What does POPIA mean for a medical practice?
POPIA requires South African practices to collect only the patient information they need, tell patients what it is used for, keep it secure and accurate, keep it only as long as necessary, and report certain breaches. In practice that means individual staff logins, a written privacy notice, a retention rule per record type and a plan for when something goes wrong.
Written by the HeroMed team · Last reviewed 7 September 2026
What POPIA asks of a practice
- Lawful purpose. Collect what you need for care, billing and legal obligations — not more.
- Transparency. A privacy notice patients can actually read, given at intake.
- Security. Individual logins, role-based access, encryption, tested backups.
- Accuracy. A way for patients to correct their information.
- Retention. A documented period per record type, aligned to HPCSA guidance.
- Breach notification. A duty to notify the Information Regulator and affected patients in defined circumstances.
The five most common gaps
- Shared reception logins
- Patient information sent over personal WhatsApp accounts
- Ex-staff accounts still active
- No written retention rule
- No named person responsible for information requests
Where to start this week
Give every staff member their own login, remove the accounts of anyone who has left, write down what you hold and for how long, and publish a privacy notice at intake. That is most of the practical exposure closed.
More detail: POPIA compliance for practices and our POPIA notice.
