Public trust centre

Clear status. Exact scope. No borrowed credibility.

PHX distinguishes applicable law, control alignment, independent assessment, certification, and roadmap—so buyers can understand exactly what a statement means.

PHX governance framework

Engineered for compliance. Evidence before claims.

PHX translates applicable law, national policy, health-data standards, and security practice into one operating governance model.

Privacy by designSecurity by designInteroperable by defaultCountry sovereigntyAuditability
01
Obligation mapping

Applicable national law & public governance

Data Protection Act, 2012 (Act 843)Cybersecurity Act, 2020 (Act 1038)Electronic Transactions Act, 2008 (Act 772)Health-sector regulationCountry-defined authority
02
Design alignment

National architecture & interoperability guidance

Ghana eGIFGovernment digital architectureAU health information exchange guidanceCountry data governanceApproved exchange profiles
03
Conformance programme

Health data & clinical semantics

HL7 FHIRHL7 v2DICOMSNOMED CTLOINCICD-10 / ICD-11WHO SMART & IDSR guidance
04
Control alignment

Security, risk & operational assurance

ISO/IEC 27001 control referenceNIST Cybersecurity FrameworkCIS ControlsISO 31000 risk principlesCOBIT & ITIL practicesIndependent assessment roadmap
PHX commitmentTrusted. Secure. Interoperable. Accountable.

Certification is claimed only for a named entity, system scope, standard version, assessment period, and independently verifiable certificate.

Status language

Five labels with different meanings

Applicable obligation

Qualified review has determined that a law or rule applies to the named entity, processing activity, country, and scope.

Control alignment

Selected controls have been mapped to guidance. This does not mean certification or full legal compliance.

Independently assessed

A named independent party evaluated a defined scope and period, with publishable evidence available.

Certified

A valid certificate exists for an exact legal entity, system scope, standard version, period, and certification body.

Roadmap

The outcome is planned but not complete and must not be presented as current capability.

Reference landscape

What may be relevant—subject to exact scope

GhanaDesign reference

Data protection and electronic systems

Ghana’s data protection, cybersecurity, electronic transactions, health, professional, and public-sector obligations require country and processing-specific review.

InternationalDesign reference

Security and risk frameworks

ISO/IEC 27001, ISO 31000, NIST, CIS, COBIT, and ITIL may inform selected controls where documented and applicable.

AssuranceRoadmap

Independent reports

Independent assessments and reports will be described only when they exist, remain valid, and can be accurately scoped.

MobileIn validation

Patient and health-worker applications

Privacy notices, store disclosures, permissions, account deletion, retention, clinical safety, and user rights must reconcile with actual application behavior.

Operational assurance

A programme, not a badge

Govern

Accountability, policies, risk ownership, legal register, and oversight.

Build securely

Secure development, review, testing, dependency control, and change management.

Operate

Access governance, monitoring, incident response, continuity, and supplier control.

Improve

Audit, findings, corrective action, evidence review, and claim expiry.

Institutional and standards logos are not used as substitutes for evidence. Where a mark is ever used, its owner’s current permission and brand conditions must be recorded.

Qualified assurance

Need evidence for procurement or country review?

Tell us the institution, country context, review purpose, and required scope. Sensitive evidence remains controlled.