POPIA Compliance
How Medifile protects your practice and your patients under South African data protection law.
What is POPIA?
The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's primary data protection law. It regulates how organisations collect, use, store, and share personal information — and gives individuals the right to know how their information is used and to request its correction or deletion.
For medical practices, POPIA applies to all patient information — names, contact details, ID numbers, and crucially, health records. Health data is classified as “Special Personal Information” under POPIA section 26, which means it receives the highest level of protection and may only be processed under strict conditions.
Non-compliance can result in fines of up to R10 million, imprisonment of up to 10 years, or both.
Your role and ours
Medifile
Operator
- We process patient data only on your instructions
- We never use patient data for our own purposes
- We are bound by a DPA under POPIA s20–21
- We implement technical security measures to protect data
- We notify you within 72 hours of any security incident
How Medifile protects patient data
We have built POPIA compliance into every layer of the platform — not bolted on after the fact.
Encryption at rest & in transit
All data is encrypted using 256-bit AES at rest and TLS 1.2+ in transit. No patient record is transmitted or stored in plain text.
Data stored in South Africa
Patient data is stored in South Africa where technically possible. Where sub-processors operate offshore, we ensure appropriate safeguards under POPIA section 72.
Immutable audit logs
Every access, upload, edit, and deletion is logged with a timestamp, user ID, and action type. Logs cannot be altered or deleted.
Consent tracking
Capture, store, and retrieve patient consent records with full version history. Know exactly when each patient consented and to what.
Retention management
The platform tracks retention periods aligned to HPCSA guidelines and flags records approaching expiry. You decide when to delete — we make sure you don't delete too early.
Breach management
If a security incident occurs, our breach workflow guides you through POPIA's mandatory notification process, with a full documentation trail.
Role-based access
Staff see only what they need to. Receptionists cannot access clinical notes without permission. No practice can access another's data.
Operator agreement
By signing up, you enter into a legally binding Data Processing Agreement (DPA) with Medifile — satisfying your POPIA obligation to have a written contract with your Operator.
Your POPIA obligations as a medical practice
Medifile handles the Operator side. Here is what you need to do as the Responsible Party:
- ☐Appoint a POPIA Information Officer and register with the Information Regulator at justice.gov.za/inforeg (free)
- ☐Inform patients that their records will be processed on Medifile — add this to your patient information leaflet or consent form
- ☐Capture patient consent using the consent tools in the platform before processing their health information
- ☐Respond to patient requests to access, correct, or delete their records — use the patient timeline and compliance tools
- ☐Use the platform's PAIA tools to respond to formal access requests within 30 days
- ☐Notify Medifile immediately if you become aware of a security incident or breach
- ☐Do not share login credentials — each staff member must have their own Medifile user account
- ☐Review your retention settings annually and ensure records are not deleted before the minimum 6-year retention period
- ☐Make your own PAIA manual available to the public — your practice needs one too, separate from Medifile's
Health records and Special Personal Information
Health data is the most sensitive category of personal information under POPIA. Section 26 prohibits the processing of Special Personal Information unless specific conditions are met. For medical practices, the primary lawful ground is POPIA section 27(1)(c): processing is necessary for the proper treatment and care of the data subject.
Patient rights under POPIA
| Right | What it means | How to action it in Medifile |
|---|---|---|
| Access (s23) | Patient can request a copy of their personal information you hold | Download records from the patient file section or invite them to the patient portal |
| Correction (s24) | Patient can request correction of inaccurate information | Edit records directly in the platform |
| Deletion (s24) | Patient can request deletion (subject to legal retention minimums) | Use the delete function in the patient record (retention lock prevents premature deletion) |
| Objection (s11(3)) | Patient can object to processing on grounds of legitimate interest | Note the objection in the patient record and contact Medifile if platform-level restriction is needed |
| Complaint | Patient can complain to the Information Regulator if rights are not upheld | Direct patient to justice.gov.za/inforeg |
Sub-processors we use
All sub-processors are bound by data processing agreements and appropriate safeguards. The full list with safeguards is in our Data Processing Agreement.
| Provider | What they do | Where data is processed |
|---|---|---|
| Supabase | Database, authentication, file storage | South Africa region where available |
| Google Cloud / Vision AI | OCR text extraction from uploaded documents | USA (Standard Contractual Clauses apply) |
| Resend | Transactional email (account, referral, security) | USA (data processing agreement in place) |
| PayFast | Subscription payment processing | South Africa |
| Vercel | Application hosting and delivery | SA edge region where available |
Contact our Information Officer
Information Regulator (South Africa)
For complaints about how we handle data:
POPIAComplaints@inforegulator.org.za
justice.gov.za/inforeg
Related documents
POPIA page content last reviewed 29 June 2026 · medifile.co.za · hello@medifile.co.za