The AIIMS Delhi ransomware attack put 40 million patient records at risk — not because encryption failed, but because raw PHI was distributed across interconnected systems with no tokenisation boundary to contain the blast radius.
What the AIIMS attack actually exposed
The AIIMS Delhi ransomware attack in November 2022 was one of the largest healthcare data incidents in Indian history. For 15 days, hospital systems were offline. An estimated 40 million patient records were at risk.
The systems that were compromised held raw patient health information: demographic records, diagnostic data, treatment histories, lab reports, insurance linkages, and physician notes — all in their original, identifiable form. When the systems were breached, every record in every connected system was immediately within the attacker's reach.
Why encryption alone is not enough
Encryption protects data at rest and in transit. It does not limit exposure once an attacker has authenticated access — which is precisely how ransomware operates. The attacker moves laterally through the network using valid credentials or exploited access paths. Once inside, encrypted storage does not prevent data exfiltration — the attacker accesses data through the same paths the legitimate application uses to decrypt it.
The blast radius problem in hospital architecture
Modern hospital systems are deeply interconnected. EMR systems share data with diagnostic labs. Labs share results with insurance TPAs. Clinical systems feed analytics and research platforms. Pharmacy systems connect to inventory management. Each integration is a potential lateral path — and each holds raw PHI that becomes fully exploitable once any node in the network is compromised.
What tokenisation changes in this architecture
PHI tokenisation replaces identifiable patient fields — name, Aadhaar, phone, diagnosis codes, insurance IDs — with non-reversible tokens at the point of data generation. Downstream systems receive tokens. Labs, analytics platforms, and insurance integrations work with governed tokens, not raw records.
When a breach occurs at the integration layer, the attacker reaches tokens that are meaningless without the vault. The blast radius is contained to a set of identifiers with zero PHI value outside the Privault environment.
DPDPA breach notification — what tokenisation changes for you
Under DPDPA, following a data breach, the Data Fiduciary must notify affected data principals and the Data Protection Board. The organisations that can demonstrate a tokenised architecture — where the breach did not expose raw PII — have a structurally different regulatory conversation than those who held raw records in every integrated system.
"The attacker accessed tokens — no raw patient data was exposed in usable form" is a materially better breach notification than "40 million patient records were at risk."
Privault for hospital and diagnostic systems
Privault by OpenBlockAI tokenises PHI fields on entry into the hospital data ecosystem. Diagnostic labs, insurance TPAs, and analytics platforms receive policy-bound tokens. Token resolution requires an authorised role, a valid purpose, and a current consent record — and every resolution is logged with timestamp and purpose tag.
Privault deploys alongside your existing EMR and diagnostic infrastructure. Schedule a PHI tokenisation architecture review to map your current blast radius and close it before an incident creates the conversation.
