Digital Health Act
This Act may be cited as the Digital Health Act, 2023.
- Jurisdiction
- Kenya
- Instrument
- Act or statute
- Citation
- Act No. 15 of 2023
- Version
- 24 Nov 2023
- Language
- en
- Official source
- View official record ↗
Source attribution: Source: Kenya Law
Statute overview
About this statute
This Act may be cited as the Digital Health Act, 2023. Section 2 provides definitions of terms used in the Act, including "Agency", "anonymization", "Board", "Cabinet Secretary", "client", and various data-related terms. Section 3 establishes the Digital Health Agency. Declares that health data is a strategic national asset. The Board may establish committees and may co-opt additional persons into committee membership when their knowledge and skills are necessary for the Agency's functions.
Search within this statute
Search all stored provisions in this version.
Legal text
Provisions of Digital Health Act
Showing 62 of 62
Part I
PRELIMINARY
- 1 Verify source ↗
PRELIMINARY - 1. Short title
This Act may be cited as the Digital Health Act, 2023.
Section 1. Short title Section This Act may be cited as the Digital Health Act, 2023. - 2 Verify source ↗
PRELIMINARY - 2. Interpretation
Section 2 provides definitions of terms used in the Act, including "Agency", "anonymization", "Board", "Cabinet Secretary", "client", and various data-related terms.
Section 2. Interpretation Section In this Act, unless the context otherwise requires— "Agency" means the Digital Health Agency established under section 5 ; "anonymization" means the removal of personal identifiers from personal data ("any information relating to an identified or identifiable natural person;") so that the data subject ("an identified or identifiable natural person who is the subject of personal data;") is no longer identifiable; "Board" means the Board of Directors of the Agency ("the Digital Health Agency established under;") constituted under section 8 ; "Cabinet Secretary" means the Cabinet Secretary for ministry responsible for matters relating to health; "client" means an individual ("data subject;") who uses, or has used, a health service, or in relation to whom health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") has been created; "consent" has the meaning assigned to it under the Data Protection Act ( Cap. 411C ); "County Executive Committee Member" means the member of county executive committee appointed and designated to supervise health services; "data" means information which— (a) is processed by means of equipment operating automatically in response to instructions given for that purpose; (b) is recorded with intention that it should be processed by means of such equipment; (c) is recorded as part of a relevant filing system ("the comprehensive integrated health information system established under;") ; (d) is recorded information which is held by a public entity and does not fall within any of paragraphs (a) to (d); "data analysis" means the process of inspecting, cleaning, transforming, consolidation and modelling of data with the goal of discovering useful information, extracting meaningful insights, suggesting conclusions and supporting decision making; "data bank" means an organised collection of data designed to efficiently store and retrieve data that can be accessed, managed and updated electronically to allow users to easily search for and access the information they need, to derive insights, make informed decisions and improve performance; "data commissioner" means the person appointed under section 6 of the Data Protection Act ( Cap. 411C ); "data controller" means a natural or legal person, public authority, agency or other body which, alone jointly with others, determines the purpose and means of processing of personal data ("any information relating to an identified or identifiable natural person;") ; or "data disposal" means the process of destroying manual or electronic records or data completely without being used or accessed for an authorized purpose; "data governance" means the overall management of the availability, usability, integrity and security of data used in an organization; "data integrity" means the overall completeness, accuracy and consistency of data ; "data life cycle" means the stages through which data passes from its creation or acquisition to its eventual deletion or archival; "data management" means the development, execution and supervision of plans, policies, programs and practices that control, protect, deliver and enhance the value of data and information assets, and involves policy formulation and adherence to data management procedures such as reporting rates, harmonized and standard data collection tools; "data privacy" means the aspect of information technology that deals with the ability an organization or individual ("data subject;") has to detemine what data in a computer system ("the comprehensive integrated health information system established under;") can be shared with third parties for purposes of the keeping of information private and safe; "data processor" means a natural or legal person, public authority, agency or other body which processes personal data ("any information relating to an identified or identifiable natural person;") on behalf of the data controller ("a natural or legal person, public authority, agency or other body which, alone jointly with others, determines the purpose and means of processing of personal data; or") ; "data reporting" means the process of collection, submission and organisation of data into informational summaries in order to monitor performance; "data retention" means the continued storage of an organization’s data for compliance with national policy guidelines and regulations; "data security" means protection of electronic health data , and specifically the means used to protect the privacy of health information contained in electronic health data that supports professionals in holding that information in confidence; "data storage" means the recording of information in a storage medium or holding information in digital format; "data subject" means an identified or identifiable natural person who is the subject of personal data ("any information relating to an identified or identifiable natural person;") ; "de-identification" means removing or hiding personal information from records in such a way that the remaining information cannot be used to identify an individual ("data subject;") ; "data verification" includes the authentication and validation of gathered data , data quality checks, audit of the health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") using the data quality protocols; "digital health" means the field of knowledge and practice that is associated with the development and use of digital technologies to improve health; "Director-General" means the Director-General for health appointed under section 16 of the Health Act ( Cap. 241 ); "disclosure" means submission of relevant information to an authorized party; "e-Health" means the combined use of electronic communication and information technology in the health sector including telemedicine ("the provision of health care services and sharing of medical knowledge over distance using telecommunications and includes consultative, diagnostic, and treatment services; and") ; "e-Health ecosystem" means the combined application of e-Health infrastructure, standards, technology, systems applications, investment, health workforce and governance that support patient-centred models of healthcare; "e-Health platform" means an ecosystem of hardware, software and technology used to deliver e-Health services; "electronic health data" means an electronic record of personal health related information about an individual ("data subject;") and shall include— (a) information concerning the physical or mental health of the individual ("data subject;") ; (b) information concerning any health service provided to the individual ("data subject;") ; (c) information concerning the donation by the individual ("data subject;") of any body part or any bodily substance; (d) information derived from the testing or examination of a body part or bodily substance of the individual ("data subject;") ; (e) information that is collected in the course of providing health services to the individual ("data subject;") ; or (f) information relating to details of the health facility accessed by the individual ("data subject;") ; "encryption" means the process of converting the content of any readable data using technical means into coded form; "enterprise class" refers to applications that are designed to be robust and scalable across a large organization, and compatible with existing databases and tools, customizable for the needs of specific departments, powerful enough to scale up along with the needs of the business using it, secure from outside threats and data leaks; "enterprise service bus" means an architectural pattern whereby a centralized software component performs integrations between applications; transformations of data models, handles connectivity, message routing, converts communication protocols and potentially manages the composition of multiple requests and may make these integrations and transformations available as a service interface for reuse by new applications; "e-waste" means waste resulting from electrical and electronic equipment including components and sub-assemblies thereof; "guardian" means a guardian recognised under any law for the time being in force; "health care professional" includes any person who has obtained health professional qualifications and licensed by the relevant regulatory body; "health care provider" has the meaning assigned to it under the Health Act ( Cap. 241 ); "health care services" has the meaning assigned to it under the Health Act ( Cap. 241 ); "health data" means data related to the state of physical or mental health of the data subject ("an identified or identifiable natural person who is the subject of personal data;") and includes records regarding the past, present or future state of the health, data collected in the course of registration for or provision of health services or data which associates the data subject ("an identified or identifiable natural person who is the subject of personal data;") to the provision of specific health services; "health data controller" means a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purpose and means of processing of health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") ; "health data custodian" means a person or organization that possesses legal custody over health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") ; "health data processor" means a person, public authority, agency or other body who is an authorised worker to process health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") ; "health facility" has the meaning assigned to it under the Health Act ( Cap. 241 ); "health informatics" means the practice of acquiring, studying and managing health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") and applying medical concepts in conjunction with health information technology systems to help health professionals provide better healthcare; "health information bank" means an electronic database under the custody and control of the Ministry of Health that contains personal health information ("data related to the state of physical or mental health of an individual and includes information provided by the client, records regarding the past, present or future state of the health,data collected in the course of registration for, or provision of health services, or data which associates the individual to the provision of specific health services;") and is designated by the Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") as a health information bank; "health information system" means a health ecosystem designed to manage health and health related system ("the comprehensive integrated health information system established under;") data that provides the foundations for decision-making and includes a system ("the comprehensive integrated health information system established under;") that collects, collates, stores, manages, analyses, synthesises, transmit patient's or client ("an individual who uses, or has used, a health service, or in relation to whom health data has been created;") ’s electronic health record and uses health and health related data for operational management or a system ("the comprehensive integrated health information system established under;") supporting healthcare policy decisions; "health records and information management" means the practice of acquiring, analysing and protecting digital and traditional medical information vital to providing quality patient or client ("an individual who uses, or has used, a health service, or in relation to whom health data has been created;") care; "health records and information manager" means an officer trained in health records and information management ("the practice of acquiring, analysing and protecting digital and traditional medical information vital to providing quality patient or client care;") and charged with the responsibility of managing health records and health information for the health services which include— (a) creating and enforcing policies for effective data management ("the development, execution and supervision of plans, policies, programs and practices that control, protect, deliver and enhance the value of data and information assets, and involves policy formulation and adherence to data management procedures such as reporting rates, harmonized and standard data collection tools;") ; (b) clinical coding and classifications; (c) coding for health insurance firms; (d) health information management; (e) health administrative data and medical data analytics and research; (f) appraisal of medical documentations and audits; (g) advice on medical legal issues; (h) advise on retrieval and disposal of Health and medical records; (i) use of e-Health applications; "health related data information" means the service delivery and administrative health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") collected, analysed and synthesised for decision making in the health sector; "health system" means an organization of people, institutions and resources that deliver health care services to meet the health needs of the population, in accordance with established policies; "health technology" means the application of organized knowledge and skills in the form of devices, medicine, vaccines, procedures and systems developed to solve a health problem and improve the quality of life; "health tourism" means a situation where a patient travels across international borders to receive medical treatment; "individual" means data subject ("an identified or identifiable natural person who is the subject of personal data;") ; "integrated e-Health information system" means a health information system ("a health ecosystem designed to manage health and health related system data that provides the foundations for decision-making and includes a system that collects, collates, stores, manages, analyses, synthesises, transmit patient's or client ’s electronic health record and uses health and health related data for operational management or a system supporting healthcare policy decisions;") that collects health and health related data that addresses the needs of all users for decision making; "Kenya Health Enterprise Architecture" means a blueprint that guides the design, development and evolution of the comprehensive integrated health information system ("a health ecosystem designed to manage health and health related system data that provides the foundations for decision-making and includes a system that collects, collates, stores, manages, analyses, synthesises, transmit patient's or client ’s electronic health record and uses health and health related data for operational management or a system supporting healthcare policy decisions;") to align investments, in technology, information and processes that are cost-effective, sustainable, and aligned with the Kenya health sector strategic goals; "medical equipment data" means data relating to a medical equipment and contains manufacturer-provided information and client ("an individual who uses, or has used, a health service, or in relation to whom health data has been created;") -created inventory information about such equipment and may include exhaust digital data and individual ("data subject;") data that may be classified as sensitive data under the Data Protection Act ( Cap. 411C ); "m-Health" means the delivery of medical services using mobile technologies; "personal data" means any information relating to an identified or identifiable natural person; "personal data breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure ("submission of relevant information to an authorized party;") of, or access to, personal data ("any information relating to an identified or identifiable natural person;") transmitted, stored or otherwise processed; "personal health data" means any information relating to the state of physical or mental health of an identified or identifiable person and includes records on the past, present or future state of that person’s health; "personal health information" means data related to the state of physical or mental health of an individual ("data subject;") and includes information provided by the client ("an individual who uses, or has used, a health service, or in relation to whom health data has been created;") , records regarding the past, present or future state of the health, data collected in the course of registration for, or provision of health services, or data which associates the individual ("data subject;") to the provision of specific health services; "personally identifiable information" means information that can be used to uniquely identify, contact or locate an individual ("data subject;") , or can be used with other sources to uniquely identify a person; "private health services" means provision of health services by a health facility that is not owned by the national or county governments and includes health care services provided by individuals, faith-based organizations, non-governmental organizations and private for profit health institutions; "processing" means any operation or sets of operations which is performed on personal data ("any information relating to an identified or identifiable natural person;") or on sets of personal data ("any information relating to an identified or identifiable natural person;") whether or not by automated means including— (a) collection, recording, organisation or structuring; (b) storage, adaptation or alteration; (c) retrieval, consultation or use; (d) disclosure ("submission of relevant information to an authorized party;") by transmission, dissemination or otherwise making available; or (e) alignment or combination, restriction, erasure or destruction. "pseudo-anonymization" means the processing of personal data ("any information relating to an identified or identifiable natural person;") in such a manner that the personal data ("any information relating to an identified or identifiable natural person;") can no longer be attributed to a specific individual ("data subject;") without the use of additional information, and such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data ("any information relating to an identified or identifiable natural person;") is not attributed to an identified or identifiable natural person; "public health services" means health services owned and offered by the national and county governments; "referral" means the process by which a given health facility transfers a client ("an individual who uses, or has used, a health service, or in relation to whom health data has been created;") service, specimen and client ("an individual who uses, or has used, a health service, or in relation to whom health data has been created;") parameters to another facility to assume responsibility for consultation, review or further management; "research for health" includes research which seeks to contribute to the extension of knowledge in any health related field, such as that concerned with the biological, clinical, psychological or social processes in human beings improved methods for the provision of health services; human pathology; the causes of disease; the effects of the environment on the human body; the development or new application of pharmaceuticals, medicines and other preventative, therapeutic or curative agents; or the development of new applications of health technology ("the application of organized knowledge and skills in the form of devices, medicine, vaccines, procedures and systems developed to solve a health problem and improve the quality of life;") ; "system" means the comprehensive integrated health information system ("a health ecosystem designed to manage health and health related system data that provides the foundations for decision-making and includes a system that collects, collates, stores, manages, analyses, synthesises, transmit patient's or client ’s electronic health record and uses health and health related data for operational management or a system supporting healthcare policy decisions;") established under section 15 ; "system integration" refers to the merging or combining of two or more components or configuration items into a higher level system ("the comprehensive integrated health information system established under;") element and ensuring that the logical and physical interfaces are satisfied and that the integrated system ("the comprehensive integrated health information system established under;") satisfies its intended purpose; "system interoperability" refers to the capability to communicate, execute programs or transfer data among various functional units such that the user needs little or no knowledge of the unique characteristics of those units; "telehealth" means the use of electronic information and telecommunications technologies including video conferencing, the internet, store-and-forward imaging, streaming media, and terrestrial and wireless communications, to support long-distance clinical health care, patient and professional health-related education, public health and health administration; "telemedicine" refers to the provision of health care services and sharing of medical knowledge over distance using telecommunications and includes consultative, diagnostic, and treatment services; and "third party" means natural or legal person, public authority, agency or other body, other than the data subject ("an identified or identifiable natural person who is the subject of personal data;") , data controller ("a natural or legal person, public authority, agency or other body which, alone jointly with others, determines the purpose and means of processing of personal data; or") , data processor ("a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller;") or persons who, under the direct authority of the data controller ("a natural or legal person, public authority, agency or other body which, alone jointly with others, determines the purpose and means of processing of personal data; or") or data processor ("a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller;") , are authorised to process personal data ("any information relating to an identified or identifiable natural person;") . - 3 Verify source ↗
PRELIMINARY - 3. Objects of the Act
Section 3 establishes the Digital Health Agency.
Section 3. Objects of the Act Section establish the Digital Health Agency ("the Digital Health Agency established under;") ; - 4 Verify source ↗
PRELIMINARY - 4. Guiding principles
Declares that health data is a strategic national asset.
Section 4. Guiding principles Section health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") is a strategic national asset;
Part II
ESTABLISHMENT OF THE DIGITAL HEALTH AGENCY
- 10 Verify source ↗
ESTABLISHMENT OF THE DIGITAL HEALTH AGENCY - 10. Committees of theBoard
The Board may establish committees and may co-opt additional persons into committee membership when their knowledge and skills are necessary for the Agency's functions.
Section 10. Committees of theBoard Section 10(1) The Board ("the Board of Directors of the Agency constituted under;") may, from time to time, establish such committees as it considers necessary for the better carrying out of its functions under this Act. Section 10(2) The Board ("the Board of Directors of the Agency constituted under;") may co-opt into the membership of a committee established under sub-section (1) such other person whose knowledge and skills are found necessary for the functions of the Agency ("the Digital Health Agency established under;") . - 11 Verify source ↗
ESTABLISHMENT OF THE DIGITAL HEALTH AGENCY - 11. Chief Executive Officer
The Board must appoint a suitably qualified person as Chief Executive Officer through an open, transparent and competitive recruitment process, and shall determine the CEO's terms and conditions of service in consultation with the Salaries and Remuneration Commission.
Section 11. Chief Executive Officer Section 11(1) The Board ("the Board of Directors of the Agency constituted under;") shall, through an open, transparent and competitive recruitment process, appoint a suitably qualified person to be the Chief Executive Officer of the Agency ("the Digital Health Agency established under;") . Section 11(2) Subject to this Act, the Chief Executive Officer shall be appointed on such terms and conditions of service as shall be determined by the Board ("the Board of Directors of the Agency constituted under;") in the instrument of appointment or otherwise in writing from time to time in consultation with the Salaries and Remuneration Commission. - 12 Verify source ↗
ESTABLISHMENT OF THE DIGITAL HEALTH AGENCY - 12. Qualification for appointment as Chief Executive Officer
Specifies duties and office term for the Chief Executive Officer: responsible for day-to-day management subject to the Board's directions; accounting officer of the Agency; holds office for three years and may be reappointed once for three years.
Section 12. Qualification for appointment as Chief Executive Officer Section 12(1)(a) has a minimum of a master’s degree from a university recognized in Kenya; Section 12(1)(b) has at least ten years' knowledge and experience in health information science, data science, data governance ("the overall management of the availability, usability, integrity and security of data used in an organization;") , health informatics ("the practice of acquiring, studying and managing health data and applying medical concepts in conjunction with health information technology systems to help health professionals provide better healthcare;") , digital health ("the field of knowledge and practice that is associated with the development and use of digital technologies to improve health;") or any other relevant field; Section 12(1)(c) has served in a management level for a period of at least five years; Section 12(1)(d) has not been convicted of an offence and is not serving a term of imprisonment; and Section 12(1)(e) meets the requirements of Chapter Six of the Constitution. Section 12(2) The Chief Executive Officer shall, subject to the directions of the Board ("the Board of Directors of the Agency constituted under;") , be responsible for the day to day management of the affairs and staff of the Board ("the Board of Directors of the Agency constituted under;") . Section 12(3) The Chief Executive Officer shall be the accounting officer of the Agency ("the Digital Health Agency established under;") . Section 12(4) The Chief Executive Officer shall hold office for a period of three years and shall be eligible for reappointment for one further term of three years. - 13 Verify source ↗
ESTABLISHMENT OF THE DIGITAL HEALTH AGENCY - 13. Corporation Secretary
Establishes the office of a Corporation Secretary, sets appointment by the Board on advice from the Salaries and Remuneration Commission, lists required qualifications, and enumerates duties including issuing meeting notices, custody of records, transmitting Board decisions to the Chief Executive Officer, governance guidance, and other duties.
Section 13. Corporation Secretary Section 13(1) There shall be a Corporation Secretary who shall be competitively recruited and appointed by the Board ("the Board of Directors of the Agency constituted under;") on such terms as the Board ("the Board of Directors of the Agency constituted under;") may, on the advice of the Salaries and Remuneration Commission, determine. Section 13(2)(a) holds a bachelor’s degree in law from a university recognized in Kenya; Section 13(2)(b) is an Advocate of the High Court of Kenya; Section 13(2)(c) has at least five years’ experience as a corporation secretary or a similar governance role; Section 13(2)(d) is a member in good standing of the Institute of Certified Secretaries of Kenya; and Section 13(2)(e) meets the requirements of Chapter Six of the Constitution. Section 13(3)(a) in consultation with the Chairperson of the Board ("the Board of Directors of the Agency constituted under;") , issue notices for meetings of the Board ("the Board of Directors of the Agency constituted under;") ; Section 13(3)(b) keep in custody, the records of the deliberations, decisions, and resolutions of the Board ("the Board of Directors of the Agency constituted under;") ; Section 13(3)(c) transmit decisions and resolutions of the Board ("the Board of Directors of the Agency constituted under;") to the Chief Executive Officer for execution, implementation and other relevant action; Section 13(3)(d) provide guidance to the Board ("the Board of Directors of the Agency constituted under;") on their duties and responsibilities on matters relating to governance; Section 13(3)(e) perform such other duties as the Board ("the Board of Directors of the Agency constituted under;") may direct. - 14 Verify source ↗
ESTABLISHMENT OF THE DIGITAL HEALTH AGENCY - 14. Staff
The Board may appoint staff as necessary for the Agency and set their terms of service on the advice of the Salaries and Remuneration Commission.
Section 14. Staff Section The Board ("the Board of Directors of the Agency constituted under;") may appoint such staff as may be necessary for the proper discharge of the functions of the Agency ("the Digital Health Agency established under;") under this Act, upon such terms and conditions of service as the Board ("the Board of Directors of the Agency constituted under;") may determine upon the advice of the Salaries and Remuneration Commission. - 5 Verify source ↗
ESTABLISHMENT OF THE DIGITAL HEALTH AGENCY - 5. Establishment of the Digital HealthAgency
Establishes the Digital Health Agency and grants it powers including suing and being sued; acquiring and disposing of movable and immovable property; receiving, investing and borrowing money; and performing other acts necessary for its functions.
Section 5. Establishment of the Digital HealthAgency Section 5(1) There is established an Agency ("the Digital Health Agency established under;") to be known as the Digital Health Agency ("the Digital Health Agency established under;") . Section 5(2)(a) suing and being sued; Section 5(2)(b) taking, purchasing or otherwise acquiring, holding, charging and disposing of movable and immovable property; Section 5(2)(c) receiving, investing, borrowing money; and Section 5(2)(d) doing or performing such other things or acts necessary for the proper performance of its functions under this Act. - 6 Verify source ↗
ESTABLISHMENT OF THE DIGITAL HEALTH AGENCY - 6. Functions of theAgency
The Agency must develop, operationalise and maintain the Comprehensive Integrated Health Information System to manage core digital systems and the infrastructure required for seamless health information exchange.
Section 6. Functions of theAgency Section develop, operationalise and maintain the Comprehensive Integrated Health Information System to manage the core digital systems and the infrastructure required for its seamless health information exchange; - 7 Verify source ↗
ESTABLISHMENT OF THE DIGITAL HEALTH AGENCY - 7. Powers of theAgency
The Board of Directors is responsible for managing and administering the Digital Health Agency, including managing assets, entering into associations, and investing surplus funds; it may not dispose of immovable property without the National Assembly's prior approval.
Section 7. Powers of theAgency Section 7(1) The Board ("the Board of Directors of the Agency constituted under;") shall be responsible for the management and administration of the Agency ("the Digital Health Agency established under;") . Section 7(2)(a) manage, control and administer the assets of the Agency ("the Digital Health Agency established under;") in such manner and for such purpose as best promotes the objects for which the Agency ("the Digital Health Agency established under;") is established in accordance with the Public Procurement and Assets Disposal Act ( Cap. 412C ): Provided that the Agency ("the Digital Health Agency established under;") shall not charge or dispose of any immovable property without the prior approval of the National Assembly; Section 7(2)(b) enter into association with such other bodies or organizations, within or outside Kenya, as it may consider desirable or appropriate and in furtherance of the purpose for which the Agency ("the Digital Health Agency established under;") is established; and Section 7(2)(c) invest the funds of the Agency ("the Digital Health Agency established under;") not immediately required for its purposes in the manner provided in this Act. - 8 Verify source ↗
ESTABLISHMENT OF THE DIGITAL HEALTH AGENCY - 8.Boardof Directors
Section 8 establishes the Board of Directors of the Digital Health Agency, lists members (including an appointed non-executive chairperson, Principal Secretaries or designated representatives, the Data Commissioner, a private-sector appointee, nominees from the Council of County Governors, and the CEO as ex‑officio), sets terms of three years with one reappointment, requires equal opportunity in some appointments, lists grounds for vacancy/removal, allows co‑option, and provides for payment of directors as determined by the Cabinet Secretary on SRC advice.
Section 8.Boardof Directors Section 8(1)(a) a non-executive chairperson who shall be appointed by the President; Section 8(1)(b) the Principal Secretary responsible for Health or a representative designated in writing; Section 8(1)(c) the Principal Secretary responsible for the National Treasury or a representative designated in writing; Section 8(1)(d) the Principal Secretary responsible for Information, Communication and Technology or a representative designated in writing; Section 8(1)(e) the Data Commissioner or a representative designated in writing; Section 8(1)(f) one person representing the private sector appointed by the Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") ; Section 8(1)(g) three persons, not being Governors, nominated by the Council of County Governors with knowledge and experience in matters of digital health ("the field of knowledge and practice that is associated with the development and use of digital technologies to improve health;") ; and Section 8(1)(h) the Chief Executive Officer, who shall be an ex-officio member of the Board ("the Board of Directors of the Agency constituted under;") . Section 8(2) The Chairperson of the Board ("the Board of Directors of the Agency constituted under;") and the members appointed under subsection (1) (f) and (g) shall serve for a term of three years and shall be eligible for re-appointment for one further term of three years. Section 8(3) In appointing persons as members of the Board ("the Board of Directors of the Agency constituted under;") under subsection (1)(f) and (g), the Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") shall ensure that the appointments afford equal opportunity to men and women, youth, persons with disabilities, minorities and marginalized groups and ensure regional balance. Section 8(4)(a) resigns in writing addressed to the Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") ; Section 8(4)(b) is adjudged bankrupt; Section 8(4)(c) is absent from three consecutive meetings without the permission of the Chairperson; Section 8(4)(d) is convicted of a criminal offence and sentenced to imprisonment for a term exceeding six months; or Section 8(4)(e) is unable to perform the functions of his office by reason of mental or physical infirmity. Section 8(5)(a) incompetence or neglect of duty; Section 8(5)(b) gross misconduct whether in the performance of the members’ functions or otherwise; or Section 8(5)(c) violation of the Constitution or any other written law. Section 8(6) The Agency ("the Digital Health Agency established under;") shall pay to the directors such remuneration, fees or allowances for expenses as may be determined by the Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") on the advice of the Salaries and Remuneration Commission. Section 8(7) The Board ("the Board of Directors of the Agency constituted under;") may co-opt any other person with necessary expertise as it may deem necessary to assist the Board ("the Board of Directors of the Agency constituted under;") in discharging its duties and responsibilities. - 9 Verify source ↗
ESTABLISHMENT OF THE DIGITAL HEALTH AGENCY - 9. Conduct of business and affairs of theBoard
The Board shall regulate its own procedure, except as provided in the Schedule.
Section 9. Conduct of business and affairs of theBoard Section Except as provided in the Schedule, the Board ("the Board of Directors of the Agency constituted under;") shall regulate its own procedure.
Part III
THE ESTABLISHMENT AND ADMINISTRATION OF THE COMPREHENSIVE INTEGRATED HEALTH INFORMATION SYSTEM
- 15 Verify source ↗
THE ESTABLISHMENT AND ADMINISTRATION OF THE COMPREHENSIVE INTEGRATED HEALTH INFORMATION SYSTEM - 15. Establishment of a comprehensive integrated health information system
Establishes a comprehensive integrated health information system to be administered by the Agency; the Agency must, in consultation with the Cabinet Secretary, set up an administrative framework and ensure the system's integrity and security. The system collects, stores, analyses and shares health-related data.
Section 15. Establishment of a comprehensive integrated health information system Section 15(1) There is established a system to be known as the comprehensive integrated health information system which shall be administered by the Agency. Section 15(2) The Agency shall, in consultation with the Cabinet Secretary, establish a framework for administration and management of the system and shall ensure the maintenance of the integrity and security of the system. Section 15(3) The system shall operate as a point of collection, collation, analysis, reporting, storage, usage, sharing, retrieval or archival of data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health, data collected in the course of registration for, or provision of health services, or data which associates the data subject to the provision of specific health services. - 16 Verify source ↗
THE ESTABLISHMENT AND ADMINISTRATION OF THE COMPREHENSIVE INTEGRATED HEALTH INFORMATION SYSTEM - 16. Components of the System
Lists components of the Information and Communication Technology environment, including the underlying infrastructure, an enterprise service bus, standards, data banks, data exchange, governance, actors and applications, an internet-enabled environment, and other related components.
Section 16. Components of the System Section an Information and Communication Technology environment which consists of the underlying infrastructure, enterprise service bus ("an architectural pattern whereby a centralized software component performs integrations between applications; transformations of data models, handles connectivity, message routing, converts communication protocols and potentially manages the composition of multiple requests and may make these integrations and transformations available as a service interface for reuse by new applications;") , standards, data banks, data exchange, governance, actors and applications, internet enabled environment, and other related components; - 17 Verify source ↗
THE ESTABLISHMENT AND ADMINISTRATION OF THE COMPREHENSIVE INTEGRATED HEALTH INFORMATION SYSTEM - 17. Objectives of thesystem
Objective: facilitate people-centred quality health service delivery.
Section 17. Objectives of thesystem Section facilitate people-centred quality health service delivery; - 18 Verify source ↗
THE ESTABLISHMENT AND ADMINISTRATION OF THE COMPREHENSIVE INTEGRATED HEALTH INFORMATION SYSTEM - 18. Technical aspect of thesystem
The Agency (the Digital Health Agency) must adopt internationally accepted standards, procedures, technical details, best practices and formalities to implement the comprehensive integrated health information system, addressing specified technical aspects.
Section 18. Technical aspect of thesystem Section 18(1) The Agency ("the Digital Health Agency established under;") shall adopt relevant internationally accepted standards, procedures, technical details, best practices, and formalities for effective implementation of the system ("the comprehensive integrated health information system established under;") . Section 18(2)(a) confidentiality, security and privacy; Section 18(2)(b) scalability and interoperability; Section 18(2)(c) accuracy, responsiveness and reliability; Section 18(2)(d) efficiency and effectiveness; Section 18(2)(e) redundancy; Section 18(2)(f) transparency; Section 18(2)(g) simplicity and accessibility; and Section 18(2)(h) consistency in use.
Part IV
HEALTH DATA GOVERNANCE
- 19 Verify source ↗
HEALTH DATA GOVERNANCE - 19. Classification ofhealth data
Defines "sensitive personal level health data" as data related to the physical or mental health of a data subject, including past, present or future health records, data collected during registration or provision of health services, or data associating the subject with specific health services.
Section 19. Classification ofhealth data Section sensitive personal level health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") ; - 20 Verify source ↗
HEALTH DATA GOVERNANCE - 20. Governing principles.
Sets governing principles for health data governance: improvement of client health; data security across the data life-cycle; equity and accountability; privacy and confidentiality; and accuracy and reliability.
Section 20. Governing principles. Section 20(1)(a) improvement of client ("an individual who uses, or has used, a health service, or in relation to whom health data has been created;") health, safeguard of individuals and communities against harm and violations; Section 20(1)(b) data security ("protection of electronic health data, and specifically the means used to protect the privacy of health information contained in electronic health data that supports professionals in holding that information in confidence;") throughout the entire data life-cycle; Section 20(1)(c) equity and accountability; Section 20(1)(d) privacy and confidentiality; and Section 20(1)(e) accuracy and reliability. - 21 Verify source ↗
HEALTH DATA GOVERNANCE - 21. Establishment ofhealth datagovernance framework
The Cabinet Secretary must, in consultation with the Director-General, establish a health data governance framework and the provision requires reporting of designated health data by health data controllers and processors in approved formats and platforms.
Section 21. Establishment ofhealth datagovernance framework Section 21(1) The Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") shall, in consultation with the Director-General , establish a health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") governance framework. Section 21(2)(a) develop guidelines to promote effective use of legacy data including data migration; Section 21(2)(b) establish standards for integration, interoperability and exchange of health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") ; Section 21(2)(c) ensure regular update and availability of the national health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") dictionary for utilization within the system ("the comprehensive integrated health information system established under;") ; Section 21(2)(d) establish standards for and conduct routine data quality checks in the system ("the comprehensive integrated health information system established under;") ; Section 21(2)(e) ensure the security and accountability of data for the system ("the comprehensive integrated health information system established under;") while promoting appropriate data use and sharing; Section 21(2)(f) provide guidance on the integration and interoperability of all health information systems into the system ("the comprehensive integrated health information system established under;") per set standards; and Section 21(2)(g) require all health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") controllers and processors to report designated health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") in accordance with ministry of health in the approved and prescribed formats and platforms. - 22 Verify source ↗
HEALTH DATA GOVERNANCE - 22. Healthdatacustodian
The Digital Health Agency shall be the custodian for all health data in Kenya.
Section 22. Healthdatacustodian Section The Agency ("the Digital Health Agency established under;") shall be the custodian for all health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") in Kenya. - 23 Verify source ↗
HEALTH DATA GOVERNANCE - 23. Healthdatause
The Cabinet Secretary must ensure health data is used for the public good; the Digital Health Agency must provide health data to the Cabinet Secretary for relevant action.
Section 23. Healthdatause Section 23(1) The Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") shall ensure that Health data use is used for public good. Section 23(2) The Agency ("the Digital Health Agency established under;") shall provide health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") to the Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") for relevant action.
Part IX
FINANCIAL PROVISIONS
- 48 Verify source ↗
FINANCIAL PROVISIONS - 48. Funds of theAgency
The Agency's funds include monies appropriated by the National Assembly, monies or assets accruing to the Agency, levy fees for services, monies from other sources provided or given as grants, and any other funds designated for or accruing to the Agency; the funds are to be used to pay expenditure and administrative expenses necessary for the Agency to discharge its functions.
Section 48. Funds of theAgency Section 48(1)(a) monies appropriated by the National Assembly for the purposes of the Agency ("the Digital Health Agency established under;") ; Section 48(1)(b) such monies or assets as may accrue to the Agency ("the Digital Health Agency established under;") in the course of the exercise of its powers or in the performance of its functions under this Act; Section 48(1)(c) such levy fees for services rendered by the Agency ("the Digital Health Agency established under;") ; Section 48(1)(d) monies from any other source provided, donated, lent or given as a grant to the Agency ("the Digital Health Agency established under;") ; and Section 48(1)(e) any other funds designated for or accruing to the Agency ("the Digital Health Agency established under;") by virtue of the operation of law. Section 48(2) There shall be paid out of the funds of the Agency ("the Digital Health Agency established under;") , all expenditure incurred, administrative expenses or for such other purposes as may be necessary for the discharge of the functions of the Agency ("the Digital Health Agency established under;") in the exercise of its powers or the performance of its functions under this Act. - 49 Verify source ↗
FINANCIAL PROVISIONS - 49. Financial year
The financial year of the Agency shall be the period of twelve months ending on the thirtieth day of June in each year.
Section 49. Financial year Section The financial year of the Agency ("the Digital Health Agency established under;") shall be the period of twelve months ending on the thirtieth day of June in each year. - 50 Verify source ↗
FINANCIAL PROVISIONS - 50. Annual estimates
The Chief Executive Officer must prepare annual revenue and expenditure estimates; the Board must approve them before the financial year and the CEO must submit them to be tabled in the National Assembly; approved estimates must not be amended before tabling.
Section 50. Annual estimates Section 50(1) Before the commencement of each financial year, the Chief Executive Officer shall cause to be prepared estimates of the revenue and expenditure of the Agency ("the Digital Health Agency established under;") for that year. Section 50(2)(a) payment of salaries, allowances, gratuities, pensions and other charges in respect of the members of the Board ("the Board of Directors of the Agency constituted under;") and Agency ("the Digital Health Agency established under;") ; Section 50(2)(b) maintenance of buildings and grounds of the Agency ("the Digital Health Agency established under;") ; and Section 50(2)(c) funding of training, research and development of activities in relation to the organization and functioning of the Agency ("the Digital Health Agency established under;") . Section 50(3) The annual estimates shall be approved by the Board ("the Board of Directors of the Agency constituted under;") before the commencement of the financial year to which they relate, and shall be submitted by the Chief Executive Officer for tabling in the National Assembly. Section 50(4) The annual estimates, once approved by the Board ("the Board of Directors of the Agency constituted under;") , shall not be amended before being tabled in the National Assembly. Section 50(5) No expenditure shall be incurred for the purposes of the Agency ("the Digital Health Agency established under;") except in accordance with the annual estimates approved under subsection (3). - 51 Verify source ↗
FINANCIAL PROVISIONS - 51. Accounts and Audit
The Board of Directors of the Agency must keep proper audit books and records of the Agency's income, expenditure, assets and liabilities; the Agency's accounts are to be audited and reported in accordance with the Public Finance Management Act (Cap. 412A) and the Public Audit Act (Cap. 412B).
Section 51. Accounts and Audit Section 51(1) The Board ("the Board of Directors of the Agency constituted under;") shall cause to be kept all proper audit books and records of accounts of the income, expenditure, assets and liabilities of the Agency ("the Digital Health Agency established under;") . Section 51(2) The accounts of the Agency ("the Digital Health Agency established under;") shall be audited and reported upon in accordance with the Public Finance Management Act ( Cap. 412A ) and the Public Audit Act ( Cap. 412B ). - 52 Verify source ↗
FINANCIAL PROVISIONS - 52. Annual report
The Chief Executive Officer must prepare an annual report on the Agency's activities at the end of each financial year.
Section 52. Annual report Section 52(1) At the end of each financial year, the Chief Executive Officer shall prepare an annual report on the activities of Agency ("the Digital Health Agency established under;") . Section 52(2) The annual report shall be submitted for tabling in the National Assembly not later than one month after the submission of the Auditor-General’s report. Section 52(3)(a) the financial statements of the Agency ("the Digital Health Agency established under;") ; Section 52(3)(b) a description of the activities and outcomes of functioning of the Agency ("the Digital Health Agency established under;") ; and Section 52(3)(c) any other information that the Agency ("the Digital Health Agency established under;") may consider relevant. - 53 Verify source ↗
FINANCIAL PROVISIONS - 53. Bank account
The Chief Executive Officer may open bank accounts for the Agency with Board and National Treasury approval and, as accounting officer, shall be responsible for proper management of the Agency's finances.
Section 53. Bank account Section The Chief Executive Officer may, in accordance with the law relating to the management of public finance, open bank accounts on behalf of the Agency ("the Digital Health Agency established under;") with the approval of the Board ("the Board of Directors of the Agency constituted under;") and the National Treasury and shall, as the accounting officer, be responsible for the proper management of the finances of the Agency ("the Digital Health Agency established under;") . - 54 Verify source ↗
FINANCIAL PROVISIONS - 54. Investment of Funds
Permitted investments include deposits in a reputable bank on the advice of the Central Bank of Kenya and government securities approved by the National Treasury; all investments under this section shall be held in the name of the Agency.
Section 54. Investment of Funds Section 54(1)(a) in such investment in a reputable bank on the advice of the Central Bank of Kenya, being an investment in which trust funds, or part thereof, are authorized by law to be invested; and Section 54(1)(b) in government securities as may be approved by the National Treasury. Section 54(2) All investments made under this section shall be held in the name of the Agency.
Part V
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA
- 24 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 24. Security, privacy anddisclosureofdatain thesystem
The Cabinet Secretary responsible for health must ensure the confidentiality, privacy and security of sensitive personal data in the integrated health information system; the Cabinet Secretary is also the data controller for research and planning uses of that system's data and must ensure privacy during data processing.
Section 24. Security, privacy anddisclosureofdatain thesystem Section 24(1) The Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") shall be responsible for the confidentiality, privacy and security of all sensitive personal data ("any information relating to an identified or identifiable natural person;") held in the system ("the comprehensive integrated health information system established under;") . Section 24(2)(a) the data subject ("an identified or identifiable natural person who is the subject of personal data;") is unable to give informed consent for the disclosure ("submission of relevant information to an authorized party;") and such consent is given by a person authorised by the data subject ("an identified or identifiable natural person who is the subject of personal data;") in writing to grant consent ; Section 24(2)(b) the disclosure ("submission of relevant information to an authorized party;") has been authorised by the implementation of written law or the enforcement of a court order; Section 24(2)(c) a health service without informed consent as authorised by written law or court order is being provided; Section 24(2)(d) the data subject ("an identified or identifiable natural person who is the subject of personal data;") is being treated in an emergency situation; Section 24(2)(e) failure to treat the data subject ("an identified or identifiable natural person who is the subject of personal data;") , or a group of people which includes the data subject ("an identified or identifiable natural person who is the subject of personal data;") , would result in a serious risk to public health; or Section 24(2)(f) a delay in providing a health service to the data subject ("an identified or identifiable natural person who is the subject of personal data;") may result in death or irreversible damage to the health of the data subject ("an identified or identifiable natural person who is the subject of personal data;") and the data subject ("an identified or identifiable natural person who is the subject of personal data;") has not expressly, by implication or by conduct refused that service. Section 24(3) The Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") shall be responsible for the privacy of the data held in the system ("the comprehensive integrated health information system established under;") during all the data . Section 24(4) Where the data held in the system ("the comprehensive integrated health information system established under;") data is intended to be used for research and planning, the Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") shall be the data controller ("a natural or legal person, public authority, agency or other body which, alone jointly with others, determines the purpose and means of processing of personal data; or") for the purposes of section 53 of the Data Protection Act ( Cap. 411C ). Section 24(5)(a) personalised authentication and log-in credentials; Section 24(5)(b) role based user rights; Section 24(5)(c) audit trails for all activities within the system ("the comprehensive integrated health information system established under;") ; Section 24(5)(d) digital and physical security of the system ("the comprehensive integrated health information system established under;") ; and Section 24(5)(e) an encrypted backup that is subject to the security measures herein. - 25 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 25. Retention and disposal ofdatainsystem
Data held in the comprehensive integrated health information system must be maintained for a minimum period of twenty years.
Section 25. Retention and disposal ofdatainsystem Section 25(1) Data held in the system ("the comprehensive integrated health information system established under;") shall be maintained for a minimum period of twenty years. Section 25(2)(a) it is required or authorised by law; Section 25(2)(b) it is authorised by the data subject ("an identified or identifiable natural person who is the subject of personal data;") ; or Section 25(2)(c) it is reasonably necessary for a lawful purpose; Section 25(2)(d) for historical, statistical or research purposes. Section 25(3) Where the period for the maintenance of the data held in the system ("the comprehensive integrated health information system established under;") is not extended under subsection (2), the data shall be secured by de-identification , anonymization ("the removal of personal identifiers from personal data so that the data subject is no longer identifiable;") , pseudo-anonymization or archiving, or establishing such technical and organisational security measures as the Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") may determine to be necessary. - 26 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 26. Establishment of health data banks
Data controllers must transmit sensitive health data to the national and county health information data banks in secure, encrypted form and must keep records of such transmissions.
Section 26. Establishment of health data banks Section 26(1)(a) establish a national health data bank and designate county health data banks; Section 26(1)(b) store the health data submitted to the system in the national health data bank; and Section 26(1)(c) establish seamless integration and interoperability of the national health data bank with other relevant databases. Section 26(2)(a) establish county health databanks; Section 26(2)(b) store the health data submitted to the system in the county health data bank; and Section 26(2)(c) establish seamless integration and interoperability of the county health data bank with other relevant databases and data banks. Section 26(3) The health information databases and data banks referred to in subsections (1) and (2) shall be established at the different levels of healthcare delivery specified under section 25 of the Health Act ( Cap. 241 ). Section 26(4) A data controller shall transmit health data containing sensitive personal data to the national health information data bank and county health information data bank in a secure and encrypted form. Section 26(5) A data controller shall maintain records of the health data containing sensitive personal data transmitted to the national health information data bank and county health information data bank under subsection(4). - 27 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 27. Use of sensitivepersonal data
Section 27 concerns use of sensitive personal data to identify a person who needs or is receiving a health service.
Section 27. Use of sensitivepersonal data Section identify a person who needs or is receiving a health service; - 28 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 28. Responsibilities ofhealth databank controller
The health databank controller must take reasonable measures to ensure that agents, data controllers or processors do not collect, use, disclose, retain or dispose of sensitive personal data unless in accordance with the law.
Section 28. Responsibilities ofhealth databank controller Section take reasonable measures to ensure that no agent or the data controller ("a natural or legal person, public authority, agency or other body which, alone jointly with others, determines the purpose and means of processing of personal data; or") or processor collects, uses, discloses, retains or disposes of sensitive personal data ("any information relating to an identified or identifiable natural person;") unless it is in accordance with the law; and - 29 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 29. Request for information by authorized person
A person authorised by the data controller to enter sensitive personal data into the comprehensive integrated health information system must ensure compliance with section 24 (2) of this Act.
Section 29. Request for information by authorized person Section A person authorised by the data controller ("a natural or legal person, public authority, agency or other body which, alone jointly with others, determines the purpose and means of processing of personal data; or") to enter sensitive personal data ("any information relating to an identified or identifiable natural person;") into the system ("the comprehensive integrated health information system established under;") shall ensure compliance with section 24 (2) of this Act. - 30 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 30. Disclosure of sensitivepersonal datadeceased persons
Disclosure may be for identifying the person, informing a person it is reasonable to inform in the circumstances, or investigating the cause of death; a request under subsection (1) must be made as provided under the relevant law.
Section 30. Disclosure of sensitivepersonal datadeceased persons Section 30(1)(a) identifying the person; Section 30(1)(b) informing a person to whom it is reasonable to inform in the circumstances of; or Section 30(1)(c) investigating the cause of death. Section 30(2) A request under subsection (1) shall be made as provided under the relevant law. - 31 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 31. Consent
Healthcare providers must obtain consent before processing sensitive personal data; data subjects may withdraw consent at any time by notifying the provider.
Section 31. Consent Section 31(1) A healthcare provider shall ensure that he or she has obtained consent to process sensitive personal data ("any information relating to an identified or identifiable natural person;") . Section 31(2)(a) for public health in accordance with the Public Health Act ( Cap. 242 ); and Section 31(2)(b) in compliance with any other statutory requirements. Section 31(3)(a) ensure confidentiality of the information of the client ("an individual who uses, or has used, a health service, or in relation to whom health data has been created;") ; Section 31(3)(b) provide prompt and accurate data necessary for treatment of the patient; Section 31(3)(c) comply with the duty to notify the data subject ("an identified or identifiable natural person who is the subject of personal data;") in accordance with the Data Protection Act ( Cap. 411C ); Section 31(4) A data subject ("an identified or identifiable natural person who is the subject of personal data;") who has issued a consent to the use or disclosure ("submission of relevant information to an authorized party;") of personal data ("any information relating to an identified or identifiable natural person;") may withdraw their consent at any time by notifying the health care provider . - 32 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 32. Processing ofpersonal datarelating to a minor or a person without capacity
If the data subject is a minor or lacks capacity to give informed written consent, the parent, appointed guardian, or next friend must act on the subject's behalf and in their best interest for purposes of section 31(1).
Section 32. Processing ofpersonal datarelating to a minor or a person without capacity Section Where a data subject ("an identified or identifiable natural person who is the subject of personal data;") is a minor or for any other reason does not have the capacity to issue informed written consent , the parent, an appointed guardian ("a guardian recognised under any law for the time being in force;") or next friend of the patient shall, for purposes of section 31 (1), act on behalf of, and in the best interest of, the patient in accordance with the law. - 33 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 33. Duty to protect sensitivepersonal data
A data controller must protect sensitive personal data and put in place reasonable administrative, technical and physical safeguards to ensure privacy, confidentiality, security, accuracy and integrity.
Section 33. Duty to protect sensitivepersonal data Section 33(1) A data controller ("a natural or legal person, public authority, agency or other body which, alone jointly with others, determines the purpose and means of processing of personal data; or") shall protect sensitive personal data ("any information relating to an identified or identifiable natural person;") and adopt reasonable administrative, technical and physical safeguards to ensure the privacy, confidentiality, security, accuracy and integrity of the data . Section 33(2)(a) the identity of the person seeking to use the information is verified; Section 33(2)(b) the data processor ("a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller;") is authorized to use it; and Section 33(2)(c) the proposed use is authorised under this Act. - 34 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 34. Disposal of health information
The Cabinet Secretary responsible for health must develop regulations for disposing of sensitive personal data.
Section 34. Disposal of health information Section The Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") shall develop regulations for the disposal of sensitive personal data ("any information relating to an identified or identifiable natural person;") . - 35 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 35. Breach ofhealth data
Section 35 lists specific acts in subsection (1) (tampering with, abusing, disclosing, disposing, losing, stealing, or sharing sensitive personal data) as offences and prescribes on conviction a fine not exceeding one million shillings or imprisonment not exceeding fifteen years or both; sensitive-personal-data offences reference penalties under section 73 of the Data Protection Act.
Section 35. Breach ofhealth data Section 35(1)(a) tampers with the data ; Section 35(1)(b) abuses a privilege; Section 35(1)(c) discloses inauthentic access to the data ; Section 35(1)(d) improperly disposes of unnecessary but sensitive data ; Section 35(1)(e) loses data ; Section 35(1)(f) steals data ; or Section 35(1)(g) shares sensitive personal data ("any information relating to an identified or identifiable natural person;") to an unauthorised party. Section 35(2) A person who commits an offence under subsection (1) shall be liable, on conviction, to a fine not exceeding one million shillings or to imprisonment for a term not exceeding fifteen years, or to both. Section 35(3) Where a person commits an offence under subsection (1) with respect to sensitive personal data ("any information relating to an identified or identifiable natural person;") , that person shall be liable, on conviction, to the penalties under section 73 of the Data Protection Act ( Cap. 411C ). - 36 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 36. Health Data Portability
A person has a right, on request, to examine and receive a copy of their personal health information held by a data controller; requests must be in writing to the relevant health facility or health information bank; health data controllers must comply with section 38 of the Data Protection Act to enable access and portability.
Section 36. Health Data Portability Section 36(1) Subject to this Act, a person has a right, on request, to examine and receive a copy of his or her personal health information ("data related to the state of physical or mental health of an individual and includes information provided by the client, records regarding the past, present or future state of the health,data collected in the course of registration for, or provision of health services, or data which associates the individual to the provision of specific health services;") maintained by a data controller ("a natural or legal person, public authority, agency or other body which, alone jointly with others, determines the purpose and means of processing of personal data; or") . Section 36(2) A request under subsection (1) shall be made in writing to the relevant health facility or health information bank ("an electronic database under the custody and control of the Ministry of Health that contains personal health information and is designated by the Cabinet Secretary as a health information bank;") . Section 36(3) The health data controller ("a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purpose and means of processing of health data;") shall comply with the provisions of section 38 of the Data Protection Act ( Cap. 411C ) in enabling access and portability of personal health records. - 37 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 37. Refusal to grant access to sensitivepersonal data
Refusal to grant access to sensitive personal data when access is restricted by a court process, order or judgement.
Section 37. Refusal to grant access to sensitivepersonal data Section access is restricted by a court process, order or judgement; - 38 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 38. Precautions on release of sensitivepersonal health data
A health data controller must not disclose personal health information from a health data information bank for market research.
Section 38. Precautions on release of sensitivepersonal health data Section 38(1)(a) be satisfied as to the identity of the person making the request; and Section 38(1)(b) where the data subject ("an identified or identifiable natural person who is the subject of personal data;") is a minor, by a person who has parental authority or by a guardian ("a guardian recognised under any law for the time being in force;") ; Section 38(1)(b)(i) where the data subject ("an identified or identifiable natural person who is the subject of personal data;") is a minor, by a person who has parental authority or by a guardian ("a guardian recognised under any law for the time being in force;") ; Section 38(1)(b)(ii) where the data subject ("an identified or identifiable natural person who is the subject of personal data;") has a mental or other disability, by a person duly authorised to act their guardian ("a guardian recognised under any law for the time being in force;") or administrator; or Section 38(1)(b)(iii) in any other case, by a person duly authorised by the data subject ("an identified or identifiable natural person who is the subject of personal data;") or by a court order. Section 38(2) A health data controller ("a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purpose and means of processing of health data;") shall not disclose, for the purpose of market research, personal health information ("data related to the state of physical or mental health of an individual and includes information provided by the client, records regarding the past, present or future state of the health,data collected in the course of registration for, or provision of health services, or data which associates the individual to the provision of specific health services;") that is contained in a health data ("data related to the state of physical or mental health of the data subject and includes records regarding the past, present or future state of the health,data collected in the course of registration for or provision of health services or data which associates the data subject to the provision of specific health services;") information bank. - 39 Verify source ↗
CONFIDENTIALITY, PRIVACY AND SECURITY OF DATA - 39. Right to rectification or erasure
Right to rectify, without undue delay, personal data in its possession or under its control that is inaccurate, outdated, incomplete or misleading.
Section 39. Right to rectification or erasure Section rectify, without undue delay, personal data ("any information relating to an identified or identifiable natural person;") in its possession or under its control that is inaccurate, outdated, incomplete or misleading; or
Part VI
E-HEALTH SERVICE DELIVERY
- 40 Verify source ↗
E-HEALTH SERVICE DELIVERY - 40. E-Health as a mode of health service delivery
E-Health shall be a recognized model of health service delivery (Section 40(1)).
Section 40. E-Health as a mode of health service delivery Section 40(1) E-Health shall be a recognized model of health service delivery. Section 40(2) E-Health Services shall be complementary to existing healthcare service delivery modalities. - 41 Verify source ↗
E-HEALTH SERVICE DELIVERY - 41. Provision ofe-Healthservices
Section 41 defines e-health services, lists who may be recognised to provide them, and requires the Cabinet Secretary to develop standards and guidelines for the e-Health platform.
Section 41. Provision ofe-Healthservices Section 41(1)(a) telemedicine ("the provision of health care services and sharing of medical knowledge over distance using telecommunications and includes consultative, diagnostic, and treatment services; and") ; Section 41(1)(b) electronic health records; Section 41(1)(c) m-health; Section 41(1)(d) e-learning; Section 41(1)(e) telehealth ("the use of electronic information and telecommunications technologies including video conferencing, the internet, store-and-forward imaging, streaming media, and terrestrial and wireless communications, to support long-distance clinical health care, patient and professional health-related education, public health and health administration;") ; and Section 41(1)(f) any other recognized e-health service. Section 41(2)(a) a healthcare provider holding a valid licence issued by a relevant regulatory body; Section 41(2)(b) a healthcare provider holding a valid licence from an equivalent regulatory authority outside Kenya but shall be recognized by the local regulatory authority; Section 41(2)(c) a health facility licenced to offer e-health services by the relevant regulatory body; or Section 41(2)(d) for foreign facilities, be licenced by an equivalent regulatory authority recognized in Kenya. Section 41(3) The Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") shall develop standards and guidelines for the e-Health platform . - 42 Verify source ↗
E-HEALTH SERVICE DELIVERY - 42. Principles and objectives of e-health
The e-Health service shall be an integral part of health service delivery to benefit people in a manner that is ethical, safe, secure, reliable, equitable and sustainable.
Section 42. Principles and objectives of e-health Section 42(1) The e-Health service shall be an integral part of health service delivery to benefit people in a manner that is ethical, safe, secure, reliable, equitable and sustainable. Section 42(2)(a) promote patient-centred health care services ; Section 42(2)(b) ensure equitable access to quality health care services using Information and Communication Technology; Section 42(2)(c) promote the integration of e-health into the healthcare system ("the comprehensive integrated health information system established under;") ; Section 42(2)(d) facilitate the integration of e-health solutions; and Section 42(2)(e) promote the use of e-health solutions. - 43 Verify source ↗
E-HEALTH SERVICE DELIVERY - 43. E-health services
Section 43 lists duties and requirements for e-health services including providing clients with management information, access to their records, managing data as prescribed by law, delivering high-quality care, ensuring agents adhere to the Act, platform interoperability, and obtaining guardian or parent consent for minors and mentally ill persons.
Section 43. E-health services Section 43(1)(a) provide the client ("an individual who uses, or has used, a health service, or in relation to whom health data has been created;") with all the information for the management of his or her health; Section 43(1)(b) ensure the client ("an individual who uses, or has used, a health service, or in relation to whom health data has been created;") can access their own health records where necessary; Section 43(1)(c) ensure the client ("an individual who uses, or has used, a health service, or in relation to whom health data has been created;") ’s data is managed as prescribed in the law; Section 43(1)(d) ensure the highest possible quality of care is delivered; Section 43(1)(e) ensure that the agents of the e-health service provider adhere to the provisions of this Act; Section 43(1)(f) ensure the platform used is interoperable with the system ("the comprehensive integrated health information system established under;") ; Section 43(1)(g) ensure that when e-health service delivery involves a minor, the consent of the parent or an appointed guardian ("a guardian recognised under any law for the time being in force;") is obtained; and Section 43(1)(h) ensure that when e-health service delivery involves a mentally ill person, the consent of an appointed guardian ("a guardian recognised under any law for the time being in force;") or next friend of the patient is obtained. Section 43(2) The use of e-health service platforms to share the information of a patient including images and lab results for consultation and training shall adhere to the standards prescribed by law. - 44 Verify source ↗
E-HEALTH SERVICE DELIVERY - 44. Reporting
E-health service providers must meet their reporting obligations when delivering e-health services.
Section 44. Reporting Section In the delivery of e-health services, it shall be the responsibility of the e-health service provider to meet their reporting obligations in accordance with the provisions of this Act.
Part VII
E-WASTE MANAGEMENT
- 45 Verify source ↗
E-WASTE MANAGEMENT - 45. E-waste management
Section 45 requires development of guidelines for safe handling and disposal of health-sector e-waste and the development of an e-waste management system, and directs measures including segregation at source, promotion of reuse and resource recovery, adoption of best available technologies, and promotion of public-private partnership models.
Section 45. E-waste management Section 45(1)(a) in consultation with county governments and relevant lead agencies, develop guidelines for the safe handling and disposal of all health sector related e-waste material; and Section 45(1)(b) in consultation with relevant stakeholders, develop an e-waste management system ("the comprehensive integrated health information system established under;") for the health sector. Section 45(2)(a) comprise an appropriate mechanism for segregation of e-waste at source, collection, transportation, and processing ; Section 45(2)(b) promote reuse and lifetime extension; Section 45(2)(c) promote activities aimed at resource recovery and recycling of e-waste materials into useful products; Section 45(2)(d) embrace the best available technologies and practices in e-waste management; and Section 45(2)(e) promote sustainable models for e-waste management through public-private partnerships.
Part VIII
HEALTH TOURISM
- 46 Verify source ↗
HEALTH TOURISM - 46. Development of guidelines onhealth tourism
The Cabinet Secretary responsible for health must safeguard transfers of a client’s medical records to and from facilities outside Kenya and, in consultation with counties and lead agencies, develop guidelines on health tourism.
Section 46. Development of guidelines onhealth tourism Section 46(1) The Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") shall take all necessary measures to safeguard the transfer of a client ("an individual who uses, or has used, a health service, or in relation to whom health data has been created;") ’s medical records to and from facilities outside Kenya. Section 46(2)(a) provide a report to the Director-General for Health stating the findings; Section 46(2)(b) not share the health information without notifying the Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") ; and Section 46(2)(c) seek guidance from ithe Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") in the manner the health information shall be stored, processed and destroyed. Section 46(3) The Cabinet Secretary ("the Cabinet Secretary for ministry responsible for matters relating to health;") shall in consultation with the County Governments, and relevant lead agencies, develop guidelines on health tourism ("a situation where a patient travels across international borders to receive medical treatment;") . - 47 Verify source ↗
HEALTH TOURISM - 47. Disclosure of sensitivepersonal datato organizations outside Kenya.
Personal health information may only be shared to persons outside Kenya for health tourism.
Section 47. Disclosure of sensitivepersonal datato organizations outside Kenya. Section Personal health information may only be shared to any person outside Kenya for the purposes of health tourism ("a situation where a patient travels across international borders to receive medical treatment;") .
Part X
MISCELLANEOUS PROVISIONS
- 55 Verify source ↗
MISCELLANEOUS PROVISIONS - 55. Protection from personal liability
Acts done in good faith by the Chairperson, a Board member, or any officer, employee or agent of the Agency (or persons acting under their direction) while executing this Act do not make those persons personally liable for actions, claims or demands arising from those acts.
Section 55. Protection from personal liability Section No matter or thing done by the Chairperson, a Board member, or any officer, employee or agent of the Agency shall, if the matter or thing is done in good faith and for the purposes of executing any provisions of this Act, render the Chairperson, Board member, or any officer, employee or agent of the Agency or any person acting under the direction of those persons personally liable for any action, claim or demand arising from the same. - 56 Verify source ↗
MISCELLANEOUS PROVISIONS - 56. Conflict of interest
Board members and the Chairperson who have a direct or indirect personal interest in a matter must disclose that interest promptly; disclosures are recorded and such persons must not participate in consideration, discussion or voting on the matter; failure to disclose is an offence; members must recuse where there is an apparent or perceived conflict.
Section 56. Conflict of interest Section 56(1) The Chairperson or a member of the Board, conflict of who has a direct or indirect personal interest in a matter being considered or to be considered by the Board, shall as soon as reasonably practicable after the relevant facts concerning the matter have come to their knowledge, disclose the nature of such interest. Section 56(2) A disclosure of interest made under subsection (1) shall be recorded in the minutes of the meeting and the chairperson or member shall not take part in the consideration or discussion on or vote during any deliberations on the matter. Section 56(3) A person who fails to make the requisite disclosure under this section commits an offence. Section 56(4) A member of the Board shall recuse themselves from proceedings before the Board in which they have apparent or perceived conflict of interest. - 57 Verify source ↗
MISCELLANEOUS PROVISIONS - 57. Confidentiality
Members of the Board and Agency staff must not publish or disclose confidential documents, communications or information learned in the course of their duties without written consent of the Board; disclosure of criminal activity is not prevented.
Section 57. Confidentiality Section 57(1) A member of the Board or staff of the Agency may not without the consent in writing given by, or on behalf of, the Board, publish or disclose to any person other than in the course of the person’s duties, the contents of any document, communication or information which relates to, and which has come to the person’s knowledge in the course of the person’s duties under this Act. Section 57(2) The limitation on disclosure referred to under subsection (1) shall not be construed to prevent the disclosure of criminal activity by a member of the Board or staff of the Agency. - 58 Verify source ↗
MISCELLANEOUS PROVISIONS - 58. Duty to cooperate
respond to any inquiry made by the Board;
Section 58. Duty to cooperate Section respond to any inquiry made by the Board; - 59 Verify source ↗
MISCELLANEOUS PROVISIONS - 59. Offences
Section 59 lists offences including obstructing, hindering, threatening, disregarding Board orders, submitting false or misleading information, or making false representations; any person who violates a provision for which no other penalty is provided is guilty of an offence and is liable on conviction to a fine not exceeding one million shillings or to imprisonment for a term not exceeding two years, or both.
Section 59. Offences Section 59(1)(a) obstructs, hinders or threatens a member, an officer, employee or agent of the Board acting under this Act; Section 59(1)(b) disregards an order of the Board; Section 59(1)(c) submits false or misleading information to the Board; or Section 59(1)(d) makes a false representation to, or knowingly misleads a member, an officer, employee or agent of Board acting under this Act, Section 59(2) Any person who violates or fails to comply with any provision of this Act for which no other penalty is provided, commits an offence, and is liable on conviction to a fine not exceeding one million shillings or to imprisonment for a term not exceeding two years, or to both. - 60 Verify source ↗
MISCELLANEOUS PROVISIONS - 60. Regulations
Regulations regarding health information management policies and procedures.
Section 60. Regulations Section health information management policies and procedures; - 61 Verify source ↗
MISCELLANEOUS PROVISIONS - 61. Compliance to the Data Protection Act (Cap. 411C)
Any person processing personal data under this Act must comply with the Data Protection Act (Cap. 411C).
Section 61. Compliance to the Data Protection Act (Cap. 411C) Section Any person processing personal data under this Act shall comply with the Data Protection Act ( Cap. 411C ). - 62 Verify source ↗
MISCELLANEOUS PROVISIONS - 62. Transitional provision
Persons who were data controllers, data processors of health data, or who handled health information before this Act must comply with the Act's requirements within six months of its commencement.
Section 62. Transitional provision Section A person, who being a data controller or data processor of health data or who has been handling health information before the commencement of this Act, shall, within six months of the commencement of this Act, comply with the requirements of this Act.
Provision text is displayed from LexChat’s stored statute record. Use the official source links to verify amendments, commencement, and current legal force.
Ask AI about this statute
Digital Health Act
Sign in to ask AI about this statute
Sign in to start authenticated, citation-grounded statute research.
Sign inLexChat organizes source-backed legal information for research. Verify amendments, commencement, and current legal force with the official publisher before relying on it.