Health data and the CNDP: prior authorisation, not declaration
Clinics, laboratories and health funds: health data falls under CNDP prior authorisation. What that changes in a project schedule and in the software.
Health data is the most protected category under law 09-08. For a clinic, a laboratory, a practice or a health coverage body, that means a regime of prior authorisation from the CNDP — not a simple declaration. The difference is not administrative: it decides the date your platform can go into production.
Authorisation, and what it means for the timeline
- Review in two months, extendable once: plan for up to four.
- No start before the decision. A submitted file authorises nothing.
- The form is F115 (application for authorisation), not F211.
The consequence for a software project: the file is prepared during scoping, not during testing. A healthcare platform that discovers prior authorisation three weeks before delivery has a scheduling problem nobody can solve.
What "health data" actually covers
Wider than the medical record: anything revealing a state of health, even indirectly. An appointment reason, a billed procedure, a pre-authorisation, a sick note, a test result, a prescription — and sometimes simply being attached to a care service.
That is why a health fund platform is as concerned as clinic software: reimbursing a procedure is health data. See insurance and health funds.
What the software has to be able to do
- Separate by role. Practitioner, front desk, administrator and billing do not need the same fields. "Everyone sees everything" is the most common default and the hardest to defend in a control.
- Log reads, not just changes. On a health record, knowing who looked at what is the core of traceability.
- Enforce a retention period per category — a test result, an accounting document and a prospecting record do not live the same length of time.
- Answer an access or deletion request without manual reconstruction.
- Encrypt at rest and in transit, and know where the data is hosted.
What directors discover late
For sensitive data the law provides for financial penalties and a liability that can reach the director personally. This is not a subject to delegate to a provider after the fact, and a compliance report resting on a system that cannot log access protects nobody.
What about hosting abroad?
Hosting health data with a provider outside Morocco constitutes a transfer, subject to its own regime, and it must appear in the file. It is not prohibited; it has to be declared and justified. Discovering it after submission means an amendment — form F112.
Related guides: the CNDP declaration, consent. Our offer: healthcare platforms and CNDP compliance.
Related articles

Compliance & regulation
CNDP declaration: who must declare, what, and how
Any company processing personal data in Morocco must declare it to the CNDP before starting. What that covers, how it differs from an authorisation, the forms and the deadlines.

Compliance & regulation
Law 09-08 and the GDPR: what overlaps, and what does not substitute
Being GDPR-compliant does not make you compliant in Morocco, and the reverse is also true. The differences that matter in practice: prior formality, authority, transfers.

Compliance & regulation
Consent to personal data in Morocco: collecting it, proving it, honouring withdrawal
Consent is not a checkbox: it is evidence you must keep and a withdrawal you must honour. What that means for a website, a form and a customer database.
Newsletter
Get our upcoming articles straight to your inbox.

