SC Issues Notice on Plea Seeking CBI Probe Into Breach of 1.5 Lakh Medical Records Across Six States
- Kaustav Chowdhury

- 2 days ago
- 4 min read
In a case with major implications for data privacy and cybersecurity in India, the Supreme Court on August 6, 2026, issued notice on a petition filed by Vitraya Technologies Pvt. Ltd. seeking a CBI or court-monitored Special Investigation Team (SIT) probe into the alleged hacking and theft of personal and medical data of approximately 1.5 lakh Indian citizens. The data was allegedly routed to a server located in Singapore, raising serious national security and privacy concerns.
A bench of Chief Justice of India Surya Kant, Justice Joymalya Bagchi, and Justice V Mohana heard the matter and issued notice to the Union of India and other respondents. Senior Advocate K Parameshwar appeared for the petitioner, while AoR Abhinav Agrawal filed the petition.
The Alleged Data Breach
Vitraya Technologies operates a digital platform for real-time settlement of health insurance claims. According to the petition, a sophisticated cyber intrusion was identified in February 2025, which involved brute-force login attempts, mass downloading of confidential records, and extraction of sensitive customer data from the petitioner's infrastructure. The breached data reportedly includes Aadhaar-linked information, insurance claims, and medical records of citizens across six states.
Upon conducting an internal investigation, Vitraya Technologies traced the suspicious activities to IP addresses linked to entities that it identifies as competitors in the health insurance claims processing space, namely Remedinet Technologies, IHX Private Limited, and Medi Assist, along with their common investor, the foreign fund M/s Bessemer Venture Partners. The company alleges that these entities coordinated the attacks. The data was allegedly transferred to a Singapore-based server, adding a cross-border dimension to the case and making it relevant to discussions about compliance with the Digital Personal Data Protection Act (DPDPA) rules and cross-border data transfer restrictions.
Delayed FIR and Inadequate Investigation
One of the most striking aspects of the case is the alleged delay and inadequacy of the police response. According to the petition, Vitraya Technologies filed a detailed complaint with the police authorities in March 2025, providing technical logs, server data, IP details, names of persons involved, and supporting material. However, it took the police until August 2025, a full five months, to register an FIR.
Senior Advocate Parameshwar submitted before the Court that the FIR was registered only under Section 66 of the Information Technology Act, 2000, which pertains to computer-related offences and carries a maximum penalty of three years' imprisonment or a fine of up to five lakh rupees. He argued that this was grossly inadequate given the scale and sophistication of the breach. Furthermore, the FIR was registered against "unknown persons" despite the fact that the petitioner had provided specific details of the suspected perpetrators.
The petition states that the investigating agency has failed to undertake any meaningful, diligent, or effective investigative measures despite follow-ups and representations made by the petitioner. This continued inaction assumes greater significance considering the grave nature of the allegations involving nationwide data privacy concerns.
Data Privacy Implications Under DPDPA 2023
The case highlights critical gaps in India's data protection framework. Medical records are among the most sensitive categories of personal data, and the Digital Personal Data Protection Act, 2023 (DPDPA) places significant obligations on data fiduciaries, including the appointment of Data Protection Officers and implementation of reasonable security safeguards. When breaches involve Aadhaar-linked data and medical records being transferred overseas, the consequences for affected individuals can be severe, ranging from identity theft to insurance fraud.
The petition invokes Article 21 of the Constitution, arguing that the right to privacy, which includes the right to have one's personal data protected, has been violated on a massive scale. This is consistent with the Supreme Court's landmark recognition of the right to privacy as a fundamental right under Article 21. The case also raises questions about the obligations of the Supreme Court regarding data-sharing restrictions and consent frameworks, which have been a focus in recent privacy jurisprudence.
Recent cases, including the Bombay High Court's order restraining a hacker group from leaking school children's data under the DPDPA and the Telangana High Court's ruling on privacy violations through secret recording of phone calls, demonstrate that Indian courts are increasingly active in enforcing data protection rights.
Why a CBI or SIT Probe Is Sought
The petitioner has sought the transfer of investigation from the Punjab Police to the CBI, alleging that the local probe has been ineffective and lacking in impartiality. Alternatively, Vitraya Technologies has urged the Supreme Court to constitute a court-monitored SIT comprising the CBI, CERT-In (Indian Computer Emergency Response Team), and other specialized cyber and national security agencies to conduct an independent, expert-driven, and time-bound investigation.
The scale of the breach, involving 1.5 lakh medical records across six states with cross-border data exfiltration, arguably exceeds the investigative capacity of a state police force. Given the technical complexity of tracing cyber intrusions, IP spoofing, and server-level data extraction, specialized agencies with expertise in cybercrime investigation would be better positioned to handle such a case.
Significance of the Case
With the DPDPA 2023 now in force and the Phase 2 compliance deadline approaching in November 2026, the Vitraya Technologies case serves as a test case for India's data protection enforcement machinery. The Supreme Court's decision to issue notice signals that the highest court takes the breach of sensitive personal data seriously and is willing to examine whether existing investigative mechanisms are adequate to deal with large-scale cybercrimes. The outcome of this case could set important precedents for how data breaches involving health records are investigated and prosecuted in India.
Case: Vitraya Technologies Pvt. Ltd. v. Union of India and Others | Diary No. 31408-2026 | Bench: CJI Surya Kant, Justice Joymalya Bagchi, Justice V Mohana

Comments