Biometrics have pervaded our private and public lives, with hospitals integrating biometric data into Electronic Medical Records (EMRs). Yet this practice operates within Nigeria's fragmented regulatory framework, where biometric data was simultaneously classified as health information and sensitive personal data, creating conflicting legal obligations. Employing doctrinal analysis, this paper argued that Nigerian law inadequately regulated biometric collection in the health sector. The paper analysed the regulatory vacuum surrounding biometric data protection in Nigeria's healthcare sector and found that strict compliance with the right to erasure under the Nigeria Data Protection Act conflicted with mandatory retention requirements in the National Health Act, thus exposing healthcare providers to liability. It further revealed that, while the National Health Act regulated posthumous health data, the Nigeria Data Protection Act omitted provisions for deceased persons' digital assets. The paper recommended the amendment of Section 25 of the National Health Act to permit pseudonymized clinical note retention with biometric deletion upon verified patient request, and the amendment of the Nigeria Data Protection Act to include post-mortem data succession provisions.