Blog updates on current trends in Business and Technology

Latest insights on business & technology — trends, analysis, and practical tips.

Everything You Need to Know About the DHA Compliance Process: A Practical Guide for Healthcare Providers and Digital Health Solution Vendors

August 5, 2026 • Tom Abuta

A HealthTech startup founder is preparing for market entry, aware that his innovative app needs official approval but unsure where to begin. An HMIS vendor is watching the regulatory landscape shift, knowing that the future of his product depends on aligning with new national standards. A hospital administrator, meanwhile, is asking a different question altogether: is the system we already depend on certified  and what happens to our SHA claims if it is not? 

This is the new reality of healthcare in Kenya. The digital transformation of the health sector is accelerating rapidly. With over 50% of health facilities already digitized and the government targeting full coverage, the need for trust, security, and seamless data exchange has never been greater. The Digital Health Agency (DHA) is at the forefront of this transformation.

Why the DHA Compliance Process Matters

The DHA Certification Framework is not just another bureaucratic hurdle. It represents a fundamental shift in how digital health is governed in Kenya, designed to build a foundation of trust. At its heart, the framework aims to ensure that every digital health solution deployed in the country meets the highest standards of functionalitysecurity, and interoperability.

Think of it as a seal of quality. When a digital health solution is certified, it assures healthcare providers, patients, and policymakers that it can be trusted with sensitive health data and will perform as expected.

For hospital owners, this has a hard edge. Under the Digital Health Act, 2023 and the Digital Health (Data Exchange) Regulations, 2025, only certified solutions may connect to national health systems the SHA claims platform, the national registries, and the emerging shared health record. In practice an uncertified HMIS cannot process SHA claims, and the Social Health Authority has signalled that facilities running non-compliant systems risk losing contracting and renewal in the current funding cycle. Certification is therefore not only a vendor concern; it is a procurement decision every facility now has to get right.

Understanding the DHA Compliance Process: A Six-Stage Journey

The certification process is a structured journey with six key stages, designed to be completed within a thirty-day period from the date of application, provided the audit can be scheduled.

Stage 1: Self-Attestation and Application

The journey begins with self-attestation. The DHA provides an interactive web-based self-attestation tool that helps you assess your system's readiness against the minimum requirements. This is not just a formality; it's a vital opportunity to identify any gaps before you formally apply.

Once you are confident your system is ready, you submit your application on Form HMIS 4 (set out in the First Schedule of the Regulations), together with your product documentation. This helps the DHA understand the scope of your solution and schedule the certification audit.

Stage 2: Documentation Review

This stage is all about proving your organization’s credibility and commitment to best practices. You will need to provide a detailed dossier including:

  1. Corporation certificates or identifying documents — specifically your Certificate of Incorporation, CR12, KRA PIN and Business Permit — to confirm your business's legal status.
  2. System manual and requirement specification to show the DHA exactly what your system does and how it works.
  3. Evidence of registration with the Office of the Data Protection Commissioner (ODPC) as a data processor or data controller. This is a non-negotiable requirement, aligning with Kenya's robust data protection laws.
  4. A Data Protection Impact Assessment (DPIA) Report. This demonstrates that you have thought through the privacy risks and put safeguards in place.
  5. A Security, Privacy, and Confidentiality Policy. This outlines how you will protect patient data. Behind this single policy the DHA expects the wider data-protection pack: a patient Privacy Notice, consent records, a Lawful Basis Assessment, a Data Retention Policy, Data Subject Rights procedures, executed Data Processing Agreements with your vendors, and where data is hosted or transferred across borders,  a Transfer Impact Assessment.
  6. A System Back-up and Recovery Policy. This is critical for business continuity and ensuring healthcare services are not disrupted. Be ready to prove it works: keep your backup-and-restore test reports, and treat your Business Continuity Plan and Disaster Recovery Plan as separate, named documents.
  7. Governance and representation documents. your organizational chart, the board resolution authorizing certification, and an appointment letter naming your authorized certification contact.
  8. System and integration documentation — system architecture and data-flow diagrams, plus API documentation (OpenAPI/Swagger) so the DHA can see how your solution is built and how it connects.
  9. Security testing evidence — an independent penetration test report and a vulnerability assessment report.

Stage 3: Certification Testing/Audits

This is where your system is put through its paces. The DHA conducts a non-consultative audit, meaning the auditors will test your system against the criteria but will not instruct you on how to fix any issues. The audit focuses on four core criteria:

1. Functionality

Does your system do what it's supposed to do? This criterion assesses whether the digital health solution meets the needs of healthcare providers and patients, enhancing service delivery and the quality of care. The detailed score sheets in the framework outline a wide range of requirements, from capturing demographics to generating patient summaries and placing orders.

2. Reporting and Public Health Alerts

Can your system support national public health goals? This includes the ability to generate reports for the Integrated Disease Surveillance and Response (IDSR) system, reportable diseases, and public health events.

3. Security, Privacy, and Confidentiality

This is a critical section for any healthcare-focused business. The framework mandates robust security controls to protect sensitive health data. This includes:

  • Role-based access control to ensure only authorized personnel can view specific data.
  • Strong user authentication to prevent unauthorized access.
  • Encryption of data at rest and in transit to protect against breaches.
  • Audit trails to track who accessed what and when, ensuring accountability.

Remember that the audit tests evidence, not intentions. Be ready to produce the artifacts behind each control, an access-control matrix, sample audit logs, your authentication design, and TLS and encryption documentation alongside an independent penetration test and vulnerability assessment.

4. Information Exchange and Interoperability

Can your system talk to other systems? This criterion ensures your solution can exchange data seamlessly with the national health information exchange — connecting through the CIHIS Enterprise Service Bus and using HL7 FHIR (R4) together with the prescribed national registries. Expect to provide interoperability mapping documents and API tests as evidence. It is vital for creating a connected, patient-centered healthcare system where information flows freely and securely.

Stage 4: Testing/Audit Report

At the conclusion of the audit, the DHA provides a detailed report outlining any non-conformances. You are then given the opportunity to provide evidence of corrective actions. An independent team within the DHA makes the final decision on certification based on the audit report and your corrective actions. If successful, your solution is listed in the certification register and you are issued a Certificate of Conformity.

Stage 5: Re-certification and Ad Hoc Audits

Certification is not a one-off achievement. You are required to maintain all certified functionalities and meet minimum requirements for at least two years. The DHA may conduct ad hoc audits to ensure continued compliance. This process encourages continuous improvement and ensures certified systems remain secure and effective.

To secure recertification, developers of digital health solutions are required to maintain all certified functionalities and minimum requirements for a period of at least two (2) years.

Stage 6: Appeals

If you are dissatisfied with the outcome of the certification audit, you have the right to file an appeal with the Complaints Committee as set out in the Digital Health (Health Information Management Procedures) Regulations, 2025.

Cybersecurity: The Bedrock of Compliance

Throughout the DHA compliance journey, cybersecurity is not just a checklist item; it's a core business imperative. The framework explicitly requires you to "Protect against any reasonably anticipated threats or hazards to the security or integrity of such information"

Why this matters to you:

  • Trust is your currency. In healthcare, patient trust is everything. Demonstrating a commitment to data security builds confidence in your brand. A data breach can be devastating, not just for patients, but for your reputation and bottom line.
  • Compliance is a differentiator. In a competitive HealthTech market, DHA certification sets you apart. It signals to potential clients, hospitals, clinics, and the government that you are a responsible and reliable partner.
  • Security is good for business. The framework requires controls like robust backup and recovery policies. This is not just about compliance; it's about ensuring your own business continuity and resilience.

Consider the interconnected nature of the digital health ecosystem. The DHA aims to create a "harmonious system with information disclosure on a strict need-to-know basis at every level”. Your system is a node in this network. A weak link puts the entire network at risk. By achieving certification, you are not just proving you are secure; you are proving you are a responsible member of a larger community.

Data Protection: More Than Just a Checkbox

The DHA Compliance Framework is built on the foundation of Kenya's Data Protection Act. The two are inseparable. The framework requires you to:

  • Register with the ODPC as a data controller or processor.
  • Conduct and submit a DPIA Report.
  • Have a comprehensive Security, Privacy, and Confidentiality Policy.

Health data is classified as sensitive personal data, meaning it requires a higher level of protection. The framework translates these legal requirements into concrete, testable measures. By achieving certification, you are demonstrating that you understand and are implementing the full scope of Kenya's data protection regime, which is essential for avoiding regulatory sanctions and building trust.

Preparing for Compliance: A Strategic Approach

Navigating the DHA Certification Framework requires careful preparation. Success depends on embedding compliance into your development and business strategy from the start. Here are some practical steps to consider:

  1. Read the Framework. The foundation of success is a deep understanding of the requirements. The framework is your primary guide. Read it, understand it, and use it to build your roadmap.
  2. Conduct a Gap Assessment. Before you even fill out the self-attestation tool, objectively assess your system against the four core criteria. Where are your strengths? Where are your gaps? This proactive step can save you significant time and effort.
  3. Prioritize Documentation. The documentation review is a critical gate. You will need to produce and refine your policies and procedures in advance. Get your DPIAs and security policies in order. This is not an afterthought; it is a fundamental part of your preparation.
  4. Invest in Security and Interoperability. The most common pitfalls are likely to be in security and interoperability. These are the areas that require the most technical expertise and strategic planning. Ensure you have a robust security architecture and adhere to the prescribed standards for data exchange.
  5. Think Long-Term. DHA compliance is not just about the initial certification. Plan for the re-certification cycle and the need for continuous adherence. This is an ongoing commitment to quality and security.

Common Readiness Challenges

Based on the framework's requirements, organizations typically face challenges in several areas:

  • Interoperability: Many legacy systems were not designed to exchange data using modern standards. This can be a significant technical hurdle that requires careful planning and investment.
  • Data Protection Impact Assessments: Conducting a thorough DPIA requires a strong understanding of data protection principles and a willingness to scrutinize your data flows and processing activities.
  • Proving Data Security: Demonstrating that your system can protect data "against any reasonably anticipated threats or hazards" requires a robust security posture. This includes having clear policies, technical controls like encryption, and incident response plans.
  • Understanding the Standards: The framework references technical standards that may be unfamiliar to some developers. This can lead to confusion and delays.
  • Security testing: Penetration testing and vulnerability assessment are often left to the end, yet the audit expects independent reports build in time for remediation.
  • Testing and quality assurance: Formal UAT, functional and performance test reports are frequently missing, as is a data-quality validation matrix showing that data is captured accurately and completely.

 

How South-End Tech Can Help You Navigate the DHA Compliance Journey

Successfully navigating the DHA compliance process requires more than just a tick-box approach. It demands a strategic, expert-led effort that integrates cybersecurity, data protection, governance into your core operations.

South-End Tech is a leading cybersecurity and data protection consulting company that understands the intricacies of Kenya's digital health landscape. We are not just consultants; we are your strategic partners in building a secure and trusted digital health ecosystem.

We can help you:

  • Prepare for Compliance: We conduct comprehensive readiness assessments to identify and bridge gaps in your security, interoperability, and documentation.
  • Strengthen Your Security Posture: Our cybersecurity experts will help you implement the required controls, from access control and encryption to audit logging and incident response.
  • Navigate the Documentation Maze: We guide you through the process of developing the necessary documentation, from Security Policies to DPIA Reports.
  • Achieve and Maintain Certification: We provide ongoing support to ensure your system meets the DHA's requirements and remains compliant through the re-certification cycle.

Conclusion: Building a Trusted Digital Health Future

As the Digital Health Agency's chairman, Silas Simatwo, has described it, the framework is a catalyst for innovation — designed to promote trust in digital health solutions by upholding the highest standards of patient care and data protection. The journey to DHA compliance may seem complex, but with the right preparation and partners, it is a manageable and rewarding path.

 

Ready to start your DHA compliance journey? Let us talk.

 Telephone: 0728223333
 Email: cybersecurity@southendtech.co.ke | info@southendtech.co.ke | dataprotection@southendtech.co.ke

 


Comments (0)