Engage Benson

Personal Information

1 / 4
“Human Error” Cost St. Luke’s Hospital KES 525,000: What Every Healthcare Provider Must Know About Patient Data Sharing

“Human Error” Cost St. Luke’s Hospital KES 525,000: What Every Healthcare Provider Must Know About Patient Data Sharing

2 August 2026

You cannot share a patient’s medical data with a third-party laboratory without their explicit, informed consent. You cannot rely on a verbal acknowledgment or a general consent form tucked into admission papers. And you certainly cannot hand one patient another patient’s medical results and then argue that you practiced data minimization. That is exactly what St. Luke Orthopaedic & Trauma Hospital Eldoret was accused of doing in ODPC Complaint No. 2125 of 2025.

Merceline Akoth Odeyo visited the hospital for medical services on 3rd July 2025. Samples were collected from her for testing. She was told to come back after two weeks for her results. When she returned, she was handed medical results that belonged to a third party, a person who shared only a similar first name with her but had a completely different surname. This happened twice.

The hospital had sent her samples to a third-party laboratory without telling her. They shared her name with that lab. When the results came back, an administrative error resulted in someone else’s sensitive health information being placed in her hands. The hospital admitted this was human error, an isolated case.

Merceline had never been informed that her data would be transferred to a third party. She had never given her consent. The hospital argued that they had obtained verbal consent, practiced data minimization by sharing only her name, and that the transfer was necessary to protect her legitimate interest under Section 30 of the Data Protection Act. The Office of the Data Protection Commissioner found that none of these arguments was valid.

Here is why this matters for every healthcare provider:

1. Sensitive personal data requires explicit consent.

Section 45 of the Data Protection Act categorises health data as sensitive personal data. Unlike ordinary personal data, sensitive data cannot be processed on the basis of legitimate interest alone. The law mandates explicit, informed consent. The hospital’s argument that the transfer was necessary to protect Merceline’s legitimate interest failed because legitimate interest is simply not a permitted ground for processing sensitive personal data.

2. Verbal consent is not enough.

The hospital claimed they obtained verbal consent from Merceline. The ODPC rejected this. Consent under Section 2 of the Act must be express, unequivocal, free, specific, and informed. It must be given by a clear affirmative action and must be capable of proof. A verbal conversation that leaves no record cannot meet this standard. If you cannot prove consent, you do not have consent.

3. The burden of proof rests with the data controller.

Section 32 of the Act places the burden on the data controller or processor to demonstrate that valid consent was obtained. The hospital failed to discharge this burden. They could not produce any evidence that Merceline had been informed that her data would be shared with a third-party laboratory, or that she had agreed to such sharing.

4. Data minimization does not excuse unlawful processing.

The hospital argued that they practiced data minimisation by sharing only Merceline’s name with the laboratory. The ODPC was not persuaded. Processing even a minimal amount of personal data without a lawful basis is still unlawful processing. You cannot reduce your liability by arguing that you only shared a name when the name itself constituted personal data being processed without consent.

5. Administrative errors are not a defence.

The hospital admitted that handing over another patient’s medical results was human error, an isolated case. The law does not recognise human error as a defence to unlawful processing. The obligation under Section 41 of the Act is to implement technical and organisational measures that prevent such errors from occurring in the first place. A system that allows one patient’s sensitive health data to be handed to another patient is a system that has failed to integrate the necessary safeguards.

6. Third-party transfers require transparency.

When a healthcare provider outsources testing to a third-party laboratory, the patient must be informed of that fact. They must know exactly who is handling their data. They must consent to that specific transfer. A general consent form that does not mention third-party sharing is insufficient.

The Outcome

The hospital was ordered to pay Merceline KES 525,000 in compensation.

What You Need to Do

If you run a healthcare facility, a clinic, or any organisation that processes sensitive personal data, this determination draws a line that many people do not know exists. Review your patient consent forms. Ensure they explicitly state that data may be shared with third-party laboratories. Ensure patients understand exactly who will handle their data. Ensure you obtain consent that is specific, informed, and capable of proof. Implement technical and organisational measures that prevent administrative errors. Train your staff on data protection obligations.

These liabilities are real. Your contracts and consent processes must anticipate them or they may devour your business. Review your data protection practices with me to scan for compliance, consent frameworks, and risk allocation.

Benson Odiwuor

Advocate of The High Court of Kenya

Should you have any questions regarding the subject, reach out at insights@bensonodiwuor.com

Found this useful? Share it with a colleague.

Share
All posts

Legal counsel, research collaboration, or speaking inquiries.

Engage Benson

Personal Information

1 / 4