POPIA · SECTION 27–32 COMPLIANCE

How HISA Safeguards Health Information

Every safeguard below is already implemented across HISA Health platforms. This page sets out, in plain terms, the technical and operational controls we follow to ensure health information is processed lawfully, securely, and only for its intended purpose.

Phase 2

Data Minimisation & Anonymisation

Minimisation & Purpose Limitation

We collect only the minimum health parameters required for each specific service. Clinical data is never repurposed for commercial or AI-training activities without explicit opt-in consent from the data subject.

Anonymisation & De-identification

Where analytical tools are built, health datasets are thoroughly de-identified to recognised standards so that individuals cannot be re-identified, protecting patient privacy in all secondary use cases.

Phase 3

Technical & Operational Safeguards

Security Safeguards (AES-256 / Encryption)

All health data is encrypted both at rest (AES-256) and in transit (TLS 1.3), ensuring that protected information remains unreadable to unauthorised parties at every stage.

Role-Based Access Controls (RBAC) & MFA

Access to health records is restricted on a strict need-to-know basis through role-based access control, and Multi-Factor Authentication is enforced for every system handling personal information.

Immutable Audit Logging

Automated, tamper-evident logs track every instance of who accessed, viewed, modified, or deleted health records — providing a complete chain of custody for medico-legal defensibility.

Operator Agreements (Section 20/21 Contracts)

Written agreements are executed with all third-party vendors — cloud providers, software tools, and analytics platforms — legally binding them to protect health data in accordance with POPIA Sections 20 and 21.

Phase 4

Data Transfers, Storage & Incident Management

Cross-Border Transfer Controls (Section 72)

Health data stored on foreign cloud servers (e.g., AWS, Azure) meets POPIA’s cross-border requirements through binding corporate rules, equivalent regional protection laws, or formal data transfer agreements.

Incident Response & Breach Notification Plan

A formal protocol is established to notify both the Information Regulator and affected data subjects immediately upon any suspected or actual data breach, in line with POPIA Section 22.

Retention & Secure Destruction Schedule

Data retention policies are aligned with statutory healthcare retention frameworks (e.g., HPCSA guidelines), followed by certified, irreversible deletion and destruction of records once retention periods expire.

For the full legal analysis underpinning these safeguards, see our Lawful Basis Memo on the Legal page.

View Legal Documents →
base44
Edit with Base44