POPIA & Compliance

The POPIA compliance checklist for medical practices

By David Howe · Founder, GreenNotes MedicalReviewed by Simone Howe
Updated 11 August 20264 min read
This checklist is general information, not legal advice. POPIA obligations depend on your specific practice. For a compliance assessment, consult an attorney or your professional body.

Patient records are “special personal information” under the Protection of Personal Information Act, which sets the bar for handling them higher than for ordinary data. This page turns our complete POPIA guide into an eight-point self-audit: work through the checks below, and anything you cannot evidence today is your compliance to-do list.

Prefer it printable?

The same eight checks as a one-page PDF — pin it up, tick it off, re-run it each year. No email address required.

Download the PDF

1. Information Officer registered with the Information Regulator

Every practice needs an Information Officer — in a small practice this is usually the practice owner. Registration is done directly with the Information Regulator, and it is the foundation the rest of your compliance hangs off: the officer is who the Regulator holds responsible.

2. PAIA manual and privacy notice published

Both must be available to patients — on your website if you have one, or on request at the practice. The privacy notice tells patients what you collect and why; the PAIA manual tells them how to ask for it.

3. Patient data collected for clear, stated purposes only

Collect what the consultation and its administration require, tell patients why, and use it for nothing else. Purpose limitation is one of POPIA’s eight conditions for lawful processing, and it is the one most easily broken by habit — old intake forms that ask for more than you need.

4. Records encrypted, access-controlled and audit-logged

Whether paper or digital, records need protection against loss and unauthorised access. For digital systems that means encryption, per-user access control and an audit trail — if your software cannot show who looked at a record and when, it is making this check hard to pass.

5. Written operator agreements with every vendor

Any software vendor or billing bureau that touches patient data processes it on your behalf, which makes them an operator under the Act — and operators need written agreements. If a vendor cannot produce one, that is a warning sign in itself.

6. A breach-notification plan in place

Decide in advance who assesses an incident, who informs the Information Regulator and affected patients, and how quickly. A breach is a bad moment to be designing a process from scratch.

7. A process for patient access and correction requests

Patients may ask what you hold about them and have it corrected. Decide how requests are received, how identity is verified, and who answers them — then write it down so a locum or receptionist handles it the same way you would.

8. A retention schedule aligned to HPCSA rules

Keep records as long as the HPCSA requires, then dispose of them securely. Retention and destruction are both part of compliance — holding records forever is a POPIA problem, not a safety net.

How often should you re-run this?

Annually as a matter of routine — and immediately whenever you change practice software, add a billing bureau, or take on staff who access patient records. Each of those events changes who touches patient data, which is exactly what the checklist audits.

For the reasoning behind each item — the eight lawful-processing conditions, what counts as a breach, and how POPIA compares to HIPAA and GDPR — read the complete POPIA compliance guide.

Prefer it printable?

The same eight checks as a one-page PDF — pin it up, tick it off, re-run it each year. No email address required.

Download the PDF

See how GreenNotes keeps your practice POPIA compliant

Explore GreenNotes
DH

David Howe

Founder, GreenNotes Medical

GreenNotes Medical builds AI-powered clinical tools for South African clinicians: AI scribe, auto-generated letters, intake, consent and practice management, all POPIA compliant. This guide was reviewed by Simone Howe, Co-Founder, GreenNotes Medical.

Related guides