DHA-Compliant HMIS: What Hospitals Need to Know
Is the system your facility already depends on genuinely certified? Or does your vendor just say it’s “compatible” with SHA? That single question separates a hospital that sails through the current contracting cycle from one that discovers, mid-claim, that its HMIS was never actually approved to connect to Kenya’s national health systems.
A DHA compliant HMIS isn’t a marketing phrase. Under the Digital Health Act, 2023 and the Digital Health (Data Exchange) Regulations, 2025, only formally certified solutions may connect to the SHA claims platform, the national registries, and Kenya’s emerging shared health record. An uncertified system simply cannot process SHA claims, regardless of how capable it looks in a demo.
This matters right now specifically. With the current FY 2026/28 SHA contracting cycle underway and facilities running non-compliant systems at risk of losing contracting and renewal entirely, certification has stopped being a vendor’s technical detail. It’s become a procurement decision every hospital administrator needs to get right.
This guide walks through what DHA certification actually requires, how the six-stage certification process works, and exactly how to verify whether your current or prospective HMIS vendor genuinely holds it.
Not sure whether your HMIS is genuinely DHA compliant? Book a free compliance check via WhatsApp and we’ll help you verify your vendor’s certification status before it becomes a problem.
What “DHA Compliant” Actually Means, Legally
The Digital Health Agency runs a formal certification framework. It functions much like a seal of quality. Once a digital health solution is certified, it signals to hospitals, patients, and regulators alike that the system can be trusted with sensitive health data and will genuinely perform as claimed.
For a hospital administrator, the practical consequence is direct. If your HMIS vendor hasn’t completed this certification, your facility cannot electronically process SHA claims through that system. You cannot demonstrate compliance during an SHA contracting review. You risk exclusion from the current funding cycle entirely. Certification, in other words, isn’t primarily your vendor’s problem. It’s yours, because your facility’s ability to operate depends on it.
The Six-Stage Certification Process, Explained for Hospital Administrators
You don’t need to run this process yourself — your vendor does. However, understanding each stage tells you exactly what to ask for as proof. This is better than accepting a vague “yes, we’re compliant” at face value.
Stage 1: Self-attestation and application. The vendor assesses their own system against DHA’s minimum requirements. They then formally apply using Form HMIS 4, alongside full product documentation. This is where the certification clock starts.
Stage 2: Documentation review. The vendor submits a substantial compliance dossier: incorporation and business registration documents, a system manual, proof of ODPC registration as a data controller or processor, a Data Protection Impact Assessment, a security and privacy policy, a backup and disaster recovery policy, governance documents, and system architecture and API documentation. This also includes independent penetration test and vulnerability assessment reports.
Stage 3: Certification testing and audit. DHA independently tests the system against four core criteria, which we’ll cover in detail below. Crucially, this is a non-consultative audit. Auditors test against the criteria, but they won’t coach the vendor on how to fix issues along the way.
Stage 4: Audit report and decision. DHA issues a report detailing any non-conformances. The vendor then has an opportunity to provide corrective evidence. After this, an independent DHA team makes the final call. A successful outcome means the system is listed on DHA’s public certification register and issued a formal Certificate of Conformity.
Stage 5: Re-certification and ad hoc audits. Certification isn’t a one-time achievement. Vendors must maintain every certified function for at least two years. DHA can run surprise audits at any point during that window to confirm continued compliance.
Stage 6: Appeals. If a vendor disputes an audit outcome, they can formally appeal to DHA’s Complaints Committee under the Digital Health (Health Information Management Procedures) Regulations, 2025.
The Four Things DHA Actually Tests
Rather than a vague compliance checkbox, DHA’s audit is built around four specific criteria. Knowing these turns “is my HMIS compliant?” into a set of concrete questions you can actually ask your vendor.
1. Functionality. Does the system genuinely support day-to-day clinical and administrative work, from capturing patient demographics through to generating summaries and placing orders? This is the baseline: a certified system has to actually work for real hospital operations, not just look capable in a sales pitch.
2. Reporting and public health alerts. Can the system generate the reports Kenya’s national health system depends on, including submissions to the Integrated Disease Surveillance and Response system for reportable diseases and public health events? A hospital’s HMIS is also, in effect, part of the national early-warning infrastructure.
3. Security, privacy, and confidentiality. Does the system enforce role-based access control, strong user authentication, encryption of data both at rest and in transit, and complete audit trails showing exactly who accessed what and when? Given that patient data counts as sensitive personal data under Kenya’s Data Protection Act, this criterion carries real regulatory weight beyond DHA certification alone.
4. Information exchange and interoperability. Can the system actually talk to the national Health Information Exchange, connecting through the CIHIS Enterprise Service Bus using the HL7 FHIR (R4) standard and the prescribed national registries? This is frequently where legacy or poorly built systems fail, since older platforms were rarely designed to exchange data this way.
How to Verify Your Vendor Is Genuinely Certified, Not Just Claiming It
“Compatible with SHA” and “DHA certified” are not the same statement. Vendors don’t always volunteer the distinction. Here’s how to check for yourself, rather than taking a sales claim at face value.
1. Check DHA’s public certification register directly rather than relying solely on a vendor’s own website or brochure claims.
2. Request a copy of the vendor’s Certificate of Conformity. A genuinely certified vendor should produce this without hesitation.
3. Ask specifically which of the four audit criteria their certification covers. Request evidence, not just a verbal assurance, for the interoperability and security requirements in particular. These are the areas legacy systems most commonly fail.
4. Ask how they handle the two-year re-certification cycle. A vendor with no clear answer here may hold a certificate that’s already lapsed or is close to lapsing without your knowledge.
5. Treat vagueness as a warning sign. If a vendor can’t clearly explain their certification status, their audit outcome, or their re-certification timeline, that uncertainty is itself useful information about how seriously they’ve taken this process.
What Happens If Your HMIS Isn’t Compliant
The consequences here aren’t theoretical. Facilities running non-compliant systems during the current SHA contracting cycle risk losing contracting and renewal outright. This means no new SHA contracts and no continued participation in SHA-funded schemes.
Beyond the immediate claims impact, an uncertified system also leaves your facility unable to demonstrate the data protection and security standards regulators increasingly expect. This exposes you to separate risk under Kenya’s Data Protection Act if something goes wrong with patient data.
Put simply, non-compliance doesn’t just slow down a single claim. It threatens your facility’s entire relationship with SHA-funded healthcare financing.
A Practical Due-Diligence Checklist for Your Facility
1. Confirm your current vendor’s certification status directly against DHA’s public register this week, not next quarter.
2. Request the Certificate of Conformity and file it alongside your facility’s own compliance records.
3. Verify your own facility’s ODPC registration as a data controller or processor. Vendor certification doesn’t automatically cover this separate, facility-level requirement.
4. Ask your vendor directly about the four audit criteria and request concrete evidence for interoperability and security specifically.
5. Diary the two-year re-certification date so it never lapses without your knowledge.
6. If you’re evaluating a new HMIS, build DHA certification status into your procurement criteria from the outset. Don’t treat it as a detail to confirm after signing a contract.
The Bottom Line
A genuine DHA compliant HMIS has passed a structured, independently audited six-stage certification process. It covers functionality, public health reporting, security, and interoperability. It holds a verifiable Certificate of Conformity to prove it.
“Compatible with SHA” is a much lower bar, and one that won’t protect your facility during a contracting review. Confirming this distinction now, before a claim gets rejected or a contract renewal gets questioned, is one of the highest-leverage things a hospital administrator can do this quarter.
Verify Your Facility’s HMIS Compliance Today
Confirming a genuine DHA compliant HMIS status shouldn’t require guesswork or trusting a vendor’s brochure. Our managed IT services for healthcare facilities team can help you verify your current vendor’s certification, or evaluate a new system against DHA’s actual four-criteria audit before you commit to it.
For related reading, see our guides on streamlining SHA and private insurance claims in Kenyan clinics and the full SHA HMIS integration guide for Kenyan hospitals.
Explore our Hospital Management System built for Kenyan health facilities, featuring offline-first architecture, SHA/CARIMED claims capture, M-Pesa integration, and KRA eTIMS-compliant receipting.
Want a free compliance check against DHA’s actual certification requirements? Book it via WhatsApp or visit Sapiens IT Lab to request a full on-site assessment.
Chat with Us on WhatsApp



