Legal

Privacy & data handling

How MedFi and AfrIgnite Smart Solutions handle personal and health data — written plainly, because the practices we serve have to answer these questions to their patients and to regulators.

Who is responsible for what

Your practice is the data controller — it decides why and how patient data is used. MedFi and AfrIgnite Smart Solutions are data processors — we process that data on your instructions, under written agreement, as the Cyber and Data Protection Act requires.

Tenant isolation by architecture

Every practice gets an isolated tenant. Your patient records, claims, ledgers and remittances are not visible to other practices on the platform, and access between tenants is enforced at the data layer — not just in the UI.

Role-based access

Access to records is granted by role (reception, nurse, doctor, finance, owner). A receptionist cannot open clinical notes they have no reason to see. Every access is logged in an audit trail that names who, what and when.

Consent capture

Patient consent for processing and sharing is captured at intake and stored against the patient record — including parental consent for minors. The records an inspector asks for are produced from the same system that captured them.

What we hold and why

We hold the data your practice enters to operate it: patient demographics, member numbers, clinical notes, claims, invoices, remittances and payments. We do not sell data. We do not use patient data to train models. Data is processed to run your practice and nothing else.

Retention and export

Your data is yours. You can export it on request. On termination we provide a full export and then delete your tenant data on a defined schedule, unless retention is required by law or an ongoing regulator matter.

Breach response

If a security incident affects your patient data we follow a documented breach-response plan: containment, assessment, and notification. Under the Act, controllers must notify POTRAZ within 24 hours of becoming aware of a breach and affected patients within 72 hours where there is high risk.

Where this sits in the law

MedFi is operated from Zimbabwe by AfrIgnite Smart Solutions, 30 Samora Machel Avenue, Harare. Our handling of personal data is governed by the Cyber and Data Protection Act [Chapter 12:07] and Statutory Instrument 155 of 2024. Practices using MedFi remain the data controller and are responsible for their own notification, licensing and DPO obligations under the Act — we support those obligations operationally but do not assume the controller role.

Your patients' rights

Patients may ask the practice what data is held about them, request correction, and in some cases request erasure. MedFi provides the tools to find, export, correct and audit a patient's records on request. Requests are handled by the practice as controller; we provide the records and the audit trail.

This page is a summary, not legal advice. For formal compliance, confirm your specific obligations with POTRAZ or a qualified legal practitioner. See our data-protection readiness page for a free self-check.

Book a working consultation

A practical session on your actual systems — reconciliation gaps, compliance exposure, or where your money is stuck. No payment. We follow up within one business day.