Skip to main content
Compliance & regulation

Health data and the CNDP: prior authorisation, not declaration

Clinics, laboratories and health funds: health data falls under CNDP prior authorisation. What that changes in a project schedule and in the software.

Digi4·· Last reviewed: ·3 min read

Health data is the most protected category under law 09-08. For a clinic, a laboratory, a practice or a health coverage body, that means a regime of prior authorisation from the CNDP — not a simple declaration. The difference is not administrative: it decides the date your platform can go into production.

Authorisation, and what it means for the timeline

  • Review in two months, extendable once: plan for up to four.
  • No start before the decision. A submitted file authorises nothing.
  • The form is F115 (application for authorisation), not F211.

The consequence for a software project: the file is prepared during scoping, not during testing. A healthcare platform that discovers prior authorisation three weeks before delivery has a scheduling problem nobody can solve.

What "health data" actually covers

Wider than the medical record: anything revealing a state of health, even indirectly. An appointment reason, a billed procedure, a pre-authorisation, a sick note, a test result, a prescription — and sometimes simply being attached to a care service.

That is why a health fund platform is as concerned as clinic software: reimbursing a procedure is health data. See insurance and health funds.

What the software has to be able to do

  • Separate by role. Practitioner, front desk, administrator and billing do not need the same fields. "Everyone sees everything" is the most common default and the hardest to defend in a control.
  • Log reads, not just changes. On a health record, knowing who looked at what is the core of traceability.
  • Enforce a retention period per category — a test result, an accounting document and a prospecting record do not live the same length of time.
  • Answer an access or deletion request without manual reconstruction.
  • Encrypt at rest and in transit, and know where the data is hosted.

What directors discover late

For sensitive data the law provides for financial penalties and a liability that can reach the director personally. This is not a subject to delegate to a provider after the fact, and a compliance report resting on a system that cannot log access protects nobody.

What about hosting abroad?

Hosting health data with a provider outside Morocco constitutes a transfer, subject to its own regime, and it must appear in the file. It is not prohibited; it has to be declared and justified. Discovering it after submission means an amendment — form F112.

Related guides: the CNDP declaration, consent. Our offer: healthcare platforms and CNDP compliance.

Newsletter

Get our upcoming articles straight to your inbox.

Chat on WhatsApp