The Digital Health (Health Information Management Procedures) Regulations, 2025 | Legal Notice 76 of 2025 — Kenya law | Esheria

The Digital Health (Health Information Management Procedures) Regulations, 2025

The Regulations may be cited as the Digital Health (Health Information Management Procedures) Regulations, 2025.

AI-assisted research synopsis — verify against the official legal text below.

Jurisdiction
Kenya
Instrument
Notice
Citation
Legal Notice 76 of 2025
Version
Undated source snapshot
Language
en

Citation provenance: source:ke:kenyalaw · schema StatuteEnrichmentPublicV1.

Source attribution: Source: Kenya Law

Statute overview

About this statute

The Regulations may be cited as the Digital Health (Health Information Management Procedures) Regulations, 2025. Requires ensuring safe management of health information. A health data controller must keep a record of engaged health data processors and must provide those processors with role-based access in the System. Certain persons may report health data breaches to the Chief Executive Officer using Form HMIS 1; health data controllers and processors must notify the Chief Executive Officer of a breach within forty-eight hours in Form HMIS 1 and provide corrective and mitigation details; failure to notify as required is an offence punishable as per section 35(2) and (3) of the Act. Requires personalized authentication and log-in for sensitive personal data