Privacy notice
This notice explains how Nyansiongo Nursing and Maternity Home Limited collects, uses, shares and protects personal data in its hospital information system (A1 Health HMIS), as required by the Data Protection Act, 2019 and its regulations.
Who is responsible
Nyansiongo Nursing and Maternity Home Limited is the data controller for the health records it keeps. WiseDigits Ltd, which provides and operates the A1 Health HMIS software, is a data processor acting on the hospital's instructions.
Contact: · P.O. Box 358-40502
What we collect
- Identity and contact details: name, date of birth, sex, national ID, passport or birth certificate number, phone, residence, next of kin.
- Health information: visits, diagnoses, allergies, vital signs, orders, laboratory and radiology results, prescriptions, admissions and care plans.
- Payment and cover details: insurance or scheme membership, invoices and payments.
- For staff users: account details, role, and a record of what they did in the system.
Why we use it, and on what basis
- To provide and manage your care, and to keep an accurate medical record.
- To bill for services and claim from insurers and public schemes.
- To meet legal duties: notifiable disease reporting and weekly surveillance (IDSR) to the Ministry of Health, routine health statistics, and records required by law.
- To protect life in an emergency.
- To improve the quality and safety of care, using statistics that do not identify you.
Who we share it with
- Health workers involved in your care, each seeing only what their role requires.
- The Ministry of Health and public health authorities, where the law requires reporting (for example notifiable diseases).
- The Kenya Health Information Exchange (Digital Health Agency), only with your consent, recorded in the system and able to be withdrawn.
- Insurers and public health schemes for claims, and laboratories or pharmacies you are referred to.
- WiseDigits Ltd as our processor, under a data processing agreement.
We do not sell personal data.
How we protect it
- Encrypted connections (TLS) for every use of the system, and AES-256 encryption of the database, uploaded documents and backups.
- Individual accounts with two-factor authentication, role-based access, automatic sign-out after inactivity, and account lockout after failed attempts.
- An audit trail of who viewed or changed records, which cannot be altered or deleted, kept for ten years.
- Emergency ("break-glass") access is time-limited, recorded and reviewed.
- Encrypted backups kept on this server and at a separate site, with regular restore tests.
How long we keep it
Medical records are kept for the periods set by Kenyan law and Ministry of Health guidance on health records. Audit records are kept for ten years. Data no longer needed is securely deleted or anonymised.
Your rights
Under the Data Protection Act you may ask to be informed about the use of your data; to see a copy of it; to have wrong or misleading data corrected; to have data deleted where the law allows; to object to its use, including withdrawing consent for sharing through the Health Information Exchange; and to receive your data in a portable form. Ask at the records office or use the contact above. We will respond within the time the law sets.
If you are not satisfied, you may complain to the Office of the Data Protection Commissioner (www.odpc.go.ke).
← Back to sign in