The Responsible Party and MediScan are each referred to as a "Party" and together as the "Parties".
The Responsible Party operates a healthcare facility ("Facility") and has contracted MediScan to provide a patient identity verification and encounter management platform ("Service"). In providing the Service, MediScan will Process Personal Information (including Special Personal Information) on behalf of the Responsible Party. This Agreement sets out the terms on which MediScan processes such information in compliance with POPIA.
| Term | Meaning |
|---|---|
| POPIA | Protection of Personal Information Act 4 of 2013 and subordinate regulations, as amended. |
| Personal Information | Has the meaning in POPIA s 1 and includes Special Personal Information. |
| Special Personal Information | Biometric data, health and medical information as defined in POPIA s 26–32. |
| Process / Processing | Has the meaning in POPIA s 1 (collection, use, storage, modification, deletion, etc.). |
| Data Subject | A patient or staff member whose Personal Information is processed under this Agreement. |
| Sub-operator | A third party engaged by MediScan to process Personal Information under this Agreement. |
| Security Incident | Any actual or reasonably suspected unauthorised access, loss, destruction, or disclosure of Personal Information. |
| Item | Detail |
|---|---|
| Subject matter | Patient identity and clinical encounter data managed through the MediScan Platform. |
| Nature | Collection, storage, retrieval, verification, transmission to HMS, audit logging, anonymised reporting. |
| Purpose | Biometric patient identification to prevent medical identity fraud; encounter management; POPIA-compliant consent capture. |
| Categories of data subjects | Patients registered at the Facility; Facility staff with Platform access. |
| Categories of personal information | Identity (name, ID number, DOB), biometric templates, health encounter records, consent records, audit events. |
| Duration | For the term of the Service Agreement plus any statutory retention obligations (minimum as set out in the Patient Privacy Notice). |
MediScan shall:
The Responsible Party shall:
The Responsible Party grants general written authorisation for MediScan to use the following Sub-operators, subject to equivalent data protection obligations:
| Sub-operator | Service provided | Data transferred | Location |
|---|---|---|---|
| Google LLC (Firebase / Firestore, Authentication) | Cloud data storage & authentication | All patient and audit data | US (us-central1); SCC in place |
| Google LLC (Firebase Cloud Storage) | Storage of uploaded clinical documents | Uploaded files (X-ray, reports, ID documents) | US (us-central1); SCC in place |
| Google LLC (Firebase Hosting & Cloud Functions) | Web application hosting & server-side processing | Static assets; transient form/email payloads | Global CDN; functions us-central1 |
| Zoho Corporation (Zoho Mail) | Transactional email of self-fill form links | Patient email address & link (no PIN, no special personal information) | EU / India; DPA in place |
MediScan will inform the Responsible Party of any intended change to the above list at least 14 days in advance, giving the Responsible Party the opportunity to object.
Processing of Personal Information outside South Africa (Google Firebase in the US) is governed by Google's Standard Contractual Clauses as approved under GDPR Article 46(2)(c). MediScan has carried out a Transfer Impact Assessment and determined that the level of protection is adequate for the purposes of POPIA s 72. A copy of this assessment is available on request.
This Agreement commences on the date of last signature and continues for the duration of the Service Agreement. Either Party may terminate this Agreement immediately on written notice if the other Party materially breaches its obligations and fails to remedy the breach within 15 business days of notice.
This Agreement is governed by the laws of the Republic of South Africa. Disputes shall be submitted to binding arbitration under AFSA rules before a single arbitrator in Johannesburg, without prejudice to the right to approach the courts for urgent relief.
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ on all API and web traffic; HSTS enforced. |
| Encryption at rest | Google Cloud Firestore AES-256 encryption at rest. |
| Access control | Role-based access (staff / admin / super_admin); facility-scoped Firestore security rules. |
| Authentication | Firebase Auth (email/password + optional MFA); WebAuthn/FIDO2 for biometric device binding. |
| Biometric protection | Fingerprint templates stored as one-way hashed vectors (SHA-256 with per-patient salt); original images never retained. |
| Audit logging | Append-only audit_log collection in Firestore; all access, mutations, and administrative actions logged with user, timestamp, and action type. |
| Penetration testing | Annual third-party penetration test; results shared with Responsible Party under NDA. |
| Vulnerability management | Dependency scanning on every CI run (Dependabot / OWASP Dependency Check). |
| Incident response | Documented IRP; 24-hour notification SLA; post-incident reports within 5 business days. |
| Business continuity | Firebase multi-region read replication; daily Firestore exports to Cloud Storage; RTO 4h, RPO 24h. |
Each Sub-operator agreement must include:
The duly authorised representatives of each Party sign this Agreement as follows: