
Medhandy is a digital health platform used by hospitals, clinics, laboratories, pharmacies, HMOs, and patients to securely exchange medical information and improve continuity of care. This Privacy Policy explains how we handle personal data, health data, and operational data in line with applicable law and accepted healthcare privacy practices.
Compliance
Written for the Nigeria Data Protection Act 2023, the National Health Act, and common healthcare privacy expectations.
Sensitive data
Covers patient records, appointments, laboratory results, prescriptions, billing, audit logs, and staff account data.
Rights and safety
Explains access, correction, retention, disclosure, breach response, and the security controls that protect the platform.
Contents
Support
For privacy, legal, or policy questions, contact support@medhandy.net.
Medhandy is committed to protecting privacy in a healthcare setting. Because the platform processes sensitive health information, this policy is designed for a health-tech environment rather than a generic software product.
This policy should be read together with the Terms of Use, the Acceptance Policy, hospital-specific rules, and any data processing agreements that apply to a facility or enterprise customer.
Medhandy is intended to operate in accordance with the Nigeria Data Protection Act 2023, the National Health Act, and accepted healthcare privacy and security practices.
Where a hospital, clinic, or enterprise customer has stricter internal rules, those rules should also be followed, provided they do not conflict with law.
We may collect the following categories of information:
We aim to collect only what is needed to deliver the service, support care, and maintain accountable system operation.
Depending on the context, Medhandy may process data on one or more of the following bases:
We use safeguards intended to protect sensitive healthcare data, including:
We retain data for as long as needed to provide the service, support care, maintain audit trails, satisfy legal obligations, resolve disputes, and preserve records required by a hospital or healthcare law.
Medical records may be retained longer than ordinary account data because healthcare records often have special legal and operational retention requirements.
If information is processed or stored outside Nigeria, we should explain where that occurs and what safeguards are in place, such as contractual protections, access restrictions, or approved infrastructure providers.
Cross-border processing should not reduce the level of protection expected for sensitive healthcare data.
Records for minors or vulnerable patients should be handled in accordance with local law, guardian consent requirements, and the responsible hospital's safeguarding policy.
If a breach occurs, Medhandy should detect, contain, investigate, remediate, and where required notify affected parties and regulators. Incidents should be reviewed to reduce recurrence and improve controls.
We may update this policy to reflect product changes, legal changes, or operational changes. Significant updates should be communicated through the app, email, or another appropriate notice channel.
Hospitals should review this policy with legal, compliance, and clinical governance teams before use in production.