In 2022, Uzma Qureishi, Senior Manager of EHR Operations at Aga Khan Hospital Nairobi, led one of the boldest bets of her career, overseeing the institution's transition to a paperless system. The transition wrote the hospital into the region's history books as the first hospital in East Africa to run a full Electronic Health Record (EHR) system, namely MEDITECH Expanse.
When Uzma Qureishi, Senior Manager, EHR Operations at Aga Khan Hospital Nairobi, took the stage at the CITO East Africa Data and Cybersecurity Summit in July, she was armed with practical tips on data management and cybersecurity. But more than that, she walked attendees through how the hospital implemented its full EHR system (MEDITECH Expanse).
For years, Aga Khan Hospital Nairobi, like many others in the region, ran on filing cabinets, folders, and paper trails. However, there was a plan to have a unified digital patient record. In 2022, with Uzma at the helm, the hospital switched to a full EHR system, becoming the first in the region. Still, as Uzma shared, the process leading to the switch was anything but straightforward.
Apart from the sheer size of the workforce that was required for data migration, a greater problem, as Uzma explained, was that the hospital runs as an interconnected web.
"Every part of being in a hospital is connected. The lab is connected to radiology, radiology is connected to pharmacy, it's a whole patient journey," she said.
And while there was an option to go hybrid and have the legacy system running alongside the new EHR system, this was still a challenge as it would compromise the patient experience.
"We might have a patient's labs, for example, in the legacy system, and then the radiology results sitting in the new system," she said.
The road less travelled
After weighing the circumstances, the hospital chose the harder and riskier path.
"We really brainstormed and said, this is going to be such a bold move, but let's see how we do it. I remember when we were making this decision, everybody wondered whether we were crazy and whether the plan would work," she recalled.
On 5 November 2022, Uzma and her team switched off the old system and left it on read-only mode in what she described as a cold turkey approach.
However, the switch was the culmination of a months-long preparation process that included training.
"We had to make sure all 3,500 plus users were trained, because they were so used to the legacy system. Then we looked at cybersecurity, and at how well our infrastructure could sustain that move," she explained.
On the night of the switch, the hospital set up a 24/7 command centre to support operations throughout the migration, while ensuring that physical patient files remained available as a contingency.
"For the first nine hours, we had people sitting in the ward with the medical records just in case the doctor needed access and a whole data migration had not come in," she explained.
Managing the data
Going fully digital brought the hospital face to face with the weight of cybersecurity and data governance issues. One of the ways the hospital has adopted to achieve data safety is through role-based access.
"You have physicians, you have nurses, you have a cardiologist, a pulmonologist among others. Every cadre has a different role, so our access is role-based, we have a matrix for it. We believe access has to go to the right person, to make the right decision."
Nevertheless, Uzma is also cognisant of unique circumstances, especially during emergencies.
"We look at the patient's journey and at every stakeholder involved in it, and ask why they need access. There will be times a nurse needs access outside his/her usual role, because of an emergency. We have a dedicated team that manages these access requests promptly, with an approval process in place to ensure that access is appropriately authorised and governed, even in emergency situations. Patient information is critical, and we have to safeguard it," she explained.
The hospital has further adopted different frameworks to promote proper data usage and comply with local regulations and international regulations.
"We govern ourselves by Kenya's Data Protection Act, which sets clear requirements around data protection and privacy. We're accredited by Joint Commission International (JCI). We also look at HIPAA and GDPR," she revealed.
For Uzma, the impact of getting access and governance right extends well beyond the hospital's own wards, addressing a wider healthcare data gap across the continent.
"If you give access to the correct job role, and your physicians are capturing the right information, you improve the quality of the data, and that data can ultimately help shape healthcare across Africa,” she said.
Uzma believes that this is especially helpful in developing medications for African populations.
"For years, many medications have been developed and studied outside Africa, with African populations often underrepresented in the data. By giving our clinicians appropriate access and capturing quality information, we are helping to build reliable local healthcare data. That data can contribute to better research, better clinical decisions and, ultimately, better healthcare outcomes for our populations," she said.





