An introduction to the protection of personal information in the healthcare practice
10. Practical implementation observations
It is of vital importance that the healthcare practice implement all these requirements of the POPIA as discussed in this introductory guidelines book.
Some final summary remarks:
- POPIA compliance is not a "get it done, be certified and that is the end of it" process.
- POPIA compliance is an ongoing process of implementation and management.
- If the practice does not have enough human resources to keep ahead of the implementation and maintenance of the POPIA provisions, it will do the practice well to outsource some of the responsibilities.
- Examples of things you can easily outsource:
- Assistance with registration of the IO
- Assistance with drafting compliance frameworks
- Assistance with drafting PIIAs & LIAs
- Drafting of operator contracts & privacy policies
- Internal employee awareness sessions
- Software systems that provide good communication lines between the practice and its patients
- Risk management assessments
- PI data management assistance
- Assistance with breach notifications
- Assistance with dealing with DS requests
To implement the provisions of the POPIA as discussed in this book, you can download the action maps PDF under Data Management on the GoodX Learning Centre.