Compliance

Compliance you can rely on

We build privacy and compliance into the platform by design — so your organisation stays protected as regulations evolve.

Frameworks

Aligned to the standards that matter

POPIA (South Africa)

Aligned with the Protection of Personal Information Act — lawful processing, purpose limitation and data subject rights for SA healthcare data.

GDPR (EU)

Where applicable, aligned with the General Data Protection Regulation including data subject rights, DPA support and international transfer safeguards.

HIPAA-style controls

Administrative, physical and technical safeguards consistent with the Health Insurance Portability and Accountability Act.

Sector regulations

Configurable workflows to support medical scheme, pharmacy and laboratory regulations across the countries we serve.

How We Comply

Privacy built into the platform

Consent & transparency

Granular consent capture and a clear privacy notice explain exactly what we process, why and how.

Data subject rights

Access, correction, portability, erasure and restriction requests handled with defined SLAs.

Data processing agreements

Standard DPAs covering processing roles, purposes, security and sub-processor disclosure.

Compliance FAQ

Frequently asked questions

DocuHealth is designed to be POPIA-compliant in how it processes, secures and transfers personal health information, including lawful processing grounds, purpose limitation, data subject rights and secure retention.

Need compliance documentation?

Request our security documentation, DPA and compliance materials.

14-day free trial · No credit card required · Cancel anytime