A man is helped scan his iris to create identification codes as part of the requirement while registering as a member of the new Worldcoin cryptocurrency at KICC Nairobi on August 1, 2023.
In every single room I have walked into as a doctor, there is one thing that has always been sacred – privacy.
We ask patients to open up about their fears, their symptoms and the details they often do not even tell their closest friends or partners and patients share with us, knowing in confidence that this information will be kept between us. It is our moral and professional duty to not break that trust. It is also enshrined in law.
These are the two prisms through which we are observing with growing concern Kenya’s established Social Health Authority (SHA). Presented as a reform designed to ensure Kenyans’ right to health, the SHA instead threatens to erode the very basis of healthcare provision: confidentiality. In centralising the health records, contributions and treatment histories of millions of Kenyans, SHA now has an extraordinary level of control over Kenyans’ health data.
The imposition of biometric IDs and the lingering questions about fraudulent payments and lost data have understandably sown fear among patients and health care providers alike. Consent processes have been reduced to fine print, and patients are routinely not informed about how their data may be shared, who will access it, or how long it will be stored. In the absence of any clarity, the SHA has moved ahead as though health data was simply another administrative asset at their disposal.
That is not only careless; it is unconstitutional. If the system continues to overreach in its data requirements, without providing adequate transparency or assurances about who can access and how that data will be used, the very trust on which effective health care depends will begin to erode. At stake is the dignity of the citizen, the patient-provider relationship. At stake is the dignity of the citizen, the patient-provider relationship.
When privacy is violated, lives are affected
Data privacy seems like an abstract or overly technical subject. In health, it may be easy to see its breach as theoretical. In a landmark case of KELIN v Cabinet Secretary, Ministry of Health, the High Court found a government directive for schools to collect and report the HIV status of their pupils to be unconstitutional. The directive, the court found, violated the children’s right to privacy (under Article 31 of the Constitution) as well as their dignity and welfare.
In another recent case, the HIV and AIDS Tribunal ordered a man to pay KSh 650,000 in damages for ‘recklessly’ revealing the HIV status of a woman he was having an affair with to a WhatsApp group he belonged to, without her consent. The Tribunal found the stigma, in this case, was greater because it was digital, therefore carries weight under the law. Most recently, the High Court ruled against WorldCoin after biometric data was collected from Kenyans without informed consent or a data protection impact assessment. These cases make it clear: mishandling data is not simply an ethical oversight; it is a legal offence, and a direct violation of our constitutional rights.
What the law demands
The law mandates that such data must be processed lawfully, fairly, and transparently, with clear, explicit, and legitimate purposes. Collection should be limited to necessary, accurate, and current information, with robust safeguards against misuse or unauthorised transfer. Article 31 of the Constitution of Kenya states that every person has the right to privacy.
Our Data Protection Act of 2019 goes even further in upholding the importance of protecting people’s data, stating in section 11 that information relating to a person's health is considered sensitive personal data and must, therefore, be accorded the highest level of care when it is processed.
The Health Act, 2017 authorised the Ministry of Health to develop specific regulations around e-health, m-health, and telemedicine platforms to be underpinned by strong data-privacy protections. The Office of the Data Protection Commissioner has even issued a guidance note on the processing of health data. Practice, though, is another matter. Many of these prot
A global standard of medical ethics
Patient confidentiality isn’t just a best practice in medicine; it’s an international professional standard. The World Medical Association, which represents physicians worldwide, has a clear position on this. It is stated in its code of medical ethics that doctors should protect the privacy of a patient even after death, and disclose personal information only with consent or when a compelling and unavoidable ethical reason arises.
Even in the latter case, information should only be shared with those who have a legitimate need to know and only to the degree that is strictly necessary. This is true whether the setting is traditional care, telemedicine, digital health records, or banks of genetic data. In all of these situations, patients must be given an opportunity to know how their information will be used, and their consent must be sought.
We can get it right
Kenya can still get this right. Going forward, the Ministry of Health, in consultation with the Data Protection Commissioner, needs to issue enforceable regulations for SHA that clearly specify the processes for how consent will be obtained, how much data is truly needed, and how violations will be reported.
SHA needs to appoint an independent Data Protection Officer and be subject to regular audits. Patients need to be empowered to know their rights in plain language and to give or withhold consent in a meaningful way. Healthcare is more than hospitals, drugs and insurance cards.
It is about human dignity. When patients share their deepest vulnerabilities, they are not simply availing themselves of services; they are entrusting us with their lives. To betray their data is to betray that trust.
Dr Bosire is a medical doctor and lawyer