How Uzma Qureishi oversaw Aga Khan Hospital's bold EHR leap

post-title

In 2022, Uzma Qureishi, Senior Manager of EHR Operations at Aga Khan Hospital Nairobi, led one of the boldest bets of her career, overseeing the institution's transition to a paperless system. The transition wrote the hospital into the region's history books as the first hospital in East Africa to run a full Electronic Health Record (EHR) system, namely MEDITECH Expanse.

When Uzma Qureishi, Senior Manager, EHR Operations at Aga Khan Hospital Nairobi, took the stage at the CITO East Africa Data and Cybersecurity Summit in July, she was armed with practical tips on data management and cybersecurity. But more than that, she walked attendees through how the hospital implemented its full EHR system (MEDITECH Expanse). 

For years, Aga Khan Hospital Nairobi, like many others in the region, ran on filing cabinets, folders, and paper trails. However, there was a plan to have a unified digital patient record. In 2022, with Uzma at the helm, the hospital switched to a full EHR system, becoming the first in the region. Still, as Uzma shared, the process leading to the switch was anything but straightforward.

Apart from the sheer size of the workforce that was required for data migration, a greater problem, as Uzma explained, was that the hospital runs as an interconnected web.

"Every part of being in a hospital is connected. The lab is connected to radiology, radiology is connected to pharmacy, it's a whole patient journey," she said.

And while there was an option to go hybrid and have the legacy system running alongside the new EHR system, this was still a challenge as it would compromise the patient experience.

"We might have a patient's labs, for example, in the legacy system, and then the radiology results sitting in the new system," she said.

The road less travelled

After weighing the circumstances, the hospital chose the harder and riskier path.

"We really brainstormed and said, this is going to be such a bold move, but let's see how we do it. I remember when we were making this decision, everybody wondered whether we were crazy and whether the plan would work," she recalled.

On 5 November 2022, Uzma and her team switched off the old system and left it on read-only mode in what she described as a cold turkey approach.

However, the switch was the culmination of a months-long preparation process that included training.

"We had to make sure all 3,500 plus users were trained, because they were so used to the legacy system. Then we looked at cybersecurity, and at how well our infrastructure could sustain that move," she explained.

On the night of the switch, the hospital set up a 24/7 command centre to support operations throughout the migration, while ensuring that physical patient files remained available as a contingency. 

"For the first nine hours, we had people sitting in the ward with the medical records just in case the doctor needed access and a whole data migration had not come in," she explained.

Managing the data

Going fully digital brought the hospital face to face with the weight of cybersecurity and data governance issues. One of the ways the hospital has adopted to achieve data safety is through role-based access.

"You have physicians, you have nurses, you have a cardiologist, a pulmonologist among others. Every cadre has a different role, so our access is role-based, we have a matrix for it. We believe access has to go to the right person, to make the right decision."

Nevertheless, Uzma is also cognisant of unique circumstances, especially during emergencies.

"We look at the patient's journey and at every stakeholder involved in it, and ask why they need access. There will be times a nurse needs access outside his/her usual role, because of an emergency. We have a dedicated team that manages these access requests promptly, with an approval process in place to ensure that access is appropriately authorised and governed, even in emergency situations. Patient information is critical, and we have to safeguard it," she explained.

The hospital has further adopted different frameworks to promote proper data usage and comply with local regulations and international regulations.

"We govern ourselves by Kenya's Data Protection Act, which sets clear requirements around data protection and privacy. We're accredited by Joint Commission International (JCI). We also look at HIPAA and GDPR," she revealed.

For Uzma, the impact of getting access and governance right extends well beyond the hospital's own wards, addressing a wider healthcare data gap across the continent.

"If you give access to the correct job role, and your physicians are capturing the right information, you improve the quality of the data, and that data can ultimately help shape healthcare across Africa,” she said.

Uzma believes that this is especially helpful in developing medications for African populations.

"For years, many medications have been developed and studied outside Africa, with African populations often underrepresented in the data. By giving our clinicians appropriate access and capturing quality information, we are helping to build reliable local healthcare data. That data can contribute to better research, better clinical decisions and, ultimately, better healthcare outcomes for our populations," she said.

 

Related articles

IT heads weigh in on cybersecurity's talent problem 

A 2025 PwC report placed knowledge and skills gaps among the top challenges organisations face when implementing AI for cyber defence. Mpesa Africa’s head of cybersecurity Tim Theuri, Ecobank Uganda’s head of IT Juliet Kyomugisha and WASREB’s head of IT Brenda Anzagi weigh in on the challenge of finding talent in IT.

Fix policy gaps before scaling AI, CIO Summit panellists say

At the recent CIO of the Future Summit held in Kampala, Uganda, participants identified AI as one of their main concerns with loopholes in AI governance emerging as one of the greatest hindrances towards its effective use.

Clearer data governance frameworks dominate discussions at CITO Summit

When Ecobank Uganda's Juliet Kyomugisha, Nation Media Group's Russell Akuom and AAR Hospital's Ibrahim Juma took to the stage at the CITO East Africa Data and Cybersecurity Summit to report back from the roundtable sessions, the consistent message was that implementation is the hard part of data governance.

PwC Kenya’s Jamila Aroi urges leaders to build cyber resilience

The first-ever CITO East Africa Data and Cybersecurity Summit took place at the Villa Rosa Kempinski Nairobi on 17 July. During the event's keynote address, Jamila Aroi, partner for technology consulting at PwC Kenya, urged business and technology leaders to develop the ability to withstand, recover from and adapt to cyber incidents. 

CIOs tackle governance and cyber resilience at CITO Summit 

As CIOS weighed in on topics of data access, governance, cyber security and cyber resilience at the CITO East Africa Data and Cyber Security Summit held at Villa Rosa Kempinski Nairobi, it was apparent that human actors have a bigger role to play than the tech. 

Tanzania's tech leaders set agenda at CITO East Africa chapter launch

Over 35 CIOs and technology leaders from across Tanzania gathered on June 11 in Dar es Salaam to help shape the future of the country's technology leadership community. The inaugural CITO East Africa Tanzania Summit served as an agenda-setting forum, creating space for candid discussions on the priorities that will define the community in the months ahead.

The rise of East Africa’s CITO community

The Uganda edition of the CITO East Africa Summit began as a room full of technology leaders comparing operational challenges. By the end of the evening, the conversation had evolved into a discussion about community, collaboration and the need for CIOs across East Africa to stop working in isolation.

Rwandan CIOs bridge IT–finance gap to get technology funded

Rwanda’s technology leaders say their biggest challenge is getting risks funded before they escalate into costly failures. Critical warnings around cybersecurity, infrastructure, and system upgrades are often raised early, but not always approved in time.

Top