Nigeria has a data protection framework, and health data sits in the most sensitive category within it. The specific obligations, and how they are enforced, continue to develop, so a practice should confirm current requirements with a qualified adviser rather than relying on general summaries including this one.

The underlying principles, though, are stable, and a practice that follows them is in a defensible position regardless of the detail.

Collect only what you need

Practices routinely collect information because a form has always asked for it. Occupation, marital status, next of kin, religion. Each field should have a reason. If nobody can say what a field is for, it should not be collected, because everything held is something that must be protected and can be lost.

Tell people what you do with it

Patients are entitled to know what you hold, why, who you share it with and how long you keep it. A short, readable privacy notice at reception and on your website covers this. It should mention the real sharing: HMOs, referral recipients, laboratories, and any software provider that processes data on your behalf.

Written in plain language, not in the legal register that guarantees nobody reads it.

Secure it in proportion to its sensitivity

  • Individual user accounts, never shared logins.
  • Access limited to what each role needs.
  • Screens positioned away from public view and locked when unattended.
  • Paper records in locked storage, not stacked on a counter.
  • Encryption on any laptop or phone holding patient data.
  • Backups that are themselves protected, including one held off site.
  • Accounts removed the day someone leaves.

Your suppliers are your responsibility

An EMR vendor, a cloud host, a billing service or a transcription service processes patient data on your behalf, and the duty to patients remains yours. There should be a written agreement covering what they may do with the data, what security they maintain, and what happens on termination.

Ask where the data is physically stored. If it leaves Nigeria, understand on what basis.

Respect patient rights

Patients can ask what you hold about them, ask for corrections, and in some circumstances object to particular uses. Have a defined route for handling such requests and a named person responsible, rather than improvising when the first one arrives.

Know what to do after a breach

A lost phone, an emailed letter to the wrong address, a stolen laptop, a file left in a public area. Decide in advance who is told internally, how it is contained, how it is recorded, and how you assess whether patients and the regulator must be notified.

Breaches are handled far better by practices that thought about it beforehand, and the difference is visible to everyone who reviews it afterwards.

Write down what you hold

A simple inventory: what data, where it lives, who can reach it, how long it is kept. It takes an afternoon and it is the foundation of every other obligation on this list.