NDPA 2023 readiness checklist for hospital systems
The Nigeria Data Protection Act 2023 makes the hospital the controller of its patient data. Software can support those duties but cannot discharge them. This checklist separates what the platform must provide from what the facility must decide.
Key takeaways
- Compliance is a hospital programme; the system supplies the controls and evidence.
- Access control and audit trails are the two controls auditors ask for first.
- Retention and deletion rules must be decided by the facility, then configured.
- Vendor and processor arrangements need written terms, not assurances.
- No vendor, including MedFlow, can certify your facility as compliant.
Governance the facility must own
- A named data protection contact and an approved data protection policy
- A record of processing activities covering clinical, HR and financial data
- Documented lawful basis for each processing purpose
- Staff training and confidentiality undertakings with evidence of completion
- An incident response and breach notification procedure with tested escalation
Controls the platform should provide
- Role-based access with least-privilege defaults and reviewable role assignments
- Audit trails for reads and writes to clinical, financial and administrative records
- Encryption of data in transit and controlled administrative access
- Emergency-access ('break glass') workflow that is recorded and reviewable
- Configurable retention and archival behaviour for each data category
- Export of a patient's data to support access and portability requests
Patient rights in day-to-day operations
- Consent capture at registration, with the record of what was consented to
- A route to correct inaccurate demographic or clinical detail without deleting history
- A defined response owner and timeline for access, correction and objection requests
- Clear notice of how data is used, published and kept current
Vendor and processor arrangements
- Written processing terms covering purpose, duration, security and sub-processors
- Stated hosting location and residency arrangements for the chosen deployment
- Breach notification obligations and timelines placed on the vendor
- Data export and exit terms agreed before signature, not at renewal
MedFlow's position
MedFlow implements controls designed to support NDPA 2023 duties — role-based access, audit trails, emergency-access governance, configurable retention and data export. This is alignment, not an independent certification, and facility-side governance remains the hospital's responsibility. Hosting region and residency wording are confirmed per deployment.
Frequently asked questions
- Does using MedFlow make my hospital NDPA compliant? No. MedFlow provides technical controls and audit evidence that support compliance. Governance, lawful basis, staff training, retention decisions and breach reporting remain the hospital's responsibility.
- Is MedFlow certified under ISO 27001 or HIPAA? MedFlow's controls are designed to align with recognised healthcare security and privacy practice. Any certification status is stated only where an independent assessment exists.
MedFlow home — Contact Ubora One Limited