Healthcare Privacy & Medical Data Governance Policy
Statutory privacy policy governing the processing, encryption, and protection of patient medical dossiers, clinical encounters, and biometric telemetry under the Protection of Personal Information Act (POPIA Act 4 of 2013).
1. Eight Core Conditions for Lawful Processing
MediCore enforces all eight statutory conditions outlined in Chapter 3 of POPIA:
- Accountability (Condition 1): Automated telemetry and audit trails track every practitioner read, write, export, and prescription event.
- Processing Limitation (Condition 2): Only clinically necessary patient information (demographics, vital signs, clinical history, billing aid) is collected.
- Purpose Specification (Condition 3): Health data is collected exclusively for clinical care, appointment scheduling, and statutory billing.
- Further Processing Limitation (Condition 4): Health records are NEVER monetized, aggregated for third-party commercial marketing, or shared with insurers without express patient consent.
- Information Quality (Condition 5): Practitioners retain live tools to rectify and update demographic and clinical records.
- Openness (Condition 6): Patients receive transparency regarding electronic health storage and medical aid submission paths.
- Security Safeguards (Condition 7): AES-256 cloud encryption, role-based practitioner access control (RBAC), and multi-factor session authentication.
- Data Subject Participation (Condition 8): Facilitation of patient requests to view, query, or extract health summaries.
2. Special Personal Information of Patients (Section 32)
Pursuant to Section 32(1)(a) of POPIA, the prohibition on processing special personal health information does NOT apply to medical practitioners, healthcare institutions, or insurance institutions, provided that:
- The processing is necessary for the proper treatment and care of the data subject, or for the administration of the healthcare practice or facility concerned.
- The personal information is treated as confidential by virtue of the ethical rules of the Health Professions Council of South Africa (HPCSA) and statutory medical oaths.
All staff and practitioners issued credentials on MediCore are contractually bound by professional confidentiality obligations under the Health Professions Act (Act 56 of 1974).
3. Cross-Border Cloud Storage & BigQuery Infrastructure (Section 72)
MediCore leverages Google Cloud Platform (BigQuery) infrastructure. Where clinical datasets or encrypted backups transition or reside in Google Cloud global data regions, such processing complies strictly with Section 72(1) of POPIA:
- The cloud infrastructure recipient is bound by Google Cloud Data Processing Agreements and ISO/IEC 27001, 27017, and SOC 2 certifications ensuring data protection standards substantially similar to POPIA.
- Data is protected by client-isolated keys and hardware security modules (HSM) preventing unauthenticated third-party interception.
4. Statutory Medical Retention & Erasure Limitations
While POPIA Section 24 provides data subjects with the right to request deletion of personal information, this right is legally constrained by statutory health record retention requirements:
- HPCSA Guidelines & NHA: Clinical records must be retained for at least six (6) years from the last consultation.
- Pediatric Records: Records of minor patients cannot be purged until the patient attains the age of twenty-one (21) years.
- Tax & Invoicing: Financial billing and medical aid claims must be retained for five (5) years under the Tax Administration Act.
Where an erasure request conflicts with statutory retention mandates, MediCore will archive the dossier into a sealed, read-only restricted status until the statutory retention period expires.
5. Data Subject Rights & Information Officer
Patients wishing to exercise their rights of access, objection, or correction should submit a request to their treating medical practice (the Responsible Party). For platform-level infrastructure inquiries:
Email: privacy@tvbnet.co.za / popia@medicore.co.za
Physical Address: Johannesburg, Gauteng, South Africa
Complaints may also be lodged with the South African Information Regulator (inforegulator.org.za).