Digital Patient Records in South African EMS

The patient report form is the most legally consequential document your organisation produces. It is simultaneously a clinical record, a billing instrument, a legal evidence document, and a data subject record under POPIA. This guide covers what the law requires of it — and why paper can no longer carry that weight.

Legislation covered: POPIA · National Health Act · Health Professions Act · EMS Regulations 2022
Audience: EMS operators, clinical leads, and compliance officers

POPIA obligations for EMS patient data

POPIA came into full effect on 1 July 2021. In March 2026, the Information Regulator published new Regulations relating to the Processing of Data Subjects' Health Information by Certain Responsible Parties — tightening the compliance environment further. For EMS organisations, POPIA is not a peripheral IT compliance matter. It governs every patient record created, every PRF stored, and every disclosure of patient information to a medical aid or receiving facility.

Health information as Special Personal Information

Section 26 of POPIA prohibits the processing of personal information concerning a person's health. This is not the general rule for personal data — it is a heightened prohibition that applies specifically to health information because of its sensitive nature and the potential for harm if misused.

The authorisation for EMS providers is found in Section 32, which permits healthcare providers registered under the Health Professions Act to process health information for the care and treatment of the patient. This authorisation is not a blanket exemption. It still requires compliance with all eight conditions for lawful processing set out in Chapter 3 of POPIA — including purpose limitation, data minimisation, security safeguards, and data subject rights.

Section 26 classifies health information as "special personal information," meaning it is generally prohibited from processing unless one of the narrow exceptions in sections 27–33 applies.

POPIA, No. 4 of 2013 — Captain Compliance Analysis, March 2026

The eight conditions for lawful processing

Even where the Section 32 authorisation applies, every EMS operator must comply with POPIA's eight processing conditions. These are not aspirational standards — they are legal requirements that apply to every patient record your organisation holds.

ConditionWhat it means for EMS records
AccountabilityYour organisation, as the Responsible Party, is accountable for compliance with all processing conditions — including for records held by third-party software providers.
Processing limitationCollect only information necessary for the specific purpose — clinical care, billing, or regulatory compliance. Not for general purposes.
Purpose specificationThe purpose for collecting the data must be specific, explicitly defined, and lawful. Data may not be retained beyond the period necessary to achieve that purpose.
Further processing limitationPatient records may not be processed for purposes incompatible with the original purpose. Sharing PRFs with third parties requires lawful grounds.
Information qualityRecords must be accurate, complete, and kept up to date. Incomplete or inaccurate PRFs breach this condition.
OpennessPatients must be informed that their data is being collected, for what purpose, and by whom — at the time of collection where possible.
Security safeguardsAppropriate technical and organisational measures must be in place to prevent unauthorised access, loss, or destruction of records.
Data subject participationPatients have rights of access, correction, and deletion. Your organisation must have a process for responding to these requests.

Breach notification obligations

POPIA imposes a mandatory breach notification obligation. Where there are reasonable grounds to believe that patient data has been accessed or acquired by an unauthorised person, the Responsible Party must notify both the Information Regulator and the affected data subjects as soon as reasonably possible.

For EMS operators, a breach can occur in a number of ways that are particularly relevant to the paper-versus-digital debate: a paper PRF left in an ambulance that is stolen, patient records accessed by an unintended recipient, a lost tablet containing unencrypted records, or unauthorised access to a shared digital folder. Each of these scenarios triggers the notification obligation.

The Information Regulator is actively enforcing POPIA. The Regulator issued its first enforcement notice in February 2024 and has signalled intent to escalate enforcement activity. Penalties reach R10 million in fines, up to 10 years imprisonment, or both. The March 2026 health information regulations signal that the healthcare sector is a focus area for enforcement.

Third-party data processors

If your organisation uses a third-party software provider to store or process patient records — whether a cloud-based system, a billing platform, or a records management service — you are the Responsible Party and you remain accountable for that provider's compliance with POPIA.

Before using any third-party service for patient data, a written Data Processing Addendum (DPA) or Operator Agreement must be in place. This contractually obligates the provider to protect the data in accordance with POPIA's requirements. Using a software provider without this agreement in place is itself a POPIA compliance failure.

Cross-border data transfers: Where patient records are stored on servers outside South Africa, the transfer is subject to Section 72 of POPIA, which requires that the recipient country or organisation provides an adequate level of protection. Cloud providers hosting data outside South Africa must be assessed against this requirement. Ithaca's servers are housed inside the Republic.

National Health Act obligations on patient records

Section 13 — the duty to create and maintain records

Section 13 of the National Health Act imposes a direct obligation on the person in charge of a health establishment to ensure that a health record is created and maintained for every user of health services. For a private EMS operator, this means that a PRF must be completed for every patient contact — without exception. The obligation is not contingent on billing, on the outcome of the call, or on whether the patient was transported.

The person in charge of a health establishment must ensure that a health record containing such information as may be prescribed is created and maintained at that health establishment for every user of health services.

Section 13, National Health Act, No. 61 of 2003

Section 14 — confidentiality of patient information

Section 14 is unequivocal: all information concerning a user, including information relating to their health status, treatment, or stay in a health establishment, is confidential. The only grounds for disclosure without patient consent are a court order, or a situation where non-disclosure represents a serious threat to public health.

This provision directly affects how EMS operators may share PRFs with medical aids. The Medical Schemes Act permits schemes to access treatment records, but this is expressly subject to Sections 14 and 15 of the National Health Act. In practice, patient consent for disclosure to the medical aid should be documented — either on the PRF itself or through a standing consent mechanism — before clinical records are submitted as part of a claim.

All information concerning a user, including information relating to his or her health status, treatment or stay in a health establishment, is confidential. No person may disclose any information unless the user consents to that disclosure in writing, a court order or any law requires that disclosure, or non-disclosure of the information represents a serious threat to public health.

Section 14, National Health Act, No. 61 of 2003

Section 15 — permitted disclosures between health workers

Section 15 creates a narrowly defined exception to the confidentiality obligation. A health worker who has access to a patient's health records may disclose that information to another health care provider where such disclosure is necessary for any legitimate purpose within the ordinary course and scope of their duties, and where the access or disclosure is in the interests of the user.

This is the legal basis for patient handover documentation. When an EMS crew transfers a patient to a receiving facility and provides the PRF to the receiving clinical team, they are acting within Section 15. The key phrase is in the interests of the user — the disclosure must serve the patient's care, not administrative convenience.

The NHA and POPIA read together: Werksmans Attorneys, a leading South African regulatory law firm, notes that where the NHA and POPIA differ, whichever provides the patient with greater protection prevails. This means EMS operators cannot rely solely on Section 32 of POPIA to justify disclosure — the NHA's Section 14 confidentiality requirement applies concurrently and may be more restrictive in specific circumstances.

Retention requirements

The HPCSA's Guidelines on Patient Records note that under the Occupational Health and Safety Act, health records must be kept for a period of 20 years after treatment. For EMS providers, the NHA, POPIA's purpose limitation condition, and medico-legal best practice all inform the appropriate retention period. Records must be retained long enough to satisfy medico-legal and billing audit requirements, but not retained longer than necessary.

Retention is a POPIA compliance issue, not just a clinical one. Retaining patient records beyond the period necessary for the defined purpose without a lawful basis is a breach of POPIA's purpose specification condition. Your organisation must have a documented retention and secure disposal policy for patient records.

HPCSA standards for patient recordkeeping

The HPCSA's Booklet 9 — Guidelines on Patient Records — provides the professional standard against which every registered practitioner's documentation is measured. These guidelines apply to all HPCSA-registered emergency care practitioners and set out what a clinically and legally adequate patient record must contain, how it must be written, and how it must be managed.

What the HPCSA requires of patient records

The HPCSA's guidelines specify the minimum content and format requirements for a compliant patient record. These apply to every patient contact, irrespective of the outcome or complexity of the call:

Personal identifying particularsFull name, date of birth, identity number, and contact details of the patient.
Time, date, and location of the consultationScene address, dispatch time, arrival time, and departure time — all documented.
Assessment of the patient's conditionPrimary and secondary survey findings, vital signs with times, and AMPLE history.
Clinical management and treatmentAll interventions performed, medications administered with doses and routes, and the patient's response to treatment.
DiagnosisClinical impression and ICD-10 diagnostic code — mandatory for all claim submissions.
Referrals and handoverDetails of any referrals, the receiving facility, and the handover signature from the accepting clinician.
Informed consent or refusalWritten proof of informed consent where applicable, or a documented refusal of treatment or transport with the patient's signature.
Crew details and registration numbersNames and HPCSA registration numbers of all treating crew members.

Record quality standards

The HPCSA guidelines specify that records must be complete, concise, and consistent. They must be made contemporaneously — at the time of the consultation, not reconstructed after the fact. The Booklet 9 guidelines explicitly state that records must be kept in non-erasable ink, and that correction fluid must not be used on paper records. An altered or corrected paper record without a countersigned correction is legally suspect.

For digital records, these principles translate into requirements for tamper-evident audit trails: every entry must be time-stamped, attributed to the practitioner who made it, and any amendments must be logged with the original entry preserved. A digital record that can be silently altered after the fact provides no more legal protection than a paper one with correction fluid applied.

Records should be complete, but concise. Records should be consistent. Self-serving or disapproving comments should be avoided. A standardised format should be used containing in order the history, physical findings, investigations, diagnosis, treatment and outcome.

HPCSA Booklet 9 — Guidelines on Patient Records

Billing records must be kept separate

The HPCSA guidelines make a specific requirement that applies directly to EMS billing operations: billing records must be kept separate from patient care records. This has practical implications for how digital systems are structured — the clinical PRF and the invoice associated with a call must be distinct documents, with access controlled separately, to meet both HPCSA and POPIA requirements.

The HPCSA publishes Booklet 9 on its website. It also publishes Booklet 5 (Confidentiality: Protecting and Providing Information), which should be read alongside Booklet 9 for a complete picture of the professional obligations on registered practitioners around patient data. Both are available through the HPCSA website.

Patient Report Form requirements for medical aid claims

The Patient Report Form serves a dual function: it is the clinical record of care rendered, and it is the primary supporting document for a medical aid claim. A PRF that satisfies the HPCSA's clinical documentation standards but omits the fields required by GEMS or another scheme will still result in claim rejection. Both sets of requirements must be met simultaneously.

GEMS mandatory PRF fields

The GEMS 2026 EMS Provider Guide specifies the following as mandatory PRF content for claims consideration. Missing any of these fields is grounds for return or rejection:

Pre- or post-authorisation reference numberObtained from the EMED Contact Centre within 3 hours of the incident.
Membership number and patient demographicsName, surname, gender, age, date of birth or ID number, and dependant code.
Scene and delivery addressFull street address or facility name for both pick-up and drop-off locations.
Level of care and crew detailsBLS, ILS, or ALS designation, with HPCSA registration numbers for all crew.
Primary and secondary surveyFull clinical assessment findings documented, including vital signs with times.
Valid ICD-10 diagnostic codeIncluding external cause codes where applicable — no generic or invalid codes.
Treatment, medication, and fluid administrationAll interventions with doses, routes, and clinical notes.
Kilometres, vehicle registration, and call signDistance travelled and vehicle identification for tariff calculation.
Patient signature and handover signatureOr documented refusal — and hospital sticker or admission form from receiving facility.

Top 5 GEMS claim rejection codes

CodeReason for rejectionCommon cause
6258Claim is staleSubmitted more than 120 days after service date
6824PRF not attachedPRF missing from claim submission package
6656Invalid ICD-10 codeIncorrect, outdated, or missing diagnostic code
6830PRF insufficient informationIncomplete clinical assessment or missing required fields
6835Billing code not foundIncorrect or outdated tariff code used

Source: GEMS 2026 EMS Provider Guide

The 120-day submission rule

Claims must be submitted within 120 days of the service date. Claims received after this period are deemed stale and will not be paid, regardless of their clinical merit. If a claim is returned for correction, the corrected resubmission must be provided within 60 days of notification — failure to do so also renders the claim stale.

Pre- or post-authorisation does not guarantee payment. A reference number confirms the call was registered — it does not confirm the PRF will meet clinical criteria for payment. Every claim is independently assessed against medical necessity criteria at adjudication, and an authorised call with a clinically inadequate PRF will still be returned or rejected.

POPIA and consent on the PRF

The patient signature on the PRF serves a dual function: it documents consent to treatment under the National Health Act, and it is the most practical mechanism for documenting consent to the processing and disclosure of their health information under POPIA. A PRF that lacks a patient signature — without a documented reason for the absence — creates a gap in both the clinical and the data protection record.

Paper versus digital records — what the law demands

South African legislation does not yet mandate that EMS records be digital. But the cumulative effect of POPIA's security safeguard requirements, the HPCSA's record quality standards, the National Health Act's confidentiality obligations, and the practical demands of medical aid audits creates a compliance environment that paper systems struggle to satisfy reliably.

Paper-based PRFs

No tamper-evident audit trail — alterations cannot be reliably detected after the fact
Physical security is inherently difficult — records left in vehicles, bases, or transit can be accessed without authorisation
Cannot encrypt or apply access controls to specific fields — any person with the document has access to all fields
Illegible handwriting creates clinical risk and is a specific HPCSA compliance failure
Retrieval for audits, medico-legal proceedings, or POPIA access requests is operationally cumbersome at scale
Incomplete fields at time of submission — operational pressure in the field consistently produces missing data
No centralised record of which records exist, have been disclosed, or have been destroyed
A breach — such as a lost record or stolen vehicle — may not be detectable, making POPIA breach notification impossible to execute accurately

Digital patient records

Time-stamped, practitioner-attributed audit trail that meets HPCSA record quality standards and POPIA accountability requirements
Encryption at rest and in transit addresses POPIA's security safeguard obligation for electronic records
Role-based access controls limit which staff can access which records — meeting POPIA's processing limitation condition
Mandatory fields prevent incomplete submissions reaching the billing stage — reducing claim rejection rates at source
Centralised record index enables retrieval for OHSC inspections, medical aid audits, and POPIA data subject access requests
Breach detection is feasible — access logs identify who accessed which records and when, enabling accurate POPIA breach notifications
Retention and secure deletion can be managed systematically against a defined policy, meeting POPIA's purpose specification condition
Offline capability allows record completion in areas without connectivity — with automatic synchronisation on reconnection

Removing quotation marks from a paper record does not make it a digital record. A scanned paper PRF stored in a shared folder is not a compliant digital record — it lacks an audit trail, cannot enforce mandatory fields, and does not provide access controls at the field level. A compliant digital patient record is a purpose-built system that enforces documentation standards at the point of care.

Data security requirements for patient records

POPIA's Section 19 requires every Responsible Party to secure the integrity and confidentiality of personal information in its possession or under its control by taking appropriate, reasonable technical and organisational measures. For EMS patient records, this obligation has specific and practical implications for how records are stored, accessed, transmitted, and eventually destroyed.

Technical security measures

01

Encryption at rest and in transit

Patient records must be encrypted both when stored and when transmitted. This applies to records on mobile devices used in the field, records in transit to a server, and records stored in any cloud or on-premises system. An unencrypted patient record on a tablet that is left in a vehicle is a POPIA security failure.

02

Role-based access controls

Not all staff need access to all patient records. A dispatcher does not require access to clinical notes. An administrator processing a billing query does not need to view the full clinical assessment. Access controls must be implemented at a granular level — administrative staff should see billing information only, and clinical records should be accessible only to authorised clinical staff.

03

Audit logging

Every access to, amendment of, or disclosure of a patient record must be logged with a time stamp and user attribution. This audit log is essential for POPIA breach investigations, for responding to data subject access requests, and for demonstrating accountability to the Information Regulator.

04

Secure backups and disaster recovery

Patient records must be backed up regularly to prevent loss due to system failure. Backups must be encrypted and stored in a secure location separate from the primary system. The ability to recover records in the event of a system failure is a POPIA security safeguard requirement and a practical operational necessity for audit and medico-legal purposes.

05

Secure destruction at end of retention period

Patient records must be destroyed securely at the end of their defined retention period. For physical records, this means shredding. For digital records, it means secure deletion that renders the data irrecoverable. Destruction must be documented. Simply deleting files from a folder does not constitute secure destruction under POPIA.

Organisational security measures

Appoint an Information OfficerPOPIA requires every private body to appoint an Information Officer (typically a senior employee) responsible for POPIA compliance. Their details must be registered with the Information Regulator.
Maintain a data processing registerDocument every category of personal information processed, the purpose, the legal basis, and the retention period. This register is the foundation of your POPIA compliance programme.
Train all staff who handle patient dataEvery crew member who completes a PRF is processing Special Personal Information. POPIA training is not optional for clinical staff — it is a security safeguard requirement.
Establish a breach response procedureBefore a breach occurs, your organisation must have a documented procedure for identifying, containing, assessing, and notifying a data breach. This includes knowing how to contact the Information Regulator.
Execute DPAs with all third-party processorsAny vendor, software provider, or billing service that processes patient data on your behalf must have a signed Data Processing Addendum in place before they access your records.
Prohibit unauthorised photography at incidentsThe GEMS 2026 Provider Guide explicitly prohibits EMS practitioners from taking or sharing patient or incident photographs without explicit written consent. Ensure all staff are trained on this requirement and that it is documented in your operational policies.

The Information Regulator: Complaints about POPIA non-compliance, including breaches involving patient data, are submitted to the Information Regulator of South Africa. The Regulator can investigate, issue enforcement notices, and impose penalties. Information about the Regulator's mandate and the complaints process is available at inforegulator.org.za.

Sources and reference documents

The following primary sources underpin the guidance in this page. These are the documents your Information Officer, compliance lead, and clinical governance team should be familiar with.

Patient records that are built for compliance from the first field.

ODIN's digital PRF enforces mandatory fields, generates tamper-evident audit trails, and stores records in a POPIA-compliant environment — so your documentation holds up clinically, legally, and at audit.