All articlesIndustry

POPI compliance for South African physiotherapy practices — what you actually need

A plain-English walkthrough of POPIA for allied health practices: what counts as personal information, where most physios slip up, and the practical steps to get compliant without losing your weekends.

HeroMed Team19 May 2026 6 min read

POPIA — the Protection of Personal Information Act — has been in force since 2021, and the Information Regulator has started issuing fines. For a busy physiotherapy practice juggling clinical notes, medical aid submissions and WhatsApp reminders, "compliance" can feel like a moving target. It doesn't have to be.

What POPIA actually means for your practice

Every patient file you keep — name, ID number, medical history, treatment notes, claims data — is personal information under the Act. As soon as you collect it, you become a responsible party with eight specific obligations: lawful processing, purpose specification, further-processing limitation, information quality, openness, security safeguards, data subject participation, and accountability.

In a clinic setting, that translates to four practical questions:

  1. Where does patient data live? Paper files, an Excel sheet, your billing software, your phone, your accountant's inbox?
  2. Who can see it? Staff, locums, your spouse who helps with admin, the cleaner with keys to the filing room?
  3. How long do you keep it? HPCSA requires clinical records for at least six years after the last consultation (longer for minors). POPIA says once you don't need it, delete it.
  4. What's your plan if something leaks? A stolen laptop, a phishing email, a misdirected WhatsApp — you have 72 hours to notify the Regulator and affected patients.

Where most practices slip up

  • WhatsApp groups with patient names — convenient, but a privacy breach waiting to happen.
  • Shared logins — every staff member should have their own account so access is traceable.
  • Old paper files in the back room — if you can't say who has accessed them, you can't say they're secure.
  • No written consent for marketing messages — birthday SMSes, newsletters and "haven't seen you in a while" reminders all need opt-in.

A 30-minute compliance starter

  1. List every place patient data lives (paper, devices, software, cloud).
  2. Give every staff member their own login to every system.
  3. Lock down or shred anything you no longer need.
  4. Write a one-page Privacy Notice for patients (we have a template — ask us).
  5. Add a tick-box consent for marketing communication.
  6. Appoint an Information Officer (usually the practice owner) and register them with the Regulator.

How HeroMed handles it for you

HeroMed was built for the South African allied health market, so POPIA isn't an afterthought:

  • Per-user logins, full audit trail, role-based access.
  • Encrypted at rest and in transit.
  • Patient consent captured and stored with the file.
  • Built-in data export and "right to be forgotten" workflow.
  • Hosted on infrastructure with formal data-residency guarantees.

Compliance is never one-and-done — but with the right system underneath you, it stops being something you worry about every month.

Want a copy of our POPIA starter pack for physiotherapy practices? Get in touch and we'll send it across.

Your practice, perfected.

Start with HeroMed Core AI, then layer in any AI Hero. 14 days free — no credit card, no lock-in.

Talk to us