Telemedicine Gone Wrong: Liability Under India's 2020 Telemedicine Practice Guidelines
- Hardi Goradia
- Jun 15
- 16 min read
Updated: Jun 19
Telemedicine Gone Wrong: Liability Under India's 2020 Telemedicine Practice Guidelines
Hardi Goradia
Attorney; Master of Laws (Health Law)
Abstract
The Telemedicine Practice Guidelines, 2020 emerged from a regulatory emergency as a framework for everyday clinical practice. As telemedicine becomes a permanent feature of Indian healthcare delivery — rather than a pandemic convenience — the liability questions the Guidelines leave open are becoming legally and clinically consequential. This article examines how liability arises when teleconsultations go wrong, analysing the standard of care applicable to digital medicine, the prescription and consent obligations under the Guidelines, platform accountability, consumer protection remedies, and the coming wave of litigation at the intersection of artificial intelligence and remote clinical practice. Drawing on Indian negligence jurisprudence and comparative frameworks from the United Kingdom, Australia, and Singapore, it argues that India's first-generation regulatory response requires substantial legislative consolidation before the complexity of digital healthcare overwhelms a system designed for a different era.

I. Introduction
Consider the following. A patient in Udaipur — an adult woman in her late thirties — downloads a telemedicine application during the second wave of the COVID-19 pandemic. She is feverish, her throat hurts, and her neck is stiff. She cannot reach the local hospital, which is overwhelmed. The application's AI-driven triage categorises her presentation as a 'mild upper respiratory infection' and directs her to a video consultation with a general practitioner in Delhi. The consultation lasts seven minutes. The doctor asks about the sore throat and the fever. He does not ask about the stiff neck. He does not ask about photophobia or sensitivity to light. He prescribes paracetamol and an antibiotic and advises rest. By the following morning, the patient is unresponsive. She is transferred to hospital by ambulance. She dies within twenty-four hours of bacterial meningitis.
The scenario is hypothetical. The legal questions it raises are not. Who bears responsibility for what happened? The doctor, who failed to take an adequate history? The platform, whose triage algorithm classified a potentially life-threatening presentation as benign? The institution whose teleconsultation service the platform operated? The technology company that designed the AI? Across state lines, through a digital medium, through the intermediation of an algorithm, a woman who sought healthcare received a response that hastened her death. The machinery for answering that question — the legal, regulatory, and evidential framework within which liability would be assessed — is what this article examines.
The Telemedicine Practice Guidelines, 2020 (the Guidelines) were issued on 25 March 2020, the same day India entered its first national lockdown, by the Board of Governors of the Medical Council of India. Their timing was not incidental. In the absence of a functioning legislature capable of rapid lawmaking, the regulator moved through the machinery available to it, appending the Guidelines to the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002. COVID-19 was not the cause of telemedicine in India; it was the catalyst for its formal legal recognition. The pandemic created the political and administrative conditions under which the regulatory system could no longer defer the question of how to govern it.
The central liability question — when virtual medicine causes real harm, who bears responsibility? — does not have a single answer. It depends on the nature of the failure, the conduct of the practitioner, the design and governance of the platform, the adequacy of consent, the content of the prescription, and the integrity of the data generated. This article works through each of those dimensions in turn.
II. The Legal Architecture of Telemedicine in India
The legal foundation of the Guidelines is professional ethics, not statute. They derive their operative force from their incorporation into the Ethics Regulations, made under the Indian Medical Council Act, 1956. Violation of the Guidelines constitutes professional misconduct under Regulation 7 of the Ethics Regulations, engaging the disciplinary jurisdiction of state medical councils and, on appeal or reference, the National Medical Commission (NMC), which replaced the Medical Council of India under the National Medical Commission Act, 2019.
The Guidelines perform five distinct regulatory functions. They define who may lawfully practice telemedicine — exclusively Registered Medical Practitioners (RMPs) recognised under the IMC Act or equivalent state legislation. They categorise consultation modes into video, audio, and text-based, a hierarchy reflecting the relative richness of clinical information each medium permits. They distinguish first consultations from follow-up consultations, with different obligations attaching to each. They create a tiered prescription framework governing which medicines may be prescribed through which consultation mode. And they impose consent, identity verification, and documentation obligations.
Whether the Guidelines create new duties or merely articulate pre-existing professional obligations has significant implications for liability. The better view is that they do both: the Guidelines clarify and confirm existing duties while creating specific, measurable standards whose violation constitutes both professional misconduct and compelling evidence of breach in civil proceedings. A structural problem with the current architecture warrants early identification. The Medical Council of India, whose Board of Governors issued the Guidelines, has been dissolved. The NMC has not updated or replaced the Guidelines, leaving a governing instrument whose parent institution no longer exists — itself a reform priority.
III. When Telemedicine Goes Wrong
Misdiagnosis Through Absence of Physical Examination
The structural difference between telemedicine and in-person medicine — the elimination of physical examination — is both the medium's primary limitation and its primary source of liability risk. Auscultation, palpation, percussion, and direct observation are either unavailable or severely restricted. The legal question is not whether physical examination was absent — that is inherent to the medium and known to both parties. The question is whether the practitioner took adequate compensatory steps: systematic history-taking, targeted red-flag questioning, and the clinical judgment to recognise when the consultation's medium was inadequate for the presenting problem. The Guidelines require the RMP to identify when in-person assessment is necessary. Failure to exercise that judgment — proceeding with a virtual consultation of a presentation requiring physical assessment — is the first paradigm of telemedicine negligence.
Failure to Recognise Emergency Presentations
The opening hypothetical illustrates the most consequential category of telemedicine liability: the patient presenting with apparently benign symptoms that, on proper history-taking, indicate a time-critical emergency. The duty to screen for urgency is not attenuated by the digital medium; it may be heightened by it, precisely because the clinician cannot observe the patient's appearance, colour, breathing, or affect directly. The Guidelines require the practitioner to direct patients to emergency services where the clinical situation demands it. Where a doctor fails to ask about symptoms that would have revealed an emergency presentation, and the patient suffers harm attributable to that omission, the combination of clinical breach and Guidelines violation creates a formidable liability position. The evidentiary advantage for the claimant is significant: the questions asked — and not asked — may be documented in the electronic consultation record.
Prescription Errors and the Categorical Framework
The Guidelines' prescription framework is the clearest bright-line standard the regime provides. List O comprises over-the-counter medications prescribable through any consultation mode. List A includes drugs prescribable after a first video consultation where clinically appropriate. List B drugs may only be provided as a refill or continuation of treatment established in a prior in-person consultation. A fourth, absolutely prohibited category encompasses narcotics, psychotropics, Schedule X drugs, habit-forming medications, and any drug requiring prior laboratory investigation. The regulatory significance of this framework is that it converts the prescribing decision into a question of categorisation. A practitioner who prescribes a Schedule X drug via text message to a patient she has never previously met violates the Guidelines on at least three dimensions — mode, drug category, and absence of prior relationship — and any harm flowing from that prescription will be assessed against that composite breach. The interaction with the Narcotic Drugs and Psychotropic Substances Act, 1985, and the Drugs and Cosmetics Act, 1940, means the violations may also constitute criminal offences under primary legislation.
Technology Failures
Platform failure during a consultation raises questions the Guidelines do not squarely address. A dropped video call at the moment a patient describes a critical symptom; a platform outage preventing access to prior records; a corrupted recording rendering a consent conversation inadmissible — each generates distinct liability questions. The practitioner is not exculpated by technical failure if she does not take reasonable steps to re-establish contact or direct the patient to alternative resources. The platform's obligations — in contract, tort, or data protection law — remain largely untested but are analytically available.
IV. The Standard of Care in Digital Medicine
The foundational authority for medical negligence in India is Jacob Mathew v State of Punjab (2005) 6 SCC 1, in which the Supreme Court adopted the Bolam formulation: a practitioner is not negligent if she acts in accordance with a practice accepted as proper by a responsible body of medical professionals skilled in that field. Jacob Mathew additionally drew the critical distinction between ordinary negligence — actionable in tort and before consumer forums — and the gross negligence or criminal rashness required to sustain a prosecution under the equivalent of Section 304A of the Indian Penal Code.
Kusum Sharma v Batra Hospital (2010) 3 SCC 480 distilled the applicable principles into six propositions, among them the requirement that negligence be assessed against the standard expected of a practitioner of the relevant specialty, and that a mere difference of professional opinion does not constitute negligence. More analytically significant for telemedicine disputes is V Kishan Rao v Nikhil Super Speciality Hospital (2010) 5 SCC 513, in which the Supreme Court declined to require expert evidence in cases of patent negligence. Applied to telemedicine, where Guidelines violations are objectively demonstrable, courts may be prepared to find breach without the resource-intensive contest of competing experts that characterises much medical negligence litigation.
The Bolitho qualification — from Bolitho v City and Hackney Health Authority [1997] 3 WLR 1151 — requires that any body of professional practice relied upon to establish compliance must withstand logical scrutiny. A practitioner who asserts that prescribing a controlled substance via text message was a recognised professional practice will find that position untenable against the explicit categorical prohibition in the Guidelines.
The standard of the 'reasonably competent telemedicine practitioner' is not a diminished standard — the medium does not reduce the duty of care — but a recalibrated one. Such a practitioner understands the inherent clinical limitations of the medium, takes active compensatory steps through history-taking and red-flag screening, operates within the Guidelines' categorical requirements, and exercises the judgment to recognise when the clinical complexity of a case exceeds what telemedicine can safely address. Departure from any of those benchmarks, with consequent harm, is the paradigm case of telemedicine negligence.
V. Informed Consent in the Virtual Environment
In Samira Kohli v Dr Prabha Manchanda (2008) 2 SCC 1, the Supreme Court moved Indian consent doctrine toward a patient-centred model, requiring disclosure of what a reasonable patient in the circumstances would want to know, rather than what the majority of practitioners would routinely disclose. The Guidelines require patient consent before any teleconsultation, encompassing consent to recording, data storage, and the identity of the treating practitioner. But the consent framework the Guidelines establish raises questions it does not answer. Does generic consent to a telemedicine consultation incorporate consent to its inherent clinical limitations — the inability to examine, the risk of incomplete assessment, the technological vulnerability? Consistently with Samira Kohli, the answer should be no. A patient who would have sought in-person care had she understood those limitations has not meaningfully consented to them.
Identity verification presents a related risk. The Guidelines permit verification through patient declaration, photograph, national identity documents, or prior records. In practice, verification is frequently perfunctory. Where a practitioner issues a prescription on the basis of an incorrectly verified identity — or where the actual recipient of a prescribed medication is a third party — the professional and regulatory consequences are severe. Language presents an underexamined dimension. India's linguistic diversity means that consultations across language barriers are common. Consent obtained in a language the patient does not adequately understand is not meaningful consent. The Guidelines say nothing about this; the gap is a foreseeable source of future disputes. The admissibility of electronically recorded consultations is governed by Section 65B of the Indian Evidence Act, 1872 (and its Bharatiya Sakshya Adhiniyam, 2023 equivalent), and the failure to preserve and properly certify consultation records is a trap for the unwary practitioner and platform alike.
VI. Prescription Liability and Regulatory Risk
The prescription framework creates, for the first time in Indian law, clearly demarcated obligations governing what a doctor may prescribe through a digital medium. The interaction between the Guidelines and the Drugs and Cosmetics Act, 1940, and its subordinate rules warrants particular attention. Prescription of drugs falling within Schedule H, Schedule H1, or Schedule X through telemedicine is constrained not only by the Guidelines but by the dispensing and recording requirements of drug control legislation. A prescription that satisfies neither the Guidelines' categorical requirements nor the drug control legislation's conditions creates overlapping regulatory exposure across professional misconduct, civil negligence, and criminal prescription offences. Consumer litigation arising from telemedicine prescription errors — framed as deficiency in service under the Consumer Protection Act, 2019 — is likely to be among the first wave of substantial digital healthcare liability claims.
VII. Data Protection, Confidentiality, and Cybersecurity
Every telemedicine consultation generates patient data of multiple kinds: consultation records, prescriptions, clinical photographs, identification documents, video recordings, and diagnostic images. This data attracts the protection of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which classify health information as sensitive personal data subject to heightened security obligations. Breach of those obligations exposes data controllers to compensation under Section 43A of the Information Technology Act, 2000.
The Digital Personal Data Protection Act, 2023 (DPDPA) significantly reconfigures the landscape. Health data attracts the Act's special category provisions, imposing on data fiduciaries — telemedicine platforms and healthcare institutions — specific obligations regarding consent, purpose limitation, data accuracy, and security. The Data Protection Board of India is empowered to impose substantial financial penalties for violations. The DPDPA's implementing rules remain outstanding at the time of writing, but the direction of travel is clear: digital health data will attract substantially enhanced regulatory scrutiny.
The cybersecurity dimension of telemedicine is not merely a compliance question — it is a patient safety question. The AIIMS Delhi ransomware attack of November 2022 demonstrated the systemic vulnerability of health information systems and the clinical consequences of their compromise. A ransomware attack on a telemedicine platform rendering patient records unavailable during an active consultation, delaying prescription issuance, or corrupting triage data generates liability in negligence, under data protection law, and potentially in contract. The evidential integrity of electronic health records — their authenticity, chain of custody, and admissibility under Section 65B certification requirements — becomes contested terrain in litigation where the consultation record is the primary evidence of what was said and decided.
VIII. Platform Liability: Can Technology Companies Be Sued?
The liability of telemedicine platforms — the entities that design, own, and operate the digital infrastructure through which consultations occur — is the most legally underdeveloped dimension of the current framework, and the one most likely to generate doctrinal innovation as litigation develops. India's major telemedicine platforms operate across a spectrum of business models: direct employment of practitioners, aggregator models connecting patients with independent physicians, hospital-integrated telehealth services, and increasingly, AI-driven clinical decision support that shapes the diagnostic and triage process before — or without — a human clinician becoming involved.
Section 79 of the Information Technology Act, 2000 confers conditional safe harbour on intermediary platforms, shielding them from liability for third-party content where they do not initiate the transmission, select its recipients, or modify its content. The healthcare context strains this framework considerably. A platform that designs clinical consultation protocols, deploys AI triage that categorises presentations before a doctor sees them, maintains a formulary of approved prescriptions, and imposes time limits on consultations is not a neutral conduit for third-party medical communications. It is an architect of clinical practice. The conditions for safe harbour are, in such cases, arguably unsatisfied.
Corporate negligence — distinct from vicarious liability — provides a parallel route to platform accountability. A platform that fails to verify the registration status of practitioners it lists, deploys an AI triage system without clinical validation for the target population, or designs a consultation workflow that structurally prevents adequate history-taking may be independently liable for those institutional failures. The Consumer Protection Act, 2019's product liability provisions provide an additional analytical tool: an AI triage system that systematically fails to identify emergency presentations may constitute a product with a 'defect' or a service with a 'deficiency' under the Act — a theory not yet tested in Indian courts but whose doctrinal basis is analytically available.
IX. Consumer Protection and Telemedicine Litigation
The foundational authority for consumer protection in medical negligence is Indian Medical Association v V P Shantha (1995) 6 SCC 651, in which the Supreme Court held that medical services fall within the Consumer Protection Act's definition of 'service.' The Consumer Protection Act, 2019 strengthened this framework significantly: enhanced compensation provisions, express product liability provisions under Chapter VI, class action mechanisms, and the Consumer Protection (E-Commerce) Rules, 2020.
Whether telemedicine platforms constitute 'e-commerce entities' within the E-Commerce Rules is a question the National Consumer Disputes Redressal Commission is likely to resolve in forthcoming litigation. The better argument is that platforms operating marketplace models — connecting patients with practitioners and facilitating transactions — fall squarely within the Rules' ambit. Jurisdictional complexity remains a significant practical obstacle. Where the patient is in one state, the doctor in another, and the platform registered in a third, the question of which consumer forum has territorial jurisdiction may determine whether a patient can practically pursue her remedy. Consumer courts have adopted a flexible approach to the locus of service delivery; the patient's location provides a defensible basis for local forum jurisdiction — an approach that, if consistently adopted, would make consumer remedies practically accessible rather than merely theoretically available.
X. Comparative Perspectives
India's 2020 Guidelines represent a first-generation regulatory response to telemedicine, valuable for the speed of their deployment. Against international comparators, however, their limitations are visible.
The United Kingdom operates through a multi-regulator, multi-instrument framework. The General Medical Council's Good Medical Practice and its specific Remote Consultations guidance make explicit that professional standards apply without diminution to digital practice. The Care Quality Commission registers and inspects online healthcare providers as regulated services, subjecting telemedicine platforms to the same governance scrutiny as hospitals and general practices. The Medicines and Healthcare products Regulatory Agency has taken enforcement action against online prescribing platforms for unsafe practices. The cumulative effect is a framework that addresses clinical, professional, governance, and product safety dimensions through distinct but mutually reinforcing instruments.
Australia's Medical Board of Australia Guidelines for Technology-Based Patient Consultations introduce an additional criterion not present in India's framework: clinical appropriateness as a precondition for telemedicine. A practitioner must assess whether the digital mode is clinically appropriate for the presenting problem — not merely whether the patient prefers it. The Therapeutic Goods Administration's emerging classification of clinical decision support software as a regulated medical device adds platform-level accountability that India's framework does not currently achieve.
Singapore's Ministry of Health licensing regime applies directly to telemedicine service providers at the institutional level, not merely to individual practitioners. A telemedicine service cannot operate without specific MOH licensing and must comply with institutional clinical governance standards. This platform-level licensing model — closer to the CQC approach in the UK — addresses, systematically, the gap that India's practitioner-focused framework leaves open. It is the comparative model most directly applicable to India's situation.
XI. Artificial Intelligence and the Next Generation of Telemedicine Risks
The liability framework for AI in clinical telemedicine is, in India as globally, largely unwritten. AI tools are already embedded in the telemedicine ecosystem at multiple levels: symptom checkers that triage patient presentations before a human clinician is engaged; diagnostic support algorithms that analyse clinical photographs; and generative AI systems that respond to patient queries and make escalation decisions algorithmically. Each of these modalities generates distinct liability questions that the current legal framework does not adequately address.
Where a practitioner relies on an AI recommendation without independent clinical scrutiny, and harm results, the practitioner cannot shelter behind the algorithm. The duty of care is personal and non-delegable. A practitioner who accepts an AI triage classification of a patient presenting with emergency symptoms without asking the clinical questions that would have revealed the emergency has been negligent regardless of what the algorithm concluded.
The more novel question concerns direct platform and developer liability for harmful AI recommendations. An AI triage system that systematically fails to identify emergency presentations — by design, by inadequate validation, or by deployment in a clinical context for which it was not trained — may constitute a product with a 'defect' or a service with a 'deficiency' under the Consumer Protection Act, 2019. India has no equivalent of the EU AI Act, 2024, which classifies clinical AI applications as high-risk systems subject to conformity assessment and human oversight requirements. The NMC has issued no guidance on AI-assisted practice. The Ayushman Bharat Digital Mission's digital health infrastructure does not address regulatory gaps in clinical AI accountability. This legislative and governance vacuum — as AI becomes increasingly integrated into telemedicine decision-making — will be filled by litigation before it is filled by regulation.
XII. The Reform Agenda
Five weaknesses in the current framework warrant priority attention from legislators, regulators, and institutional actors.
First, the Guidelines' status as a professional ethics instrument means their violation does not create standalone statutory liability. A dedicated Telemedicine Act — drawing on the model of the Clinical Establishments (Registration and Regulation) Act, 2010 — would provide the statutory foundation the regime currently lacks, create clearer enforcement powers, and signal the legislative recognition that telemedicine has become integral to healthcare delivery.
Second, the absence of platform licensing is the most consequential structural gap. Telemedicine platforms exercise enormous influence over clinical practice while operating under no specific regulatory framework. A licensing regime, modelled on Singapore's Ministry of Health framework and administered by the NMC, would impose baseline clinical governance obligations and create an accountable regulatory relationship with the platforms.
Third, minimum technical standards for telemedicine platforms — governing encryption, data availability, consultation recording integrity, audit trails, AI validation requirements, and performance under load — do not exist in regulatory form. Their absence leaves patients and practitioners exposed to technology risks for which neither has an adequate legal remedy.
Fourth, mandatory adverse event reporting for telemedicine is conspicuously absent. Without systematic capture and analysis of adverse outcomes, the regulator cannot identify risk patterns, cannot assess whether particular platforms are generating disproportionate harm, and cannot intervene preventively.
Fifth, the professional indemnity insurance landscape for telemedicine-specific liability requires regulatory clarity. The Insurance Regulatory and Development Authority of India has not addressed telemedicine liability as a distinct insurable risk category, and the extent to which standard medical indemnity policies respond to cross-jurisdictional telemedicine claims and AI-assisted consultation errors is uncertain.
XIII. Conclusion
The Telemedicine Practice Guidelines, 2020 deserve recognition for what they accomplished: a functional regulatory framework, deployed at speed in the midst of an unprecedented public health emergency, that legitimised the practice of remote medicine across a country of 1.4 billion people and created — for the first time in Indian law — specific, enforceable standards for digital clinical practice. That is a genuine regulatory achievement.
But the Guidelines were forged for an emergency and have not been updated for permanence. As telemedicine transitions from pandemic convenience to primary healthcare modality — as artificial intelligence assumes greater clinical responsibility, as cross-border digital health services dissolve jurisdictional boundaries, as electronic health records become the primary substrate of clinical decision-making — the liability questions the Guidelines leave open will generate litigation of escalating complexity and consequence.
The courts, consumer forums, and professional disciplinary bodies that will adjudicate the first generation of telemedicine liability disputes are working with inherited tools: a negligence doctrine built for the hospital ward, a consent regime designed for the operating theatre, a professional ethics framework conceived before the smartphone, and an intermediary liability safe harbour fashioned for internet commerce rather than clinical practice. Adapting those tools to the realities of digital healthcare — through legislative consolidation, platform licensing, AI accountability frameworks, and mandatory incident reporting — is not merely a regulatory aspiration. It is a patient safety imperative.
Telemedicine liability will be one of the defining medico-legal questions of the next decade. The practitioner who understands its contours now, and the institution that builds its governance framework around them, will be better placed to navigate what is coming than those who are surprised by it.
Sources
This article draws on primary legal sources including the Telemedicine Practice Guidelines, 2020; the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002; the National Medical Commission Act, 2019; the Consumer Protection Act, 2019; the Digital Personal Data Protection Act, 2023; the Information Technology Act, 2000; and the Narcotic Drugs and Psychotropic Substances Act, 1985. Judicial authorities discussed include Jacob Mathew v State of Punjab (2005) 6 SCC 1; Kusum Sharma v Batra Hospital (2010) 3 SCC 480; V Kishan Rao v Nikhil Super Speciality Hospital (2010) 5 SCC 513; Samira Kohli v Dr Prabha Manchanda (2008) 2 SCC 1; Indian Medical Association v V P Shantha (1995) 6 SCC 651; Bolam v Friern Hospital Management Committee [1957] 1 WLR 582; and Bolitho v City and Hackney Health Authority [1997] 3 WLR 1151.


Comments