Table of Contents
- Introduction
- Background: What SHA Is, and Why This Matters Now
- The Timeline
- What the National Digital Health Infrastructure Actually Is
- DHA Certification: What It Actually Requires
- The Five-Step Certification Process
- The Technical Integration Requirements
- Why Certification Matters Beyond Claims
- Real Challenges Facilities Are Facing
- What Your Facility Should Do Right Now
- The Bottom Line
- Frequently Asked Questions
- Get Your Facility Ready
SHA HMIS Integration Guide for Kenyan Hospitals
SHA HMIS integration Kenya facilities once treated as a distant, optional upgrade has become an urgent, deadline-driven compliance requirement almost overnight. As of mid-2026, the Social Health Authority (SHA) and the Digital Health Agency (DHA) have moved from encouraging digital adoption to mandating it. They’ve attached a hard deadline with real, immediate consequences for facilities that miss it.
If you run a hospital, clinic, or dispensary anywhere in Kenya, this guide covers everything currently known about what’s required. It explains why it’s happening now and exactly what your facility needs to do before the deadline arrives.
Because this is a genuinely fast-moving, recently introduced policy area, treat the specific dates below as the most current information available at the time of writing. Confirm directly with SHA or your HMIS vendor before making final decisions. Implementation details continue to be refined.
Want a straight assessment of where your facility stands right now? Book a free SHA HMIS integration readiness assessment via WhatsApp – we’ll check your current system against the actual requirements below.
Background: What SHA Is, and Why This Matters Now
The Social Health Authority replaced Kenya’s former National Health Insurance Fund (NHIF) under the Social Health Insurance Act, enacted in November 2023. SHA began full operations on 1 October 2024. The government restructured public health insurance into three separate schemes under SHA’s management: the Primary Healthcare Fund (PHC Fund), the Social Health Insurance Fund (SHIF), and the Emergency, Chronic and Critical Illness Fund (ECCIF). Collectively, these schemes form the financing backbone of Kenya’s Universal Health Coverage push, branded as Taifa Care.
For the first two years of SHA’s existence, facilities largely interacted with the scheme through the SHA Provider Portal. This was a web-based claims and verification system. That changed abruptly in late June 2026. SHA and the Digital Health Agency jointly announced that the Provider Portal is being phased out entirely. Direct, certified HMIS-to-HIE integration will replace it.
The Timeline: What’s Already Happened and What’s Coming
Understanding the sequence of events matters. The transition is happening in stages with different deadlines for different facility types.
29 June 2026 – At a stakeholder forum convened by the Ministry of Health, SHA, and DHA, SHA CEO Dr. Mercy Mwangangi announced that all healthcare providers have three months to fully integrate their systems with the national HMIS framework or face decontracting. Health Cabinet Secretary Aden Duale reinforced the mandate. He described a fully connected digital ecosystem as essential to Taifa Care’s success.
Midnight, 29 June 2026 – The migration officially took effect for Level 4 public hospitals. They must now submit all new SHA claims exclusively through the Taifa Care HMIS platform. The legacy Provider Portal no longer accepts new claims from these facilities. Claims already submitted through the old portal before the cutover continue to be processed without interruption.
1 September 2026 – This is the hard deadline referenced for private facilities. Any private health facility without a DHA-certified HMIS integrated into the national Health Information Exchange (HIE) by this date will be unable to process SHA claims. They also cannot obtain new SHA contracts and risk exclusion from the national health financing system entirely.
FY 2026/28 contracting cycle – SHA has stated explicitly that healthcare providers who do not meet the prescribed HMIS and integration requirements will not be eligible for contracting. This applies to contract renewal and continued participation in SHA-funded schemes during this cycle. Non-compliance isn’t a temporary inconvenience. It’s a genuine threat to a facility’s ability to operate under SHA at all.
As of the most recent published figures, 11,034 healthcare facilities had been accredited by SHA overall. Of these, 6,228 public facilities (roughly 93%) had completed digital transformation. Additionally, 5,078 facilities were already operating on the SHA HMIS platform. Furthermore, 2,978 facilities were actively submitting claims electronically.
What the National Digital Health Infrastructure Actually Is
To understand what “integration” technically means, it helps to understand what your HMIS is actually connecting to.
The Digital Health Agency (DHA) is the government body responsible for building and operating Kenya’s Comprehensive Integrated Health Information System (CIHIS). This is the national digital health backbone. DHA’s mandate, established under the Digital Health Act 2023, includes creating national registries, certifying digital health solutions, and setting the interoperability standards every connected system must follow.
The Health Information Exchange (HIE) is the operational core of this system. It uses FHIR (Fast Healthcare Interoperability Resources) as its standards-based platform. This enables secure, real-time, bi-directional data sharing between different health systems.
The HIE hosts several critical live components:
• The Kenya Client Registry – a centralised, authoritative database ensuring every patient has a unique identifier recognised across the entire healthcare system. It uses both demographic validation and advanced matching to prevent duplicate records.
• National Shared Health Record (SHR) – a centralised repository aggregating patient health data from multiple sources (EMRs, laboratories, pharmacies). It uses FHIR and SNOMED CT standards, with role-based access and patient consent controls.
• Electronic Health Insurance Claims Platform – handles automated claim submission, tracking, and settlement for SHA. It includes AI/ML-based fraud detection, real-time monitoring, and secure payment gateway integration.
• Health Interoperability Services Layer (ISL) – the central hub responsible for routing and transforming messages between different connected health systems.
Your HMIS doesn’t connect to SHA directly in isolation. It connects to this entire layered national architecture. Consequently, the certification and integration requirements are as specific and technically demanding as they are.
DHA Certification: What It Actually Requires
Under the Digital Health Act 2023 and the associated Digital Health (Data Exchange) Regulations, only DHA-certified digital health solutions may legally connect to the national CIHIS Enterprise Service Bus. An uncertified HMIS simply cannot exchange data with SHA or any other national health system. This applies regardless of how technically capable it otherwise is.
DHA’s certification framework sets out six specific requirements every HMIS vendor (or facility running a custom system) must satisfy:
1. Self-Attestation Report – complete an internal compliance review and gap analysis against the certification framework. Submit it on the official Form HMIS 4. It assesses your own system against the full standard before formally applying.
2. ODPC Registration – register with the Office of the Data Protection Commissioner as both a data controller and a data processor. This is a requirement under Kenya’s Data Protection Act for any entity processing personal health data.
3. Data Protection Impact Assessment (DPIA) – conduct a formal, documented assessment with a qualified assessor. It identifies specific risks and the mitigation measures in place. Complete it before certification submission.
4. Security, Privacy & Confidentiality Policy – document an enforceable policy setting out exactly how patient health data is protected within the system.
5. Backup & Recovery Policy – document backup procedures, tested recovery time objectives, and verified disaster recovery protocols. Critically, having a backup strategy on paper isn’t sufficient. The certification process specifically requires demonstrating that recovery actually works.
6. Interoperability & Standards Compliance – demonstrate conformance with national data standards. This includes FHIR-based data exchange, ICD-11 diagnostic coding, and alignment with the national product catalogue codes. You must also prove capability to interface with CIHIS via the Enterprise Service Bus.
The Five-Step Certification Process
Facilities and vendors seeking certification work through a defined process on the official DHA Portal:
1. Account creation – register on the DHA Portal. Select either a Business Account (for healthcare organisations and HMIS vendors) or a Student/Innovator Account, as applicable.
2. Self-attestation – complete the internal compliance review and conduct the required gap analysis. Then submit the self-attestation form within the DHA Certification Dashboard.
3. Application submission – upload all required certification documents through the portal, along with proof of the applicable certification fee payment.
4. DHA technical review – DHA reviews all submitted documentation. They may test the solution directly in a certified lab environment to verify FHIR integration and standards conformance against the live national platform.
5. Outcome notification and certificate issuance – DHA notifies the applicant of the outcome within 30 days of completing the review. Vendors who disagree with an outcome can appeal to the DHA Complaints Committee. Once certified, systems appear on the DHA public registry and can connect to CIHIS. Certifications are subject to periodic renewal.
The Technical Integration Requirements, in Detail
Beyond certification itself, DHA has published a detailed HIE Integration Guide specifying exactly what a compliant HMIS must implement technically. This is the level of technical detail that genuinely defines SHA HMIS integration Kenya vendors and facilities are now expected to meet. It’s not a vague general expectation.
DHA categorises requirements as Critical (must-have for production), Standard (expected), or Advanced (optional enhancement). A system must complete 100% of Critical and Standard components to be eligible for production deployment.
Core integration principles (both Critical):
• Use only official DHA-provided APIs for any data exchange. No third-party or unofficial interfaces are permitted.
• Implement integration directly within the HMIS itself. No external middleware may act as an intermediary.
Client Registry integration:
• Register patients, including a default PIN system linked to the Afya Yangu patient portal – Critical
• Search comprehensively by ID number, name, date of birth and phone number- Critical
• Decrypt patient data securely using DHA-issued keys – Critical
• Store and map core patient fields locally to reduce repeated API calls – Standard
• Update patient information, handle dependents (spouse and children registered as next of kin), and implement an advanced consent workflow for data sharing – Standard
Eligibility checking:
• Implement patient eligibility search with clear results – Critical
• Initiate an SHA visit once eligibility is confirmed – Critical
• Display scheme-specific eligibility, active coverage periods, benefit limits and waiting periods across SHIF, ECCIF, PCIF and POMF – Standard
Facility Registry integration:
• Search facilities by code, name, location and level – Critical. Include local caching of facility details to populate claims consistently without repeated API calls.
Health Worker Registry integration:
• Mirror the Facility Registry pattern for practitioners: searchable by ID or registration number – Critical. Include locally cached practitioner details used consistently across all submitted claims.
Claims integration:
• Map SHA codes into the local HMIS database – Critical
• Flag and check preauthorisation requirements before services are rendered – Critical
• Submit and process preauthorisation requests – Critical
• Display SHA-payable intervention amounts – Standard
• Implement ICD-11 diagnostic search – Critical
• Build a complete claim bundle using locally stored patient, facility and practitioner data alongside services rendered and diagnoses – Critical. Submit claims at the point of service delivery and poll for status updates. Handle rejected claims requiring resubmission clearly – Critical.
Advanced, optional features:
• Include facility-level context (adapting workflows to what a specific facility level can actually offer) and service filtering by facility level. Both aim at improving usability rather than being strict compliance requirements.
Why Certification Matters Beyond Just Claims Processing
The consequences of non-integration extend well past simply being unable to submit SHA claims electronically:
Data protection liability. An uncertified HMIS that experiences a data breach while handling patient health data exposes the facility itself. This isn’t just the software vendor’s problem. Regulatory action under the Data Protection Act targets the facility too.
Market and referral access. Insurers, county governments, and national procurement processes increasingly treat DHA certification as a baseline requirement. Facilities running uncertified systems risk exclusion from tenders, referral networks and insurance scheme panels well beyond SHA specifically.
National health intelligence visibility. Facilities that are properly connected and submitting quality data become visible in national health planning, disease surveillance and resource allocation decisions. Facilities that remain disconnected are effectively invisible in the data driving national funding and policy decisions that ultimately affect them.
Patient experience. Once your HMIS is integrated, patients gain access through the Afya Yangu patient portal to their own health record, insurance interactions and, with consent, the ability to share their data across facilities. This meaningfully improves continuity of care, particularly during emergencies where a patient’s history would otherwise be unknown.
Real Challenges Facilities Are Facing
This transition isn’t without genuine, well-documented friction. It’s worth acknowledging honestly rather than presenting integration as simple for every facility.
The Kenya Medical Association has raised specific concerns that facilities in marginalised counties face chronic power outages and unstable internet connectivity. This makes consistent real-time cloud synchronisation genuinely difficult in practice, not just inconvenient.
The financial burden of upgrading local infrastructure, servers, and connectivity currently falls on individual facilities rather than being centrally subsidised. Staff training on new HMIS interfaces adds to this cost. This creates real risk that smaller dispensaries and rural facilities could struggle to remain compliant purely on cost and infrastructure grounds, independent of patient volume.
This is precisely why choosing an HMIS built with offline-resilient architecture matters more under this new mandate than it did previously. When the SHA Provider Portal’s lighter requirements were more forgiving of intermittent connectivity, offline capability was less critical. Now, it’s essential.
What Your Facility Should Do Right Now
1. Confirm your current HMIS vendor’s certification status directly. Ask specifically whether they have completed SHA integration. Find out where they stand in the DHA certification process. Get their realistic timeline for full production approval.
2. Verify your facility’s own ODPC registration. Certification requires the system operator to register as both a data controller and data processor. Confirm this is already in place rather than assuming your vendor’s registration covers your facility separately.
3. Review your backup and disaster recovery setup honestly. Certification specifically requires demonstrated, tested recovery capability, not just a documented policy that’s never actually been tested.
4. Assess your power and connectivity resilience. If your facility experiences frequent outages, prioritise an HMIS with genuine offline capability rather than one that simply assumes constant connectivity.
5. Budget for the transition now, not in August. Infrastructure upgrades, staff training and any vendor migration take real time. The deadline does not move based on individual facility readiness.
6. Use the official support channels if you’re stuck. SHA and DHA have committed to providing round-the-clock technical support during the transition period. Access it through the toll-free helpline 147 and a dedicated DHA helpdesk email.
The Bottom Line
SHA HMIS integration Kenya facilities are now required to complete isn’t a distant future requirement. It’s an active, deadline-driven mandate with a hard cutoff already set for private facilities on 1 September 2026. Genuine consequences, including decontracting and exclusion from SHA-funded schemes, await facilities that miss it.
Confirm your current system’s certification status today. Address any gaps in backup testing, data protection registration, or connectivity resilience now. Treat this as the operational priority it has become, rather than an IT project that can wait.
Get Your Facility Ready Before the Deadline
Navigating DHA certification requirements, the technical HIE integration specification and Data Protection Act compliance simultaneously is a significant undertaking for any facility to manage alone. Our managed IT services for healthcare facilities team can assess your current HMIS against the actual certification requirements. We’ll help close any gaps before the deadline.
For related reading, see our guides on streamlining SHA and private insurance claims in Kenyan clinics and key Data Protection Act compliance requirements for Kenyan health facilities.
Explore our Hospital Management System built for Kenyan health facilities. It features offline-first architecture, SHA/CARIMED claims capture, M-Pesa integration and KRA eTIMS-compliant receipting.
Want a free readiness check against the actual SHA and DHA requirements? Book it via WhatsApp or visit Sapiens IT Lab to request a full on-site assessment – we’ll show you exactly where your facility stands before the deadline arrives.
Chat with Us on WhatsApp



