Six layers of protection
Defence-in-depth means no single point of failure can expose your patient data.
Encryption at Rest and in Transit
Your files are stored encrypted using AES-256 - the same standard used by banks and major financial institutions. All data in transit between your browser and our servers is protected with TLS encryption. Files are never stored unencrypted.
South African Data Residency
Your database and file storage are hosted in South Africa, on enterprise-grade infrastructure certified to international security standards. Patient records never leave South African borders. The web application is served globally via enterprise CDN infrastructure for performance and reliability.
Role-Based Access Control
Granular permissions for every user role - Practice Owner, Doctor, Assistant. Row Level Security (RLS) is enforced at the database layer, which means even a misconfigured API call cannot expose data from another practice.
Multi-Factor Authentication
TOTP-based MFA is available to all users via any authenticator app (Google Authenticator, Authy, and others). Every login and authentication event is recorded to your practice audit trail with a timestamp.
Comprehensive Audit Logs
Every action - upload, download, share, edit, delete - is written to your practice audit log. Access to audit records is restricted by database-level row security. You can export your full audit history at any time for compliance reporting.
Responsible Data Access
Medifile staff do not access practice data unless support is explicitly requested. All support access is logged and documented. Our Data Processing Agreement (DPA), included with every plan, sets out exactly how we handle your data as an Operator under POPIA.
Built on enterprise-grade infrastructure
Medifile runs on enterprise cloud infrastructure with SOC 2 Type II certification and a 99.9% uptime SLA. Your database and file storage are hosted in South Africa (Cape Town). The web application is delivered globally via enterprise CDN for fast, reliable access from any location.
- SOC 2 Type II certified infrastructure
- Point-in-time database recovery
- 99.9% uptime SLA
- Automatic failover and backups
- Offline-first PWA - works during load shedding
- Patient data hosted in South Africa (Cape Town)
Breach notification process
In the event of a security incident, POPIA Section 22 requires notification of the Information Regulator and affected data subjects. Here is exactly what we do.
Breach detection
Unusual access patterns and bulk downloads are flagged for review. Security events are investigated promptly.
Internal assessment (within 24 hours)
The Medifile Information Officer assesses whether a breach meets the POPIA Section 22 notification threshold - i.e., whether it is likely to harm data subjects.
Notification to Information Regulator (within 72 hours)
If the threshold is met, we notify the Information Regulator within 72 hours as required by POPIA Section 22(1). We assist affected practices with their own notification obligations.
Data subject notification
Affected data subjects (patients) are notified as soon as reasonably possible after the Regulator is informed. Medifile provides notification templates and tracks delivery confirmation.
Data Processing Agreement (DPA)
Our standard DPA is included with all plans. Enterprise customers can request a customised DPA with additional clauses. The DPA formalises our obligations as an Operator under POPIA. Read our full Privacy Policy for details on how we handle your data.
Ready to secure your patient records?
Start your free 14-day trial. No credit card required.