A stolen card gets cancelled in hours. A medical history cannot be cancelled at all.
Patient records are worth more to a criminal than card details, because they cannot be reissued. POPIA also treats health information as a special category, which raises the bar on what a practice has to be able to show.
Why are patient records more valuable than financial data?
Because they are permanent. A compromised card is cancelled and reissued within hours and the loss stops there. An identity number, a date of birth, an address and a medical history cannot be reissued, so they remain usable for identity fraud indefinitely and are traded accordingly. That permanence is what sets the price.
What does POPIA say about health information?
POPIA classifies information concerning health as special personal information, and Section 26 prohibits processing it unless a specific exception applies. For a practice treating patients the treatment exception applies, but the classification still raises the standard of care expected under Section 19, and it makes a breach involving patient records materially more serious than one involving ordinary contact details.
The Information Regulator names health among the sectors it is targeting for proactive compliance audits in its 2026 and 2027 plan.
What actually goes wrong in a medical practice?
The three most common incidents are ransomware encrypting the practice management system and the appointment book, a compromised reception mailbox used to invoice patients fraudulently, and an unencrypted laptop or backup drive leaving the building. The third is the one practices consistently underestimate, and it is a reportable breach on its own.
What happens if the practice management system goes down?
Without a tested recovery plan, a practice loses access to appointments, clinical notes, billing and medical aid submissions simultaneously, and reverts to paper while trying to see patients. With verified backups and a documented recovery order, the same event is a disrupted morning. The difference is entirely in what was prepared beforehand.
What does LANTEK put in place for a practice?
Encrypted devices, enforced multi-factor authentication, tested backup of the practice management system and of Microsoft 365, monitoring that alerts on unusual access to patient data, email security, awareness training for reception and administrative staff, and the documented POPIA control set including the Section 19 evidence a regulator would ask to see.
We go further where the risk is concentrated
Before you call
Do you work with medical aid submission systems?
Is a lost laptop a reportable breach?
How long must we keep patient records?
A free dark web scan
and thirty minutes.
We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.
Worried about what it takes to move?
Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.