National Accreditation Board for Hospitals & Healthcare Providers (NABH)‘s Digital Health Standard for Hospitals — one of several digital-health programmes NABH runs — has eight chapters.
Read the standard yourself. NABH’s Digital Health Standard for Hospitals is available in full, free, at nabh.co/digital-health-standards — creating a free NABH account is required to access it. Nothing in this piece substitutes for the source document itself.
Digital Infrastructure (DIS) is one of the smallest chapters by standard count — just 2 standards — and carries only 14 Objective Elements, the second-fewest of any chapter, just behind MOM’s 13 and tied with HRM.
But DIS is the one chapter every other chapter depends on: it covers the network, power, and security backbone that a hospital’s digitised OPD consultations, nursing notes, and medication records all sit on top of.
Recommended starting point: This piece is from a series on the NABH Digital Health Standard for Hospitals and assumes familiarity with many fundamental terms such as Chapters, Standards, Objective Elements, the four bands, and tier requirements. If these terms are new to you, it may make more sense to start from the beginning.
NABH’s digital infrastructure requirements here are deliberately about the infrastructure layer itself — network reliability, power continuity, encryption, firewalls — not the applications running on top of it. A hospital can own a fully licensed HMIS and still fail DIS if the infrastructure underneath it can’t be trusted.
A note on ordering: within each standard below, Objective Elements are grouped by band — Core first, then Commitment, then Achievement, then Excellence — rather than listed alphabetically by letter. This makes each standard’s actual weight easier to read at a glance, but it does mean the lettering runs out of sequence in places. The letter itself is unchanged from the standard; only the reading order is regrouped.
DIS.1 — ICT Capabilities to Facilitate Digital Operations
DIS.1 requires the hospital to use Information and Communication Technology (ICT) capabilities to facilitate its digital operations, across 9 Objective Elements — the larger of DIS’s two standards, and where the hospital IT infrastructure that NABH cares about most directly shows up: device access, browser support, network resilience, and how systems are hosted and reached.
Core
- DIS.1.f. A power backup for digital systems — UPS and generator, ensuring digital equipment keeps running through a power outage rather than going dark exactly when it’s needed most.
Commitment
- DIS.1.b. Support for more than one widely used browser, for any web-based digital system — Chrome, Firefox, Safari, Edge, and similar, so access doesn’t depend on staff using one specific browser.
Achievement
- DIS.1.a. A digital system that supports URL accessibility across devices — tablet, mobile, and desktop alike, including for staff using screen readers or other assistive tools.
- DIS.1.c. Electronic devices provided to treating medical practitioners to access electronic health records — hardware, not just software access rights, so records are reachable on-demand rather than gated by device availability.
- DIS.1.e. Backup available for the internal network — redundant network components (switches, routers, servers) so that if one link fails, another takes over automatically instead of the network simply going down.
Excellence
- DIS.1.d. Allied services staff equipped with adequate electronic devices to access the hospital’s administrative applications — extending device access beyond clinical staff to administrative and allied functions.
- DIS.1.g. A digital system that supports single sign-on (SSO) — one set of credentials across multiple systems, reducing both login friction and the security risk of staff juggling (or writing down) multiple passwords.
- DIS.1.h. A digital system largely deployed on cloud-based solutions rather than on-premises — hosted outside the hospital’s own server room, managed by a cloud provider, rather than run entirely on hardware inside the building.
- DIS.1.i. Hospital staff using mobile devices rather than fixed devices to access the hospital’s digital system — laptops, tablets, and smart devices as the primary access point, rather than desktop terminals staff have to be physically at.
DIS.2 — Data Security Controls to Prevent Security Breach
DIS.2 requires the hospital to use data security controls to prevent a security breach, across 5 Objective Elements.
Core
- DIS.2.b. An active, valid anti-virus to prevent, detect, and remove malware for hospital applications — not a license that expired two renewal cycles ago, but a currently maintained, actively monitoring anti-virus across hospital systems.
Commitment
- DIS.2.c. A firewall that monitors incoming and outgoing network traffic — software, hardware, next-generation, or cloud-based, filtering traffic between the hospital’s internal network and the outside internet.
Achievement
- DIS.2.a. A digital means to ensure hospital data is encrypted — patient information converted into an unreadable format that only authorised keys can decrypt, protecting it from exposure if intercepted or accessed without authorisation.
- DIS.2.d. A digital system that captures the audit trail of each transaction — a chronological record of activity across the system, supporting both regulatory compliance and the ability to investigate a breach or error after the fact.
Excellence
- DIS.2.e. A digital mechanism for secure remote access to hospital data — VPN, cloud-based access, or remote desktop tooling that lets authorised staff reach patient records and collaborate on care from outside the hospital, without opening up an unsecured access point.
DIS at a Glance — Every Standard, By the Numbers
| Standard | TL;DR | Core | Commitment | Achievement | Excellence | Total |
|---|---|---|---|---|---|---|
| DIS.1 | Device access, browser support, network backup, power backup, SSO/cloud/mobile | 1 | 1 | 3 | 4 | 9 |
| DIS.2 | Encryption, anti-virus, firewall, audit trails, secure remote access | 1 | 1 | 2 | 1 | 5 |
| DIS total | 2 standards, 14 Objective Elements | 2 | 2 | 5 | 5 | 14 |

The Self-Check
An owner doesn’t need an IT background to run this check — just direct answers from whoever manages the hospital’s systems:
- Does the hospital have a UPS and generator that switch over automatically during a power outage (DIS.1.f), or does “power backup” mean someone has to remember to start a generator manually?
- Is there a currently active, licensed anti-virus running across hospital systems (DIS.2.b) — or one that expired without anyone renewing it?
- If the primary network link goes down, does a backup path take over automatically (DIS.1.e), or does the hospital’s digital system simply stop working until IT intervenes?
- Is hospital data — including backups — encrypted both at rest and in transit (DIS.2.a), or only “sometimes,” when someone remembers to apply it?
- Has anyone outside the hospital’s HMIS vendor ever independently reviewed this infrastructure, or has every assessment so far come from the company that sold the software in the first place?

A hospital answering “no” to the first two questions has Core-level gaps — the same tier of gap as a Core failure in any other chapter.
Why DIS Isn’t Optional, Even Though It’s One of the Smallest Chapters
DIS carries only 14 of the standard’s 182 Objective Elements, but 2 of those are Core: power backup (DIS.1.f) and an active anti-virus (DIS.2.b). Both are non-negotiable at Silver tier, exactly like Core elements in any other chapter — a hospital cannot defer them as “later phase” work.
But DIS’s real weight isn’t in its Core count — it’s structural. Every other chapter’s Achievement and Excellence claims assume a working digital system underneath them. A hospital that has digitised OPD consultations or medication records but runs them on a network with no backup path, or on a system with a lapsed anti-virus license, or in an on-prem server room, hasn’t actually met the spirit of those chapters’ scoring — it has built its clinical digitisation on infrastructure that can fail at the exact moment it’s needed most.
This is also where an independent, non-vendor assessment matters most. A HMIS vendor’s job is to sell and support software, not to audit whether the underlying network, power, and security infrastructure can reliably support it. A hospital that assumes its HMIS purchase automatically covers DIS is very likely wrong — DIS.1 and DIS.2 are about the infrastructure layer itself, not the application sitting on top of it.

This is the same instinct behind understanding why a system works at a structural level rather than just clearing the nearest bar — DIS is the structural layer for every other chapter’s claims, and operational excellence for Indian hospitals depends on getting foundational layers right before layering more visible digitisation on top.
FAQ
How many Objective Elements does the DIS chapter have in NABH’s Digital Health Standard for Hospitals?
14 — the second-fewest of any chapter, just behind MOM’s 13, tied with HRM, out of 182 total across the standard.
What are DIS’s Core (mandatory) Objective Elements?
Two: a power backup for digital systems, i.e., UPS and generator (DIS.1.f), and an active, valid anti-virus to prevent, detect, and remove malware (DIS.2.b).
What does NABH’s DIS chapter require for network reliability?
DIS.1.e requires backup availability for the internal network, so that if one network component fails, a redundant one takes over rather than the network going down entirely.
Does having a HMIS system automatically satisfy DIS?
No. DIS.1 and DIS.2 assess the infrastructure layer — network, power, security — not the clinical or administrative application running on top of it. A HMIS vendor’s software license doesn’t cover an independent infrastructure audit.
The Decision
The question DIS asks isn’t whether a hospital has bought a HMIS license — every other chapter in this standard assumes that answer is already yes. It’s whether the infrastructure underneath that purchase would still be standing if the power went out, the primary network link failed, or a piece of malware got through an outdated anti-virus. A hospital’s OPD consultations, nursing notes, or medication records are only as digitally mature as the infrastructure they run on — and that infrastructure is exactly what DIS measures.

Leave a Reply