Before you rely on this
This page is drafted for PracticeScan as it is actually built, but it is not legal advice. Have it reviewed by an admitted attorney before you rely on it commercially, and complete every field marked To be completed below. An incomplete notice does not satisfy section 18 of POPIA.
1. Who is responsible for what
POPIA splits responsibility between the party who decides why information is processed and the party who processes it on their behalf. That split matters here, because it determines who a patient should approach.
- The practice is the responsible party
- Your treating practice decides what clinical information to record about you, why, and for how long. It is accountable to you for those decisions and for the accuracy of your record.
- PracticeScan is the operator
- We provide the software that stores and displays the record. We process patient information only on the documented instruction of the practice, and we do not use it for our own purposes. Section 7 below sets out the terms that govern this.
- Practice staff are our customers
- For the accounts of practitioners and reception staff, and for billing, PracticeScan is the responsible party in its own right.
If you are a patient and you want your record corrected or explained, contact your practice first. They hold the clinical relationship and can act immediately. You can also contact us directly using section 11.
2. Privacy notice
This is the notification required by section 18 of the Protection of Personal Information Act 4 of 2013.
2.1 What we process about patients
- Identity and demographics. Name, South African ID number, date of birth and gender. The date of birth and gender are derived from the ID number where one is supplied.
- Contact details. Phone number, email address and residential address.
- Medical scheme details. Scheme, plan or option, membership number, main member and dependant code.
- Next of kin. Name, relationship, contact numbers, email and address.
- Clinical information. Allergies and adverse reactions, chronic conditions, current and chronic medication, medical history, discipline specific assessments and notes, and prescriptions.
- Appointments and billing. Dates, times, reason for the visit, treating practitioner, attendance status, fees charged and amounts paid.
- Consent records. Treatment consent, POPIA consent, record sharing consent and biometric consent, including who gave it and when.
2.2 What we process about practice staff
Email address, display name, assigned role, practice type, the practice you belong to, and for prescribers your name and HPCSA registration number. We also record authentication events and an audit trail of the patient records you open and change.
2.3 Why we process it
- To identify a patient correctly and to avoid treating the wrong person.
- To make a patient's clinical picture available to the practitioners treating them.
- To schedule, confirm, reschedule and cancel appointments.
- To produce prescriptions that meet South African legal requirements.
- To record fees and payments for a consultation.
- To keep an audit trail, which POPIA and the National Health Act both effectively require of a system holding health records.
- To operate, secure, support and improve the service.
2.4 On what legal basis
Health information is processed under section 32 of POPIA, which permits medical professionals and healthcare institutions to process a patient's health information where it is necessary for the proper treatment and care of that patient. We also rely on your consent where we record it, on the practice's legitimate interests in running a lawful practice, and on legal obligations under the National Health Act 61 of 2003 and the guidance of the Health Professions Council of South Africa.
2.5 Whether supplying it is voluntary
Supplying your information is voluntary, but it is not optional in practice. A practice cannot lawfully or safely treat you without an identifiable record, an allergy history and a medication history. If you decline to supply them, your practitioner may be unable to treat you.
2.6 Who else sees it
- Your treating practice, limited by discipline. A practice sees the shared record, which covers demographics, medical scheme, next of kin, allergies, chronic conditions, medication and consent, plus the clinical records of its own discipline. A dentist does not see a psychologist's notes. This is enforced on the server by database rules and access claims, not merely hidden in the interface.
- MediScan, our hospital and clinic product, which shares the same patient record. A patient treated in both settings has one record rather than two.
- Our operators, listed in section 2.7.
- Nobody else, unless you consent, or a court order, subpoena or statute compels disclosure. We do not sell personal information, and we do not use patient information for advertising or profiling.
2.7 Our operators
| Operator | What they do | Where |
|---|---|---|
| Google Cloud Platform and Firebase (Google LLC) | Authentication, database, server functions and website hosting | Region to be confirmed |
| Email provider to be named | Delivers appointment reminders, cancellation notices and patient self-completion links | To be completed |
2.8 Transfers outside South Africa
Our infrastructure runs on Google Cloud Platform, which may store or process information outside South Africa. Section 72 of POPIA permits this where the recipient is subject to a law, binding rules or an agreement that provides an adequate level of protection. We rely on Google's data processing terms and its standard contractual clauses for that purpose. Confirm the deployment region and attach the current Google terms before publishing.
3. Health and biometric information
POPIA treats information about your health and your biometrics as special personal information under section 26, and prohibits processing it unless a specific exception applies.
3.1 Health information
We process it under the section 32 exception described in 2.4, on the instruction of the medical professional treating you, and subject to their duty of confidentiality under section 14 of the National Health Act.
3.2 Biometric information
Where your practice uses a fingerprint scanner to confirm your identity, the fingerprint is captured and stored by MediScan, not by PracticeScan, and practice users cannot read the biometric records through this product. A fingerprint is used only to confirm that you are the person the record belongs to. It is never used for any other purpose, and biometric enrolment requires your specific consent, which is recorded.
3.3 Children
Information about a child is processed on the authorisation of a competent person, usually a parent or guardian, as required by section 35 of POPIA. Consent records capture who gave consent and their relationship to the patient.
4. How long we keep records
Health records are not deleted when a patient asks, because a practitioner is obliged to retain them. Retention is set by the practice as responsible party, guided by the Health Professions Council of South Africa and the National Health Act.
- Clinical records
- Retained for the period the practice is required to keep them, which under HPCSA guidance is generally at least six years from the last consultation, and longer for minors, for records of mental health patients and where treatment involved occupational exposure.
- Appointment and billing records
- Retained for the period required by tax and company law, which is generally five years.
- Audit logs
- Retained so that access to a health record can be reconstructed for as long as the underlying record exists.
- Patient self-completion links
- The link expires four hours after it is issued and requires a separate six digit PIN given to the patient by reception.
- Practice user accounts
- Deactivated accounts are disabled and their sessions revoked immediately. The profile is retained while it is needed to interpret the audit trail.
When a retention period ends, records are deleted or de-identified in line with section 14 of POPIA.
5. Your rights
Under POPIA you may:
- Ask what we hold about you and get a copy, under section 23. We must confirm free of charge whether we hold your information. A copy may carry a prescribed fee.
- Ask for correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained, under section 24. Where a clinical entry cannot be deleted because it must be retained, a correction is recorded alongside it rather than overwriting the original, so the clinical history stays intact and auditable.
- Object to processing on reasonable grounds, under section 11(3).
- Withdraw consent at any time where processing relies on it, without affecting processing that already happened.
- Not be subject to a decision based solely on automated processing. PracticeScan makes no automated clinical decisions. Every clinical judgement in this system is recorded by a person.
- Complain to the Information Regulator, as set out in section 11.
We respond to a request within a reasonable time and no later than the period the Regulator prescribes. We will ask you to verify your identity first, because releasing a health record to the wrong person is itself a breach.
6. Security
Section 19 of POPIA requires appropriate, reasonable technical and organisational measures. These are the measures actually in place.
- Access is enforced on the server. Database rules and signed access claims decide what each account can read. The interface filters as well, but the interface is not the control.
- Discipline isolation. A practice can read the shared record plus its own discipline. Requests for another discipline's records are refused by the database, not merely hidden.
- Hospital only data is out of reach. Practice accounts cannot read fingerprints, biometric credentials, encounters, devices, facilities or uploads.
- Sessions are short. Sign in lasts only for the browser session, with no long lived token left on a shared front desk machine, and an idle session is signed out automatically after 20 minutes across all open tabs.
- Nothing clinical is cached on the device. Offline database persistence is deliberately disabled, so patient information is not written to browser storage.
- Transport and browser hardening. HTTPS with HSTS, a strict content security policy, no third party script hosts, frame and content type protections.
- Audit trail. Patient list views, record views, record saves and automatic sign outs are logged with the account, the practice type and the patient involved.
- Tamper evident prescriptions. Each prescription carries a code derived from its contents, so any later change to the patient, date, prescriber or medication produces a different code and is detectable.
6.1 If something goes wrong
Where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovery, as section 22 requires. If you believe an account has been compromised, tell us immediately using section 11.
7. Operator terms for practices
Sections 20 and 21 of POPIA require a written contract between a responsible party and its operator. These terms form that contract between your practice and PracticeScan, and apply for as long as we process patient information on your behalf.
- Instruction. We process patient information only on your documented instruction, which includes the ordinary operation of the service, and never for our own purposes.
- Confidentiality. We treat all patient information as confidential and do not disclose it unless the law requires it. Where the law compels disclosure we will tell you unless we are prohibited from doing so.
- Security. We maintain the measures in section 6 and will not weaken them materially without telling you.
- Sub-operators. We use the operators listed in 2.7. We will give you reasonable notice before adding another, and we remain responsible for their performance.
- Breach notification. We notify you without undue delay after becoming aware of a compromise, with enough detail for you to meet your own obligations.
- Assistance. We assist you in responding to data subject requests and, where relevant, to the Information Regulator.
- Return and deletion. On termination you may export your practice's records. After the export window in section 8.10 we delete or de-identify them, except where we must retain them by law.
- Audit. On reasonable written notice, and no more than once a year unless a compromise has occurred, we will provide the information reasonably necessary to demonstrate compliance with these terms.
8. Terms of service
These terms govern a practice's use of PracticeScan. By creating an account or using the service, the practice and each of its users accept them.
8.1 Who we are
Legal entity name, company registration number, registered address and the name of the responsible director to be completed. This disclosure is required by section 43 of the Electronic Communications and Transactions Act 25 of 2002.
8.2 Licence
We grant your practice a non-exclusive, non-transferable right to use PracticeScan for the number of practitioners you have subscribed for, during your subscription, for the purpose of running your practice. We retain all intellectual property in the software.
8.3 Accounts
Accounts are issued to named individuals and must not be shared. The practice is responsible for its users' actions, for removing access when someone leaves, and for telling us promptly if credentials are compromised. Because the audit trail attributes every record access to an account, a shared login destroys the evidentiary value of that trail and may put the practice in breach of its own obligations.
8.4 Fees
PracticeScan is sold per practitioner per month.
| Tier | Practice size | Per practitioner per month |
|---|---|---|
| Solo | 1 practitioner | R499 |
| Practice | 2 to 5 practitioners | R429 |
| Group | 6 or more practitioners | R369 |
Onboarding and training is R2,500 once off per practice. A fingerprint scanner is R800 to R1,500 per device once off, and is optional. Annual billing is charged at ten months. Prices are quoted in South African Rand. Confirm whether prices include or exclude VAT, and state the payment terms, billing cycle, accepted payment methods and the notice period for a price change.
8.5 Acceptable use
You may not use PracticeScan to store information you have no lawful basis to hold, access a record you have no treating relationship with, attempt to defeat the discipline isolation or any other access control, probe or load test the service without written permission, resell or sublicense access, or reverse engineer the software except to the extent the law permits.
8.6 Clinical responsibility
PracticeScan is a record keeping and scheduling tool. It does not practise medicine, does not diagnose, and does not check prescriptions for interactions, contraindications or dose errors. Every clinical decision, and the accuracy and legality of every prescription, remains the responsibility of the registered practitioner who makes it. Do not rely on the system to catch a clinical mistake.
8.7 Availability
We aim for high availability but do not guarantee uninterrupted service, and we may take the service down for maintenance. If you commit to a service level for Group tier customers, state the target, the measurement window and the remedy here.
8.8 Warranties and liability
The service is provided as it stands. To the fullest extent the law allows, we exclude implied warranties, and we are not liable for indirect or consequential loss, loss of profit, or loss of data to the extent it results from your failure to export or maintain your own records. Nothing in these terms excludes liability that cannot lawfully be excluded, including under the Consumer Protection Act 68 of 2008 where it applies. Insert the liability cap, typically the fees paid in the preceding twelve months, once your attorney has confirmed it.
8.9 Indemnity
You indemnify us against claims arising from your use of the service in breach of these terms or of any law, including claims by a patient arising from information you recorded.
8.10 Term and termination
Either party may terminate on notice period to be completed. We may suspend access immediately for non-payment or for a serious breach of section 8.5. On termination you have export window to be completed to export your records, after which section 7.7 applies. Your obligation to retain health records under HPCSA guidance survives termination, so export before the window closes.
8.11 Changes
We may change these terms. Material changes will be notified to the practice's registered email address before they take effect, and the date at the top of this page will change.
8.12 Governing law
These terms are governed by the law of the Republic of South Africa, and the parties submit to the jurisdiction of the South African courts. Specify the dispute resolution route, including whether arbitration applies and which forum.
10. PAIA and access requests
The Promotion of Access to Information Act 2 of 2000 gives you a right of access to records we hold. Our PAIA manual sets out the records we hold, how to request them, the prescribed forms and the applicable fees.
Publish the PAIA manual and link it here. A private body must compile one and make it available. Include the Information Officer's details, the categories of records held, and the request procedure.
A request for a patient's own health record should normally go to the treating practice, which holds the clinical relationship. Section 14 of the National Health Act also governs access to health records and, in some circumstances, requires that a record be given to you through a healthcare provider who can explain it.
11. Contact and complaints
11.1 Information Officer
Every private body must register an Information Officer with the Information Regulator. Name, email address, telephone number and postal address of the Information Officer to be completed, and registration with the Regulator confirmed.
11.2 Reaching us
Support email, privacy email, telephone number and physical address to be completed.
11.3 The Information Regulator
If you are not satisfied with how we have handled your information or your request, you may complain to the Information Regulator of South Africa.
Information Regulator (South Africa)JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
PO Box 31533, Braamfontein, Johannesburg, 2017
Complaints: complaints.IR@justice.gov.za
General enquiries: enquiries@inforegulator.org.za
You may also complain to the Health Professions Council of South Africa about the conduct of a registered practitioner, or to the practice itself.