ZIMBABWE'S healthcare sector has raised concerns over the financial and administrative burden created by new data protection requirements, with medical practitioners calling for a review of the regulatory framework ahead of compliance inspections scheduled to begin next month.
The Postal and Telecommunications Regulatory Authority of Zimbabwe (Potraz) has made it mandatory for healthcare service providers to obtain data controller licences and appoint data protection officers (DPOs).
The requirements have attracted renewed attention following Potraz's announcement that compliance inspections of healthcare institutions will begin on September 1, 2026.
While stakeholders acknowledge the importance of protecting personal information, particularly sensitive medical records, concerns are mounting that the current implementation framework could impose disproportionate costs on healthcare providers and, ultimately, patients. Under the licensing regime, healthcare providers face costs starting at approximately US$300 annually for a data controller licence.
For small private practices with limited staff, patient numbers, and financial resources, practitioners said the additional costs could put significant pressure on already constrained operations.
Medicine lecturer and prominent medical doctor Johannes Marisa, representing private doctors, said the additional regulatory costs could ultimately have an impact on the affordability and sustainability of private medical practice.
“The regulations add an extra burden on the already struggling private medical institutions. I don't think it's sustainable, considering that HPAZ [Health Professions Authority of Zimbabwe] is already regulating the profession,” Marisa said.
Marisa noted that such expenses could eventually be passed on to patients through higher consultation and service fees, potentially making healthcare less affordable.
Medical doctor and public policy analyst Marlon-Ralph Nyakabau said the regulatory approach needed to be reconsidered to ensure that data protection obligations were proportionate to the actual risks faced by different organisations.
“The current approach is inflexible, overly prescriptive and insufficiently risk-based,” Nyakabau said.
He argued that a one-size-fits-all model failed to adequately recognise differences in the scale, complexity, and potential consequences of data breaches across organisations.
Nyakabau’s wider work in digital health has emphasised the importance of privacy and confidentiality as healthcare becomes increasingly digitised.
The debate has also raised questions about whether the new requirements sufficiently take into account existing legislation governing the health sector.
The Medical Services Amendment Act, 2026, prohibits the denial of emergency medical treatment, while the Health Professions Act [Chapter 27:19] requires healthcare practitioners to create, maintain, and securely retain patient records for prescribed periods.
Healthcare providers, therefore, have limited discretion over the number of patients they treat or the records they are legally required to maintain.
The Zimbabwe Medical Association (ZiMA) has also weighed in, arguing that the new licensing requirements could duplicate existing regulatory obligations and increase compliance costs without necessarily delivering a corresponding improvement in the protection of patient information.
Healthcare professionals are already regulated by the HPAZ and its professional councils, which enforce requirements relating to patient confidentiality, record management, ethical conduct, and professional accountability.
Practitioners who breach these obligations can face serious disciplinary consequences, including suspension or removal from professional registers.
Marisa said they were calling on the Ministry of ICT and Potraz to reconsider the implementation framework and adopt a more proportionate, risk-based approach.