Section 41 Kenya DPA 2019 Controller-to-Processor Addendum

Medical Data Processing Agreement (DPA)

This Healthcare Data Processing Addendum constitutes the legally binding data protection commitment between the Healthcare Facility (Data Controller) and BizedHMS (Data Processor) under Kenyan law.

Effective Date: 1 February 2026
Digital Health Act 2023 Aligned

1. Scope & Processing Instructions

This Data Processing Agreement ("DPA") supplements the BizedHMS Master Subscription Agreement. It applies to all processing of Protected Health Information (PHI) and Personal Data carried out by BizedHMS on behalf of the registered Healthcare Facility.

BizedHMS agrees to process Personal Data solely in accordance with the documented instructions of the Healthcare Facility and for the explicit purposes of providing hospital administrative, clinical workflow, electronic prescription, pharmacy inventory, and billing services.

2. Medical Confidentiality & Staff Obligations

BizedHMS ensures that all personnel authorized to process Protected Health Information have committed themselves to strict confidentiality agreements and undergo regular training on medical privacy laws and the Kenya Data Protection Act 2019. Access is strictly limited to authorized engineers performing necessary maintenance or system support.

3. Technical & Organizational Security Measures

In alignment with DHA Certification Phase 3 Technical Documentation:

A. Encryption Standards (DHA-EIS):

AES-256 cryptographic encryption for all databases, medical attachments, and backups. TLS 1.3 for all web, mobile, and API transport. Master cryptographic keys managed through secure HSM-backed key vaults compliant with NIST SP 800-57.

B. Immutable Audit Trails (DHA-ATS):

Full logging of every record creation, read, consultation update, prescription dispense, and financial invoice. Audit trails include verified timestamp (East Africa Time / UTC), operator ID, IP address, and changed attributes.

C. Backup & Disaster Recovery (DHA-BRP / DHA-DRP):

Automated 3-2-1 backup topology with cross-zone replication within Kenya, achieving an RPO of ≤ 1 hour and RTO of ≤ 4 hours. Backups undergo routine automated restoration integrity verification.

4. 72-Hour Security Breach Notification

Mandatory Incident Protocol: In the event of a confirmed personal data breach affecting patient records, BizedHMS shall notify the Healthcare Facility without undue delay and in any event within 72 hours of becoming aware of the incident, providing detailed diagnostics, affected data scopes, and mitigation actions to support the Facility's statutory notification to the ODPC.

5. Sub-processors & Hosting Partners

All cloud infrastructure providers and telecommunication gateways (e.g. Safaricom Daraja M-Pesa API, licensed Kenyan SMS gateways) must meet equivalent data protection standards and maintain physical data residency in Kenya.

6. Ministry of Health & DHA Compliance Audits

BizedHMS agrees to make available to the Healthcare Facility and relevant regulatory bodies (Digital Health Agency, Ministry of Health, and ODPC) all technical documentation and certification audit test reports necessary to demonstrate compliance with national digital health standards.