Back to Journal
South Africa Guides

South Africa SLP Documentation: HPCSA & POPIA

A practical, source-linked guide to HPCSA recordkeeping and POPIA considerations for South African speech therapy practices.

Adham Yasser
Adham YasserAuthor
Published
Calculating...Reading Time

Regional guide: South Africa

This article discusses South African recordkeeping and privacy context. It is educational, not legal advice, and it cannot determine whether a particular clinic, workflow, or software configuration is compliant. Check the current official guidance and obtain professional advice for your circumstances.

A South African speech therapy practice has to think about clinical records and personal-information processing together. HPCSA guidance shapes professional recordkeeping expectations. POPIA governs how personal information is processed, protected, shared, and retained.

The practical question is not whether a clinic owns a secure app. It is whether the entire workflow—from intake and consent to session notes, recordings, access, exports, and deletion—has a clear purpose and accountable owner.

Start with the current HPCSA ethics guidance, including Booklet 9, and the official text of the Protection of Personal Information Act. Vendor copy should never replace those sources.

What useful patient records need to support

HPCSA Booklet 9 describes patient records as part of safe, continuous professional care. Exact content depends on the encounter and setting, but a defensible record should make the clinical story understandable, attributable, and retrievable.

Use the following as an audit checklist rather than a claim that every field or SOAP format is legally required for every session:

Patient identity and relevant demographic information
The reason for the encounter or referral
Relevant history, assessment findings, and clinical interpretation
The treatment plan and measurable goals
Session-level observations, response, cueing, and progress where relevant
The treating practitioner and date of each entry
Relevant reports, referrals, and clinical correspondence
Consent, notices, or authorizations required for the actual workflow
A better review question

Could another qualified clinician understand what was addressed, how the patient responded, what the data means, and what should happen next—without asking the original therapist to rebuild the session from memory?

Retention is a policy, not a single number

HPCSA recordkeeping guidance describes general retention periods and important exceptions. Different rules can apply to minors, records involved in disputes, occupational-health records, and other circumstances. That makes “keep everything for six years” an unsafe policy shortcut.

Build a documented retention schedule that identifies the record category, the event that starts the retention period, applicable exceptions, who can authorize disposal, and how deletion is recorded. Verify each period against the current Booklet 9 and any other law, contract, payer rule, or professional requirement that applies to the clinic.

What POPIA changes about the workflow

POPIA places health information and children's information within specially protected categories. It also distinguishes between a responsible party, which determines why and how information is processed, and an operator that processes information for that responsible party.

A clinic will often be the responsible party for its patient workflow, while software, hosting, transcription, or communication providers may act as operators in defined contexts. Those roles and obligations depend on the actual arrangement; a product label cannot settle them.

Consent may be relevant, especially for recordings and children's information, but it is not accurate to treat one checkbox as the only possible lawful basis for all healthcare processing. Map each purpose and confirm the applicable authorization with a qualified adviser.

Purpose and authority

Document why each category of information is collected, what authorizes the processing, what the patient or caregiver is told, and how they can exercise applicable rights.

Appropriate safeguards

Use risk-appropriate technical and organizational controls: restricted access, authentication, encryption, auditability, staff procedures, vendor review, backup, and incident response. POPIA does not certify a clinic because one encryption algorithm appears on a feature page.

Operator and vendor terms

Understand where data goes, which subprocessors receive it, how long each copy remains, how an operator reports an incident, and what happens to information when the relationship ends.

Retention and deletion

Keep the finalized clinical record for the required period while applying a separate, purpose-based lifecycle to temporary audio, working transcripts, exports, and backups.

Recordings and AI need their own data map

An audio-assisted documentation workflow introduces more than a final SOAP note. It may create a recording, temporary processing copy, transcript, structured observations, model output, clinician edits, and an exported record. Each artifact needs a defined purpose, access rule, retention period, and deletion path.

Ask whether clinicians can review the evidence behind an extracted metric and correct the draft before finalization. Also ask exactly when raw audio is deleted. For RelyCare, the approved description is specific: clinicians review and approve the final record, and raw session audio is deleted after finalization—not immediately after transcription.

Do not rely on a compliance badge

A vendor can provide useful controls and contractual commitments, but the clinic still has to configure access, establish an appropriate processing basis, train staff, follow its retention policy, and review the output used in the clinical record.

The WhatsApp question is about governance

WhatsApp is common in South African healthcare, but familiarity does not answer whether a particular use is appropriate. A clinic should define what may be communicated, which account and devices may be used, who retains access, how the communication enters the patient record when necessary, and how caregiver notices or permissions are handled.

Avoid blanket statements that WhatsApp is compliant or non-compliant. Evaluate the specific workflow, data, settings, contracts, access controls, and retention behavior.

Prepare for security compromises before one occurs

POPIA section 22 addresses notification when personal information has been accessed or acquired by an unauthorized person. The Information Regulator's current guidance says responsible parties should notify the Regulator and affected data subjects as soon as reasonably possible, subject to the Act's process.

Clinics should know who investigates, who contacts an operator, how evidence is preserved, who decides whether notification is required, and which current Regulator channel is used. Do not import a GDPR “72-hour rule” into POPIA copy.

Questions to answer before recording a real session

A useful vendor review follows the data rather than stopping at a security page. Ask for answers in contracts, privacy documents, product settings, and a live workflow demonstration. The clinic should be able to reconcile those answers with its own notices, policies, and professional duties.

What exactly is collected?

List audio, transcript text, speaker labels, structured observations, generated notes, patient identifiers, support logs, analytics, exports, and backups. “Session data” is too broad to support a useful risk review.

Where does each artifact go?

Identify hosting regions, AI or transcription providers, support access, subprocessors, and cross-border transfers. The answer may differ for raw audio, the finalized note, and product telemetry.

How is the information used?

Separate delivering the clinic service from product analytics, troubleshooting, model improvement, and marketing. Confirm whether a provider uses clinical content for training and whether contractual restrictions match the clinic's expectation.

What can the clinic control?

Review user roles, access removal, exports, corrections, deletion requests, recording settings, audit information, and retention controls. Ask which actions require vendor support and what happens when the contract ends.

What happens when processing fails?

Test interrupted uploads, poor audio, missing speakers, incorrect metrics, duplicate sessions, and a failed deletion job. A safe workflow needs visible failure states and a way for the clinician to continue without treating incomplete output as a final record.

How are incidents handled?

Confirm how quickly an operator informs the clinic, what facts it provides, who preserves evidence, how the clinic reaches the vendor, and how contractual responsibilities align with the clinic's own section 22 process.

Assign responsibilities inside the clinic

Technology does not decide who is allowed to record, who reviews an AI draft, or who handles a caregiver request. Name those owners. A practice lead may approve the documentation standard; an information officer may oversee privacy governance; clinicians remain responsible for the content they approve; and administrators should receive only the access their work requires.

Training should cover more than which button to press. Staff need to know when recording is appropriate, how to respond when permission or authority is unclear, how to identify unsupported AI content, where the finalized record belongs, and how to report a suspected incident. Repeat the review when the product, vendor list, clinic workflow, or official guidance changes.

Your session ended. The documentation should not follow you home.

RelyCare turns session audio into a review-ready SOAP note draft with target details and transcript-linked evidence. Your clinician reviews and approves the final record.

A practical clinic review

Can each clinical entry be attributed to the practitioner who reviewed it?
Can staff see only the patient information their role requires?
Can the clinic explain every system that receives audio, transcripts, or notes?
Are temporary artifacts deleted on a documented lifecycle?
Does the clinic have current operator terms and a subprocessor list?
Can a clinician inspect and correct AI-generated content before approval?
Does the retention schedule cover minors and relevant exceptions?
Is there a tested security-compromise response process?

Official sources to review

The bottom line

Good documentation and responsible information handling are not separate software features. They are connected clinic processes. A useful system makes the clinical record easier to review while giving the clinic clear control over access, retention, correction, export, and deletion.

The right standard is not “the vendor says compliant.” It is “our clinic can explain the workflow, point to the applicable authority, and show how people, contracts, and technical controls work together.”

Adham Yasser

Adham Yasser

Founder & CEO, RelyCare

Adham is the founder of RelyCare, an AI documentation platform built for speech-language pathology clinics. He writes from a product-builder's perspective about clinical workflows, documentation technology, and the evidence clinics should demand before adopting AI. Clinical and legal decisions should be checked against the primary sources linked in each guide.

Connect on LinkedIn
Apply for a Pilot

Founder-led RelyCare pilot

Test RelyCare against your real documentation workflow.

Bring the note formats, review standards, and privacy requirements your clinic already uses. We will agree on what the pilot needs to prove before clinical use.