Sector · hospitals and clinics
Patient data is regulated twice over in Kenya.
Health administration and the provision of patient care are named in the Third Schedule of the 2021 Registration Regulations. Registration with the Office of the Data Protection Commissioner is mandatory for you regardless of how many beds you have — and the Data Protection Act is only the first of the two laws you sit under.
01 Why you specifically
The KES 5,000,000 in the first paragraph is a turnover threshold for the registration exemption. It is not the fine. The two figures are easy to blur and they mean different things.
Longer version, with the fees and the process: ODPC registration in Kenya.
The size exemption does not reach you
Outside the listed sectors, a Kenyan business is exempt from registering with the ODPC only if its annual turnover is below KES 5,000,000 and it has fewer than ten employees — both conditions, not either. Health administration and patient care are in the Third Schedule, so that test never applies to you. A single-doctor clinic is covered on the same basis as a referral hospital.
Registration costs between KES 4,000 for a micro or small organisation and KES 40,000 for a large one, and the certificate runs for 24 months. That is the paperwork. The duties that follow are the part that creates actual work.
02 The duties
Four obligations that expect you to be able to show your work
-
Security safeguards
Appropriate technical and organisational measures, judged against the sensitivity of what you hold — and health data is about as sensitive as personal data gets in Kenyan law.
-
Audit trails and event monitoring
Records of what happened in your systems, and somebody actually looking at them.
-
Regularly reviewing and testing software for vulnerabilities
Regularly is the load-bearing word. A dated external exposure report, and a record of what you fixed after it, is exactly the kind of evidence this duty expects you to be able to produce when asked.
-
Breach notification within 72 hours
Which is difficult from a standing start, and much easier if you already know what your external footprint looks like and who owns each part of it.
The exposure, stated accurately
An infringement can cost up to KES 5,000,000 or 1% of annual turnover, whichever is lower, per infringement. For most hospitals in this country that means the turnover figure, not the headline one. We write it that way every time, because quoting the ceiling alone overstates what you actually face — and fear is a poor basis for a security decision.
03 The second law
We do not run unsolicited assessments of healthcare domains at all. A snapshot happens because somebody at the hospital asked for it, and the record of who asked is stored with the exact wording they agreed to.
The Digital Health Act 2023, and the possibility of being critical infrastructure
On top of the Data Protection Act, hospitals carry the safeguards in the Digital Health Act 2023. Health services can also be designated critical information infrastructure, which raises the stakes again — both for you and for anybody who touches your systems without authority.
That last point is why an outside party's discipline matters more here than anywhere else. Under Kenya's Computer Misuse and Cybercrimes Act 2018, as amended in 2025, probing a protected system carries penalties up to KES 25 million and 20 years, and Kenya has no responsible-disclosure safe harbour. A vendor who offers to "just have a quick look at" a hospital's systems is describing an offence.
04 Where to start
Not clinical systems. Nothing in this service connects to a patient record system, and no tier on our price list changes that without your written authorisation.
Honest qualification: reading DNS means asking whichever name servers answer for your domain, which may be yours or your provider's. That single lookup is the only contact a free snapshot involves.
Start outside, where an attacker starts
The free snapshot reads public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences. Nothing we do reaches a patient record system, a laboratory system or a device on your network, verified domain or not.
What it does show is the part of you a stranger can already see: whether somebody can send email that appears to come from your hospital to a patient or a supplier, what your own certificates have published about internal-sounding systems, whether your domain is locked against transfer, and what stray DNS records an old supplier left behind.
A person reads all of it, ranks the three issues that matter most for a hospital specifically, and writes it in language a matron or a finance director can act on. It arrives by email in one to two business days.
If you would rather the work were done than described, the fix sprints have published fixed prices. Ongoing managed cover for a hospital — sites, domains, staff identities, devices — is quoted after a scoping conversation, and we publish no figure for it. A clinic and a multi-facility group are not the same job, and a list price spanning both would be a guess made at your expense.
05 Limits
What this is not, in a sector where that matters
-
It does not make your hospital compliant
Compliance covers consent, notices, retention, supplier contracts, staff training and more. This is documented evidence about one technical control. Anybody selling you compliance in a box is selling something that does not exist.
-
It is not a penetration test
We do not attempt to break into anything, and we do not offer to.
-
It is not monitoring
It is one day's picture. Nothing watches your domain afterwards and nothing alerts you. Our monthly option is a person re-reading the same public records and writing to you — not a detection and response service, and we will not describe it as one.
-
It cannot see inside
Your internal network, your staff devices and your clinical systems are invisible to it. The report says so on its front page.
One free snapshot per domain every 30 days. We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences. This is not a penetration test.
See what your hospital looks like from outside
One domain, read from public records, written up by a person and emailed to you in one to two business days. Free, and nothing connects to your systems.
Get the free snapshot for our hospital Read a sample report first