Aligning Practice with Law and Governance
A colleague remarked, almost in passing, that their institution now receives a significant proportion of its radiology reports and specialised laboratory interpretations from outside the country. What began as a pragmatic solution to workforce gaps and the need for timely subspecialty input had quietly become routine practice. Yet as we spoke, their tone shifted from operational satisfaction to reflective caution. They found themselves wondering, not about the quality of the reports, which were often excellent, but about the underlying structure of responsibility. When an image is acquired locally, transmitted across borders, interpreted remotely, and then acted upon at the bedside, where, in legal and professional terms, does the act of care truly reside?
The increasing use of cross-border teleradiology and remote laboratory reporting is not merely a technical or operational shift, it reconfigures the medico-legal architecture of care. The clinical act of interpretation remains central to diagnosis and treatment, yet it is now disaggregated from the physical site of care. This creates a layered set of legal relationships, duties, and risks that must be deliberately structured rather than assumed.
At the core is the question of duty of care and locus of responsibility. The reporting radiologist or pathologist, even if located outside Kenya, is undertaking a professional act that directly influences patient management. In principle, that professional owes a duty of care to the patient. However, from a practical and legal standpoint within Kenya, the patient’s primary relationship remains with the local healthcare institution and attending clinician. This creates a dual exposure. The foreign specialist carries professional liability, but enforcement against them may be difficult due to jurisdictional limits. Consequently, the Kenyan hospital or clinician is likely to remain the primary defendant in any claim, on the basis of non-delegable duty and vicarious liability. Courts are generally reluctant to allow institutions to avoid responsibility by pointing to outsourced expertise, particularly where the patient had no role in selecting the remote provider.
Closely related is the issue of standard of care. The applicable benchmark is not automatically that of the foreign specialist’s jurisdiction. Kenyan law will typically apply a local standard, informed by what a reasonable practitioner would do in comparable circumstances. Where remote reporting is involved, this standard becomes hybridised. It must account for the constraints of remote interpretation (e.g., lack of clinical context, inability to directly examine the patient) while still requiring reasonable diligence in reporting. A recurrent risk arises where remote specialists report in a vacuum, without sufficient clinical information. In such cases, liability may extend to the referring clinician or institution for failing to provide adequate context, thereby undermining the quality of the report.
A third axis concerns licensure and regulatory compliance. Under Kenyan law, medical practice is regulated by the Kenya Medical Practitioners and Dentists Council (KMPDC). The question arises whether a foreign radiologist or pathologist reporting on Kenyan patients is “practising medicine in Kenya.” While the statutory framework has not fully caught up with the realities of telemedicine, a purposive interpretation would suggest that where the service materially affects patient care within Kenya, regulatory oversight is engaged. This creates a compliance gap. Many institutions rely on foreign providers who are not registered locally, exposing the institution to regulatory scrutiny and potential sanctions. The absence of clear telemedicine regulations does not eliminate risk. It shifts the burden onto institutions to justify their arrangements within existing legal principles.
Data governance introduces another layer of complexity. Radiological images and laboratory data constitute personal health information under the Data Protection Act, 2019. Cross-border transfer of such data is permissible only where adequate safeguards exist. This includes ensuring that the receiving jurisdiction provides an equivalent level of data protection or that appropriate contractual protections are in place. In practice, many arrangements fall short of this threshold. The medico-legal risk here is twofold, first, regulatory penalties for unlawful data transfer, and second, civil liability arising from breaches of confidentiality or data misuse. Importantly, anonymisation is often assumed but not rigorously implemented, especially where full DICOM datasets or laboratory identifiers are transmitted.
There is also the matter of informed consent. Patients are rarely told that their images or samples will be interpreted outside the country. From a legal perspective, this is not a trivial omission. Consent is not limited to the procedure itself but it extends to material aspects of how care is delivered. The cross-border transmission of sensitive health data, and the involvement of unseen third-party professionals, are arguably material facts that a reasonable patient would wish to know. Failure to disclose this may not invalidate the clinical act per se, but it weakens the ethical and legal defensibility of the care process.
From a risk management standpoint, contractual structuring is often the weakest link. Many institutions operate on informal or loosely defined service agreements with teleradiology or reference laboratories. Critical provisions are frequently absent or underdeveloped. Clear allocation of liability, indemnity clauses, minimum turnaround times, requirements for clinical correlation, escalation protocols for critical findings, and obligations regarding data protection compliance are required. Without these, the institution retains residual risk without adequate recourse.
The evidentiary dimension should not be overlooked. In the event of litigation or regulatory inquiry, the integrity and traceability of reports become critical. Questions arise as to authentication of reports, audit trails, time stamps, and the ability to call the reporting specialist as a witness. Where the specialist is outside jurisdiction, securing their testimony may be difficult, thereby weakening the defence. Additionally, discrepancies between preliminary and final reports, or between local and remote interpretations, can become focal points of dispute.
Against this backdrop, the way forward is not to retreat from remote reporting, which offers undeniable benefits in access, turnaround time, and subspecialty expertise, but to formalise it within a robust medico-legal framework. Institutions should first adopt a structured governance model for telemedicine services. This includes formal credentialing of remote specialists, even where they are not locally licensed, by verifying qualifications, experience, and standing in their home jurisdiction. Where feasible, a pathway toward local recognition or collaboration with locally licensed practitioners should be explored.
Second, contractual arrangements must be elevated to a professional standard. Agreements should clearly define the scope of services, standard of care expectations, liability allocation, indemnity coverage, and dispute resolution mechanisms. They should also incorporate explicit data protection clauses aligned with Kenyan law, including provisions on cross-border data transfer and breach notification.
Third, there must be clinical integration rather than mere outsourcing. Remote reporting should be embedded within a system that ensures adequate clinical information is provided, facilitates direct communication between the reporting specialist and the treating clinician, and establishes protocols for urgent or unexpected findings. This reduces the risk of “detached reporting” and aligns the process with acceptable standards of care.
Fourth, institutions should implement enhanced consent processes. Patients should, at least in general terms, be informed that aspects of their diagnostic evaluation may be conducted remotely, potentially outside the country, with appropriate assurances on confidentiality and quality standards.
Fifth, data governance frameworks must be strengthened. This includes conducting data protection impact assessments, ensuring secure transmission channels, anonymising data where possible, and maintaining clear records of data flows. The institution, as data controller, must retain oversight and accountability.
Finally, there is a need for regulatory evolution and professional guidance. The KMPDC, in conjunction with the Ministry of Health and the Office of the Data Protection Commissioner, should develop clear guidelines on telemedicine and cross-border reporting. In the interim, institutions should align themselves with international best practices while remaining anchored in Kenyan legal principles.
In essence, remote reporting does not dilute responsibility, It merely redistributes it across a more complex network. Unless that network is deliberately structured, the legal burden will continue to gravitate back to the local institution and clinician, often at the point of failure.
