Hospitals Must Obtain Explicit Consent Before Sharing Patient’s Data with Third Party Laboratories

Background

In Merceline Akoth Odeyo v St. Luke Orthopaedic & Trauma Hospital Eldoret, the Complainant filed a complaint with the Office of the Data Protection Commissioner (ODPC), alleging that the Respondent mishandled her sensitive health data by failing to keep it accurate and up to date and by providing her with another patient’s medical records. She stated that, on two separate visits to the Respondent’s facility, she was given medical test results belonging to a third party who had a similar first name but a different surname.

She further alleged that the Respondent told her that they would seek clarification from the third-party laboratory that conducted the test. She maintained that she had never been informed that her sensitive personal and health data would be shared with that laboratory and that any such disclosure occurred without her informed consent.

The Respondent’s

ResponseThe Respondent stated that:
  • the testing services were outsourced to a third-party laboratory, and the Complainant was informed of this arrangement during her visit.
  • the Complainant’s samples were sent to the third-party laboratory, which assigned each sample a unique barcode for identification and, after testing, emailed the results report to the hospital’s official laboratory email address.
  • to safeguard confidentiality and data security, a hospital laboratory technologist personally delivered the sample to the referral laboratory.
  • an administrative error occurred while processing the referral laboratory’s results, but it was an isolated instance of human error during data reconciliation.
  • the samples were transferred solely to provide the medical services requested by the Complainant and to protect her legitimate interests.

Determination

The Data Commissioner held as follows:
  • The Respondent relied on consent and legitimate interests as the lawful basis for processing the Complainant’s personal data. However, Section 45 of the Data Protection Act, 2019 sets out the permitted grounds for processing sensitive personal data, including health data, and legitimate interest is not one of them.
  • Under Section 32 of the Act, the data controller bears the burden of proving that consent was validly obtained. The Respondent provided no written record of consent and failed to show that the alleged consent met the standard of being explicit and informed.
  • The principle of transparency under Section 25 of the Act requires a data subject to be informed about who is processing their highly sensitive personal data. The Respondent failed to show that the Complainant was duly notified under Section 29 before her sensitive personal data was shared with any third party.
  • The Respondent’s admission of an administrative error in reconciling the test results confirmed a failure to maintain the accuracy and integrity of the Complainant’s sensitive health data, contrary to Section 25(e) of the Act.
  • Section 41 of the Act requires data controllers and processors to implement adequate technical and organizational measures to secure personal data. The admitted reconciliation error showed that the Respondent’s internal processes were inadequate and amounted to a breach of those security obligations.
  • The existence of a Data Sharing Agreement with the referral laboratory did not negate the independent obligation to obtain the data subject’s explicit consent before sharing her sensitive personal data. The general consent form introduced after the incident further indicated that the previous consent mechanism was inadequate.
  • Accordingly, the Respondent was found liable and ordered to pay the Complainant Kenya Shillings Five Hundred and Twenty-Five Thousand (KES 525,000/-) in compensation.