POPIA CompliantSA Data ResidencySOC 2 Certified

Security built for medical records

Your patients trust you with their most sensitive information. We take that responsibility as seriously as you do. Here is exactly how Medifile protects your data.

POPIA CompliantSA Data ResidencySOC 2 Certified InfrastructureAES-256 EncryptionDatabase-Layer RLSOffline-Ready PWA
Security Architecture

Six layers of protection

Defence-in-depth means no single point of failure can expose your patient data.

Encryption at Rest and in Transit

Your files are stored encrypted using AES-256 - the same standard used by banks and major financial institutions. All data in transit between your browser and our servers is protected with TLS encryption. Files are never stored unencrypted.

AES-256 at restTLS in transit

South African Data Residency

Your database and file storage are hosted in South Africa, on enterprise-grade infrastructure certified to international security standards. Patient records never leave South African borders. The web application is served globally via enterprise CDN infrastructure for performance and reliability.

South Africa (Cape Town)Enterprise infrastructure

Role-Based Access Control

Granular permissions for every user role - Practice Owner, Doctor, Assistant. Row Level Security (RLS) is enforced at the database layer, which means even a misconfigured API call cannot expose data from another practice.

Database-layer RLSPrinciple of least privilege

Multi-Factor Authentication

TOTP-based MFA is available to all users via any authenticator app (Google Authenticator, Authy, and others). Every login and authentication event is recorded to your practice audit trail with a timestamp.

TOTP-based MFALogin audit trail

Comprehensive Audit Logs

Every action - upload, download, share, edit, delete - is written to your practice audit log. Access to audit records is restricted by database-level row security. You can export your full audit history at any time for compliance reporting.

Full action historyExportable for compliance

Responsible Data Access

Medifile staff do not access practice data unless support is explicitly requested. All support access is logged and documented. Our Data Processing Agreement (DPA), included with every plan, sets out exactly how we handle your data as an Operator under POPIA.

Staff access loggedDPA included
Infrastructure

Built on enterprise-grade infrastructure

Medifile runs on enterprise cloud infrastructure with SOC 2 Type II certification and a 99.9% uptime SLA. Your database and file storage are hosted in South Africa (Cape Town). The web application is delivered globally via enterprise CDN for fast, reliable access from any location.

  • SOC 2 Type II certified infrastructure
  • Point-in-time database recovery
  • 99.9% uptime SLA
  • Automatic failover and backups
  • Offline-first PWA - works during load shedding
  • Patient data hosted in South Africa (Cape Town)

Data processing locations

Database and file storageπŸ‡ΏπŸ‡¦ South Africa, Cape Town
Application hosting🌐 Global CDN (enterprise)
Transactional emailπŸ”’ Encrypted delivery, GDPR compliant
AuthenticationπŸ‡ΏπŸ‡¦ South Africa, Cape Town
POPIA Section 22

Breach notification process

In the event of a security incident, POPIA Section 22 requires notification of the Information Regulator and affected data subjects. Here is exactly what we do.

01

Breach detection

Unusual access patterns and bulk downloads are flagged for review. Security events are investigated promptly.

02

Internal assessment (within 24 hours)

The Medifile Information Officer assesses whether a breach meets the POPIA Section 22 notification threshold - i.e., whether it is likely to harm data subjects.

03

Notification to Information Regulator (within 72 hours)

If the threshold is met, we notify the Information Regulator within 72 hours as required by POPIA Section 22(1). We assist affected practices with their own notification obligations.

04

Data subject notification

Affected data subjects (patients) are notified as soon as reasonably possible after the Regulator is informed. Medifile provides notification templates and tracks delivery confirmation.

72-hour clock: POPIA Section 22 requires notification to the Information Regulator as soon as reasonably possible, and within 72 hours of becoming aware of a breach. Medifile's incident response process is designed to meet this deadline.

Data Processing Agreement (DPA)

Our standard DPA is included with all plans. Enterprise customers can request a customised DPA with additional clauses. The DPA formalises our obligations as an Operator under POPIA. Read our full Privacy Policy for details on how we handle your data.

Request DPA

Ready to secure your patient records?

Start your free 14-day trial. No credit card required.