Purpose-limited data use
Child and growth information is collected to create, analyze, store, and share the growth record within the defined product workflow.
Privacy and security
NeoScan’s SRS defines privacy and security requirements for sensitive child health information under the Kenya Data Protection Act 2019 and Kenya Health Act.
Privacy principles
Child and growth information is collected to create, analyze, store, and share the growth record within the defined product workflow.
A parent or guardian must give explicit, revocable consent before data or chart images are shared with a clinic.
Parents see their own children. Providers see consented clinic records. Administrators review clinic registrations and audit logs.
Record creation, viewing, editing, manual overrides, and sharing are designed to leave immutable activity records.
Encryption is specified for the cloud database, local offline storage, and data moving between the app and backend.
The SRS names KDPA 2019 and the Kenya Health Act as the governing framework, not United States HIPAA.
Consent-controlled sharing
The proposed app shows a consent screen before a child’s history or scans are shared with a registered clinic.
A unique clinic access token connects the request to a registered practice.
The parent sees what will be shared and why.
Consent is logged with a timestamp.
The parent can stop clinic access to future data.
Growth history
Verified measurements, chart scans, reference views, and review flags.
Existing access
The design allows a parent to revoke access to new data at any time.
Encryption and transport
These controls are specified in the SRS and still require implementation, testing, and compliance review.
Authentication
Initial access uses email and password with secure password hashing. The SRS then defines additional protections for subsequent sessions.
Biometric unlock or a six-digit PIN after initial registration.
Required SMS-based six-digit MFA code during login.
Temporary 15-minute lock after five consecutive failed attempts, with email notification.
Single-use email token that expires after 30 minutes.
Audit logging
Every growth-record create, read, update, manual override, or share action is specified to create a write-once log entry.
No user role—including system administrators—is meant to modify or delete those entries.
Data location and sharing
PostgreSQL stores WHO reference tables, patient records, growth scans, anomaly logs, referrals, consent-related data, and audit trails.
Encrypted local SQLite stores are used only while a scan or profile waits to synchronize.
Explicit parental consent is required before a clinic or pediatrician receives a child’s record.
The SRS states that data is not stored or transmitted outside Kenya without explicit consent and a lawful basis under KDPA.
Questions
No. The role model limits providers to patients explicitly shared with their clinic through consent.
Yes. The design allows consent to be revoked, immediately ending the clinic’s access to new data.
No. It summarizes the controls required by the SRS. Formal implementation review and legal assessment are still needed.
Privacy or project enquiry