Kenya Data Protection Act 2019 (ODPC) Compliant

Privacy Policy & Patient Data Governance

How BizedHMS collects, processes, encrypts, and protects sensitive health data in accordance with the Kenya Data Protection Act 2019, Digital Health Act 2023, and Ministry of Health regulatory frameworks.

Effective Date: 1 February 2026
100% In-Country Kenya Data Hosting
AES-256 / TLS 1.3 Encryption

1. Roles & Legal Framework

BizedHMS operates as a cloud-based Hospital Management Information System (HMIS). Under the Kenya Data Protection Act, 2019 (DPA) and guidelines issued by the Office of the Data Protection Commissioner (ODPC):

  • Healthcare Facilities (Clinics, Maternity Homes, Hospitals): Act as the Data Controller. The healthcare facility determines the purpose, legal basis, and patient consent for collecting medical history, clinical notes, laboratory results, and billing records.
  • BizedHMS (Platform Provider): Acts as the Data Processor. We securely store, compute, transmit, and protect data strictly on behalf of the registered healthcare facility and under their documented instructions.
  • Digital Health Act 2023 (DHA) Alignment: All health data architecture adheres to the Ministry of Health Digital Health Standards, including interoperability with the Comprehensive Integrated Health Information System (CIHIS) and Social Health Authority (SHA) claims endpoints.

2. Categories of Data Processed

To provide hospital administration, clinical decision support, dispensary inventory, and billing services, the platform processes:

Sensitive Health Information

Patient medical history, triage vitals (blood pressure, temperature, BMI), clinical consultation notes, ICD-10/11 diagnoses, electronic prescriptions, lab test orders and results, and surgical/nursing charts.

Patient & Staff Identifiers

National ID number, passport number, SHA / SHIF member number, full legal name, phone number (used for queue SMS/WhatsApp alerts and M-Pesa STK push billing), and staff role credentials.

3. In-Country Data Residency & Storage

Mandatory In-Country Hosting: In strict compliance with Section 48 & 49 of the Kenya Data Protection Act 2019 and the Digital Health Act 2023, all primary databases, electronic health records (EHR), and automated backups are hosted within certified Tier-3 data centers physically located in the Republic of Kenya. No patient health data is transferred cross-border without explicit regulatory authorization.

4. Technical & Organizational Safeguards

BizedHMS enforces defense-in-depth security measures specified under the DHA Technical Certification standards:

  • Encryption: All data at rest is encrypted using AES-256. All data in transit across public and private networks is encrypted using TLS 1.3.
  • Role-Based Access Control (RBAC): Granular staff permissions restrict access so receptionists, cashiers, nurses, doctors, and pharmacists only view the data necessary for their clinical duty.
  • Immutable Audit Trails: In accordance with DHA-ATS standards, every view, edit, prescription, and financial transaction creates a write-once, timestamped log containing user ID, timestamp, and IP address.
  • 3-2-1 Backup Strategy: Continuous automated backups with Recovery Point Objective (RPO) ≤ 1 hour and Recovery Time Objective (RTO) ≤ 4 hours.

5. Data Retention & Patient Rights

In compliance with the Kenya Health Act and Ministry of Health clinical record policies:

  • Retention: Medical records are retained for the statutory minimum period required by Kenyan medical regulations (typically 7 years for adult patient records and up to age 25 for paediatric records).
  • Data Subject Rights: Patients may request access to, correction of, or copies of their health records through the treating health facility (Data Controller). BizedHMS provides automated export tools (FHIR R4 / PDF) to facilitate timely compliance.

6. Google API Services User Data Policy & Limited Use Disclosure

Compliance with Google API Services User Data Policy (OAuth 2.0 Verification)
Mandatory Limited Use Statement: BizedHMS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6.1 Google User Data Accessed

When healthcare workers, clinic administrators, or medical personnel choose to sign in to BizedHMS using Google Single Sign-On (OAuth 2.0), our application requests access strictly to the following user data:

  • Google Account Email Address: To verify your identity and associate your account with your healthcare organization.
  • Basic Profile Information (Full Name & Profile Picture): To personalize your provider profile, consultation signatures, and audit log stamps.
  • Google Unique Identifier (sub / User ID): To securely match and authenticate returning sessions without handling or storing your Google password.

6.2 How We Use Google User Data

Google user data is used exclusively to facilitate secure authentication, account provisioning, and access control for staff members within their registered medical facility.

  • We NEVER use Google user data for advertising, retargeting, promotional marketing, or user profiling.
  • We NEVER sell, rent, or trade Google user data to data brokers or third parties.
  • We NEVER use Google user data to train generalized machine learning, foundation, or artificial intelligence models.

6.3 Data Sharing with Third Parties

BizedHMS does not transfer, disclose, or share Google user data with any third parties, with the strict exception of:

  • Essential Cloud Infrastructure Sub-processors: Our certified Tier-3 in-country cloud hosting environment in Kenya, operating under strict business associate and data processing agreements solely to host and secure the application database.
  • Legal & Regulatory Mandates: Where required by Kenyan law or court order under the Kenya Data Protection Act 2019.

6.4 Storage, Encryption & Protection Practices

All data received through Google OAuth is protected in transit with TLS 1.3 encryption and stored in our database with AES-256 encryption at rest. Access to production environments is strictly restricted via multi-factor authentication (MFA) and least-privilege role-based access control (RBAC).

6.5 Retention Period & Accessible Data Deletion Process

Retention Duration: Google user data is retained only for as long as your user account remains active in your healthcare facility tenant.

How to Request Immediate Deletion:

  1. Direct Email Request: Send an email to privacy@bized.app or support@bized.app with the subject line "Google User Data Deletion Request". Our compliance team will acknowledge receipt within 24 hours and permanently purge all associated Google user profile records from our active databases within 30 days.
  2. Revoking Access via Google Account: You can revoke BizedHMS's access to your Google account at any time by visiting your Google Security Dashboard at Google Account Permissions (https://myaccount.google.com/permissions).

7. Contacting Our Data Protection Officer (DPO)

For inquiries regarding data protection, Google user data handling, compliance certifications, or security audits, contact our Data Protection Team:

Data Protection Officer (DPO) — BizedHMS Kenya

Privacy Inquiries: privacy@bized.app • Compliance: compliance@bized.app • Support: support@bized.app

Physical Address: Nairobi, Kenya

Supervisory Authority: Office of the Data Protection Commissioner (ODPC), Nairobi, Kenya