Zimbabwe healthcare data protection
Reporting a Patient Data Breach in Zimbabwe: the Twenty-Four Hour Rule
Section 19 of the Cyber and Data Protection Act [Chapter 12:07] requires a data controller to notify POTRAZ within twenty-four hours of any security breach affecting the data it processes. For a healthcare provider that clock starts with a lost file or a misdirected result, not only with a hacked server, and it runs through weekends.
What the law actually says
Section 19 of the Cyber and Data Protection Act is one sentence long, and it is the hardest deadline in the whole regime. The data controller shall notify the Authority within twenty-four hours of any security breach affecting data he or she processes. There is no materiality threshold written into that sentence, no carve-out for small breaches and no provision that pauses the clock while you investigate.
The notification form is Form DP3, set out in the Fourth Schedule to SI 155 of 2024. Twenty-four hours is not enough time to work out what your process is, so the practical work of complying with section 19 happens long before a breach, not during one.
What counts as a breach in a clinical setting
Healthcare providers tend to picture a breach as a cyber attack, and then fail to report the far more common everyday incidents that are equally within section 19. A security breach affecting patient data does not require an attacker, malice or even a computer.
- A paper patient file lost, misfiled beyond recovery, or left where an unauthorised person could read it.
- Results, a referral letter or a discharge summary sent to the wrong patient, the wrong practitioner or the wrong fax or email address.
- A laptop, tablet, phone or USB drive holding patient data lost or stolen, whether or not it was encrypted.
- A WhatsApp message about a patient sent to the wrong contact or the wrong group.
- An email about several patients sent with addresses in the visible field rather than blind copied.
- A member of staff, current or former, accessing records they had no clinical reason to open.
- A break-in at the practice where the records room or the archive was accessible.
- A ransomware infection or unauthorised access to the practice management or electronic records system.
- A supplier, laboratory or billing bureau notifying you that they have suffered a breach involving your patients.
- Records left behind, insecurely stored or improperly disposed of when a practice moves premises or closes.
The last of those is worth dwelling on. Where a laboratory, medical aid administrator, billing bureau or IT provider processes patient data on your instructions, their breach is your notification. Section 10(4)(a) of SI 155 makes the controller accountable for a representative, agent, assignee, data processor, recipient or data protection officer who contravenes, and section 33(6) of the Act makes the controller liable for fines incurred by its agent or assignee. Outsourcing the processing does not outsource the duty to report.
Why health data raises the stakes
Health data is sensitive personal data, dealt with under section 11 of the Act, and contravening section 11 is one of the five sections named in section 33(2), which carries a fine of up to level 11 or imprisonment of up to seven years or both. Where the practice treats minors, section 10(5) of SI 155 adds the children’s data regime on top.
The practical difference is what a disclosure does to the patient. A leaked shopping list is an annoyance. A disclosed HIV status, mental health history, pregnancy, substance use record or genetic result can cost someone their employment, their marriage or their safety, and it cannot be undone by an apology. That is why the reporting duty is tight and why an inspector will treat a breach response as a test of whether the practice understood what it was holding.
What to do in the first twenty-four hours
- Contain it. Recall the message, revoke the access, secure the room, isolate the affected device. Containment comes before paperwork, and the clock is running while you do it.
- Record the time you became aware. This single fact is what makes a twenty-four hour notification demonstrable afterwards, and it is the one most often lost.
- Tell your Data Protection Officer immediately. Under section 14 of SI 155 the officer deals with requests from and communications with the Authority, so this is precisely their role and not something to handle around them.
- Establish the scope as far as you can. Which patients, which categories of data, how many individuals, whether the data was encrypted, and whether it has been recovered.
- Notify the Authority on Form DP3 within twenty-four hours. Send it on what you know. The deadline does not extend because the investigation is incomplete, so an honest notification recording what is still being established is the correct filing.
- Decide about telling the affected patients, and record the reasoning either way. Where the breach is likely to affect them, telling them promptly and plainly is both the right thing and the defensible one.
- Keep a written timeline as events happen rather than reconstructing it later. Section 24 of the Act requires you to be able to demonstrate compliance, and a contemporaneous log is what demonstration looks like.
- Close the loop afterwards with what changed as a result, because the second identical breach is a much worse conversation than the first.
Being ready before it happens
A breach procedure that has never been tested is a document rather than a capability. These are the things to settle while nothing is going wrong.
- Name who can declare a breach, including out of hours, at a weekend and over a public holiday. A single named person with no deputy is a single point of failure against a twenty-four hour clock.
- Keep a part-completed Form DP3 with the practice particulars and officer details already filled in, so that only the incident facts are added under pressure.
- Write down, in advance, what you will send when the full extent is not yet known.
- Make sure reception and nursing staff know that a misdirected result or a lost file is reportable. Most breaches are found by the people least likely to think of themselves as involved in compliance.
- Hold written data processing agreements with your laboratory, billing bureau, medical aid administrator and IT provider, as section 10(4)(f) of SI 155 requires, and make sure each one obliges them to tell you immediately rather than at their convenience.
- Run the procedure as a dry exercise once a year against a realistic scenario, and time it.
- Train the team and keep the training record. Training is mandatory for licensed controllers under CDPG 1 of 2025, and inspectors ask for the record rather than the assurance.
An outsourced Data Protection Officer exists in large part for this. A breach discovered late on a Friday afternoon does not wait until Monday, and a regulatory notification drafted in a hurry by whoever happens to be available is not the same document as one drafted by the officer who will have to answer for it. The engagement options are set out on the main compliance page.
What a breach reveals to an inspector
A breach notification tells POTRAZ that an incident occurred. What it also does, unavoidably, is show the regulator how the practice operates. A notification filed inside the deadline, from a named officer, referring to a record of processing that already existed, with a containment log and a remediation plan attached, describes an organisation in control of its obligations.
A notification filed late, by whoever was available, about systems that appear in no register and processors with whom there is no written agreement, describes something else, and it invites the inspector to look further. Preparation is what determines which of those two an inspection finds, and it is done well before the breach.
Frequently asked questions
How long does a Zimbabwean clinic have to report a data breach?
Twenty-four hours. Section 19 of the Cyber and Data Protection Act [Chapter 12:07] requires the data controller to notify the Authority within twenty-four hours of any security breach affecting data it processes. The notification is made on Form DP3, in the Fourth Schedule to SI 155 of 2024.
Does a lost paper file count as a data breach?
Yes. Section 19 refers to any security breach affecting the data you process, and it draws no distinction between paper and electronic records. A lost or misfiled patient record, a misdirected result and a stolen laptop are all within it. Paper records are fully in scope of the Act.
Do we have to report a breach if no patient was harmed?
Section 19 contains no materiality threshold and no carve-out for breaches that appear harmless, so the safe and correct course is to notify. Whether individual patients should also be told is a separate judgement, and the reasoning either way should be written down at the time.
What if our laboratory or billing provider is breached?
Where they process patient data on your instructions, you are the controller and the notification duty is yours. Section 10(4)(a) of SI 155 makes the controller accountable for a processor, recipient or agent who contravenes, and section 33(6) of the Act makes the controller liable for fines incurred by its agent or assignee. Your written agreement with them under section 10(4)(f) should require them to notify you immediately.
What happens if we miss the twenty-four hour deadline?
Notify anyway, as soon as you can, and record honestly when you became aware and why the notification was late. A late notification is a worse position than a timely one, and a concealed breach is worse than either. Section 24 of the Act requires you to be able to demonstrate your compliance to the Authority, and a contemporaneous record is what that demonstration rests on.
Who notifies POTRAZ, the doctor or the Data Protection Officer?
The duty sits on the data controller, which is the practice. In practice the Data Protection Officer prepares and files the notification, because section 14 of SI 155 makes the officer responsible for dealing with requests and communications involving the Authority and for acting as the contact point for data subjects.
Do we have to tell the affected patients?
The twenty-four hour duty in section 19 is a duty to notify the Authority. Whether to tell patients is a separate decision that turns on the likely effect on them, and where a breach is likely to affect a patient, telling them promptly and plainly is both the right course and the defensible one. Record the reasoning whichever way you decide.
Get licensed and inspection-ready
Compliance packages start at $250. Every engagement begins with a one-hour consultation at $90, credited in full toward your package when you proceed. POTRAZ fees are separate and passed through at cost.
On our other sites
- The full list of offences and penalties Every offence the Act and SI 155 create, with the maximum penalty and the section it comes from, on our StoneGuard site.
- Preparing for a POTRAZ inspection The evidence file an inspector expects, assembled obligation by obligation, on the Lioncap Ventures site.