A HealthTech startup founder is preparing for market entry, aware that his innovative app needs official approval but unsure where to begin. An HMIS vendor is watching the regulatory landscape shift, knowing that the future of his product depends on aligning with new national standards. A hospital administrator, meanwhile, is asking a different question altogether: is the system we already depend on certified and what happens to our SHA claims if it is not?
This is the new reality of healthcare in Kenya. The digital transformation of the health sector is accelerating rapidly. With over 50% of health facilities already digitized and the government targeting full coverage, the need for trust, security, and seamless data exchange has never been greater. The Digital Health Agency (DHA) is at the forefront of this transformation.
Why the DHA Compliance Process Matters
The DHA Certification Framework is not just another bureaucratic hurdle. It represents a fundamental shift in how digital health is governed in Kenya, designed to build a foundation of trust. At its heart, the framework aims to ensure that every digital health solution deployed in the country meets the highest standards of functionality, security, and interoperability.
Think of it as a seal of quality. When a digital health solution is certified, it assures healthcare providers, patients, and policymakers that it can be trusted with sensitive health data and will perform as expected.
For hospital owners, this has a hard edge. Under the Digital Health Act, 2023 and the Digital Health (Data Exchange) Regulations, 2025, only certified solutions may connect to national health systems the SHA claims platform, the national registries, and the emerging shared health record. In practice an uncertified HMIS cannot process SHA claims, and the Social Health Authority has signalled that facilities running non-compliant systems risk losing contracting and renewal in the current funding cycle. Certification is therefore not only a vendor concern; it is a procurement decision every facility now has to get right.
Understanding the DHA Compliance Process: A Six-Stage Journey
The certification process is a structured journey with six key stages, designed to be completed within a thirty-day period from the date of application, provided the audit can be scheduled.
Stage 1: Self-Attestation and Application
The journey begins with self-attestation. The DHA provides an interactive web-based self-attestation tool that helps you assess your system's readiness against the minimum requirements. This is not just a formality; it's a vital opportunity to identify any gaps before you formally apply.
Once you are confident your system is ready, you submit your application on Form HMIS 4 (set out in the First Schedule of the Regulations), together with your product documentation. This helps the DHA understand the scope of your solution and schedule the certification audit.
Stage 2: Documentation Review
This stage is all about proving your organization’s credibility and commitment to best practices. You will need to provide a detailed dossier including:
Stage 3: Certification Testing/Audits
This is where your system is put through its paces. The DHA conducts a non-consultative audit, meaning the auditors will test your system against the criteria but will not instruct you on how to fix any issues. The audit focuses on four core criteria:
1. Functionality
Does your system do what it's supposed to do? This criterion assesses whether the digital health solution meets the needs of healthcare providers and patients, enhancing service delivery and the quality of care. The detailed score sheets in the framework outline a wide range of requirements, from capturing demographics to generating patient summaries and placing orders.
2. Reporting and Public Health Alerts
Can your system support national public health goals? This includes the ability to generate reports for the Integrated Disease Surveillance and Response (IDSR) system, reportable diseases, and public health events.
3. Security, Privacy, and Confidentiality
This is a critical section for any healthcare-focused business. The framework mandates robust security controls to protect sensitive health data. This includes:
Remember that the audit tests evidence, not intentions. Be ready to produce the artifacts behind each control, an access-control matrix, sample audit logs, your authentication design, and TLS and encryption documentation alongside an independent penetration test and vulnerability assessment.
4. Information Exchange and Interoperability
Can your system talk to other systems? This criterion ensures your solution can exchange data seamlessly with the national health information exchange — connecting through the CIHIS Enterprise Service Bus and using HL7 FHIR (R4) together with the prescribed national registries. Expect to provide interoperability mapping documents and API tests as evidence. It is vital for creating a connected, patient-centered healthcare system where information flows freely and securely.
Stage 4: Testing/Audit Report
At the conclusion of the audit, the DHA provides a detailed report outlining any non-conformances. You are then given the opportunity to provide evidence of corrective actions. An independent team within the DHA makes the final decision on certification based on the audit report and your corrective actions. If successful, your solution is listed in the certification register and you are issued a Certificate of Conformity.
Stage 5: Re-certification and Ad Hoc Audits
Certification is not a one-off achievement. You are required to maintain all certified functionalities and meet minimum requirements for at least two years. The DHA may conduct ad hoc audits to ensure continued compliance. This process encourages continuous improvement and ensures certified systems remain secure and effective.
To secure recertification, developers of digital health solutions are required to maintain all certified functionalities and minimum requirements for a period of at least two (2) years.
Stage 6: Appeals
If you are dissatisfied with the outcome of the certification audit, you have the right to file an appeal with the Complaints Committee as set out in the Digital Health (Health Information Management Procedures) Regulations, 2025.
Cybersecurity: The Bedrock of Compliance
Throughout the DHA compliance journey, cybersecurity is not just a checklist item; it's a core business imperative. The framework explicitly requires you to "Protect against any reasonably anticipated threats or hazards to the security or integrity of such information"
Why this matters to you:
Consider the interconnected nature of the digital health ecosystem. The DHA aims to create a "harmonious system with information disclosure on a strict need-to-know basis at every level”. Your system is a node in this network. A weak link puts the entire network at risk. By achieving certification, you are not just proving you are secure; you are proving you are a responsible member of a larger community.
Data Protection: More Than Just a Checkbox
The DHA Compliance Framework is built on the foundation of Kenya's Data Protection Act. The two are inseparable. The framework requires you to:
Health data is classified as sensitive personal data, meaning it requires a higher level of protection. The framework translates these legal requirements into concrete, testable measures. By achieving certification, you are demonstrating that you understand and are implementing the full scope of Kenya's data protection regime, which is essential for avoiding regulatory sanctions and building trust.
Preparing for Compliance: A Strategic Approach
Navigating the DHA Certification Framework requires careful preparation. Success depends on embedding compliance into your development and business strategy from the start. Here are some practical steps to consider:
Common Readiness Challenges
Based on the framework's requirements, organizations typically face challenges in several areas:
How South-End Tech Can Help You Navigate the DHA Compliance Journey
Successfully navigating the DHA compliance process requires more than just a tick-box approach. It demands a strategic, expert-led effort that integrates cybersecurity, data protection, governance into your core operations.
South-End Tech is a leading cybersecurity and data protection consulting company that understands the intricacies of Kenya's digital health landscape. We are not just consultants; we are your strategic partners in building a secure and trusted digital health ecosystem.
We can help you:
Conclusion: Building a Trusted Digital Health Future
As the Digital Health Agency's chairman, Silas Simatwo, has described it, the framework is a catalyst for innovation — designed to promote trust in digital health solutions by upholding the highest standards of patient care and data protection. The journey to DHA compliance may seem complex, but with the right preparation and partners, it is a manageable and rewarding path.
Ready to start your DHA compliance journey? Let us talk.
Telephone: 0728223333
Email: cybersecurity@southendtech.co.ke | info@southendtech.co.ke | dataprotection@southendtech.co.ke