Egypt's data protection law and your patient records: what clinics must do
Plain-language guide to Egypt's Law 151 of 2020 for clinics: sensitive data, consent, who sees phones and photos, retention, breaches and vendor questions.
Egypt's Personal Data Protection Law (Law 151 of 2020) treats health data as sensitive personal data. For a clinic that means every patient record, every before-and-after photo and every WhatsApp conversation is regulated, and the clinic, not the software vendor, is the responsible party. This is a practical guide, not legal advice; the law's executive regulations and the Data Protection Centre's guidance govern the details.
What the law expects of a clinic
- A lawful basis and consent. Processing health data requires explicit consent for the purposes you state. Marketing messages need their own consent, separate from treatment.
- Purpose limitation. Data collected for treatment cannot be reused for a campaign the patient did not agree to.
- Security. Appropriate technical and organisational measures: access control, encryption, logging.
- Patient rights. Access to their data, correction, and withdrawal of consent.
- Breach handling. Notification to the authority and, where required, to affected people within the prescribed period.
- Cross-border transfer rules. Where data is stored and processed matters.
The four places clinics leak data
- Phone numbers in lists. Every receptionist with the patient list can walk out with it. Mask numbers by role and log exports.
- Photos on personal phones. Before-and-after photos taken on a technician's phone and sent on WhatsApp are outside any control. Capture them in the system, encrypt them at rest, and restrict who can view them.
- Shared logins. One "reception" account used by five people makes an audit trail meaningless. Each person needs their own login, with two-factor authentication for anyone who can export data.
- Ex-employees. Deactivate accounts on the day someone leaves, and revoke mobile app sessions.
Consent that holds up
A consent form per treatment, signed on a tablet at reception and stored against the visit, does three jobs: it documents the medical consent, it records the data-processing consent, and it captures the marketing preference (WhatsApp, SMS, email) as separate checkboxes. Keep the template versioned so you can show which text a patient signed.
Retention
Keep clinical records as long as medical practice rules require, then delete or anonymise. Marketing data is different: once a patient withdraws consent, stop messaging immediately. Your system should let a patient's consent flags be changed in one place and have every automation respect them.
Questions to ask your software vendor
- Where are our data stored, and in which country?
- Does each clinic have its own isolated database, or do we share tables with other clinics?
- Are photos encrypted at rest? Who holds the key?
- Can phone numbers be masked per role? Is there an export log?
- Is there two-factor authentication? Per-user logins?
- Can we export all our data if we leave, and will you delete it afterwards?
- What is your breach process, and how fast will you tell us?
A vendor who cannot answer these in writing is a risk you carry, because under the law the clinic answers for its processors.
A 30-day starting plan
- Week one: separate logins for everyone, two-factor for admins, deactivate old accounts.
- Week two: mask phone numbers for roles that do not need them; turn on export logging.
- Week three: move photo capture into the system; delete copies from personal phones.
- Week four: update the consent template with data and marketing consent; start signing it on a tablet.
None of this needs a lawyer to start. It does need software that was built with these controls in it.