How to Share Medical Records Using Secure Digital QR Codes

17 August 2026 · 4 min read

A QR code on a clinic reception counter is now a routine sight in Indian hospitals. Scan it, agree to share your records, and OPD registration moves from twenty minutes to two. The mechanism behind it is worth understanding — because 'scan the QR' hides real choices about which records get shared, for how long, and who ends up with a permanent copy.

What the QR code actually does

A QR code at a hospital's registration counter opens a consent request. When you scan it and approve, one of two things happens:

  • A demographic scan-and-share sends your name, age, gender and ABHA number to the hospital's system, cutting the OPD registration to a few seconds. No clinical data changes hands.
  • A records scan-and-share requests one or more specific record types — lab reports, discharge summaries, prescriptions — from your linked lockers, for a stated duration.

The difference matters. The first is the digital equivalent of handing over a filled admission form. The second is opening your file to a doctor you have not yet met.

Why the consent model is the safety feature

Under ABDM, no data is shared without a matching consent artefact. That artefact names four things — who is asking, what data type they are asking for, how long they want it for, and what purpose — and the record is delivered only against a scope that matches. If the scope is 'lab reports of last 6 months for the OPD consultation', the hospital does not get your discharge summary from 2019.

  • Consent field: Requester · What it decides: Which hospital or clinician is asking
  • Consent field: Info type · What it decides: Lab reports, prescriptions, discharge summaries, wellness records
  • Consent field: Purpose · What it decides: Care, disease-management, self, research (fewer rights)
  • Consent field: Time range · What it decides: From-date and to-date of records requested
  • Consent field: Duration of access · What it decides: How long the requester may re-fetch what you approved

The impact when it works

The scan-and-share initiative has issued over 9 crore tokens across Indian hospitals and, by the government's own measurement, saved patients ~90 crore minutes in registration queues. An IIHMR study put the OPD wait for participating patients at 2–5 minutes, down from about an hour. Half of India — over 100 crore records — is now linked to a digital account of some form.

What to check before you approve

Two questions are worth pausing on, whichever app is showing the consent screen:

  • Is the requester the hospital you are actually at? A misplaced QR code that opens a consent for another provider is a phishing pattern.
  • Does the duration make sense? A follow-up consultation may legitimately ask for a week; a permanent grant is almost never right.

Revoking after the visit

A grant does not have to run to its stated expiry. Once the visit is over — and especially once the doctor has downloaded what they need — revoke the consent from the app that issued it. That does not delete anything the hospital has already stored; it stops them fetching anything new.

This is worth a small standing habit: after every visit that involved a consent, open the sharing screen and revoke. A locker where old consents accumulate is one where any hospital in the list can pull fresh reports whenever they like.

References

MyGov Blog — QR codes for faster hospital registrations

Digital Health News — over half of India now has digital health records

DPO India — digital health records, privacy and ABDM

ABDM Sandbox — health facility QR scan flow

Jharkhand State News — 100 crore health records accessible via ABHA

Free for 90 days, no card needed. After that, keeping the record costs ₹349 for the year.

General information, not medical advice. Always talk to a qualified doctor about your own care. Where this and your doctor disagree, your doctor is right.