ABDM compliance for Indian hospitals: the M1, M2 & M3 requirements explained

What each ABDM milestone actually requires, what your hospital software has to do to satisfy it, and which hospitals are facing real deadlines right now. Verified against the National Health Authority’s own documentation — not repeated from other vendors.

Last verified against NHA sources:

Jump to the requirements

What is ABDM?

The Ayushman Bharat Digital Mission (ABDM) is the National Health Authority’s framework for a nationwide interoperable digital health ecosystem in India. For a hospital or clinic, ABDM compliance means the facility’s software can create and verify ABHA identifiers, publish patient health records as linkable care contexts, and retrieve records from other facilities under patient consent. These capabilities are grouped into integration milestones M1, M2 and M3, with a fourth milestone, M4, covering the National Healthcare Providers Registry.

Already know the requirements?

Medikunj already does all of this — ABHA at the front desk, records linked as you work, consent-based retrieval in the doctor’s screen.

Skip the reading and see it working on a real hospital’s workflow. Or keep scrolling for the full requirements.

Time-sensitive

If your HMIS still uses V1 or V2 APIs, your ABDM credentials are at risk

The National Health Authority states that software using V1 or V2 APIs for Milestone M1 must migrate to V3 APIs to avoid deactivation of its credentials, and separately that no implementation is accepted for the certification exit process if M1 was done using V1 or V2 APIs. Only V3 is acceptable for Milestone 1.

This is the most urgent item on this page. Ask your software vendor one question: which ABDM API version are we running for M1? If the answer is unclear, our ABDM compliance checklist walks through what to ask.

Source: ABDM Sandbox, National Health Authority

The milestones

What ABDM M1, M2, M3 and M4 actually require

ABDM integration is grouped into milestones. Each one turns your hospital software into a different role inside the national health data network. These are the National Health Authority’s own names for them.

MilestoneOfficial NHA nameWhat it makes your software
M1ABHA creation and verificationAn identity provider — creates and verifies patient ABHA
M2Linking health records with ABHA addressA Health Information Provider (HIP) — publishes records
M3Health records exchange between health facilitiesA Health Information User (HIU) — retrieves records
M4National Healthcare Providers Registry (NHPR)Registers professionals and facilities natively

A correction worth knowing: many health-tech articles state that M4 is NHCX insurance claims processing. It is not. The National Health Authority names Milestone 4 as NHPR, the National Healthcare Providers Registry. NHCX is a separate integration track. NHA also states that M4 can only be initiated after M1, M2 and M3 are complete.

Source: NHA — Milestone 4 (NHPR) documentation

Milestone 1

What does ABDM Milestone M1 require?

M1 requires your software to create an ABHA number using Aadhaar or a Driving Licence, and to verify a patient’s ABHA number or ABHA address during registration.

NHA publishes an exact test-case matrix for M1, and it distinguishes between private applications such as a hospital HMIS and government applications. Several capabilities that are optional for a private hospital system are mandatory for a government one.

CapabilityPrivate appGovernment app
Create ABHA Number using Aadhaar OTPMandatoryMandatory
Create ABHA Number using Aadhaar BiometricsOptionalMandatory
Create ABHA Number using Aadhaar Demographics (Offline)NAMandatory
Create ABHA Number using Driving LicenceOptionalOptional
Create ABHA AddressMandatoryMandatory
Download ABHA CardMandatoryMandatory
Profile UpdateOptionalOptional
Verify ABHA — Scan Health Facility QRMandatoryMandatory
Verify ABHA — Scan User ABHA QROptionalOptional
Verify ABHA — By OTPMandatoryMandatory
New vs Returning PatientsMandatoryMandatory

ABHA number vs ABHA address — the distinction almost everyone gets wrong

An ABHA numbercan be created only through Aadhaar or a Driving Licence. NHA’s official ABHA portal offers exactly those two options and no others. An ABHA addressis a separate identifier that can be created using demographic details, and it is verified by mobile OTP, a facility QR scan, or the patient’s ABHA QR. So mobile OTP is real in ABDM — it belongs to verification and to the ABHA address, never to creating the ABHA number itself.

Source: NHA — Milestone 1 documentation

Milestone 2

What does ABDM Milestone M2 require?

M2 makes your hospital a Health Information Provider. NHA lists four functionalities: link health records with the ABHA address, allow users to discover their health records, save user consents, and share health records after verifying consent.

In practice this means every visit, admission, lab report and prescription becomes a “care context” attached to the patient’s ABHA address. NHA’s documentation covers health record formats, understanding and linking care contexts, HIP-initiated linking, notification to mobile, discovery and link, storing consent notifications, requests for health records, and the packaging and transfer of health data.

Source: NHA — Milestone 2 documentation

Milestone 3

What does ABDM Milestone M3 require?

M3 makes your hospital a Health Information User. In NHA’s words, it means developing HIU services “to provide view of patient’s medical history to authorized healthcare workers with complete consent.”

NHA marks all four M3 capabilities as mandatory, and it names the applicable role explicitly as HMIS / LMIS (private) — which is exactly what a hospital management system is.

  • Requesting ConsentMandatory
  • Storing Consent ArtefactsMandatory
  • Getting Health RecordsMandatory
  • Display Health RecordsMandatory

Source: NHA — Milestone 3 documentation

Mandates

Is ABDM compliance actually mandatory for my hospital?

There is no national notification making ABDM integration mandatory for every Indian hospital. What exists instead is state-level enforcement tied to AB-PMJAY empanelment — and it is already active, with real deadlines and real financial penalties.

The widely-repeated claim that ABDM becomes mandatory for all hospitals by 2027 is not supported by any government source we could find. We searched PIB, the National Health Authority, the Ministry of Health and Family Welfare, and abdm.gov.in. If a national mandate is notified, this page will be updated — but as of the verification date above, it has not been.

Example of a live state directive

Odisha’s State Health Assurance Society directed private hospitals empanelled under AB-PMJAY–GJAY to integrate four things with ABDM by 31 August 2026: their Hospital Management Information System, ABHA-based patient medical records, the Health Facility Registry, and the Health Professional Registry. Reported penalties for missing the deadline are the withholding of incentives under the Ayushman scheme, with de-empanelment for persistent non-compliance.

So your exposure depends on two things: whether your hospital is AB-PMJAY empanelled, and which state it operates in. There is no single national answer, and any vendor giving you one is guessing. Check your State Health Agency’s circulars directly.

Certification

How ABDM certification actually works

“ABDM certified” is a specific status conferred by the National Health Authority through a four-step exit process from the ABDM Sandbox. It is worth knowing what it involves, because the word gets used loosely.

  1. 1a

    Functional Testing

    An NHA-empanelled functional testing agency evaluates your integrated software, on a chargeable basis. NHA lists nine empanelled agencies. The evaluation must not exceed 7 working days from onboarding, and the FT report must reach the ABDM team within that window.

  2. 1b

    Internal Demo by NHA

    FT reports go to NHA in its approved template — NHA states no report is accepted outside that format. Once the ABDM Integration team approves the report, it schedules an internal demonstration.

  3. 2

    WASA / Safe-to-Host Certificate

    Security testing of the web or mobile application by an STQC or CERT-In empanelled agency. The resulting “Safe-to-Host” certificate is submitted to NHA. STQC may separately perform validation testing on sample applications.

  4. 3

    Health Tech Committee (HTC) approval

    The final go-live approval. You submit the FT report, the Safe-to-Host certificate, and the Sandbox Exit Form with the FT certificate, WASA certificate, a signed Undertaking (physical hard copy by courier or speed post) and GSTIN certificate — then demonstrate the implemented milestones to the committee.

  5. 4

    Production access

    On approval, NHA emails the production client-id and secret separately. NHA notes the secret is extremely confidential and must not be shared.

The nine NHA-empanelled functional testing agencies

  • AKS Information Technology Services
  • Avasure Technologies
  • AQM Technologies
  • Code Decode Labs
  • ESF Labs
  • FIME India
  • Nangia & Co LLP
  • Oxygen Consulting Services
  • Suma Soft

Source: NHA — ABDM Sandbox Entry & Exit process

One implementation

How Medikunj implements ABDM

Medikunj implements the M1, M2 and M3integration requirements inside the screens hospital staff already use — ABHA creation at the registration desk, record linking as consultations and admissions are recorded, and consent-based retrieval in the doctor’s workspace.

Built to the National Health Authority’s published specifications

Medikunj is ABDM-compliant, implementing the M1, M2 and M3 integration requirements as specified by NHA — ABHA creation and verification at registration, care-context linking of visits, admissions, lab reports and prescriptions, and consent-based retrieval of records held at other facilities.

ABDM is one of several obligations that land on the same records. The DPDP Act governs how you handle that patient data, and your hosting architecture determines whether ABHA lookups keep working when your internet does not.

Read the compliance guides

Reality check

Most integrations never reach production

NHA’s own integrators dashboard tells a sobering story about how hard this is in practice.

3,177

active integrators

approved by NHA's committee to begin integration

547

successful integrators

completed integration and live on production

54

NHCX approved

applications approved on the separate NHCX track

Roughly 83% of approved integrators have not yet reached production. If your vendor tells you ABDM integration is a quick configuration change, that number is worth raising with them — our hospital software buyer’s guide covers the other questions worth asking before you sign.

Source: NHA — ABDM Sandbox integrators dashboard

FAQ

ABDM compliance: common questions

There is no national notification making ABDM integration mandatory for every Indian hospital. What exists is state-level enforcement tied to AB-PMJAY empanelment: State Health Agencies have issued directives with real deadlines and financial penalties. Odisha's State Health Assurance Society, for example, required AB-PMJAY-GJAY empanelled private hospitals to integrate their HMIS, ABHA-based records, the Health Facility Registry and the Health Professional Registry with ABDM by 31 August 2026, with incentives withheld for non-compliance and de-empanelment for persistent failure. Whether your hospital faces a deadline depends on whether it is AB-PMJAY empanelled and which state it operates in — check your State Health Agency's circulars.

We could not find any government source for this. The claim appears widely across health-tech vendor websites, but searches of PIB, the National Health Authority, the Ministry of Health and Family Welfare, and abdm.gov.in returned no notification, circular or press release establishing a national 2027 mandate. Treat it as unverified. The verifiable pressure on hospitals today comes from state directives tied to AB-PMJAY empanelment, not from a national deadline.

ABDM (Ayushman Bharat Digital Mission) is the National Health Authority's overall framework for interoperable digital health in India. ABHA (Ayushman Bharat Health Account) is the patient identifier within that framework. A patient has an ABHA number and an ABHA address; a hospital integrates with ABDM so that it can create, verify and link records against that ABHA.

M1 is ABHA creation and verification — your software becomes able to create and verify a patient's ABHA at registration. M2 is linking health records with the ABHA address — your software becomes a Health Information Provider, publishing records as care contexts that a patient can discover and share by consent. M3 is health records exchange between health facilities — your software becomes a Health Information User, requesting records held elsewhere under patient consent and displaying them to authorised staff. A fourth milestone, M4, covers the National Healthcare Providers Registry and can only begin after M1, M2 and M3 are complete.

No. Many vendor articles state that M4 is NHCX insurance claims processing; the National Health Authority's own documentation names Milestone 4 as NHPR, the National Healthcare Providers Registry, which enables native registration of health professionals and health facilities. NHCX is a separate integration track, listed separately by NHA.

No. The National Health Authority's official ABHA portal offers exactly two options for creating an ABHA number: Aadhaar, or Driving Licence. Mobile OTP is used for verification of an ABHA address and for login, and demographic details including a mobile number can be used when creating an ABHA address — but the ABHA number itself cannot be created from a mobile number alone.

NHA has stated that software still using V1 or V2 APIs for Milestone M1 must migrate to V3 APIs to avoid deactivation of its credentials, and that no implementation is accepted for the certification exit process if M1 was done using V1 or V2 APIs. If your HMIS vendor has not migrated to V3, your ABDM credentials are at risk. This is the single most time-sensitive item on this page — ask your vendor directly which API version they are on.

NHA publishes only one official timeframe: functional testing must not exceed 7 working days from onboarding with the testing agency. The rest of the timeline — sandbox integration, the security audit, and scheduling with the Health Tech Committee — is not published as a fixed duration and varies by application. Be sceptical of vendors quoting precise integration timelines, because NHA does not define them.

At minimum it should create and verify ABHA at registration using the M1 capabilities NHA marks mandatory for private applications, link every visit, admission, lab report and prescription to the patient's ABHA address as a care context, and retrieve records from other facilities under consent. It should also be running the V3 APIs for M1. Medikunj is built to the M1, M2 and M3 specifications published by the National Health Authority, with ABHA creation at the registration desk, record linking as consultations and admissions are recorded, and consent-based retrieval inside the doctor's workspace.

No. They are separate obligations that overlap. ABDM governs interoperability and consent-based health data exchange under the Health Data Management Policy. The Digital Personal Data Protection Act, 2023 imposes its own duties on any organisation processing personal data in India, including notice, consent, purpose limitation, security safeguards and breach reporting. Being ABDM-compliant does not by itself make a hospital DPDP-compliant.

Sources

Official sources used on this page

Every requirement on this page was read from a National Health Authority or Government of India source. We have linked them so you can verify anything here yourself — each one opens in a new tab, so you will not lose your place on this page.

See ABHA creation and record linking on a real screen

A 20-minute working screen-share — ABHA created at the front desk, records linked as the consultation happens, consent-based retrieval in the doctor’s workspace. No slide deck.