SHA HMIS Compliance Is an Infrastructure Problem, Not Just a Software One
The Social Health Authority has set a hard deadline: every contracted healthcare facility must adopt a Digital Health Agency-certified HMIS integrated with the National Health Information Exchange by September 1, 2026. Facilities that miss this date lose their SHA contracts and cannot process claims.
Most facility managers are asking the right first question — which HMIS to adopt. But there is a second question that receives far less attention: does the facility's underlying IT infrastructure actually support that HMIS? A certified HMIS running on an unreliable connection, an unsecured network, or without compliant data handling is still a non-compliant facility. SHA's digital requirements reach all the way down to the infrastructure layer.
The six infrastructure requirements SHA compliance depends on
Reliable, redundant internet connectivity for always-on SHA claims processing
Secure, segmented networks that isolate clinical data from general traffic
Kenya Data Protection Act 2019 compliant data handling for all patient records
Biometric patient verification at point of care
Encrypted backup with tested and documented restore procedures
Secured, managed endpoints on every HMIS-connected device
1. Reliable, redundant connectivity
SHA's national Health Information Exchange requires your HMIS to hold a live, authenticated connection throughout every clinical interaction. Patient eligibility verification, claims submission, and diagnostic data exchange all happen in real time. There is no offline mode — if your connection drops, claims cannot be processed and patient verification fails.
Most clinics and mid-tier hospitals operate on a single ISP connection. When that link goes down, the HMIS goes with it. Under the SHA reimbursement model, clinical encounters during an outage may not be reimbursable at all. A single ISP is not a connectivity strategy for a SHA-contracted facility — it is a revenue risk.
Sentire designs and manages dual-ISP WAN configurations that automatically route traffic to a secondary provider when the primary link fails. Switchover takes under 60 seconds with no manual intervention and no disruption to active HMIS sessions. Primary and secondary links run on separate infrastructure, routed through our TP-Link Omada managed networking platform, to eliminate shared failure points.
2. Secure network segmentation
SHA's HMIS requirements intersect directly with the Kenya Data Protection Act 2019. Patient records processed through your HMIS are classified as sensitive personal data under the DPA, and the Act requires appropriate technical safeguards. A flat network where clinical workstations share traffic with reception PCs, staff Wi-Fi, and any other connected device does not meet that standard.
Network segmentation using VLANs creates enforced boundaries between your clinical environment and everything else on the premises. Traffic between segments is controlled by policy and logged, giving you the documented isolation evidence your DPA compliance requires. Without it, a compromise anywhere on your network — a staff device with malware, an unmanaged printer — can reach patient data.
Sentire's healthcare network segmentation service designs and implements VLAN-isolated clinical environments. A managed firewall enforces inter-VLAN policy, generates access logs for audit purposes, and blocks unauthorised lateral movement. All network security policies are documented in a format suitable for DPA audit evidence.
3. Data Protection Act 2019 compliance
The Kenya Data Protection Act 2019 designates health data as sensitive personal data. Any healthcare facility processing patient records through a digital HMIS is a data controller under the Act. The obligations are specific: data must be stored securely, protected against unauthorised access, retained only as long as necessary, and subject to documented governance procedures.
SHA's own accreditation audits increasingly verify that facilities have these controls in place. A facility that has adopted a DHA-certified HMIS but cannot demonstrate secure data handling or a documented retention policy is exposed to regulatory risk under both SHA and the Office of the Data Protection Commissioner.
Sentire implements role-based access controls across all HMIS-connected systems through our cybersecurity services, powered by Sophos. Patient data is accessible only to authorised staff. Access events are logged and retained in a tamper-evident format. All data in transit between clinical systems and the national HIE is encrypted end to end.
4. Biometric patient verification
SHA mandates real-time biometric patient verification at point of care. Facilities must be able to verify patient identity against the SHA database at every clinical encounter. This requires both the HMIS software integration and the physical biometric hardware at reception and clinical entry points.
Sentire installs and manages ZKTeco biometric systems configured for patient-facing verification workflows. ZKTeco devices integrate with access control and time-and-attendance logging, providing the identity verification audit trail that SHA and DPA compliance both require. Our biometric access control service covers hardware installation, software configuration, staff training, and ongoing support.
5. Encrypted backup with tested recovery
Clinical systems have a higher tolerance for brief outages than they do for data loss. Patient records lost due to a failed server, ransomware, or accidental deletion cannot be recovered without a tested backup. SHA's digital framework implies continuous availability of patient histories for claims verification — a facility that cannot produce previous encounter records is in a difficult position during any audit or dispute.
Beyond SHA, the Kenya DPA 2019 requires data controllers to protect personal data against accidental loss or destruction. An untested backup is not a backup — it is a liability. Recovery procedures must be verified to work before they are needed.
Sentire's backup and disaster recovery service, powered by Acronis and Veeam, implements automated encrypted backup for all HMIS servers and clinical databases. Daily incremental and weekly full backups are retained offsite. Restore exercises are carried out monthly and results documented — giving you a verified recovery time objective and a paper trail for DPA compliance.
6. Endpoint management on HMIS-connected devices
Every device accessing your HMIS — consultation room terminals, reception desks, pharmacy workstations — is a potential entry point for malware that could compromise patient data or bring down your claims processing. Unmanaged, unpatched devices on the clinical network are one of the most common causes of healthcare data breaches.
Sentire deploys and manages Sophos endpoint protection across all HMIS-connected devices through our managed IT support service. Centralised policy enforcement ensures every device runs current antimalware signatures, system patches are applied on schedule, and any threat is detected and contained in real time. Device health is monitored continuously — you do not find out a workstation is compromised when it takes the HMIS down.
What an SHA-ready IT environment looks like
Dual-ISP WAN with sub-60s automatic failover
Clinical VLAN isolation with firewall policy logging
DPA-compliant access controls and data encryption
ZKTeco biometric patient verification hardware and configuration
Encrypted offsite backup with monthly tested restore procedures
Sophos managed endpoint security on all HMIS devices
The September 1 window is closing
With the deadline now only weeks away, facilities that have not yet addressed the infrastructure layer need to move quickly. A network segmentation and connectivity project for a mid-size clinic typically takes two to three weeks from site assessment to completion. Backup and endpoint deployments can run in parallel.
Sentire carries out a free IT infrastructure assessment for healthcare facilities. We assess your connectivity, network architecture, data protection controls, backup, biometric systems, and endpoint security against SHA and DPA requirements. The assessment produces a written gap report with a clear remediation plan and timeline. There is no obligation to proceed, but it gives you an accurate picture of what needs to change before the deadline.
Book your free SHA infrastructure assessment
We assess your connectivity, network security, data protection controls, backup, and endpoint security against SHA and DPA requirements — and give you a written gap report. Call us on +254 726 051100 or request a site visit.