the year.
General information, not medical advice. Always talk to a qualified doctor about your own care. Where this and your doctor disagree, your doctor is right.