NDPR Compliance

Last updated: August 19, 2026

NDPR Compliant Platform

MediAID Plus is designed and operated in compliance with the Nigeria Data Protection Regulation (NDPR) and the Nigeria Data Protection Act, as administered by the Nigeria Data Protection Commission (NDPC). We are committed to protecting Personal Health Information (PHI) and ensuring the security and privacy of all healthcare data.

Security Measures

Encryption

All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256 encryption standards.

Access Controls

We implement role-based access controls (RBAC) to ensure that only authorized personnel can access PHI. Multi-factor authentication (MFA) is required for all administrative accounts.

Audit Logs

Comprehensive audit logs track all access to PHI, including who accessed what data, when, and from where. These logs are retained in accordance with NDPR requirements.

Data Backup and Recovery

Regular automated backups ensure data availability and recovery in case of system failures. Backup data is also encrypted and stored securely.

Data Processing Agreement (DPA)

As a Data Processor under the NDPR, we enter into Data Processing Agreements (DPAs) with the Data Controllers we serve. Our DPA ensures that we:

  • Use and disclose PHI only as permitted by the DPA and the NDPR
  • Implement appropriate safeguards to prevent unauthorized use or disclosure
  • Report any security incidents or breaches as required by law
  • Ensure subcontractors also comply with NDPR requirements
  • Return or destroy PHI upon termination of the agreement

Administrative Safeguards

Data Protection Officer

We have designated a Data Protection Officer responsible for developing and implementing security policies and procedures.

Workforce Training

All employees undergo regular NDPR compliance training to ensure they understand their responsibilities in protecting PHI.

Incident Response

We maintain an incident response plan to quickly identify, contain, and remediate any security incidents or breaches.

Physical Safeguards

  • Data centers are secured with 24/7 monitoring and access controls
  • Server rooms require biometric authentication for entry
  • All physical media containing PHI is securely stored and destroyed when no longer needed

Data Subject Rights

In compliance with the NDPR, patients have the right to:

  • Access their health information
  • Request amendments to their records
  • Request an accounting of disclosures
  • File complaints regarding privacy practices
  • Request restrictions on certain uses and disclosures

Compliance and Certifications

  • NDPR Compliant Infrastructure
  • SOC 2 Type II Certified
  • ISO 27001 Certified
  • Regular Third-Party Security Audits

Contact Us

For questions about our NDPR compliance practices, please contact our Data Protection Officer:

MediAID Plus

Data Protection Officer

Email: security@mediaidplus.com.ng

Phone: +234 (813) 589-8558

Address: C21, Meridian Park Estate, Awoyaya, Lagos 101241, Nigeria