Nanto Health

Nanto Health resource

DHA certification in Kenya: a practical guide for facilities and system vendors

How Digital Health Agency certification works in Kenya: which systems need it, the four scoring domains, the six-step process, timelines, hosting questions and how to verify a vendor's claim.

The short answer

DHA certification is the Digital Health Agency's assessment of a digital health system against national requirements before that system is deployed in a Kenyan healthcare facility. The Agency states on its certification portal that certification is mandatory for all digital health systems deployed in public and private healthcare facilities.

Certification attaches to the system and to the scope it is certified for, not to the facility. A facility does not sit the assessment. A facility chooses a system, and then carries the consequence of that choice. That is why the practical question for a facility manager is not "how do I get certified" but "can my vendor show me where their system stands, and can I verify it independently".

Where the requirement comes from

The Digital Health Act, 2023 established the Digital Health Agency as the national body responsible for digital health systems, including the certification of health information systems and the national health information exchange. The Health Information Management Procedures Regulations, 2025 set the standards, the assessment criteria and the ongoing obligations that follow certification.

The operating position published by the Agency is straightforward. Systems that hold health data or connect to national infrastructure are expected to be certified, and certification carries continuing duties rather than a one-off approval.

Which systems need certification

The Agency's published category list covers most of what a facility runs:

  • Electronic medical record systems that hold patient records and clinical documentation.
  • Health information systems and hospital-wide management systems covering administrative, financial and clinical operations.
  • Laboratory information systems.
  • Pharmacy and medication management systems.
  • Imaging and diagnostic systems, including PACS and radiology information systems.
  • Digital health platforms and applications, including telehealth and patient engagement tools.

A system is assessed against what it declares. A renal or outpatient system is not assessed as though it were a hospital-wide platform, and a vendor should not be describing capability it did not declare. Read the category list on the Agency's system categories page.

How a system is scored: four domains

The published scoring framework weights four domains equally, at 25 per cent each:

  1. Functionality. Core system capabilities, workflow support and clinical feature completeness.
  2. Reporting and public health alerts. Routine reporting, IDSR notifications and public health emergency alerting.
  3. Security, privacy and confidentiality. Data protection, access controls, encryption and compliance with national regulations.
  4. Information exchange and interoperability. Standards-based data exchange and integration.

Within those domains, criteria are split three ways. Mandatory criteria must all be met. Recommended criteria contribute to a weighted score. Optional criteria add bonus points. A system can therefore score well overall and still fail, because a single unmet mandatory criterion is decisive. See the scoring framework for the current weighting.

Reporting is worth noting for buyers. It carries the same weight as security and the same weight as interoperability, and it is the domain facilities most often forget to ask about when comparing systems.

The six-step process

The Agency publishes the certification journey as six stages, each with an applicant responsibility and an Agency responsibility:

  1. Self-attestation. The applicant completes a self-assessment questionnaire documenting system capabilities and compliance claims.
  2. Document submission and review. The applicant submits technical documentation, architecture diagrams and compliance evidence. The Agency reviews for completeness and runs a preliminary compliance check.
  3. Demonstrations and test labs. The applicant demonstrates system functionality in an approved test environment.
  4. Full system testing. The applicant supports integration and stress testing across the certification criteria.
  5. Certification decision. The Agency issues certification or a conditional approval with requirements. Gaps and non-conformities are addressed by the applicant.
  6. Post-certification monitoring. The applicant maintains compliance and reports significant system changes. The Agency conducts periodic audits and surveillance.

The stage that decides most timelines is the second one. Document review is where applications sit longest, and it is a paperwork problem rather than a software problem. Mismatched company names, unsigned policies and missing signatory roles are ordinary reasons an application stalls.

Timelines, remediation and recertification

The Agency's published guidance states that the process typically takes three to six months from application to decision, and that applicants with complete documentation may move faster. A system that fails a required criterion receives detailed feedback on non-conformities, gets a remediation period and may resubmit, with additional testing fees possible on re-evaluation.

Certification is not permanent. The published position is that recertification is required every three years, and that significant system changes may trigger an interim review. The Agency also runs surveillance audits during the certification period, which can include remote assessment, documentation review and site visits.

For a facility, the practical consequence is that "our vendor is certified" is a statement with a date attached. Ask when, for what scope and when it next expires.

What the interoperability assessment actually checks

The interoperability domain is the most deterministic part of the assessment, because it is machine-checked rather than judged.

Conformance is measured against Kenya's core FHIR implementation guide and its domain-specific children, covering areas such as claims, prescriptions, clinical summaries and referrals. Validation runs in three layers: syntax, meaning structure, cardinality and data types; semantics, meaning clinical sense and referential integrity, so a claim that references no patient fails; and terminology, meaning code values are checked against the Kenya National Health Terminology Service.

Two details matter to anyone preparing. A payload declares the profile it claims to support, and the system is tested against the profiles it claims rather than everything in the guide. And the validation output is the standard HL7 validator error log, which means failures are self-diagnosable before anyone else sees them. A vendor that cannot run that validation against its own output before formal testing is discovering its failures in the worst possible place.

The developer material sits at the Agency's AfyaConnect developer portal and the health information exchange documentation. Both change, so pin the version you tested against and record it.

Cloud hosting and data residency

Cloud-hosted systems can be certified. The Agency states that they must meet security, data residency and compliance requirements, and that additional considerations apply to cloud deployments including data sovereignty and hosting location verification.

This is the least settled area in practice, and it is worth being precise about what is unresolved rather than guessing. The questions a buyer or a vendor should be putting in writing are: which jurisdictions are acceptable, what document is accepted as residency evidence, whether the requirement extends to backups, replicas and disaster-recovery copies or only to the primary store, and whether a hosting change after certification is a notification, a reassessment or a fresh certification.

Do not make an infrastructure decision on a verbal answer. Ask the Agency in writing and keep the reply.

What the deadline talk means

A September 2026 compliance date has circulated widely among facilities and vendors, and a good deal of anxiety with it. Two things are worth separating.

The date is real as policy, and the Agency has been consistent that it is not the Agency's to move. But the Agency has also described certification as a continuing process rather than a shutter that comes down, and the practical currency is demonstrated progress rather than a finish line reached on a particular morning.

For a facility, that translates into one question for your vendor: can you show me that you have applied, where you are in the process and what is outstanding. An application that has not been filed at all is a different risk from one sitting in document review. Confirm the current position with the Agency at certification.dha.go.ke rather than relying on second-hand accounts, including this one.

How to verify a certification claim

This is the section to act on. Vendor claims in this market have been running ahead of the paperwork, and the Agency has publicly denied that any communication named a limited set of permitted systems.

  • Use the Agency's certificate verification tool with the certificate number, not the vendor's brochure.
  • Check the national register of certified systems, which lists the scope each system is certified for.
  • Treat "HIE compliant", "integration ready" and "in final stages" as marketing language. None of them is certification.
  • Ask for the certificate number, the certified scope and the expiry date in writing. A certified vendor can supply all three in a sentence.
  • Where a vendor is still in the process, ask which stage and what is outstanding. An honest answer to that is more informative than a confident claim.

Ten questions to put to your system vendor

  1. Have you applied for DHA certification, and what stage is the application at today?
  2. What scope have you declared, and does it cover the services this facility actually runs?
  3. Which of the four domains are you weakest in, and what are you doing about it?
  4. Can you show reporting and public health alerting working, not just described?
  5. Which FHIR implementation guide version do you validate against, and can you show a clean validator run?
  6. Where is our data hosted, and what residency evidence do you hold?
  7. Who is your named data protection officer, and are you registered with the Office of the Data Protection Commissioner?
  8. What happens to our records if we leave you, and in what format do we get them?
  9. If your certification lapses or a change triggers reassessment, what is your plan and who bears the cost?
  10. What is your written support channel and response time when something breaks during a claim cycle?

What is not yet published

Being straight about the gaps is more useful than pretending they are closed. As at 21 August 2026, several things vendors and facilities reasonably want are not publicly available: a downloadable implementation guide package with a stated version and URL, a published test-scenario pack with pass and fail criteria, a published response-time commitment for certification queries, and a settled written standard for data residency evidence. The Agency has said a vendor community channel and a frequently-asked-questions set are being established.

If you are a facility, that is not your problem to solve. It is a reason to ask your vendor for evidence rather than assurance.

Common questions

Is DHA certification mandatory in Kenya?
Yes. The Digital Health Agency states that certification is mandatory for all digital health systems deployed in public and private healthcare facilities.
Who is certified, the facility or the software vendor?
The system is certified, for the scope it declares. A facility does not sit the assessment. It chooses a system and carries the consequence of that choice, which is why verifying the vendor's position matters.
What does DHA assess?
Four domains carrying equal weight of 25 per cent each: functionality; reporting and public health alerts; security, privacy and confidentiality; and information exchange and interoperability. Mandatory criteria must all be met, recommended criteria contribute to a weighted score and optional criteria add bonus points.
How long does DHA certification take?
The Agency's published guidance states three to six months from application to decision, and faster where documentation is complete. Document review is where applications sit longest.
How do I check whether a system is actually DHA certified?
Use the Agency's certificate verification tool with the certificate number, and check the national register of certified systems, which lists the scope each system is certified for. Claims such as HIE compliant or integration ready are not certification.
Does DHA certification expire?
Yes. The published position is that recertification is required every three years, significant system changes may trigger an interim review, and the Agency runs surveillance audits during the certification period.
Can a cloud-hosted system be certified?
Yes. The Agency states that cloud-hosted systems can be certified provided they meet security, data residency and compliance requirements, with additional considerations for data sovereignty and hosting location verification.

Where Nanto Health fits

Nanto Health is a dialysis-focused electronic medical record and SHA claim-readiness platform for Kenyan facilities. It is built around the outpatient renal workflow rather than as a hospital-wide system, which is a deliberate scope choice and the same choice that shapes how it is assessed.

Nanto Health does not currently claim DHA certification. We publish this guide because facilities are being asked to make a system decision under time pressure with incomplete public information, and a buyer who knows how to verify a claim is better off regardless of which system they choose.

For related reading, see EMR vs HMIS in Kenya for the scope distinction that determines what a system is certified for, what an HMIS actually covers, and SHA dialysis claims in Kenya for the record a claim has to stand on. The dialysis EMR and SHA claim-readiness pages describe the scope Nanto Health is built for, and security and accountability covers the controls behind the security and privacy domain. Request a demo to walk through your facility's workflow.

Sources

This guide was written against the Digital Health Agency's published certification material on 21 August 2026: the certification process, the scoring framework, the system categories and the certification FAQ, together with the Agency's vendor sensitization session held on 21 August 2026. Points drawn from that session are described as the Agency's stated position and are not a substitute for written guidance. These sources change. Confirm current requirements at dha.go.ke before relying on any figure or date here.