Compliance
Compliance checklist for Indian dental clinics: what's actually required
By Kythro Team, Product team · · 7 min read
Indian dental clinics get a lot of advice about compliance. Most of it is correct in isolation and overwhelming in aggregate. A clinic owner trying to figure out what they actually need to do before opening, or what they need to fix in an existing operation, ends up either ignoring the topic or hiring an expensive consultant to tell them most of what is in this post.
Here is the practical version, organised by what is actually required versus what is good practice. This is not legal advice. State rules vary. Your specific situation may have edge cases. But this is the operational baseline.
The 8 things that are actually required
Skip these and you have real legal exposure. Get them in place before you take your first patient.
1. State Dental Council registration
Every practising dentist in your clinic, including associates and visiting consultants, must be registered with the State Dental Council in the state where the clinic operates. Annual renewal. Keep originals on file.
2. Clinical Establishment registration
Most states require dental clinics to register under the Clinical Establishments Act (or the state's equivalent). The exact name and process varies. Karnataka has KPME, Maharashtra has BMC. Find out what applies in your state and complete it before opening.
3. Bio-Medical Waste authorisation
Mandatory under the Bio-Medical Waste Management Rules, 2016. You need:
- Authorisation from the State Pollution Control Board.
- A signed contract with an authorised bio-medical waste handler (the company that collects the yellow, red, and white bins).
- Records of waste generated, monthly.
This is the single most-checked compliance item in routine inspections. Get it right before opening.
4. Trade licence and shop establishment registration
Issued by the local municipal corporation. Annual renewal. Cheap. Often forgotten by clinics that started as a doctor's home practice and grew.
5. PCPNDT registration (if you have an X-ray)
If your clinic has any X-ray machine, even an OPG, you need PCPNDT registration. State-level. Renewable. Different from the radiation safety angle below.
6. AERB registration for X-ray equipment
The Atomic Energy Regulatory Board requires every X-ray machine to be registered. The supplier of the machine usually handles the initial registration. Renewals are your responsibility.
7. GST registration
Required above the threshold (currently ₹20L turnover for service businesses in most states). Most clinics cross this in year 1 or 2. Register before you have to, not after.
8. Patient consent and documentation
Not a "registration" but legally required. For every invasive procedure, you must have:
- Documented informed consent (paper or verifiable electronic).
- A clinical record showing diagnosis, treatment plan, and outcomes.
- Retention of records for the period your state requires (commonly 3 to 7 years).
Failure here is the most common reason clinics lose medico-legal cases. Even when the clinical work was correct.
The 4 things you should do
Not strictly legally required, but the cost of skipping them is high enough that you should treat them as required.
9. Professional indemnity insurance
Personal indemnity for each dentist. Annual premium ₹3,000 to ₹15,000 depending on coverage. The cost of one un-insured dispute will dwarf a decade of premiums.
10. Public liability insurance for the clinic
Covers patient slips, falls, equipment-related injuries unrelated to clinical procedures. Annual premium ₹5,000 to ₹20,000. Buy it.
11. Data privacy and patient consent for digital records
The DPDP Act, 2023 is now in force. If you maintain digital patient records (you do, even if it is just an Excel sheet), you have data fiduciary obligations. Specifically:
- Patient consent for data collection and processing.
- A privacy notice that explains what you do with their data.
- A process for patient data access and deletion requests.
For most clinics this is not onerous. A one-page consent form added to the new-patient intake covers most of it. Skipping it altogether is increasingly risky.
12. Sterilisation log
For every autoclave cycle, log: date, time, load, operator, indicator strip result. This is not optional in a rigorous inspection but is treated casually by many clinics. The log lives in a notebook or in your PMS. If you cannot produce it on request, you have a problem.
The 6 things you can skip until someone specifically asks
These come up in compliance discussions but are either situational or low-priority.
13. ISO 9001 certification
Not required. Useful if you are bidding for corporate contracts (think TCS or Infosys employee benefit programmes). Otherwise, ignore.
14. NABH accreditation
Not required for routine dental practice. Hospital-grade accreditation. Useful for large multi-speciality groups seeking insurance empanelments. Most stand-alone clinics will never need it.
15. Specific state-level "best practice" certifications
Some states have voluntary clinical-excellence certifications. They are good marketing if you have time. They are not required.
16. Disability-access certifications
Required only for clinics in certain commercial premises and for specific rebate schemes. Building access ramps and accessible toilets are good practice and often required by the building, not by the clinic regulations.
17. Industry-association memberships (IDA, IOS)
Recommended, but not required. Useful for CPD and community. Skipping them does not create legal exposure.
18. Continuing dental education (CDE) credits
Some states require a certain number of CDE credits per registration cycle. Most do not enforce. Useful clinically. Optional bureaucratically.
The compliance audit you should run yourself
Once a year, ideally before your renewal cycle, run this 30-minute audit:
- Pull every required registration. Confirm each is current and on file (item 1 to 8 above).
- Check the BMW handler contract is current and the monthly waste records are up to date.
- Confirm professional indemnity is current for every practising doctor.
- Open three random patient records from the last 6 months. Confirm consent, treatment plan, and outcome documentation are present and complete.
- Pull the autoclave log for the last 30 days. Confirm it is being filled in.
- Check that any X-ray equipment has current AERB registration.
Anything failing the audit gets fixed in the following 14 days. This single annual exercise prevents about 80 percent of compliance issues clinics actually encounter.
What this looks like in software
A practice management system that earns its keep should make most of this nearly automatic. Specifically:
- Consent capture against every treatment record, with a timestamp and the exact consent text.
- Sterilisation logs entered once and queryable later.
- Treatment plan documentation that prevents you from billing without a corresponding plan and consent.
- Records retention that does not depend on a paper file in a cupboard.
This is a chunk of why we built Kythro the way we did. Compliance gets easier when the right thing happens by default and the wrong thing requires effort.
The honest summary
The 8 hard requirements are not optional. Get them right, keep them current, and run the annual self-audit. The 4 should-dos are cheap relative to the cost of skipping them, so do them too. The 6 optional items are almost always a distraction from the real work of running the clinic well.
Compliance is mostly a forgotten-about-it-and-something-broke problem, not a hard-to-do problem. A clinic that runs a 30-minute audit once a year and fixes whatever it finds will sail through nearly every inspection that comes its way.
Run your clinic on Kythro.
Start a free 30 day trial. No credit card required.