Patient records and the Data Protection Act: duties for clinics
Health status and medical records are special personal data under Uganda's 2019 Act. What a clinic or pharmacy must do on consent and storage.
A clinic's filing cabinet holds some of the most sensitive information in the country: who has what condition, what they were prescribed, what they paid. A pharmacy's prescription file holds much the same. Since 2019 that information has had a specific legal status in Uganda, and the duties that come with it apply to a two-room clinic as much as to a hospital. This post sets out what the Data Protection and Privacy Act, 2019 says and what a small health business should do about it.
Health data is "special personal data"
Section 9(1) of the Act prohibits collecting or processing personal data which relates to a person's religious or philosophical beliefs, political opinion, sexual life, financial information, health status or medical records. That is the starting point: a patient's diagnosis, prescription and payment history are all in the protected category.
Section 9(3) then sets out when a data collector, processor or controller may collect or process such data anyway. The exceptions include where the processing is in the exercise of a right or obligation conferred by law on an employer, and where the information is given freely and with the consent of the data subject. The Act elsewhere allows processing for medical purposes and to prevent or mitigate a serious and imminent threat to public health or safety, or to the life or health of the data subject or another person. For a clinic, the practical reading is that the patient's informed consent and the medical purpose of the visit are what make holding the record lawful, and both should be documented.
Registration with the Personal Data Protection Office
Part VI of the Act establishes a data protection register. Section 29(2) requires the Authority to register every person, institution or public body collecting or processing personal data, together with the purpose for which the data is collected or processed, and section 29(3) says an application to register is made in the prescribed manner. Section 30 makes the register open to public inspection.
The register is not aimed only at large firms. The NGO Bureau's Circular No. 01 of 2022, issued on 7 October 2022, reminded non-governmental organisations that under section 29 of the Act and regulation 15(1) every person, institution and public body collecting or processing personal data must register with the Personal Data Protection Office, pointed them to the online registration at pdpo.go.ug, and warned that enforcement action against unregistered organisations would begin in November 2022. A clinic or pharmacy that holds patient names, phone numbers and medical details is collecting and processing personal data and should be on that register.
What to do this quarter
Register. Complete the Personal Data Protection Office registration for the business, stating the purposes for which patient and customer data is held.
Write a short privacy notice. One page, in plain language, displayed at reception and on the registration form, saying what you collect, why, who sees it and how long you keep it. Consent given against a clear notice is the "freely given" consent section 9(3) refers to.
Decide who sees what. A receptionist needs names and appointment times. A cashier needs the bill. A clinician needs the clinical record. Give each role only its own view, on paper by separating the files and on screen by using the access controls in your software.
Lock the paper. Prescription files and patient cards go in a lockable cabinet, and the key does not live in the lock.
Set a retention rule. Other laws already dictate some retention periods, such as the two-year rule for dispensed prescriptions under the National Drug Policy and Authority Act. Write down how long each record type is kept and destroy securely when the period ends.
Plan for a breach. Know who in the business decides what to do if a phone with patient data is lost or a file goes missing, and keep the Personal Data Protection Office's contact details to hand.
Software choices matter
The Act applies whether the record is on paper, in a spreadsheet or in a system. Spreadsheets are the weak point: they are copied, emailed and left on shared laptops. A system that logs who viewed or changed a record, enforces roles and keeps data in one place is easier to defend than a folder of files, and it produces the audit trail an investigator would ask for.
The upside
Compliance here is mostly good practice that patients notice. A clinic that asks for consent clearly, keeps the queue from overhearing the consultation and never loses a card builds the kind of trust that brings patients back. The Act simply puts a legal floor under behaviour good clinics already had.
Sources
Run the whole business from one login.
Point of sale, stock, CRM, accounting free in every plan, payroll and Kit AI. Start on the web today and add the till, the phone app and the desktop app as you grow.
No card needed · 14-day trial