Wendy Tembedza | Partner | Webber Wentzel | mail me |
Health data is one of the most valuable assets in modern healthcare. The Protection of Personal Information Act (POPIA) places strict requirements on its use. POPIA compliance for health data is therefore critical for all healthcare stakeholders.
Healthcare sector stakeholders understand the value of data in ensuring appropriate patient treatment.
Protecting patients in modern healthcare
Technologies such as artificial intelligence allow practitioners to derive insights from the data they hold. As a result, managing data in a manner that ensures POPIA compliance for health data must remain front of mind in all processing activities.
This obligation becomes particularly acute given the volume of data that evolving technologies allow healthcare institutions to collect and use. When these datasets include special personal information, the obligation to process such information lawfully becomes even more significant. POPIA regulates the processing of special personal information, including health and sex life information, more closely than other forms of personal information.
The implications of POPIA’s strict regulation mean that any responsible party considering the collection of such data must conduct a pre-collection assessment. This assessment ensures that intended processing activities will be lawful under POPIA. Conducting this assessment is integral to establishing a lawful basis for processing from the outset. All handling of health and sex life information must remain lawful throughout its lifecycle, from collection and use to deletion and destruction.
Legal and operational considerations
POPIA prohibits processing health and sex life information unless a justification exists. One general exception occurs when the data subject provides consent. Consent must be informed, voluntary and specific. It cannot be overly generalised. Organisations must ensure that any reliance on consent meets these requirements. POPIA compliance for health data becomes particularly important when data is used for purposes differing from the original reason for collection.
POPIA provides additional exemptions for processing special personal information. Health information may be processed by medical professionals, healthcare institutions, or social services while providing healthcare. Certain exemptions also apply to insurance companies, medical schemes, administrators, and managed healthcare organisations under specific circumstances.
Even when a responsible party falls within an exemption, POPIA’s eight conditions for lawful processing still apply. Role players must ensure that all processing activities remain lawful and consistent with POPIA’s standards of care. POPIA compliance for health data requires ongoing diligence, even within exempt categories.
Automated decision-making using health and sex life information must also comply with POPIA. A data subject cannot face decisions with legal consequences or substantial effects based solely on automated processes, except in limited instances. POPIA specifically identifies health as an example of data that could lead to significant legal or personal consequences. This underscores the importance of assessing all healthcare-related processing activities, especially when relying on technology for diagnostics or treatment decisions.
Enhancing transparency for data subjects
The Information Regulator has emphasised the need to regulate health and sex life information through recently published Draft Regulations. These Draft Regulations aim to assist responsible parties in implementing POPIA correctly and to enhance transparency for data subjects regarding their information.
The Draft Regulations cover insurance companies, medical schemes, administrators, managed healthcare organisations and pension funds. This regulatory approach underscores the importance of ensuring that all processing activities are undertaken with care. Routine assessment of processing activities is essential for ongoing POPIA compliance for health data.
As healthcare-related technologies continue to advance, new and innovative ways of using patient data emerge. Organisations must ensure that their use of such technologies complies with POPIA’s requirements. Adherence to the Act ensures data is used responsibly while safeguarding patient trust. POPIA compliance for health data is, therefore, a cornerstone of modern healthcare operations.
Healthcare stakeholders must embed these principles into everyday practice. Only by maintaining rigorous compliance with POPIA can organisations ensure lawful processing, protect patient privacy and support innovation in patient care.




























