Privacy & medical data
Your information deserves careful protection.
This system is designed to support the practice’s obligations under POPIA and applicable healthcare confidentiality requirements.
What information is collected and why
The practice collects only information reasonably needed to administer appointments and payments, provide healthcare, conduct telehealth consultations, maintain appropriate clinical records and meet legal or professional obligations. Payment references are kept separate from clinical information where practical. Complete card numbers, CVV numbers, banking credentials and PayFast passwords are never stored by this website.
Health information, recording and AI assistance
Health information is treated as sensitive clinical information. An online consultation is not recorded unless separate recording consent has been captured. AI-assisted transcription or note preparation requires separate consent. AI output assists the practitioner and is not an independent diagnosis. Any AI draft retained as part of the clinical record must first be reviewed or approved by an authorised healthcare practitioner.
Your choices
You may ask for recording to stop at any time. Withdrawing recording or AI-processing consent should not prevent appropriate care where the consultation can reasonably continue without those technologies. Additional guardian consent and age-appropriate participation may apply for younger patients, subject to a practitioner-approved policy.
Who may access information
Access is limited by role. Appointment administrators may manage contact details, appointment status, payment status and consultation logistics, but do not automatically receive access to recordings, transcripts, detailed screening responses, clinical notes or AI summaries. Technical administration does not automatically provide clinical access.
Service providers and cross-border processing
Approved providers may include appointment, telehealth, hosting, database, email or SMS, secure storage and AI-processing services. Before live use, the practice will document each provider’s purpose, the minimum information transmitted, known storage location, retention settings, agreement status and any lawful basis required for cross-border processing.
Protection, retention and patient requests
Sensitive records are protected through authenticated access, server-side permissions, private storage, access logging and configurable retention controls. Different record categories may have different retention periods. A request to correct, export, restrict or delete information will be assessed against applicable healthcare and legal record-retention duties; required clinical records are not automatically deleted.
Privacy enquiries
The practice’s Responsible Party and Information Officer details must be formally approved before production activation. Until then, privacy enquiries may be directed to info@drsebastiao.co.za or +27 76 600 4251.
