HomeBlogYour Patient Records Sit Under Three Laws, Not One

Your Patient Records Sit Under Three Laws, Not One

Patient records fall under POPIA, the National Health Act and the HPCSA guidelines at once. Plus what the March 2026 health regulations do not change.

Read this before you rely on anything below. This is general information about South African law, written by a business owner rather than a lawyer and not reviewed by one. It is not legal advice and no attorney-client relationship arises from reading it. Patient records sit under POPIA, the National Health Act and the HPCSA's rules at the same time; section 17 of the National Health Act creates a criminal offence, and a mistake here can become a professional conduct matter as well as a regulatory one. The section on the March 2026 regulations is based on published commentary rather than on the gazetted text, which we were not able to obtain. Check the instruments themselves and take advice on your own facts before acting.

Health information starts out prohibited

Most POPIA discussions begin with the eight conditions for lawful processing. For a medical or dental practice the starting point is stricter than that.

Section 26 prohibits the processing of special personal information, and information concerning a data subject's health is squarely in that category. The default position is not "process it carefully". The default is no.

Which means every practice in the country is operating on an exemption, and it is worth knowing which one, because the exemption has conditions attached and they describe things you are already supposed to be doing.

Section 32 is the door you walk through

Section 32 lifts the prohibition for particular parties in particular circumstances. The paragraph that covers you is 32(1)(a): medical professionals, healthcare institutions and facilities may process health information where it is necessary for the proper treatment and care of the data subject, or for the administration of the institution or professional practice concerned.

Two things follow that are easy to miss.

The administration limb is real. Billing, scheduling, medical aid claims and running the practice are covered. You do not need a strained argument that invoicing is clinical care.

The permission is bounded by necessity. Necessary for treatment and care, or for administration. It does not extend to whatever else the record could be useful for later. A patient list is not a marketing list, and repurposing it for a newsletter about your new aesthetics offering is a different processing purpose that section 32 does not authorise. Direct marketing has its own rules in section 69.

Section 32(2) then attaches the condition: the person processing must be subject to an obligation of confidentiality by virtue of office, employment, profession or legal provision, or established by written agreement. For a doctor that duty already exists. For your receptionist, your locum, your bookkeeper and the student doing filing over December, it may not, and section 32(3) requires that those without a statutory duty treat the information as confidential in any event.

The practical translation is a signed confidentiality undertaking for every person who can see a patient record, including part-timers and contractors. It is the cheapest item on this page and the one most often missing.

The March 2026 regulations, and whether they are about you

On 6 March 2026 the Information Regulator published regulations dealing specifically with the processing of health information, in force immediately with no transitional period. Practices have been asking whether this changes what they do.

Read the list of who they cover before you worry. On the published summaries — we have worked from those rather than the gazette, which we could not obtain — the categories are insurance companies, medical schemes, medical scheme administrators, managed healthcare organisations, administrative bodies, pension funds, employers, and institutions acting on behalf of those bodies.

A treating practice is not in that list. On our reading, the regulations are aimed at the section 32(1)(b) and 32(1)(f) side of the world, the people who process health information for risk assessment, benefit administration and employment purposes, rather than at the practitioner treating the patient under 32(1)(a). Much of the commentary you will find is written for employers, and a GP reading those headlines can reasonably conclude they have been newly regulated when they have not.

Two qualifications, because this is not quite a clean escape.

You are also an employer. A practice holds sick notes, incapacity records and injury-on-duty paperwork for its own staff. In that capacity you are an employer processing health information, and the employer category is on the list. The regulations may reach your HR filing cabinet even where they do not reach your patient files. See POPIA and employee data.

Commentary differs on how much they add. Several provisions in the draft were dropped before the final version, and a fair reading is that what remains largely restates POPIA's existing requirements around lawful basis, security safeguards and cross-border transfers rather than creating a new regime. That is a reason to read them rather than to panic, and if your practice sits in one of the listed categories for any part of what it does, read them properly.

POPIA is not the only law on the shelf

This is the part that distinguishes healthcare from every other sector we write about. Three regimes apply to the same record at the same time.

  • POPIA, as above.
  • The National Health Act 61 of 2003. Section 14 makes all information about a user, including their health status, treatment and stay at a health establishment, confidential. Disclosure is permitted where the user consents in writing, where a court or any law requires it, or where non-disclosure poses a serious threat to public health. Section 17 requires the person in charge of a health establishment holding records to set up control measures preventing unauthorised access to the records and to the storage facility. Failing to do so is an offence, carrying a fine or imprisonment of up to a year, or both. Do not read "health establishment" as meaning hospitals: the Act defines it to cover the whole or part of any public or private institution, facility, building or place, for profit or not, operated or designed to provide inpatient or outpatient treatment or diagnostic or therapeutic interventions. A two-room dental practice is inside that.
  • The HPCSA guidelines, principally Booklet 9 on patient records. These are ethical guidelines rather than statute, but they bind registered practitioners through the professional conduct process, and they are where the retention periods live.

Note what section 14 of the National Health Act does that POPIA does not: it requires written consent for disclosure. POPIA's definition of consent does not demand writing. Where the two overlap, the stricter one governs, and in practice that means a verbal "yes, send it to my attorney" is not enough.

How long to keep records

Section 14 of POPIA says do not keep records longer than necessary for the purpose, unless another law authorises or requires retention. Healthcare is the clearest case in the country of another set of rules doing exactly that.

The HPCSA guidance sets out that health records should be kept:

  • For at least six years from the date the record became dormant.
  • For a minor, until the patient's 21st birthday, because a minor has three years after reaching majority in which to bring a claim.
  • For a mentally incompetent patient, for the duration of that patient's lifetime.

Two practical points. First, these are floors, not ceilings, and holding a record for thirty years because nobody ever looked at the question is not the same as a considered retention decision. Second, deletion under POPIA means the record cannot be reconstructed. A patient file dragged to the recycle bin on a machine that backs up nightly has not been deleted, and paper records need shredding rather than a bin bag.

The practice WhatsApp group

Almost every practice has one, and it is where the most personal information moves with the least thought. A photograph of a lesion, a patient's name and a question about a dose, sent to a group that includes a locum who left in March.

We are not going to tell you to stop, because clinical communication is genuinely urgent and the alternatives are worse when somebody is bleeding. But three things are worth doing:

  • Know who is in the group. Someone should be responsible for removing people who have left. This is the single most common failure and the easiest to fix.
  • Separate clinical from administrative. A group used for leave requests and lunch orders should not be the group where clinical photographs go.
  • Remember it is on a phone. A device holding patient information needs a passcode and, ideally, the ability to be wiped remotely. Section 19 requires reasonable technical measures, and an unlocked phone in a handbag is not one.

The same applies to personal email. A patient record forwarded to a private address to look at over the weekend has left every control the practice has.

Your practice management software is an operator

Your PMS vendor, billing bureau, medical aid switching house, transcription service, cloud backup and appointment-reminder SMS provider all process patient information on your behalf. Each is an operator, and section 21 requires a written contract obliging them to maintain the security safeguards in section 19 and to notify you immediately of unauthorised access.

Standard software licence agreements frequently do not contain this. Ask for the addendum, and if the vendor does not know what you are talking about, that is itself informative.

If any of it is hosted outside South Africa, which increasingly it is, you also have a cross-border transfer under section 72 to account for. That is a separate obligation from section 21, and health information is the last category you want to be casual about.

When someone who is not the patient asks

This is where practices get into difficulty, usually by being helpful. The gateways in section 14 of the National Health Act are narrow: written consent from the user, a court order or a law requiring disclosure, or a serious threat to public health.

  • An employer asking why a patient was booked off is entitled to a sick note, not to a diagnosis.
  • A medical scheme has a contractual basis for claims information, which is not the same as an open-ended right to the clinical record.
  • An attorney, including one who says they act for the patient, needs the patient's written authority. Ask for it.
  • A family member, however concerned and however senior, is not the patient. This includes the spouse.
  • The police need a warrant, a court order, or a statutory provision. "Assisting with an investigation" is not one of the gateways.

Requests from other treating providers are different: section 15 of the National Health Act allows disclosure to another provider where it is necessary for a legitimate purpose within the ordinary course of duties and in the interests of the user. Continuity of care is provided for. General curiosity is not.

When the patient asks for their own record, that is an access request. Section 23 of POPIA gives the right, but it sets no fixed deadline of its own — it says a reasonable time. The 30 days everyone quotes comes from PAIA, which is the machinery for actually getting a copy of a record out of a private body: section 56 requires a decision within 30 days, extendable once under section 57 where the volume genuinely warrants it. It is a deadline for deciding, not for delivering. See how to respond to an access request, and note that a record often contains information about third parties, which has to be handled before the file goes out.

When something goes wrong

Section 22 requires notification to the Information Regulator, and to the affected data subjects, where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. There is no threshold exempting small practices and no exception for embarrassment.

A stolen laptop, a PMS account still active for a departed employee, an email of results to the wrong patient, a lost appointment book. Health information makes each of these more serious, not less. Decide now who makes the call and where the Regulator's form lives, because the middle of the incident is a poor time to research it. See what to do after a data breach.

Where to start

  • Has every person who can see a patient record signed a confidentiality undertaking, including locums, students and cleaners with keys?
  • Is your Information Officer registered with the Regulator?
  • Do you have written operator contracts with your PMS, billing and backup providers?
  • Do you know whether any of that data sits outside South Africa?
  • Is there a retention rule written down, and does anything actually get destroyed?
  • Who removes departed staff from the clinical WhatsApp group and the PMS?
  • Do you ask for written authority before releasing a record to an attorney or an insurer?
  • Does your practice hold staff health records, and have you looked at the March 2026 regulations in that capacity?
  • Are your paper records in a room that locks, as section 17 of the National Health Act requires?

POPIA Ready generates a privacy policy, a PAIA manual and five other documents customised to your practice, free to preview. The free checklist will show you what else is missing.

General guidance on South African law as at September 2026, not legal advice. Healthcare sits across POPIA, the National Health Act and the HPCSA's ethical rules, and questions about disclosure without consent, or about a specific patient record, deserve a professional opinion and a word with your indemnity provider.

Get Compliant Today

Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.

Generate Documents - Free to Preview

Continue Reading

Your WhatsApp Messages Are Records You Must Keep for Five Years

Read article →

Reading an Employee's Email Can Be a Criminal Offence

Read article →

Adding a Customer to a WhatsApp Group Shows Everyone Their Number

Read article →