Nanto Health

Nanto Health resource

Where health data must be hosted in Kenya

A practical guide to Kenya's health-data residency rules, the unavailability exception and the questions a facility should get answered in writing.

The short answer

Kenya's data-protection rules do not amount to a simple sentence saying that every copy of every health record must sit on a server in Kenya. They do establish conditions for processing and transferring personal data outside Kenya, and health data receives stronger protection because it is sensitive personal data.

For a facility choosing a health system, the responsible answer is therefore not “any cloud is fine” or “every cloud outside Kenya is unlawful”. Ask what data is stored, where the primary service and copies are located, which transfer safeguard is being used and what happens if an approved service is unavailable.

What the Data Protection Act actually does

The Data Protection Act, 2019 treats health data as sensitive personal data. That matters because processing must have a lawful basis, respect the data-subject rights and follow the safeguards that apply to sensitive information.

The Act also controls transfers of personal data outside Kenya. A controller or processor needs an appropriate safeguard for the transfer, or the other lawful condition recognised by the Act. A contract with a cloud provider is evidence of an arrangement, not by itself proof that every cross-border transfer is permitted.

That is the localisation question in its useful form: not merely “which country is the data centre in?” but “what processing and transfer arrangement can the controller evidence?”

Health data is not just another database

A dialysis record can contain diagnoses, treatment observations, medicines, identifiers and payment information. A facility should map each category rather than accept a vague answer that data is “secure”. The map should include the production database, logs, backups, replicas, exports, support access and disaster-recovery copies.

Data minimisation still applies. A vendor should not copy real patient information into a test environment simply because the hosting platform makes it convenient. Access should be limited to the people and service providers who need it, retained for a defensible period and recorded well enough to investigate an incident.

The Nanto Health security overview explains the product-side boundary without disclosing private infrastructure details. It is not a certification statement and it does not replace a facility's own data-protection assessment.

What the unavailability exception does and does not mean

Kenya's health-information rules recognise that an approved local service may not always be available and provide an exception for unavailability in the circumstances set out by the rules. That is a continuity provision, not a standing permission to choose an overseas primary system because it is cheaper or easier.

Before relying on an exception, document the facts: what service was unavailable, when it failed, what reasonable alternative was considered, what minimum data was processed during the interruption and how the record was reconciled afterwards. Keep the evidence with the facility's incident and continuity records.

Do not treat a vendor's use of the word “fallback” as proof that the exception applies. Ask the controller, processor and relevant authority or adviser to confirm the position for the actual workflow.

Where the Sovereign Health Cloud fits

The Ministry of Health has described a Sovereign Health Cloud as a national direction under development. That is an important policy signal, but it is not the same thing as a live service, a published service specification or a completed legal determination for every health-data workload.

Until the responsible public bodies publish the service, its scope, assurance material and operating terms, a facility should not claim that the Sovereign Health Cloud is available for its records or use the phrase as a substitute for a current hosting assessment.

The question that is still open

There is a practical distinction between a Kenya-serving copy and a Kenya-based primary system of record. A service may serve users in Kenya while its primary database, backup, support access or disaster-recovery environment sits elsewhere.

Public guidance does not remove the need to resolve that distinction for the particular system. Ask the relevant authority or your data-protection adviser whether the requirement for your workload is satisfied by a Kenya-serving copy, or whether the primary record and all defined copies must be hosted in Kenya. Obtain the answer in writing and keep the version and date.

Questions for a health-system vendor

  1. Which personal and health-data fields are stored, logged, cached or exported?
  2. Where are the primary database, backups, replicas and disaster-recovery copies located?
  3. Can support staff access records from outside Kenya, and how is that access controlled?
  4. Which controller-processor agreement and transfer safeguard cover processing outside Kenya?
  5. How are test, analytics and monitoring environments kept free of real patient data?
  6. What happens during a hosting or connectivity outage, and how is late-entered data reconciled?
  7. What evidence can you provide for deletion, export and access requests when the contract ends?
  8. Which public requirement or written opinion supports your residency position?

Where Nanto Health fits

Nanto Health is a dialysis-specific electronic medical record and SHA claim-readiness platform for Kenyan facilities. This guide does not describe Nanto Health's hosting location, and it is not a claim that the platform satisfies a regulatory hosting requirement for a particular facility.

Facilities should assess the complete processing chain, including the clinical record, claim-readiness artefacts, backups and support access. For the difference between a specialty EMR and a wider facility system, read EMR vs HMIS in Kenya. For the clinical workflow that needs protecting, see the dialysis EMR overview.

Sources

Sources checked on 29 August 2026: the Data Protection Act, 2019 on Kenya Law, the Office of the Data Protection Commissioner and the Ministry of Health. Kenya Law returned an access-denied response from this checking environment, so the existing repository citation was reused rather than replaced with an unverified mirror. The Ministry homepage was live when checked; the Sovereign Health Cloud wording above is deliberately limited to a policy direction under development, not a claim that a live service is available. Confirm the current position with the ODPC, the Ministry of Health and your professional advisers before making a hosting decision.