MediTrack

Privacy Notice

Last updated: 21 July 2026. This notice explains how MediTrack handles personal and health information. It is provided as a template and should be reviewed against the Uganda Data Protection and Privacy Act, 2019.

Who is responsible for your data

Your health facility is the data controller for the information held about you in MediTrack, operating within Uganda's national health information framework. For questions or requests, contact your facility administrator or Data Protection Officer (details available at your facility reception).

What we collect

Identifying details (name, national/health ID, date of birth, contact), and clinical information created during your care — visits, vital signs, diagnoses, prescriptions and dispensed medicines, laboratory and radiology results, immunisations, referrals, and billing/insurance records.

Why we use it and our lawful basis

To provide and coordinate your care, to run the facility (pharmacy, laboratory, billing), to meet public-health and legal reporting duties, and to keep the system secure. Processing is on the basis of the provision of healthcare, legal obligations, and — where required — your consent.

Who can see it

Access is role-based: staff see only what their role and their facility require. Sensitive access is logged. In an emergency, a clinician may use a recorded "break-glass" override to view records to protect life; every such access is audited. You can record consent preferences for how your data is shared between facilities and roles.

Sharing

De-identified, aggregate counts (for example monthly totals) are reported to the national health management information system (DHIS2/HMIS) as required. Your identifiable record may be shared with another facility when you are referred there for care. We do not sell your data or use it for advertising.

How long we keep it

Clinical records are retained in line with national medical-records retention requirements and are not deleted on request while retention obligations apply; instead of deletion, records are archived (soft-deleted) and access-controlled. Operational data with no clinical value — login sessions, password-reset tokens, and security rate-limit logs — is purged automatically on a short cycle.

Your rights

You may access your record and download a copy at any time from the patient portal ("Download my record"). You may ask your facility to correct inaccurate details, ask questions about how your data is used, and lodge a complaint with the facility or the national data-protection authority.

Security

Data is transmitted over encrypted connections (HTTPS), passwords are stored only as secure hashes, optional two-factor authentication is available, and access is audited. No system is perfectly secure, but we apply appropriate safeguards.

Cookies

MediTrack uses a single essential session cookie to keep you signed in. It is not used for tracking or advertising, so no separate cookie consent is required.

Contact

To exercise any right or ask a question, contact your facility administrator or Data Protection Officer.

← Back to MediTrack