Insights · Technology & data
The e-Sushrut advisory needs an answer from your system owner
For hospitals using e-Sushrut, the useful question is whether the recommended upgrade reached their own installation, with evidence that somebody checked it.
On 28 April 2026, CERT-In published advisory CIVN-2026-0207, rated critical, for C-DAC's e-Sushrut hospital management information system. It describes six vulnerabilities with potential consequences including unauthorised account access and exposure of patient information. The stated solution is to contact C-DAC to upgrade to the latest version.
The advisory identifies a system and a remediation route.
It does not name a version below which every installation is affected, or establish that a particular hospital was breached. This April warning is not evidence of an attack happening today.
Ask for the record from your own installation
Lifeline's operational recommendation: if your hospital uses e-Sushrut, ask the person responsible for it to produce the vendor's response to this advisory, the upgrade record and the result of the agreed verification. A forwarded notice or a general assurance that software is maintained should lead to that evidence.
First identify who actually controls the installation. The hospital, a public authority, a hosting provider and an implementation partner may have different responsibilities. Put the support contact and the person authorised to approve changes in the same record. If the system is centrally managed, request confirmation for your instance from that operator.
Where the position is unclear, arrange a documented review with the vendor and your authorised technology team. The hospital should not test suspected weaknesses against live accounts or patient records merely to find out whether it is affected.
What this means for your hospital
Close the loop on the recommendation. Ask C-DAC or the responsible support provider what remediation applies to your deployment and how completion can be confirmed. Record the response date, responsible person and outstanding work. Avoid inventing a patch version from an article or assuming that another hospital's upgrade resolved yours.
Plan the work with operations. An upgrade window needs agreement from the people who manage admissions, pharmacy, diagnostics and billing. Identify which activities depend on the system and how staff will record work if it is temporarily unavailable. Assign responsibility for reconciling those records when normal service returns.
Make acceptance a hospital task. After the authorised technical checks, have named staff confirm that agreed routine workflows operate as expected. Keep the change record, vendor confirmation and any unresolved exceptions together. This is a proposed acceptance process, not a claim that a successful login proves the system is secure.
Prepare an escalation route. If staff encounter signs of unauthorised access, preserve relevant records through the authorised incident team and escalate promptly to the operator. Have that team determine the response and applicable reporting obligations for the actual circumstances. An old advisory alone cannot establish whether your hospital has a reportable incident.
For hospitals using other software, this episode is a useful prompt to check the same ownership questions with their own vendors. It does not establish that another product has these vulnerabilities. Add maintenance responsibilities and a usable continuity plan to your technology and data review, alongside the existing work on patient-data governance.
Sources
- CERT-In CIVN-2026-0207, 28 April 2026 — affected system, severity and recommended vendor upgrade.
Retrospective analysis published on 14 September 2026. We have not assessed any hospital's installation or established its patch status. The operational checklist is Lifeline's analysis; obtain deployment-specific guidance from the responsible vendor.
Make responsibility for your systems visible.
We review hospital technology workflows, vendor responsibilities and implementation records so your team can see who owns each decision and what remains open.
More from Insights
Your next AI purchase needs an operating case
Before approving another pilot, define the task, the person checking its output and the result that would justify paying for it. A hospital example shows what to measure.
India's health-AI framework puts hospital governance on the agenda
A national framework gives hospital leaders a reason to put ownership, evidence and review around the AI tools they already use or plan to buy.
Allied-health degree changes need a place in your hiring plan
New course names and training pathways will reach hospitals through recruitment and clinical placements. Update the checks before they become a staffing problem.