Data Protection Act Compliance for Kenyan Hospitals

Compliance & Security · 7 min read · Updated 2026-08-18

Patient records are the most sensitive category of personal data the Data Protection Act, 2019 recognises, health data is explicitly classed as "sensitive personal data" with a higher bar for how it's collected, stored, and shared. For a Kenyan hospital or clinic, this isn't an abstract legal question, it's a set of concrete operational requirements. Here is what actually applies.

Why health data gets special treatment

Under the Act, sensitive personal data, which includes health status, includes anything revealing a person's medical history, treatment, or physical or mental health. Processing it requires a clear legal basis, in a clinical setting this is usually the patient's consent to treatment plus the legitimate purpose of providing care, and it must be handled with additional safeguards beyond ordinary personal data.

What this means in practice for a facility

  • Consent and purpose. Patients should understand, in plain terms, that their records are held for their care and that access is controlled. This doesn't require a legal document at every visit, it requires that your intake process makes the purpose clear and that data isn't repurposed beyond care and billing without a lawful basis.
  • Access control. Not everyone on staff needs to see every record. Role-based access, receptionists don't need full clinical notes, pharmacy doesn't need billing history it doesn't require, is both good practice and a compliance expectation.
  • Data minimisation. Collect what you need for care and billing, not everything a form could theoretically ask for.
  • Security safeguards. The Act expects "appropriate technical and organisational measures" against unauthorised access, loss, or destruction. In practice: encrypted storage, access logs, and a real backup strategy, not a filing cabinet with a lock.
  • Breach notification. A data breach affecting patient records must be reported to the Office of the Data Protection Commissioner (ODPC) and, in relevant cases, to affected individuals. Facilities need a way to even detect a breach, which paper records generally cannot do.

Where paper and loose spreadsheets fall down

A paper file or an Excel sheet shared over WhatsApp or email has none of the controls the Act expects: no access log of who viewed what, no encryption, no way to prove data wasn't copied or leaked, and no audit trail if something goes wrong. Compliance isn't really achievable on paper at any real scale.

What to demand from your systems

If you run any digital system, whether a full HMS or just a billing spreadsheet, ask:

  1. Is data isolated per facility, so one hospital's records are never visible to another's staff, even on a shared platform?
  2. Is access role-based, so each staff member sees only what their role requires?
  3. Is there an audit trail of who accessed or modified a record, and when?
  4. Is data encrypted in transit and at rest?
  5. Is there a real, tested backup, not just an assumption that the cloud provider handles it?
  6. If something went wrong, could you actually detect it and report it within a reasonable window?

A practical starting checklist

  • [ ] Confirm your intake process makes the purpose of data collection clear to patients
  • [ ] Set role-based access so staff only see what their role needs
  • [ ] Move away from WhatsApp/email for sharing patient records between staff
  • [ ] Confirm your system logs who accessed or changed a record
  • [ ] Have a written, tested backup and recovery plan
  • [ ] Know who is responsible for breach reporting if something goes wrong

How AfyaConnect approaches this

AfyaConnect isolates every facility's data with row-level security, so no facility's patient records are ever visible to another's staff on the shared platform, and access within a facility is role-based by design. Every record carries an audit trail, data is encrypted, and backups are automatic. For hospitals still discussing this in the context of moving off paper, see what changes when you switch from paper or Excel.

Compliance is easier to build in from day one than to retrofit. Register your facility or see the full feature set to see how patient data isolation is handled in practice.

Related guides