Last updated: August 19, 2026
MediAID Plus is designed and operated in compliance with the Nigeria Data Protection Regulation (NDPR) and the Nigeria Data Protection Act, as administered by the Nigeria Data Protection Commission (NDPC). We are committed to protecting Personal Health Information (PHI) and ensuring the security and privacy of all healthcare data.
All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256 encryption standards.
We implement role-based access controls (RBAC) to ensure that only authorized personnel can access PHI. Multi-factor authentication (MFA) is required for all administrative accounts.
Comprehensive audit logs track all access to PHI, including who accessed what data, when, and from where. These logs are retained in accordance with NDPR requirements.
Regular automated backups ensure data availability and recovery in case of system failures. Backup data is also encrypted and stored securely.
As a Data Processor under the NDPR, we enter into Data Processing Agreements (DPAs) with the Data Controllers we serve. Our DPA ensures that we:
We have designated a Data Protection Officer responsible for developing and implementing security policies and procedures.
All employees undergo regular NDPR compliance training to ensure they understand their responsibilities in protecting PHI.
We maintain an incident response plan to quickly identify, contain, and remediate any security incidents or breaches.
In compliance with the NDPR, patients have the right to:
For questions about our NDPR compliance practices, please contact our Data Protection Officer:
MediAID Plus
Data Protection Officer
Email: security@mediaidplus.com.ng
Phone: +234 (813) 589-8558
Address: C21, Meridian Park Estate, Awoyaya, Lagos 101241, Nigeria