1. Scope and responsibilities
This policy applies to personal information handled by Denmyd staff, contractors and service providers. It supports our privacy notice and the security safeguard obligations in POPIA. It is a statement of required practices, not a claim of independent certification or a guarantee that no incident can occur.
For Imatri, the healthcare practice’s instructions and written operator agreement must define processing scope, authorised access, service providers, incident cooperation and record return or deletion. Clinical decisions and the lawful collection of patient information remain the practice’s responsibility.
2. Security requirements
- Collect and expose only information needed for the task; do not place patient records or contact messages in routine diagnostic logs.
- Use individually assigned accounts, least-privilege access and prompt removal of access when roles change. Apply multi-factor authentication to privileged access where supported.
- Protect information in transit using current TLS; assess encryption at rest, key management and backups according to the sensitivity and risks of each system.
- Keep supported software updated, review vulnerabilities and restrict access to production systems and secrets.
- Require confidentiality and appropriate safeguards from operators; assess their access, processing locations and incident arrangements.
- Define retention and recovery requirements, protect backups and test restoration for systems holding important records.
- Review access and security events without unnecessarily recording message contents, credentials or health information.
3. Confidentiality and purpose limits
Staff and providers may not browse, copy, disclose, sell or reuse customer or patient information for their own purposes. Support access must be authorised and limited to the issue being resolved. Sharing is allowed only for the purposes and lawful circumstances explained in our privacy notice. Information must not be used for unrelated marketing or to train general-purpose AI models.
4. Responding to a suspected compromise
Report concerns to enquiries@denmyd.com, marked “Security concern”. Describe what happened and how to contact you, without sending exposed data or credentials.
Our response must include containment, investigation, preservation of necessary evidence, assessment of affected information and corrective action. When acting as an operator, we must inform the responsible party immediately where there are reasonable grounds to believe personal information was accessed or acquired by an unauthorised person. Where Denmyd is the responsible party, notifications to the Information Regulator and affected people must follow section 22 of POPIA, as soon as reasonably possible, subject to applicable exceptions and permitted delays.
5. Keeping your own access safe
Use unique passwords, enable available multi-factor authentication, keep devices updated and remove access when staff leave. Never share a password or send patient records through the public enquiry form. Verify unexpected payment or bank-detail changes through a known contact number.
6. Privacy and security enquiries
Denmyd Medical Equipment (Pty) LtdRegistration number: 2011/011722/07
11 Polo Crescent, Woodmead Office Park, Woodmead, 2191, Gauteng, South Africa
enquiries@denmyd.com
+27 11 656 4559
For personal-information rights, see the privacy policy. For formal requests to access records, see access to information.