Digital Patient Records in South African EMS
The patient report form is the most legally consequential document your organisation produces. It is simultaneously a clinical record, a billing instrument, a legal evidence document, and a data subject record under POPIA. This guide covers what the law requires of it — and why paper can no longer carry that weight.
The legal framework governing EMS patient records
Patient records in South African EMS are not governed by a single piece of legislation. They sit at the intersection of at least four distinct legal frameworks, each imposing its own obligations. Understanding how these layers interact is not optional for any operator managing clinical documentation — the consequences of getting it wrong extend from claim rejection through to criminal liability.
Data protection
POPIA, No. 4 of 2013
Patient health information is classified as Special Personal Information under Section 26 of POPIA — the highest protection category in South African data law. Processing is generally prohibited unless one of the narrow authorisations under Sections 27–33 applies. For EMS providers, the relevant authorisation is Section 32, which permits processing for healthcare purposes.
Penalties for non-compliance reach R10 million in fines, up to 10 years imprisonment, or both. The Information Regulator is actively enforcing POPIA as of 2024.
Health legislation
National Health Act, No. 61 of 2003
Section 13 imposes an obligation on every health establishment to create and maintain a health record for every user of health services. Section 14 declares all patient information confidential, permitting disclosure only with written consent, by court order, or where non-disclosure presents a serious threat to public health.
For EMS providers, the NHA and POPIA must be read together — where their requirements differ, whichever provides the patient with greater protection prevails.
Professional conduct
Health Professions Act, No. 56 of 1974
The HPCSA's Ethical Rule 27A requires every registered practitioner to keep accurate patient records as a condition of professional registration. The HPCSA's Booklet 9 (Guidelines on Patient Records) provides the detailed standards for what records must contain, how they must be maintained, and for how long they must be retained.
These obligations apply to every practitioner individually — and to the operator who deployed them.
Clinical operations
EMS Regulations, 2022 (GN R 2819)
The 2022 EMS Standards Regulations require that EMS systems have processes in place to ensure users are treated in accordance with current HPCSA-approved clinical guidelines, and that patient handover follows a standardised method. The patient report form is the primary instrument through which compliance with both requirements is documented and evidenced.
The GEMS 2026 Provider Guide specifies the exact PRF fields required for a claim to be considered for payment.
The POPI Act and the NHA Act, in so far as it relates to the processing of healthcare information, must be considered together with the HPCSA Guidelines on Confidentiality: Protecting and Providing Information to ensure that healthcare information is processed and managed in accordance with all applicable requirements.
Werksmans Attorneys — The Legal and Ethical Processing of Healthcare InformationPOPIA obligations for EMS patient data
POPIA came into full effect on 1 July 2021. In March 2026, the Information Regulator published new Regulations relating to the Processing of Data Subjects' Health Information by Certain Responsible Parties — tightening the compliance environment further. For EMS organisations, POPIA is not a peripheral IT compliance matter. It governs every patient record created, every PRF stored, and every disclosure of patient information to a medical aid or receiving facility.
Health information as Special Personal Information
Section 26 of POPIA prohibits the processing of personal information concerning a person's health. This is not the general rule for personal data — it is a heightened prohibition that applies specifically to health information because of its sensitive nature and the potential for harm if misused.
The authorisation for EMS providers is found in Section 32, which permits healthcare providers registered under the Health Professions Act to process health information for the care and treatment of the patient. This authorisation is not a blanket exemption. It still requires compliance with all eight conditions for lawful processing set out in Chapter 3 of POPIA — including purpose limitation, data minimisation, security safeguards, and data subject rights.
Section 26 classifies health information as "special personal information," meaning it is generally prohibited from processing unless one of the narrow exceptions in sections 27–33 applies.
POPIA, No. 4 of 2013 — Captain Compliance Analysis, March 2026The eight conditions for lawful processing
Even where the Section 32 authorisation applies, every EMS operator must comply with POPIA's eight processing conditions. These are not aspirational standards — they are legal requirements that apply to every patient record your organisation holds.
| Condition | What it means for EMS records |
|---|---|
| Accountability | Your organisation, as the Responsible Party, is accountable for compliance with all processing conditions — including for records held by third-party software providers. |
| Processing limitation | Collect only information necessary for the specific purpose — clinical care, billing, or regulatory compliance. Not for general purposes. |
| Purpose specification | The purpose for collecting the data must be specific, explicitly defined, and lawful. Data may not be retained beyond the period necessary to achieve that purpose. |
| Further processing limitation | Patient records may not be processed for purposes incompatible with the original purpose. Sharing PRFs with third parties requires lawful grounds. |
| Information quality | Records must be accurate, complete, and kept up to date. Incomplete or inaccurate PRFs breach this condition. |
| Openness | Patients must be informed that their data is being collected, for what purpose, and by whom — at the time of collection where possible. |
| Security safeguards | Appropriate technical and organisational measures must be in place to prevent unauthorised access, loss, or destruction of records. |
| Data subject participation | Patients have rights of access, correction, and deletion. Your organisation must have a process for responding to these requests. |
Breach notification obligations
POPIA imposes a mandatory breach notification obligation. Where there are reasonable grounds to believe that patient data has been accessed or acquired by an unauthorised person, the Responsible Party must notify both the Information Regulator and the affected data subjects as soon as reasonably possible.
For EMS operators, a breach can occur in a number of ways that are particularly relevant to the paper-versus-digital debate: a paper PRF left in an ambulance that is stolen, patient records accessed by an unintended recipient, a lost tablet containing unencrypted records, or unauthorised access to a shared digital folder. Each of these scenarios triggers the notification obligation.
The Information Regulator is actively enforcing POPIA. The Regulator issued its first enforcement notice in February 2024 and has signalled intent to escalate enforcement activity. Penalties reach R10 million in fines, up to 10 years imprisonment, or both. The March 2026 health information regulations signal that the healthcare sector is a focus area for enforcement.
Third-party data processors
If your organisation uses a third-party software provider to store or process patient records — whether a cloud-based system, a billing platform, or a records management service — you are the Responsible Party and you remain accountable for that provider's compliance with POPIA.
Before using any third-party service for patient data, a written Data Processing Addendum (DPA) or Operator Agreement must be in place. This contractually obligates the provider to protect the data in accordance with POPIA's requirements. Using a software provider without this agreement in place is itself a POPIA compliance failure.
Cross-border data transfers: Where patient records are stored on servers outside South Africa, the transfer is subject to Section 72 of POPIA, which requires that the recipient country or organisation provides an adequate level of protection. Cloud providers hosting data outside South Africa must be assessed against this requirement. Ithaca's servers are housed inside the Republic.
National Health Act obligations on patient records
Section 13 — the duty to create and maintain records
Section 13 of the National Health Act imposes a direct obligation on the person in charge of a health establishment to ensure that a health record is created and maintained for every user of health services. For a private EMS operator, this means that a PRF must be completed for every patient contact — without exception. The obligation is not contingent on billing, on the outcome of the call, or on whether the patient was transported.
The person in charge of a health establishment must ensure that a health record containing such information as may be prescribed is created and maintained at that health establishment for every user of health services.
Section 13, National Health Act, No. 61 of 2003Section 14 — confidentiality of patient information
Section 14 is unequivocal: all information concerning a user, including information relating to their health status, treatment, or stay in a health establishment, is confidential. The only grounds for disclosure without patient consent are a court order, or a situation where non-disclosure represents a serious threat to public health.
This provision directly affects how EMS operators may share PRFs with medical aids. The Medical Schemes Act permits schemes to access treatment records, but this is expressly subject to Sections 14 and 15 of the National Health Act. In practice, patient consent for disclosure to the medical aid should be documented — either on the PRF itself or through a standing consent mechanism — before clinical records are submitted as part of a claim.
All information concerning a user, including information relating to his or her health status, treatment or stay in a health establishment, is confidential. No person may disclose any information unless the user consents to that disclosure in writing, a court order or any law requires that disclosure, or non-disclosure of the information represents a serious threat to public health.
Section 14, National Health Act, No. 61 of 2003Section 15 — permitted disclosures between health workers
Section 15 creates a narrowly defined exception to the confidentiality obligation. A health worker who has access to a patient's health records may disclose that information to another health care provider where such disclosure is necessary for any legitimate purpose within the ordinary course and scope of their duties, and where the access or disclosure is in the interests of the user.
This is the legal basis for patient handover documentation. When an EMS crew transfers a patient to a receiving facility and provides the PRF to the receiving clinical team, they are acting within Section 15. The key phrase is in the interests of the user — the disclosure must serve the patient's care, not administrative convenience.
The NHA and POPIA read together: Werksmans Attorneys, a leading South African regulatory law firm, notes that where the NHA and POPIA differ, whichever provides the patient with greater protection prevails. This means EMS operators cannot rely solely on Section 32 of POPIA to justify disclosure — the NHA's Section 14 confidentiality requirement applies concurrently and may be more restrictive in specific circumstances.
Retention requirements
The HPCSA's Guidelines on Patient Records note that under the Occupational Health and Safety Act, health records must be kept for a period of 20 years after treatment. For EMS providers, the NHA, POPIA's purpose limitation condition, and medico-legal best practice all inform the appropriate retention period. Records must be retained long enough to satisfy medico-legal and billing audit requirements, but not retained longer than necessary.
Retention is a POPIA compliance issue, not just a clinical one. Retaining patient records beyond the period necessary for the defined purpose without a lawful basis is a breach of POPIA's purpose specification condition. Your organisation must have a documented retention and secure disposal policy for patient records.
HPCSA standards for patient recordkeeping
The HPCSA's Booklet 9 — Guidelines on Patient Records — provides the professional standard against which every registered practitioner's documentation is measured. These guidelines apply to all HPCSA-registered emergency care practitioners and set out what a clinically and legally adequate patient record must contain, how it must be written, and how it must be managed.
What the HPCSA requires of patient records
The HPCSA's guidelines specify the minimum content and format requirements for a compliant patient record. These apply to every patient contact, irrespective of the outcome or complexity of the call:
Record quality standards
The HPCSA guidelines specify that records must be complete, concise, and consistent. They must be made contemporaneously — at the time of the consultation, not reconstructed after the fact. The Booklet 9 guidelines explicitly state that records must be kept in non-erasable ink, and that correction fluid must not be used on paper records. An altered or corrected paper record without a countersigned correction is legally suspect.
For digital records, these principles translate into requirements for tamper-evident audit trails: every entry must be time-stamped, attributed to the practitioner who made it, and any amendments must be logged with the original entry preserved. A digital record that can be silently altered after the fact provides no more legal protection than a paper one with correction fluid applied.
Records should be complete, but concise. Records should be consistent. Self-serving or disapproving comments should be avoided. A standardised format should be used containing in order the history, physical findings, investigations, diagnosis, treatment and outcome.
HPCSA Booklet 9 — Guidelines on Patient RecordsBilling records must be kept separate
The HPCSA guidelines make a specific requirement that applies directly to EMS billing operations: billing records must be kept separate from patient care records. This has practical implications for how digital systems are structured — the clinical PRF and the invoice associated with a call must be distinct documents, with access controlled separately, to meet both HPCSA and POPIA requirements.
The HPCSA publishes Booklet 9 on its website. It also publishes Booklet 5 (Confidentiality: Protecting and Providing Information), which should be read alongside Booklet 9 for a complete picture of the professional obligations on registered practitioners around patient data. Both are available through the HPCSA website.
Patient Report Form requirements for medical aid claims
The Patient Report Form serves a dual function: it is the clinical record of care rendered, and it is the primary supporting document for a medical aid claim. A PRF that satisfies the HPCSA's clinical documentation standards but omits the fields required by GEMS or another scheme will still result in claim rejection. Both sets of requirements must be met simultaneously.
GEMS mandatory PRF fields
The GEMS 2026 EMS Provider Guide specifies the following as mandatory PRF content for claims consideration. Missing any of these fields is grounds for return or rejection:
Top 5 GEMS claim rejection codes
| Code | Reason for rejection | Common cause |
|---|---|---|
| 6258 | Claim is stale | Submitted more than 120 days after service date |
| 6824 | PRF not attached | PRF missing from claim submission package |
| 6656 | Invalid ICD-10 code | Incorrect, outdated, or missing diagnostic code |
| 6830 | PRF insufficient information | Incomplete clinical assessment or missing required fields |
| 6835 | Billing code not found | Incorrect or outdated tariff code used |
Source: GEMS 2026 EMS Provider Guide
The 120-day submission rule
Claims must be submitted within 120 days of the service date. Claims received after this period are deemed stale and will not be paid, regardless of their clinical merit. If a claim is returned for correction, the corrected resubmission must be provided within 60 days of notification — failure to do so also renders the claim stale.
Pre- or post-authorisation does not guarantee payment. A reference number confirms the call was registered — it does not confirm the PRF will meet clinical criteria for payment. Every claim is independently assessed against medical necessity criteria at adjudication, and an authorised call with a clinically inadequate PRF will still be returned or rejected.
POPIA and consent on the PRF
The patient signature on the PRF serves a dual function: it documents consent to treatment under the National Health Act, and it is the most practical mechanism for documenting consent to the processing and disclosure of their health information under POPIA. A PRF that lacks a patient signature — without a documented reason for the absence — creates a gap in both the clinical and the data protection record.
Paper versus digital records — what the law demands
South African legislation does not yet mandate that EMS records be digital. But the cumulative effect of POPIA's security safeguard requirements, the HPCSA's record quality standards, the National Health Act's confidentiality obligations, and the practical demands of medical aid audits creates a compliance environment that paper systems struggle to satisfy reliably.
Paper-based PRFs
Digital patient records
Removing quotation marks from a paper record does not make it a digital record. A scanned paper PRF stored in a shared folder is not a compliant digital record — it lacks an audit trail, cannot enforce mandatory fields, and does not provide access controls at the field level. A compliant digital patient record is a purpose-built system that enforces documentation standards at the point of care.
Data security requirements for patient records
POPIA's Section 19 requires every Responsible Party to secure the integrity and confidentiality of personal information in its possession or under its control by taking appropriate, reasonable technical and organisational measures. For EMS patient records, this obligation has specific and practical implications for how records are stored, accessed, transmitted, and eventually destroyed.
Technical security measures
Encryption at rest and in transit
Patient records must be encrypted both when stored and when transmitted. This applies to records on mobile devices used in the field, records in transit to a server, and records stored in any cloud or on-premises system. An unencrypted patient record on a tablet that is left in a vehicle is a POPIA security failure.
Role-based access controls
Not all staff need access to all patient records. A dispatcher does not require access to clinical notes. An administrator processing a billing query does not need to view the full clinical assessment. Access controls must be implemented at a granular level — administrative staff should see billing information only, and clinical records should be accessible only to authorised clinical staff.
Audit logging
Every access to, amendment of, or disclosure of a patient record must be logged with a time stamp and user attribution. This audit log is essential for POPIA breach investigations, for responding to data subject access requests, and for demonstrating accountability to the Information Regulator.
Secure backups and disaster recovery
Patient records must be backed up regularly to prevent loss due to system failure. Backups must be encrypted and stored in a secure location separate from the primary system. The ability to recover records in the event of a system failure is a POPIA security safeguard requirement and a practical operational necessity for audit and medico-legal purposes.
Secure destruction at end of retention period
Patient records must be destroyed securely at the end of their defined retention period. For physical records, this means shredding. For digital records, it means secure deletion that renders the data irrecoverable. Destruction must be documented. Simply deleting files from a folder does not constitute secure destruction under POPIA.
Organisational security measures
The Information Regulator: Complaints about POPIA non-compliance, including breaches involving patient data, are submitted to the Information Regulator of South Africa. The Regulator can investigate, issue enforcement notices, and impose penalties. Information about the Regulator's mandate and the complaints process is available at inforegulator.org.za.
Sources and reference documents
The following primary sources underpin the guidance in this page. These are the documents your Information Officer, compliance lead, and clinical governance team should be familiar with.
The full text of POPIA in an accessible, navigable format. Includes Section 26 (Special Personal Information), Section 32 (healthcare authorisations), Section 19 (security safeguards), and Section 22 (breach notification). The starting point for any POPIA compliance programme.
The enforcement authority for POPIA. Responsible parties must register their Information Officer with the Regulator and notify the Regulator of data breaches. The Regulator's website contains guidance on compliance, the complaints portal, and information on enforcement actions.
The full consolidated text of the National Health Act via the Southern African Legal Information Institute. Sections 13, 14, and 15 govern patient record creation, confidentiality, and permitted disclosures by health workers. SAFLII provides freely accessible versions of South African legislation.
The HPCSA publishes Booklet 9 (Guidelines on Patient Records) and Booklet 5 (Confidentiality) as part of its ethical guidelines series. These set the professional standard for patient documentation against which registered practitioners' records are assessed. Both are available via the HPCSA's publications pages.
The primary regulatory instrument for EMS operations, published under the National Health Act. Sets the operational framework within which patient documentation must occur, including clinical practice guideline adherence and standardised patient handover requirements.
An authoritative analysis of how POPIA and the National Health Act interact in the healthcare context, written by one of South Africa's leading regulatory law firms. Explains the Section 32 exemption, the concurrent application of the NHA, and the obligations on both healthcare providers and third-party operators.
Patient records that are built for compliance from the first field.
ODIN's digital PRF enforces mandatory fields, generates tamper-evident audit trails, and stores records in a POPIA-compliant environment — so your documentation holds up clinically, legally, and at audit.
