The verdict in three sentences
Health data is the most sensitive category there is: it falls under strict data-protection law and regulator oversight (in Senegal, Law 2008-12 and the CDP). Any healthcare application must rest on four non-negotiable pillars: encryption (at rest and in transit), strict access control, secure hosting and access logging. An initial audit costs 1,500,000 to 4,000,000 FCFA (about 2,300-6,100 EUR), a modest investment against the cost of a patient-records breach, which runs into tens of millions of FCFA and irreparable loss of trust.
Minimum measures for a healthcare application
This is not about "good intentions" but verifiable technical measures. Here is the 2026 baseline and its implementation cost.
| Measure | Description | Priority | Estimated cost |
|---|---|---|---|
| Encryption in transit | HTTPS/TLS everywhere, HSTS | Critical | 100,000-300,000 FCFA |
| Encryption at rest | Encrypted database and backups | Critical | 300,000-800,000 FCFA |
| Access control (RBAC) | Roles, least privilege, MFA | Critical | 500,000-1,500,000 FCFA |
| Access logging | Audit trail on record access | High | 300,000-900,000 FCFA |
| Secure hosting | Hardened server, firewall, backups | Critical | 400,000-1,200,000 FCFA/year |
| Security audit | Penetration test + report | High | 1,500,000-4,000,000 FCFA |
The cost of a healthcare data breach
The risk is not theoretical: clinics, practices and labs are prime ransomware targets. Here is the scale of consequences of a breach or lockout.
| Incident type | Consequence | Estimated cost |
|---|---|---|
| One-off unauthorised access | Regulator notification, remediation | 2,000,000-5,000,000 FCFA |
| Ransomware (lockout) | Downtime, restoration | 5,000,000-20,000,000 FCFA |
| Mass records breach | Fine, patient loss | 15,000,000-50,000,000+ FCFA |
| No backup | Permanent data loss | Incalculable |
Beyond the figure, a healthcare organisation stakes its reputation: a patient whose record leaks does not return, and negative word of mouth spreads fast. 2026 order of magnitude, indicative.
Regulatory compliance: concrete obligations
Data-protection law typically requires a declaration or authorisation with the regulator for health-data processing, clear patient information on data use, a right of access and rectification, and security measures proportionate to sensitivity. In practice: appoint a data lead, keep records of processing, formalise a privacy policy and technically secure the application. Compliance is as much legal as technical.
Mini case study
Dr Sarr runs a medical centre that digitises records for 8,000 patients via a web application. Before go-live he commissions a 2,200,000 FCFA security audit that reveals two critical flaws: no MFA on clinician accounts and unencrypted backups. Remediation costs 1,400,000 FCFA. Total invested: 3,600,000 FCFA. Six months later a ransomware attempt is blocked by the new defences, and a clean backup enables recovery in 2 hours. The avoided cost of a full lockout was estimated at 8,000,000 to 15,000,000 FCFA: the audit paid for itself more than twice over.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Does the law require local hosting?
It imposes security guarantees and frames transfers outside the country, without systematically requiring local hosting. For health data, secure and controlled hosting, ideally local or in a jurisdiction with equivalent guarantees, is strongly recommended.
Is MFA really essential?
Yes. Most fraudulent access exploits stolen or weak passwords. Multi-factor authentication on all clinician accounts is the highest-ROI measure: low cost, drastic reduction in account-compromise risk.
How much does full compliance cost?
For a mid-size healthcare application, budget 3,000,000 to 8,000,000 FCFA for the technical baseline and audit, plus 400,000 to 1,200,000 FCFA/year for secure hosting and monitoring. The amount depends on record volume and required rigour.
What to do in case of a confirmed breach?
Activate the response plan: contain the incident, notify the regulator within the deadline, inform affected patients if the risk is high, and document. A pre-set response plan sharply reduces the cost and duration of the incident.
Is a small practice really concerned?
Yes. Data sensitivity does not depend on the size of the organisation. A practice of a few clinicians handles health data and must apply encryption, access control and backups, even at a more modest scale.
Let's scope your project. Describe your healthcare application (record volume, clinician access, current hosting), and we will price the audit and compliance work. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

