Patient records are “special personal information” under the Protection of Personal Information Act, which sets the bar for handling them higher than for ordinary data. This page turns our complete POPIA guide into an eight-point self-audit: work through the checks below, and anything you cannot evidence today is your compliance to-do list.
Prefer it printable?
The same eight checks as a one-page PDF — pin it up, tick it off, re-run it each year. No email address required.
1. Information Officer registered with the Information Regulator
Every practice needs an Information Officer — in a small practice this is usually the practice owner. Registration is done directly with the Information Regulator, and it is the foundation the rest of your compliance hangs off: the officer is who the Regulator holds responsible.
2. PAIA manual and privacy notice published
Both must be available to patients — on your website if you have one, or on request at the practice. The privacy notice tells patients what you collect and why; the PAIA manual tells them how to ask for it.
3. Patient data collected for clear, stated purposes only
Collect what the consultation and its administration require, tell patients why, and use it for nothing else. Purpose limitation is one of POPIA’s eight conditions for lawful processing, and it is the one most easily broken by habit — old intake forms that ask for more than you need.
4. Records encrypted, access-controlled and audit-logged
Whether paper or digital, records need protection against loss and unauthorised access. For digital systems that means encryption, per-user access control and an audit trail — if your software cannot show who looked at a record and when, it is making this check hard to pass.
5. Written operator agreements with every vendor
Any software vendor or billing bureau that touches patient data processes it on your behalf, which makes them an operator under the Act — and operators need written agreements. If a vendor cannot produce one, that is a warning sign in itself.
6. A breach-notification plan in place
Decide in advance who assesses an incident, who informs the Information Regulator and affected patients, and how quickly. A breach is a bad moment to be designing a process from scratch.
7. A process for patient access and correction requests
Patients may ask what you hold about them and have it corrected. Decide how requests are received, how identity is verified, and who answers them — then write it down so a locum or receptionist handles it the same way you would.
8. A retention schedule aligned to HPCSA rules
Keep records as long as the HPCSA requires, then dispose of them securely. Retention and destruction are both part of compliance — holding records forever is a POPIA problem, not a safety net.
How often should you re-run this?
Annually as a matter of routine — and immediately whenever you change practice software, add a billing bureau, or take on staff who access patient records. Each of those events changes who touches patient data, which is exactly what the checklist audits.
For the reasoning behind each item — the eight lawful-processing conditions, what counts as a breach, and how POPIA compares to HIPAA and GDPR — read the complete POPIA compliance guide.
Prefer it printable?
The same eight checks as a one-page PDF — pin it up, tick it off, re-run it each year. No email address required.
See how GreenNotes keeps your practice POPIA compliant
Explore GreenNotes