Home
Macedonia

Audit: Moj Termin was without maintenance for 738 days, raising ownership and data‑security risks

Audit shows 738 days without maintenance contracts, 333.3 million denars invested and intellectual‑property and IT‑security weaknesses.

·Macedonia
Audit: Moj Termin was without maintenance for 738 days, raising ownership and data‑security risks

The State Audit Office's final report on the information system Moj Termin found that from 1 January 2021 to 30 April 2026 the system was uncovered by maintenance contracts for a total of 738 days, representing 37.9 percent of the analysed period. Maintenance agreements were arranged on an annual basis without ensuring continuity. During the same period, 333.3 million denars (5.42 million euros) were invested in maintenance for Moj Termin and related systems at public health institutions, of which only 9 percent related to the national health information system and 91 percent to other systems in public health.

The audit — titled “Moj Termin - optimisation of healthcare processes and improvement of healthcare quality” — excluded costs for application software and maintenance used by family physicians and private healthcare providers. The report also notes that 48 percent of total investments at public health institutions that use other information systems are concentrated with three software companies, indicating increased risk of concentration and limited competition.

Institutional gaps, ownership and staffing

The Agency for Electronic Health did not prepare a functional analysis of staffing needs and filled only 29 percent of the planned posts; some needs are met through annually renewed contracts for services. Although the Agency is responsible for development and upgrades of the integrated health information system, it has no authority to carry out public procurements related to Moj Termin. The term Moj Termin is not registered and legally protected by state institutions but by a private economic operator with whom the Ministry of Health signs maintenance contracts. This means the Ministry is not the copyright holder of the term Moj Termin; those rights are controlled by a private operator and there is a risk of intellectual property disputes over Moj Termin.

The audit found that central systems for electronic timekeeping and for material‑financial and accounting operations in public health institutions have not been established. The registry for medical equipment contains incomplete data that prevent full utilisation of medical devices, and the absence of functional national systems is linked to shortages of healthcare workers. In 2024 the economic operator maintaining the National Electronic Health Records System registered the term Moj Termin with the State Office for Industrial Property and initiated registration of the Moj Termin logo, which the audit notes is very similar to the original system logo.

An on‑site check of the SMS notification system for scheduled or cancelled appointments showed serious gaps. At General City Hospital "8 September" — Skopje, in the period from 1 January 2021 to 30 April 2026 the number of delivered SMS reminders for scheduled appointments was drastically lower than the total number of realised referrals, amounting to only 10.1 percent. The report also found that surgical interventions are not recorded in Moj Termin by that hospital despite it being one of the busiest in the country, and that the promoted transparency function for waiting lists does not reflect reality due to missing key data such as referral dates and the total number of operations scheduled by doctors.

Ministry controls in public health institutions were not continuous: in 2023 there were 62 planned inspections, of which 24 were carried out (38.7 percent), while in 2024, 2025 and 2026 no annual plans were adopted and no inspections were carried out. The audit identified significant weaknesses in IT security and personal data protection: procedures and control mechanisms for managing user access, activity monitoring and protection of sensitive data were not implemented. The report recommends measures to improve governance of the system, ensure continuous maintenance, strengthen IT security and data protection, and establish integrated and effective control mechanisms to improve the efficiency, security and quality of health services.

Photo: press material from the event

Related articles