Xtudio Xtudio
Compliance

Egypt's data protection law and your patient records: what clinics must do

Plain-language guide to Egypt's Law 151 of 2020 for clinics: sensitive data, consent, who sees phones and photos, retention, breaches and vendor questions.

Egypt's Personal Data Protection Law (Law 151 of 2020) treats health data as sensitive personal data. For a clinic that means every patient record, every before-and-after photo and every WhatsApp conversation is regulated, and the clinic, not the software vendor, is the responsible party. This is a practical guide, not legal advice; the law's executive regulations and the Data Protection Centre's guidance govern the details.

What the law expects of a clinic

  • A lawful basis and consent. Processing health data requires explicit consent for the purposes you state. Marketing messages need their own consent, separate from treatment.
  • Purpose limitation. Data collected for treatment cannot be reused for a campaign the patient did not agree to.
  • Security. Appropriate technical and organisational measures: access control, encryption, logging.
  • Patient rights. Access to their data, correction, and withdrawal of consent.
  • Breach handling. Notification to the authority and, where required, to affected people within the prescribed period.
  • Cross-border transfer rules. Where data is stored and processed matters.

The four places clinics leak data

  1. Phone numbers in lists. Every receptionist with the patient list can walk out with it. Mask numbers by role and log exports.
  2. Photos on personal phones. Before-and-after photos taken on a technician's phone and sent on WhatsApp are outside any control. Capture them in the system, encrypt them at rest, and restrict who can view them.
  3. Shared logins. One "reception" account used by five people makes an audit trail meaningless. Each person needs their own login, with two-factor authentication for anyone who can export data.
  4. Ex-employees. Deactivate accounts on the day someone leaves, and revoke mobile app sessions.

Consent that holds up

A consent form per treatment, signed on a tablet at reception and stored against the visit, does three jobs: it documents the medical consent, it records the data-processing consent, and it captures the marketing preference (WhatsApp, SMS, email) as separate checkboxes. Keep the template versioned so you can show which text a patient signed.

Retention

Keep clinical records as long as medical practice rules require, then delete or anonymise. Marketing data is different: once a patient withdraws consent, stop messaging immediately. Your system should let a patient's consent flags be changed in one place and have every automation respect them.

Questions to ask your software vendor

  • Where are our data stored, and in which country?
  • Does each clinic have its own isolated database, or do we share tables with other clinics?
  • Are photos encrypted at rest? Who holds the key?
  • Can phone numbers be masked per role? Is there an export log?
  • Is there two-factor authentication? Per-user logins?
  • Can we export all our data if we leave, and will you delete it afterwards?
  • What is your breach process, and how fast will you tell us?

A vendor who cannot answer these in writing is a risk you carry, because under the law the clinic answers for its processors.

A 30-day starting plan

  1. Week one: separate logins for everyone, two-factor for admins, deactivate old accounts.
  2. Week two: mask phone numbers for roles that do not need them; turn on export logging.
  3. Week three: move photo capture into the system; delete copies from personal phones.
  4. Week four: update the consent template with data and marketing consent; start signing it on a tablet.

None of this needs a lawyer to start. It does need software that was built with these controls in it.

In the product Patient Records See how Xtudio handles this in the Patient Records module.