All answers
Intake, consent and patient data

Is HeroMed POPIA compliant?

HeroMed is built for POPIA from the ground up: patient data is stored and processed on a POPIA-aligned basis, access is restricted to the practice''s own users, patient consent is recorded on the patient record — including per-channel consent for email, WhatsApp and SMS — and every message sent to a patient leaves an auditable history. Compliance is shared: the platform provides the controls, and the practice remains the responsible party for how patient information is used.

Written by the HeroMed team · Last reviewed 17 September 2026

What the platform provides

  • Patient records and clinical notes held on a POPIA-aligned basis, with access limited to your practice's users
  • Consent recorded on the patient record, including per-channel consent for email, WhatsApp and SMS, honoured on every send
  • An auditable history of patient communication and of who signed each clinical note
  • Minimised message content — clinical detail stays inside the record, not in a reminder
  • Data-subject requests supported: what is held on a patient can be produced and corrected

What stays your responsibility

POPIA makes the practice the responsible party. You decide what you collect, why, who in your team can see it and how long you keep it. HeroMed gives you the controls and the record; the policy is yours.

Practical steps for a practice

  1. Collect channel consent at intake, not later.
  2. Keep clinical detail out of reminders and confirmations.
  3. Review who in your team has access to what, and remove leavers promptly.
  4. Know your retention period for clinical records and apply it consistently.

More detail: POPIA for medical practices and our POPIA notice.

Related questions

Your practice, perfected.

Start with HeroMed Core AI, then layer in any AI Hero your practice requires. 14 days free — no credit card, no lock-in.

Talk to us