Privacy Policy

At Midhill Hospital, we are committed to protecting your privacy and ensuring the security of your personal information. This policy outlines how we collect, use, and safeguard your data in accordance with Kenyan data protection laws.

Last updated: July 21, 2025

Information We Collect

We collect various types of information to provide you with quality healthcare services:

  • Personal Information: Name, date of birth, national ID number, contact details, and emergency contact information
  • Medical Information: Medical history, diagnoses, treatments, medications, and test results
  • Financial Information: Payment details, insurance information, and billing records
  • Technical Information: IP address, browser type, and usage data when you visit our website

How We Use Your Information

We use your information for the following purposes:

  • Providing medical care and treatment
  • Managing appointments and scheduling
  • Processing payments and insurance claims
  • Communicating with you about your care
  • Improving our services and patient experience
  • Complying with legal and regulatory requirements
  • Ensuring the safety and security of our facilities

Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

  • With Your Consent: When you explicitly authorize us to share your information
  • Medical Necessity: With other healthcare providers involved in your care
  • Legal Requirements: When required by law, court order, or government regulations
  • Public Health: For public health reporting as required by Kenyan health authorities
  • Service Providers: With trusted third-party service providers who assist in our operations

Data Security and Protection

We implement comprehensive security measures to protect your personal information:

  • Encryption of sensitive data in transit and at rest
  • Secure access controls and authentication systems
  • Regular security audits and vulnerability assessments
  • Staff training on data protection and privacy
  • Physical security measures for our facilities
  • Regular backup and disaster recovery procedures

Your Rights and Choices

Under Kenyan data protection laws, you have the following rights:

  • Access: Request a copy of your personal information
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your information (subject to legal requirements)
  • Portability: Request transfer of your data to another provider
  • Objection: Object to certain processing activities
  • Withdrawal: Withdraw consent for processing (where applicable)

Data Retention

We retain your personal information for as long as necessary to provide healthcare services and comply with legal obligations:

  • Medical records are retained for a minimum of 7 years as required by Kenyan health regulations
  • Financial records are retained for 7 years for tax and audit purposes
  • Website usage data is retained for 2 years for analytics and improvement
  • We securely dispose of information when it is no longer needed

Cookies and Tracking Technologies

Our website uses cookies and similar technologies to enhance your experience:

  • Essential Cookies: Required for basic website functionality
  • Analytics Cookies: Help us understand how visitors use our site
  • Preference Cookies: Remember your language and display preferences
  • Security Cookies: Help protect against fraud and ensure secure access

You can control cookie settings through your browser preferences. However, disabling certain cookies may affect website functionality.

Children's Privacy

We are committed to protecting the privacy of children. For patients under 18 years of age:

  • We collect information with parental or guardian consent
  • Parents or guardians have the right to access and control their child's information
  • We follow special procedures for handling pediatric patient data
  • Children's information is subject to additional security measures

International Data Transfers

Your personal information is primarily stored and processed in Kenya. In limited circumstances, we may transfer data internationally:

  • Only when necessary for your medical care (e.g., specialist consultations)
  • With appropriate safeguards and data protection agreements
  • In compliance with Kenyan data protection regulations
  • With your explicit consent when required

Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements:

  • We will notify you of significant changes through our website or direct communication
  • The updated policy will be effective immediately upon posting
  • We encourage you to review this policy periodically
  • Continued use of our services constitutes acceptance of updated terms

Contact Us

If you have any questions about this privacy policy or our data practices, please contact us:

Data Protection Officer

Midhill Hospital

Naivasha Road, Dagoretti, Nairobi, Kenya

+254 713 338 084
privacy@midhillhospital.org

You also have the right to lodge a complaint with the Office of the Data Protection Commissioner in Kenya if you believe your rights have been violated.

Quick Navigation