POPIA Compliance

How Medifile protects your practice and your patients under South African data protection law.

POPIA CompliantHealth DataSA Data StorageHPCSA Aligned

What is POPIA?

The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's primary data protection law. It regulates how organisations collect, use, store, and share personal information — and gives individuals the right to know how their information is used and to request its correction or deletion.

For medical practices, POPIA applies to all patient information — names, contact details, ID numbers, and crucially, health records. Health data is classified as “Special Personal Information” under POPIA section 26, which means it receives the highest level of protection and may only be processed under strict conditions.

Non-compliance can result in fines of up to R10 million, imprisonment of up to 10 years, or both.

Why this matters for your practice. As a medical professional, you are the Responsible Party for your patients' information under POPIA. When you use a platform like Medifile to store and manage records, Medifile acts as your Operator — processing data only on your instructions, under strict contractual obligations.

Your role and ours

Your Practice

Responsible Party

  • You decide why patient data is collected and how it is used
  • You obtain patient consent where required
  • You appoint a POPIA Information Officer
  • You respond to patients' rights requests
  • You notify the Information Regulator of data breaches

Medifile

Operator

  • We process patient data only on your instructions
  • We never use patient data for our own purposes
  • We are bound by a DPA under POPIA s20–21
  • We implement technical security measures to protect data
  • We notify you within 72 hours of any security incident

Read our full Data Processing Agreement →

How Medifile protects patient data

We have built POPIA compliance into every layer of the platform — not bolted on after the fact.

Encryption at rest & in transit

All data is encrypted using 256-bit AES at rest and TLS 1.2+ in transit. No patient record is transmitted or stored in plain text.

Data stored in South Africa

Patient data is stored in South Africa where technically possible. Where sub-processors operate offshore, we ensure appropriate safeguards under POPIA section 72.

Immutable audit logs

Every access, upload, edit, and deletion is logged with a timestamp, user ID, and action type. Logs cannot be altered or deleted.

Consent tracking

Capture, store, and retrieve patient consent records with full version history. Know exactly when each patient consented and to what.

Retention management

The platform tracks retention periods aligned to HPCSA guidelines and flags records approaching expiry. You decide when to delete — we make sure you don't delete too early.

Breach management

If a security incident occurs, our breach workflow guides you through POPIA's mandatory notification process, with a full documentation trail.

Role-based access

Staff see only what they need to. Receptionists cannot access clinical notes without permission. No practice can access another's data.

Operator agreement

By signing up, you enter into a legally binding Data Processing Agreement (DPA) with Medifile — satisfying your POPIA obligation to have a written contract with your Operator.

Your POPIA obligations as a medical practice

Medifile handles the Operator side. Here is what you need to do as the Responsible Party:

  • Appoint a POPIA Information Officer and register with the Information Regulator at justice.gov.za/inforeg (free)
  • Inform patients that their records will be processed on Medifile — add this to your patient information leaflet or consent form
  • Capture patient consent using the consent tools in the platform before processing their health information
  • Respond to patient requests to access, correct, or delete their records — use the patient timeline and compliance tools
  • Use the platform's PAIA tools to respond to formal access requests within 30 days
  • Notify Medifile immediately if you become aware of a security incident or breach
  • Do not share login credentials — each staff member must have their own Medifile user account
  • Review your retention settings annually and ensure records are not deleted before the minimum 6-year retention period
  • Make your own PAIA manual available to the public — your practice needs one too, separate from Medifile's

Health records and Special Personal Information

Health data is the most sensitive category of personal information under POPIA. Section 26 prohibits the processing of Special Personal Information unless specific conditions are met. For medical practices, the primary lawful ground is POPIA section 27(1)(c): processing is necessary for the proper treatment and care of the data subject.

What Medifile does with health records. Medifile processes health records only to provide the platform to your practice. We do not analyse, sell, or use patient health data for our own purposes. We do not train AI models on identifiable patient data. Our AI summary feature generates summaries only from data you upload, and those summaries remain within your practice account.

Patient rights under POPIA

RightWhat it meansHow to action it in Medifile
Access (s23)Patient can request a copy of their personal information you holdDownload records from the patient file section or invite them to the patient portal
Correction (s24)Patient can request correction of inaccurate informationEdit records directly in the platform
Deletion (s24)Patient can request deletion (subject to legal retention minimums)Use the delete function in the patient record (retention lock prevents premature deletion)
Objection (s11(3))Patient can object to processing on grounds of legitimate interestNote the objection in the patient record and contact Medifile if platform-level restriction is needed
ComplaintPatient can complain to the Information Regulator if rights are not upheldDirect patient to justice.gov.za/inforeg

Sub-processors we use

All sub-processors are bound by data processing agreements and appropriate safeguards. The full list with safeguards is in our Data Processing Agreement.

ProviderWhat they doWhere data is processed
SupabaseDatabase, authentication, file storageSouth Africa region where available
Google Cloud / Vision AIOCR text extraction from uploaded documentsUSA (Standard Contractual Clauses apply)
ResendTransactional email (account, referral, security)USA (data processing agreement in place)
PayFastSubscription payment processingSouth Africa
VercelApplication hosting and deliverySA edge region where available

Contact our Information Officer

Information Officer

ML Meiring, ML Meiring t/a Medifile

hello@medifile.co.za

IO Registration: Pending

Information Regulator (South Africa)

For complaints about how we handle data:

POPIAComplaints@inforegulator.org.za

justice.gov.za/inforeg

Related documents

POPIA page content last reviewed 29 June 2026 · medifile.co.za · hello@medifile.co.za