Skip to content

Health data

Health data protection in Morocco: Law 09-08 and the CNDP

Health data protection in Morocco: what Law 09-08 and the CNDP expect from a medical practice, and the practical steps that keep patient records secure.

By MediNEEO TeamPublished 8 min read

Health data protection in Morocco rests first on Law No. 09-08 of 2009, on the protection of individuals with regard to the processing of personal data, and on the authority that enforces it: the CNDP. For a medical or dental practice, this means two complementary pieces of work: completing the formalities and following the law’s core principles, then putting concrete security measures in place day to day. This guide covers both.

Disclaimer. This article is general information written for healthcare professionals. It is not legal advice. Laws and procedures change: for your specific situation, check the CNDP website or consult a lawyer.

Why health data is a category of its own

A patient file holds some of the most personal information there is: medical history, diagnoses, treatments, prescriptions, X-rays, sometimes details of family life. Law 09-08 classes health-related data as sensitive data, a category subject to stricter rules than ordinary personal data such as a name, phone number or address.

On top of this legal requirement sits medical confidentiality, which binds the practitioner and the whole team independently of Law 09-08. The two reinforce each other: confidentiality governs who may know a piece of information; Law 09-08 governs how it is collected, used, kept and protected.

Law 09-08 and the CNDP: the core principles

Who does it apply to?

As soon as a practice records information about its patients — in software, a spreadsheet or an organised paper filing system — it is processing personal data. The practice (in practice, the practitioner in charge or the entity that runs the practice) is the data controller. Providers who process that data on its behalf — an online software vendor, a hosting company, an IT contractor — act as processors.

The CNDP’s role

The CNDP (Commission nationale de contrôle de la protection des données à caractère personnel — Morocco’s data protection authority) oversees the application of the law. It receives prior formalities, informs controllers and individuals about their rights and duties, handles complaints and can carry out inspections.

Prior formalities: declaration or authorisation

The law requires processing to be brought to the CNDP’s attention before it begins, under two main regimes: a prior declaration and, for certain processing considered more sensitive, a prior authorisation. Processing involving health data generally falls under the stricter regime.

Forms, filing methods and any simplified procedures for particular sectors change over time. Check the CNDP website for the current procedure that applies to a medical practice before you start or change your processing — for example, when you switch software.

Purpose and proportionality

Data must be collected for specified, explicit and legitimate purposes — here, patient care, appointment management and billing — and not reused for an incompatible purpose. Collect only what is useful: an “occupation” or “marital status” field belongs in the file only if it genuinely serves medical or administrative follow-up.

Retention

Data should not be kept longer than necessary for its purpose. For medical records, the right period also depends on professional obligations and liability timeframes: set a written policy after taking advice (your professional body, a lawyer) and apply it — including to paper archives and backups.

Informing patients and respecting their rights

Patients must be informed that their data is processed: by whom, for what purpose, who it may be shared with and how to exercise their rights. A notice in the waiting room and a short statement on the registration form are simple ways to do this.

The law gives patients, among other things, a right of access to their data, a right to rectification of inaccurate information, and a right to object, on legitimate grounds, to certain processing. Decide who handles these requests, how you verify the requester’s identity, and how you record your answer.

The security obligation

The data controller must implement appropriate technical and organisational measures to protect data against destruction, loss, alteration, disclosure or unauthorised access. This duty extends to choosing processors who offer sufficient guarantees. It is where the law meets the daily life of the practice most directly.

Practical measures for your practice

Access based on each person’s role

The principle is simple: each person sees only what they need. The receptionist manages the schedule and front desk; the assistant sees what relates to the care they prepare; the practitioner has the full clinical record. Good software lets you set these rights by role instead of giving everyone full access.

Individual accounts, never shared passwords

A single “practice” login on the front-desk computer makes it impossible to know who viewed or changed what. Every team member needs their own account with a strong personal password. When someone leaves, their account is disabled the same day.

Lock your screens

A screen left open on a patient file, visible from the waiting room, is a data leak. Turn on automatic locking after a few minutes of inactivity, angle front-desk screens away from patients, and build the habit of locking your computer (Windows + L, or Ctrl + Cmd + Q on a Mac) whenever you step away.

Back up — and test the restore

A failed disk, a stolen laptop or ransomware can make records inaccessible. If your data sits on a local computer, set up regular backups with at least one encrypted copy kept off-site. And test a restore from time to time: an untested backup is only a hope.

Choosing hosting and a software vendor

With online software, part of your security depends on your provider. Before you sign, ask precise questions:

  • Where is the data hosted, and by which hosting company? If it is stored outside Morocco, Law 09-08 regulates transfers abroad: depending on the destination country, CNDP authorisation may be required.
  • How is your practice’s data kept separate from other customers’ data?
  • Does the contract set out the provider’s obligations as a processor (confidentiality, security, what happens to the data when the contract ends)?
  • Can you get your data back in a usable format if you change systems?

Our guide to choosing clinic-management software in Morocco covers these criteria alongside the other points to check. As an example, in MediNEEO the separation between practices is enforced directly in the database (row-level security): a request for another practice’s record returns nothing.

Encrypt data in transit

Every connection to online software should use HTTPS (the padlock in the address bar). Avoid sending reports, results or X-rays through personal email or consumer chat apps; if you must share a document, use a secure channel and keep the information to the strict minimum.

Keep a record of sensitive actions

Traceability tells you who did what, and when. In a clinical record, it protects the patient as much as the practitioner. In MediNEEO, every team member signs in with their own account, permissions depend on their role, and a signed clinical note is locked so it can no longer be changed. The same care applies to prescriptions, covered in our article on e-prescriptions in Morocco.

Don’t forget paper

Paper files, printed prescriptions and care forms are health data too. Keep them in locked cabinets, never leave documents lying at the front desk, and shred papers you throw away rather than putting them in the bin.

Train your team

Most incidents come from everyday habits: a password on a sticky note, an attachment opened too quickly, information given over the phone to an unverified “relative”. A short awareness session when each person joins, followed by a yearly refresher, works better than a long procedure nobody reads. A confidentiality agreement signed by every team member reminds everyone that confidentiality applies to all.

What to do after an incident

A stolen computer, an email sent to the wrong person, a hacked account: respond methodically.

  1. Contain: change the affected passwords, disable compromised accounts, disconnect an infected computer from the network.
  2. Assess: which data, how many patients, what risks for them?
  3. Alert your software vendor or IT provider, who can help you gauge the extent of the incident.
  4. Seek guidance from the CNDP and, if needed, a lawyer on the steps to take and whether to inform the patients concerned.
  5. Document the incident and the measures taken, then fix the root cause so it does not happen again.

Frequently asked questions

Does Law 09-08 apply to a small practice?

Yes. The law does not depend on the size of the organisation: as soon as a practice records information about identifiable patients, it processes personal data — and health data in particular. CNDP formalities and the security obligation therefore apply to a practitioner working alone as well.

Do I need to declare my practice software to the CNDP?

What you declare is not the software but the processing your practice carries out with it. Changing software, hosting provider or purpose may, however, mean updating your formality. Check the current procedure on the CNDP website.

Can a patient ask for a copy of their file?

Law 09-08 gives patients a right of access to their personal data, and professional ethics rules also govern how medical records are shared. Verify the requester’s identity, answer within a reasonable time and keep a record of the request and your response.

Can we use a messaging app to communicate with patients?

For appointment reminders it is common: keep the message to the date, time and practice name, with no mention of the reason for the visit. To share results or medical documents, a secure channel limited to the strict minimum is a better choice. For organising those reminders, see our article on reducing patient no-shows.

Does the European GDPR apply to a Moroccan practice?

The reference framework in Morocco is Law 09-08, overseen by the CNDP. The GDPR is a separate European regulation that applies only in specific situations; if your activity involves patients or providers in Europe, ask a legal adviser.

Topics

  • Health data
  • Compliance
  • Security

What next?

See MediNEEO in your practice.

Get your team onboarded in less than a day. We’ll migrate your patient records for you.

All articles