# Avalon Health > Avalon Health is an AI-powered electronic medical records and healthcare infrastructure platform for clinics, pharmacies, hospitals, laboratories and radiology centres in Africa. It also provides POTRAZ Cyber and Data Protection Act compliance and outsourced Data Protection Officer (DPO) services for Zimbabwean healthcare providers. ## Platform Avalon Health delivers electronic medical records with AI-assisted clinical dictation, a results inbox with AI parsing, drug interaction checking, FHIR and HL7 interoperability, WhatsApp patient messaging, offline mode and document scanning. Dedicated systems cover provider clinical workspaces, laboratory information systems, radiology (RIS/PACS), pharmacy management and hospital management. Platform-level controls include PII tokenisation at rest, AES-256 encryption, append-only audit logging, role-based access control, multi-factor authentication and consent capture. ## Get started - [Get started](https://avalonhealth.cloud/get-started): a short questionnaire that asks what brings you to Avalon and routes you from there. Practices and clinics, doctors and specialists, hospitals, laboratories and pharmacies are asked about size, sites, what they use for records today, what they most need and their timeline, and close on a demo. Patients are asked what they were looking for and pointed at the Avalon patient portal at https://patient.avalonhealth.cloud rather than being sold the practice platform. Medical aids, insurers and everyone else answer one open question. A demo walks through the platform using scenarios relevant to your specialty and practice size; most practices are fully operational within 2 to 4 weeks, covering setup, data migration from legacy systems, staff training and go-live support. ## POTRAZ Data Protection Compliance - [Compliance for healthcare providers](https://avalonhealth.cloud/compliance): POTRAZ Cyber and Data Protection Act (Chapter 12:07) compliance and DPO services for Zimbabwean clinics, pharmacies, hospitals, labs and radiology centres. Data Controller licensing from $250, ahead of the POTRAZ inspections that begin 1 September 2026 with healthcare in the first wave. Compliance packages are one-off service fees: Starter from $250 (get licensed), Pro $650 (inspection-ready), Enterprise from $1,500 (audit, multi-site rollout, ongoing reviews). A required Data Protection Officer is provided on Outsourced, Dedicated or Full-time retainers, quoted per organisation by size tier. Government fees are billed at cost: a $30 POTRAZ application fee that applies from Tier 2 upward (no application fee at Tier 1), plus a Data Controller licence fee that scales from $50 to $2,500 by record volume. A $90 consultation begins any engagement and is credited toward the package. Avalon Health members save 10% on the service fee. ## Compliance guides Long-form, fully static guides at real URLs. Each answers a specific question about the Cyber and Data Protection Act (Chapter 12:07), SI 155 of 2024 and CDPG 1 of 2025 as they apply to Zimbabwean healthcare providers. - [POTRAZ licence for doctors and private practices](https://avalonhealth.cloud/compliance/potraz-licence-for-doctors): Tier 1 covers practices holding up to 1,000 records at a $50 licence fee ex VAT, with no application fee at Tier 1. A DPIA and a designated Data Protection Officer are still required, because health data and children's data are sensitive data. - [POTRAZ licence for clinics and hospitals](https://avalonhealth.cloud/compliance/potraz-licence-for-clinics-and-hospitals): How multi-site groups work out their tier across all sites and record types. Licence fees are $300 at Tier 2 (1,001 to 100,000 records), $500 at Tier 3 (to 500,000) and $2,500 at Tier 4 (above 500,000), all ex VAT, with a $30 application fee that applies from Tier 2 upward and is not charged on renewals. Covers departmental ROPAs, third-party data processing agreements and cross-border transfers. - [Medical practice data compliance gaps](https://avalonhealth.cloud/compliance/medical-practice-data-compliance): The findings a gap analysis surfaces most often, namely unsecured paper files and archives, consent wording that does not cover sharing, no retention rule, CCTV with no notice or ROPA entry, patient data sent over ordinary WhatsApp and email, and no written breach or data subject access request procedure. - [POTRAZ inspections of healthcare providers](https://avalonhealth.cloud/compliance/potraz-inspections-healthcare): Inspections begin 1 September 2026 with healthcare in the first wave. The documents inspectors ask for, what they examine on a walk through the premises, and the staff training records required under CDPG 1 of 2025. - [Data Protection Officer for healthcare](https://avalonhealth.cloud/compliance/data-protection-officer-for-healthcare): Why SI 155 of 2024 makes a DPO a condition of holding a Data Controller licence, what the role covers, and when an outsourced DPO on record makes more sense than an internal appointment. - [What POTRAZ compliance costs a medical practice or clinic](https://avalonhealth.cloud/compliance/potraz-licence-cost-healthcare): The full cost picture for a healthcare provider. $50 ex VAT at Tier 1 with no application fee, $300 plus a one-off $30 application fee at Tier 2, $500 at Tier 3 and $2,500 at Tier 4, all paid to POTRAZ at cost. Covers why the cumulative archive count decides the tier, what recurs annually under section 5(1) of SI 155 of 2024, and the three month renewal deadline in section 5(2). - [Reporting a patient data breach: the twenty-four hour rule](https://avalonhealth.cloud/compliance/health-data-breach-notification-zimbabwe): Section 19 of the Cyber and Data Protection Act requires notification to POTRAZ within twenty-four hours of any security breach affecting patient data, on Form DP3 in the Fourth Schedule to SI 155 of 2024. Covers what counts as a breach in a clinical setting including lost paper files and misdirected results, the first twenty-four hours step by step, and why a processor's breach is the practice's notification. ## Verified legal references used on these guides - SI 155 of 2024 section 5(1): a data controller licence is valid for twelve months. Section 5(2): renewal is applied for at least three months before expiry. Section 5(3): failing without just cause to renew by expiry is an offence. - SI 155 of 2024 section 6: the licence categories run from a minimum of 50 data subjects (Tier 1, maximum 1,000) to more than 500,000 (Tier 4). - SI 155 of 2024 section 3(3): processing without a data controller licence is an offence carrying a fine up to level 11 or up to seven years imprisonment. - SI 155 of 2024 section 7: submitting false information when applying is an offence carrying the same maximum. - SI 155 of 2024 section 10(4)(a) and (f): the controller is accountable for its processors, recipients and agents, and must hold a written data processing agreement with each processor. - SI 155 of 2024 section 10(5): children's data requires parental or guardian consent, verification of that consent, regular data protection impact assessments, and data protection by design and by default. - SI 155 of 2024 section 12(6): failing to appoint a Data Protection Officer is an offence carrying a fine up to level 7 or up to two years imprisonment. - SI 155 of 2024 section 14: the Data Protection Officer deals with requests from the Authority and from data subjects and acts as the contact point for data subjects. - SI 155 of 2024 Fourth Schedule: Form DP3, the security breach notification. - Cyber and Data Protection Act section 11: sensitive information, which includes health data. - Cyber and Data Protection Act section 19: a security breach is notified to the Authority within twenty-four hours. - Cyber and Data Protection Act section 24: take all necessary measures to comply, and have internal mechanisms for demonstrating that compliance to data subjects and the Authority. - Cyber and Data Protection Act section 33(2): a data controller contravening sections 11, 13, 18(4), 24 or 28 faces a fine up to level 11 or up to seven years imprisonment. Section 33(6): the controller is liable for fines incurred by its agent or assignee. - Fines are expressed as levels on the standard scale. The instruments fix the level, not an amount of money, so no dollar value for a fine is stated on these pages. ## Related sites - [StoneGuard](https://stoneguard.co.zw/compliance): our general compliance product for organisations outside healthcare, with guides on licence cost, SI 155, penalties, and sector guides for schools, NGOs and churches. - [Lioncap Ventures](https://lioncapventures.com/compliance): our parent consultancy, with the interactive tier and retainer calculator and guides on Forms DP1, DP2 and DP3, inspection preparation and outsourcing the DPO role. ## Contact - WhatsApp: +263 772 724 514 - Book a call: https://calendly.com/avalonhealth/30min