All answers
Intake, consent and patient data

What does POPIA mean for a medical practice?

POPIA requires South African practices to collect only the patient information they need, tell patients what it is used for, keep it secure and accurate, keep it only as long as necessary, and report certain breaches. In practice that means individual staff logins, a written privacy notice, a retention rule per record type and a plan for when something goes wrong.

Written by the HeroMed team · Last reviewed 7 September 2026

What POPIA asks of a practice

  • Lawful purpose. Collect what you need for care, billing and legal obligations — not more.
  • Transparency. A privacy notice patients can actually read, given at intake.
  • Security. Individual logins, role-based access, encryption, tested backups.
  • Accuracy. A way for patients to correct their information.
  • Retention. A documented period per record type, aligned to HPCSA guidance.
  • Breach notification. A duty to notify the Information Regulator and affected patients in defined circumstances.

The five most common gaps

  1. Shared reception logins
  2. Patient information sent over personal WhatsApp accounts
  3. Ex-staff accounts still active
  4. No written retention rule
  5. No named person responsible for information requests

Where to start this week

Give every staff member their own login, remove the accounts of anyone who has left, write down what you hold and for how long, and publish a privacy notice at intake. That is most of the practical exposure closed.

More detail: POPIA compliance for practices and our POPIA notice.

Related questions

Your practice, perfected.

Start with HeroMed Core AI, then layer in any AI Hero your practice requires. 14 days free — no credit card, no lock-in.

Talk to us