POPIA and healthcare risk:
The critical compliance gaps in medical practices and facilities
Read time: 7–8 minutes
– Natasha Naidoo
– Surav Naidoo
In this ethics article, Natasha Naidoo, Director, and Surav Naidoo, candidate attorney of Fairbridges Attorneys examine the evolving compliance landscape under Protection of Personal Information Act, 4 of 2013 (POPIA) in the healthcare sector, following the publication of the 2026 Regulations Relating to the Processing of Data Subjects’ Health Information. Although not all healthcare practitioners and facilities fall directly within the regulations’ primary scope, the impact is far-reaching across the broader healthcare data ecosystem.
The article explores key risk areas including confidentiality obligations, cross-border data transfers, consent requirements, third-party service provider contracts, and the governance of clinical and administrative data. It highlights the practical steps required to ensure that patient health information is processed lawfully, securely, and transparently in an increasingly regulated environment.
POPIA in 2026: What has changed?
South African medical practitioners and healthcare facilities should take note of an important development in 2026. The Information Regulator published the Regulations Relating to the Processing of Data Subjects’ Health Information by Certain Responsible Parties, 2026 in Government Gazette No. 54268 on 6 March 2026 (the regulations). The regulations were issued under section 112(2)(c) of POPIA and commenced on the date of publication. They are therefore already in force.
The fine print nobody can ignore
The regulations do not apply to all healthcare practitioners or healthcare facilities in the same way. Their express scope is limited to the processing of health information by insurance companies, medical schemes, medical scheme administrators, managed healthcare organisations, administrative bodies, pension funds, employers, institutions working for employers, administrative bodies or pension funds, and applicable operators.
You’re not named, but you’re definitely involved
Healthcare practitioners and healthcare facilities are not expressly listed as the primary responsible parties to whom the regulations apply. However, the regulations remain highly relevant to them because they routinely interact with medical schemes, administrators, managed-care organisations, insurers, employers and other entities that fall within the regulations’ scope.
When ‘health information’ means everything and then some
The regulations define ‘health information’ broadly as personal information relating to the physical and/or mental health of a data subject, including the provision of healthcare services and any testing, treatment or diagnosis which reveals information about a person’s health status. This confirms that clinical notes, diagnoses, test results, medical certificates, sick notes, treatment records and billing-related health information may fall within a protected category of personal information.
Why this exists in the first place
The purpose of the regulations is to assist responsible parties in interpreting section 32(6) of POPIA correctly, to improve transparency for data subjects regarding how their health information may be used, and to provide a framework for enforcement by the Information Regulator.
Follow the data trail (it always leaves the practice)
For practitioners and healthcare facilities, the practical importance of the regulations lies in the healthcare data ecosystem. While they may not be expressly named in the regulations, the information generated within medical practices and healthcare facilities is frequently transmitted to schemes, administrators, managed-care organisations, insurers, employers and third-party service providers. This means that both practitioners and facilities must be able to justify what information they collect, why it is shared, who receives it, and whether the disclosure is necessary and lawful.
"POPIA health information regulations are already in force and primarily apply to insurers schemes administrators employers and managed healthcare organisations"
Locks, logs and legal obligations
A key feature of the regulations is the emphasis on confidentiality, integrity and availability of health information. Responsible parties must maintain appropriate and reasonable technical and organisational measures to prevent loss, damage, unauthorised destruction, unlawful access and unlawful processing. These safeguards must address both physical and electronic health records and must include proper disposal of records to prevent unauthorised access after disposal.
This has practical implications for practitioners and healthcare facilities alike. Patient files should not be left exposed at reception. Screens should not be visible to unauthorised persons. Emails containing patient information should be sent securely and to the correct recipient. Staff should be trained not to discuss patient information where they can be overheard. Electronic systems should be protected by appropriate access controls, passwords, antivirus software, firewalls and, where appropriate, encryption.
Confidentiality is no longer just a principle
The regulations emphasise that health information must be processed subject to a duty of confidentiality. In the context of medical practices and healthcare facilities, this reinforces the need for proper confidentiality provisions in contracts with billing companies, IT providers, transcription services, laboratories, off-site storage providers, waste-disposal providers and any other third party that handles patient information.
The cloud has no borders (and neither does POPIA risk)
The regulations provide that health information may not be transferred outside South Africa unless one or more of the requirements in section 72(1) of POPIA is met. This is relevant where practices and healthcare facilities use cloud-based software, foreign-hosted backups, international transcription providers or platforms that may permit offshore access to patient information. Practitioners and facilities should know where patient data is stored, who can access it, and whether the necessary contractual and legal safeguards are in place.
Consent is still King
Consent remains important particularly where health information is used or disclosed for purposes beyond ordinary treatment and practice administration. Broad, generic consent clauses may not be sufficient where information is disclosed to an employer, insurer, medical scheme, administrator or other third party for a purpose that may have consequences for the patient.
Informed consent remains central to the provision of health services, subject to recognised exceptions. The Health Professions Council of South Africa’s ethical guidance on confidentiality also requires practitioners to treat patient information as private and sensitive, to obtain consent where possible, to anonymise information where identifiable data is not required, and to limit disclosures to what is necessary.
"Healthcare practitioners and facilities are not directly listed under the regulations but remain central within the broader healthcare data ecosystem"
Audits: Where compliance meets reality
Medical scheme audits are a good example of the tension between disclosure and confidentiality. Schemes may request patient records to verify claims or investigate billing anomalies. Practitioners and healthcare facilities should not simply refuse to cooperate, but they should also avoid over-disclosure. The correct approach is to identify the lawful basis for the disclosure, assess the scope of the request, provide what is reasonably necessary, and keep a record of what was disclosed and why.
Your forms might be legally out of date
Practices and healthcare facilities should also review their patient intake forms, privacy notices and consent documentation. Patients should be told what information is collected, why it is collected, who it may be shared with, and how it will be protected. Consent clauses should be clear, specific and aligned with actual processing activities, including disclosures to medical schemes, laboratories, specialists, insurers, employers and third-party administrators.
Your service providers are part of your risk profile
Contracts with operators and service providers should include POPIA-aligned obligations dealing with confidentiality, security, access control, breach notification, record retention, destruction and subcontracting. A practice or healthcare facility that outsources billing or IT services cannot ignore what happens to patient information once it leaves its environment.
From policy to practice - where compliance actually lives or dies
Practitioners and healthcare facilities must review privacy notices, consent wording and operator agreements. They are required to map disclosures to medical schemes, employers, insurers, laboratories and administrators. They must use express consent where appropriate, particularly where disclosure may affect the patient personally.
Cloud hosting and possible cross-border transfers must be considered. Reception, billing and administrative staff must receive training. Provisions must be made to secure physical and electronic records. Proper record destruction procedures must be implemented. Information Officer registration and POPIA governance arrangements must be confirmed.
Compliance is no longer a paper exercise
The 2026 regulations do not create a new standalone consent regime for every practitioner or healthcare facility. Health information is, however, an enforcement priority. The practical message is that patient information must be handled deliberately, securely and proportionately. Practitioners and facilities may process health information where necessary for treatment, care and administration, but that does not remove the need for confidentiality, appropriate consent, minimum necessary disclosure, sound contractual safeguards and proper data-security practices.
The bottom line: Show, don’t just say
What is clear is that compliance is no longer only about having a privacy notice on file. It is about being able to demonstrate, in practical terms, that patient information is collected, used, shared, stored and destroyed responsibly. The regulations can be accessed as a pdf at National Government Regulations selecting 54273 6-3-2026 pages 104 to 110.
Natasha Naidoo is a Director at Fairbridges Wertheim Becker and heads the Insurance and Medical Law Team in the Johannesburg office. With extensive experience across insurance, reinsurance, medical malpractice, and healthcare regulatory law, Natasha provides comprehensive legal services to local and international clients. She advises and acts for major insurers in litigious matters across all lines of insurance. In the healthcare sector, Natasha acts for private healthcare facilities and healthcare practitioners in medical malpractice claims, professional misconduct matters, and personal injury litigation. She has also represented the Department of Health in South Africa
Surav Naidoo is a Candidate Attorney at Fairbridges Attorneys. He obtained his LLB degree in 2023 and completed the Law Society of South Africa–University of South Africa Long Distance Learning School for Legal Practical Vocational Training Programme, as well as the Trial Advocacy Course in 2024. He is currently preparing to write his final two board exams in August, having passed the first two in March, further strengthening his legal foundation. He is committed to continuous professional development and intends to pursue an LLM after gaining practical experience and identifying his area of specialisation, with a particular interest in Sports Law and legal advocacy.
Images:Gallo Images
CONTENTS
Smarter diabetes management in primary care
Medical Academic chats with Dr Ankia Coetzee, an eminent endocrinologist and faculty member at Tygerberg Hospital and Stellenbosch University, to explore contemporary approaches to type 2 diabetes (T2DM) management in clinical practice.
Navigating contraception alongside modern weight-loss therapies
Dr Malikah van der Schyff, obstetrician and gynaecologist, speaks to Medical Academic about the growing use of injectable weight-loss and diabetes therapies among women of reproductive age.
Influenza management across the family – practical considerations for antiviral therapy
Medical Academic asked Prof Keertan Dheda about the practical and evidence-based management of influenza in South Africa, with particular focus on the appropriate use of antiviral therapy.
Antimalarial prophylaxis – supporting confident travel decisions
Medical Academic interviews Prof Tiaan de Jager about the principles of antimalarial prophylaxis and the importance of evidence-based prevention strategies.
POPIA and healthcare risk: The critical compliance gaps in medical practices and facilities
In this ethics article, Natasha Naidoo, Director, and Surav Naidoo, candidate attorney of Fairbridges Attorneys examine the evolving compliance landscape under Protection of Personal Information Act, 4 of 2013 (POPIA) in the healthcare sector.
Closing the gap between hypertension guidelines and reality
Hypertension remains one of the most prevalent and consequential cardiovascular (CV) risk factors worldwide yet achieving long-term blood pressure (BP) control continues to be a major clinical challenge.
