All writing
7 min readDistribution, Partnerships, Nigeria

The Aggregate Is the Asset

The lazy version of healthcare distribution is a spreadsheet of names. A channel that lasts gives a partner a reliable way to reach people without ever handing over who those people are.

Somewhere in the early conversation with almost every new partner, someone on the other side of the table asks, gently, whether they'll get "the data." Not maliciously. They're picturing something useful — a list of everyone who came through their gym or their cooperative or their office and used the service, names and numbers, something they could hold in a spreadsheet and feel like they own. It's an understandable instinct, and it's also the wrong ask, both for the obvious reason and a less obvious one that took me longer to see clearly.

I understand the appeal well enough that I don't think it's worth dismissing outright before taking it seriously. A list feels like leverage. It feels like something you could act on later, independent of whatever the current arrangement produces — a hedge against the partnership ending, a fallback asset if the relationship goes cold. That instinct isn't stupid. It's just aimed at the wrong object, and seeing why takes walking through both reasons it fails.

The obvious reason is legal. Under the Nigeria Data Protection Act, health-related information sits in the category of sensitive personal data, and the Nigeria Data Protection Commission has been unambiguous on this — even something as specific as a person's disability status counts as sensitive because it's health-related, with real discrimination risk if it ends up circulating or feeding into some automated system that starts sorting people by it. Handing a gym owner a spreadsheet with names, numbers, and which clinical service each person used is not a convenience. It's a liability sitting in an inbox, and most partners handing it around have no idea they're now legally responsible for something they never asked to be responsible for.

The less obvious reason is that the partner doesn't actually want the list. They want proof the arrangement is working. Those are different needs, and conflating them is where most of these channels either collapse under compliance risk or quietly wither because nobody ever built the version that would have satisfied the real need in the first place.

Start with the event, not the export

The mistake begins earlier than the data question, usually at the point where a channel gets designed around a segment rather than an outcome. "We'll get access to their member list" is segment thinking. It treats the partner's audience as an export waiting to happen. The better starting question is what event you're actually trying to create — a screening appointment booked, a follow-up consult completed, a referral that turns into a first visit — and then working backward to ask what a partner, using language and channels they already control, would need to do to make that event more likely.

A cooperative chairperson doesn't think of members as a list. She thinks of them as people who show up to a Thursday meeting, or people who read the notices pinned in the union office, or people who trust her enough to act on something she personally vouches for. Design the channel around that shape — a QR code on a printed notice she distributes herself, a script she can deliver in two sentences at the meeting — and you never needed her membership roster in the first place. The audience was always defined the way she already understood it. Exporting it into a spreadsheet would have been a downgrade, not an upgrade, stripping out exactly the trust that made her endorsement worth anything.

Three boxes

The cleanest way I've found to keep this straight, for myself and for a partner sitting across the table wondering what they're actually agreeing to, is three boxes.

The first box is what the partner may distribute. This is approved copy, a booking link, a QR code, a script for a field officer or front-desk staffer to read aloud — material engineered to start a journey, containing nothing about any specific individual because at this stage there isn't one yet. Nobody has enrolled in anything. This box is safe by construction.

The second box is what the provider needs at the point of booking — name, contact detail, preferred time, and consent, collected directly through the provider's own intake process rather than assembled by the partner beforehand and handed over as a batch. This distinction matters more than it looks like it should. A person typing their own number into a booking form controlled by the clinic is making a choice about who receives that number. A person whose number gets copied from a partner's attendance sheet into a shared spreadsheet never made that choice at all — the consent, if it exists, was given to the wrong party for the wrong purpose.

The third box is what the partner gets back, and this is usually the box where the relationship either holds or breaks. In the overwhelming majority of cases, what a partner actually needs is an aggregate report — forty-one people from your office booked screenings this month, twenty-six attended, here's the week-over-week trend — not row-level detail about who among their staff has a family history of hypertension. If a genuine need exists for follow-up contact with a specific person, that requires its own separate, explicit opt-in from that person, given for that specific purpose, not inherited from whatever consent got given somewhere else in the chain.

What consent actually looks like on the ground

Consent that only exists as a clause in a signed agreement between two organizations is not consent the individual actually gave. It has to be legible at the exact point where a person decides to act, and that point looks completely different depending on the channel.

A poster taped to the mirror in a gym has to say something in one glance, because nobody stands in front of a gym mirror reading fine print — it needs to communicate, essentially, what happens if you scan this and what you're agreeing to, in language a person can absorb between reps. A WhatsApp flow can carry slightly more, because the person is already engaged in a back-and-forth and has a moment to read a sentence before tapping a button. A field officer's spoken script is different again — it has to survive being said quickly, sometimes to someone standing at a market stall who's only half listening, sometimes to someone in an office corridor who has ninety seconds before a meeting starts. Writing one version of a consent statement and using it everywhere is a shortcut that produces something legible nowhere, because the format each channel demands is different enough that a message tuned for one reads as noise in the other two.

Three parties, not two

There's a structural reason this three-box discipline matters more in healthcare than it would in, say, a retail loyalty programme, and it comes down to how Nigerian health financing is actually organized. Nigeria's National Health Insurance Authority Act set up several distinct coverage arrangements: programmes for the formal sector and the organised private sector, coverage for vulnerable groups routed through the Basic Healthcare Provision Fund, and GIFSHIP for people outside formal employment altogether — and the practical effect of having several parallel tracks is that the person receiving care, the entity authorizing it, and the entity paying for it are frequently three different actors. An employer might authorize a screening benefit for staff without ever needing to know which staff used it. A cooperative might fund a health package for its members without needing the clinical detail behind any individual claim. Building a channel that assumes the partner needs to see everything, because they're the one who introduced the person, misreads who actually needs to know what. The party authorizing the spend usually needs proof of value, not proof of identity — and confusing the two is what turns a perfectly reasonable financing arrangement into an unnecessary data-sharing one.

When a partner asks for the list anyway

Sometimes, even after all of this, a partner still asks for row-level data. When that happens, the right move is to ask what decision they're actually trying to make. Nearly every time, underneath the request, is a version of "prove to me this is real." An HR lead wants to justify the arrangement to her own management. A cooperative chairperson wants something concrete to report back at the next general meeting. Neither of those needs requires a single name. Both are usually solved, more convincingly than a raw list would solve them, by a clean weekly aggregate — attendance trends, completion rates, a short note on what's working and what isn't — delivered on a schedule they can rely on rather than dumped once and never followed up.

That reporting cadence, done consistently, tends to do something the spreadsheet never could: it gives the partner a reason to keep showing up to their own side of the arrangement, because they can see, in numbers rather than in names, that the thing is actually happening. The asset was never the list. It was always the aggregate, delivered on time, treated as something worth building well rather than as an afterthought bolted onto the end of a legal agreement — the number that lets a chairperson stand up at her own meeting and say, with confidence, that this is working, without ever needing to know, or carry the risk of knowing, which of her members it worked for.

Notes on sources

  • Health-related information, including disability status, classified as sensitive personal data under the Nigeria Data Protection Act 2023, with real discrimination risk: NDPC, "Disability Details are Sensitive Health Data".
  • National Health Insurance Authority Act, 2022 and its distinct coverage tracks (Formal Sector, Organised Private Sector, Vulnerable Group via the Basic Healthcare Provision Fund, GIFSHIP): nhia.gov.ng/nhia-act.