Zimbabwe healthcare data protection
Medical Practice Data Protection Compliance: The Gaps We Find Most Often
A gap analysis of a Zimbabwean medical practice against the Cyber and Data Protection Act [Chapter 12:07] tends to surface the same findings: paper records that are not physically secured, consent wording that does not cover sharing, no retention rule, CCTV without a notice, patient details sent over ordinary WhatsApp and email, and no written breach procedure. Each one is fixable, and each one is what an inspector looks for.
Why a gap analysis comes first
Compliance work that starts with paperwork produces paperwork. Compliance work that starts with a gap analysis produces a shorter list of real fixes. The analysis walks the practice as it actually operates: where files physically sit, who opens the records room, what the receptionist says when a patient asks why their details are needed, how a result gets to a referring doctor, and what happens to a file when a patient stops attending. The findings below are the ones that recur.
Paper records are in scope and they are usually the weakest point
The Act protects personal data regardless of the medium. A patient file in a cardboard folder attracts the same duties as the same file in a database, and inspectors do look at filing rooms, patient registers and archives. The recurring findings are practical rather than technical: a records room that is unlocked during clinic hours because staff are in and out of it constantly, files stacked on the reception counter where anyone in the waiting area can read the name on the cover, an archive in a storeroom that other tenants or contractors can reach, day registers left open at the front desk, and no record of who has removed a file or when it came back.
The fix is a physical records security checklist covering access control to the records area, a sign-out discipline for removed files, storage that is locked outside working hours, separation of the archive from general storage, and secure destruction rather than ordinary disposal at the end of the retention period. None of this is expensive. It is simply rarely written down, and if it is not written down an inspector cannot credit it.
Consent wording that does not cover what the practice actually does
Most practices have something a patient signs. Fewer have wording that matches the processing. The common failure is that the form covers treatment but is silent on everything that follows: sending results to a referring practitioner, submitting a claim to a medical aid society, sharing an image with a radiologist, storing the file in a cloud system, or contacting the patient with appointment reminders on a messaging channel.
Health data is sensitive personal data, which raises the standard for the basis you rely on. Consent, where it is the basis, has to be specific and informed, which means the patient has to be told what is collected, why, who else will see it and how long it is kept, in language they can read. A signature under a single line that says the patient agrees to treatment does not carry all of that. Practices treating minors have a further layer, because children’s data is also sensitive and consent normally runs through a parent or guardian, which the form has to reflect.
No retention rule, so nothing is ever deleted
Almost every practice we assess keeps every record indefinitely, because no one has ever been given a rule that says otherwise. Retention is a data protection obligation in both directions: you must keep records long enough to meet your clinical and legal duties, and you must not keep personal data longer than is necessary for the purpose it was collected for. Indefinite retention by default fails the second half of that test, and it quietly inflates the licence tier, because dormant files still count towards the record total.
The remedy is a written retention schedule recorded in the ROPA, setting a period per category of record, with a defined review point and a secure destruction method. It has to be a rule the practice can actually follow, and it has to distinguish between categories, since a clinical file, a billing record and a job application do not carry the same period.
CCTV without a notice
CCTV in a waiting area, a reception or a dispensary records identifiable people, so the footage is personal data and the practice is its controller. The recurring finding is not the camera itself but the absence of the surrounding obligations: no visible notice telling people they are being recorded and who is recording them, no stated purpose, no retention period for the footage, no restriction on who can view it, and no entry in the ROPA at all.
Cameras positioned so that they capture screens, open files or the records area create a further problem, because the footage then contains clinical information as well as images of people. Where a camera overlooks a consulting or treatment area the practice should expect an inspector to ask about it directly. The fix is a notice at each entrance and monitored area, a documented purpose and retention period, access limited to named people, and the processing entered in the ROPA.
Patient data sent over ordinary WhatsApp and email
This is the single most common finding across Zimbabwean healthcare providers, and it is also the one practices are most reluctant to change, because the habit is convenient and clinically useful. Results, referral letters, images and full patient identifiers move over ordinary personal messaging and consumer email accounts, often on personal devices that are shared at home, unlocked, and backed up to accounts the practice does not control.
Sensitive health data needs a secure channel, encrypted devices and documented safeguards. In practice that means moving clinical correspondence onto a controlled system rather than personal accounts, enabling device encryption and screen locks, keeping practice data out of personal cloud backups, and writing down which channel is approved for what. Where messaging is used to reach patients, it should carry the minimum identifying detail necessary rather than a full result.
No written breach procedure and no one who owns it
A data breach in a practice is rarely dramatic. It is a lost phone with clinic messages on it, a file that has gone missing from the archive, a result sent to the wrong number, or a laptop taken in a break-in. What determines whether that becomes an enforcement problem is whether the practice can show it recognised the incident, assessed it, contained it, notified where notification was required, and recorded it.
The gap is almost never that staff would hide an incident. It is that no one has told them what counts as one, who to tell, or how quickly. A breach response procedure has to name the person to be informed, define the assessment and containment steps, set the notification path and the timeline, and provide an incident register that is filled in every time, including for incidents that turn out not to be notifiable. The register is evidence in itself.
No DSAR procedure for when a patient asks for their own file
Patients have rights over their own data, including the right of access. A request can arrive verbally at the front desk, and the person who receives it is usually the least prepared for it. Without a procedure, requests are either refused out of caution or answered informally, and both create exposure. The practice needs a written data subject access request procedure covering how a request is recognised and logged, how the requester is identified before anything is released, what is included and what may be withheld, the response timeline, and how the response is recorded.
Untrained staff and no training record
Under CDPG 1 of 2025, the POTRAZ assessment guidelines, training is mandatory for staff who handle personal data. In a medical practice that reaches well beyond clinicians: reception, records, nursing, billing and anyone who cleans or secures the records area. The finding is usually not that staff are careless but that no session has ever been formally run and no attendance record exists. An inspector asks for the training record, so an informal briefing leaves nothing to produce.
Turning the findings into a plan
A gap analysis is only useful if it ends in a prioritised remediation plan. The sequence we use puts the items whose absence is an offence first, which means the licence and the processing notification, then the documents the rest of the evidence depends on, the ROPA and the DPIA, then the highest-risk practical fixes, usually unsecured transmission of patient data and uncontrolled access to the records area, and finally the lower-risk housekeeping. Training runs alongside, because it can be scheduled around clinic hours.
Every Avalon Health compliance package includes the gap analysis and report, and the engagement begins with a $90 consultation that is credited in full toward the package. Packages start at $250. The technical half of this list is already covered for practices on the Avalon Health platform, which provides PII tokenised at rest, AES-256 encryption, append-only audit logging, role-based access control, multi-factor authentication and consent capture.
Frequently asked questions
Are paper patient files covered by the Cyber and Data Protection Act?
Yes. The Act protects personal data regardless of the medium, so a paper file carries the same duties as an electronic record. Inspectors examine filing rooms, patient registers and archives, and physical records security is part of every compliance package.
Can a practice send patient results over WhatsApp?
Sending patient details over ordinary consumer messaging or email is one of the most common inspection findings. Health data is sensitive data and needs a secure channel, encrypted devices and documented safeguards. Where messaging is used to reach patients it should carry the minimum identifying detail necessary rather than a full result.
Does a practice need a notice for its CCTV cameras?
Yes. CCTV footage of identifiable people is personal data and the practice is its controller. That requires a visible notice at monitored areas, a documented purpose and retention period, access limited to named people, and an entry in the Records of Processing.
How long should a medical practice keep patient records?
Long enough to meet clinical and legal duties, and no longer than is necessary for the purpose. The practical requirement is a written retention schedule recorded in the ROPA that sets a period for each category of record, with a review point and a secure destruction method. Keeping everything indefinitely by default fails the test and inflates your licence tier, because dormant files still count towards the record total.
What counts as a data breach in a medical practice?
Most are ordinary: a lost phone holding clinic messages, a file missing from the archive, a result sent to the wrong number, or a stolen laptop. What matters is whether the practice can show it recognised the incident, assessed and contained it, notified where required, and recorded it in an incident register.
Who in a practice has to be trained?
Everyone who handles personal data, which includes reception, records, nursing and billing staff, not only clinicians. Training is mandatory under CDPG 1 of 2025 and inspectors ask for the training record, so the session and its attendance have to be documented.
Get licensed and inspection-ready
Compliance packages start at $250. Every engagement begins with a one-hour consultation at $90, credited in full toward your package when you proceed. POTRAZ fees are separate and passed through at cost.