Build a POPIA-Ready Data Governance Plan for Your Practice
Ten focused modules. One finished document. By the end of this course, you won't just understand health data governance; you'll have a written plan your practice can actually adopt.
Β
A practical CPD course built for health practitioners in South Africa.
6 CPD points Β· Lifetime access Β· R999 R499
Enroll in Data GovernanceYou Know Patient Data Matters. But Is It Actually Governed?
Every health practice collects sensitive personal information. Most practitioners take that seriously. Far fewer have anything written down.
Ask yourself:
If a locum joined tomorrow and needed access to patient records, who decides, and on what basis?
If your practice management system failed this afternoon, what is your recovery plan?
Can you tell a patient exactly what data you hold about them, and how it has been used?
If you wanted to write up an interesting case series, are you legally allowed to use those records?
Which laws apply to your practice, and where are the current versions stored?
Most data governance failures are not malicious. They are accidental: a system nobody set up, a decision nobody made, a responsibility nobody was clearly given. The practitioner had entirely good intentions. There just wasn't a plan.
This course closes that gap by producing an actual document.
Each module ends with a worksheet that drafts one section of your own governance plan. By Module 10, those sections assemble into a single, usable plan you can adopt, hand to a new staff member, share with your team, or produce if a regulator asks. Not a certificate and a vague intention to sort it out later.
What You'll Get
Ten modules, each with a short animated video, a full lesson with worked examples and a glossary, a downloadable PDF summary, and a worksheet that drafts your plan as you go.
Module 1 β Course Overview
- The six-pillar governance framework and why the pillars are interdependent
- Why health data is a special category of personal information
- The foundation layer: SOPs, data custodians, infrastructure, quality control
- The accountability layer: enforcement and data provenance
Module 2 β What Is a Governance Plan For?
- Transparency, accountability, clarity and why writing it down is not bureaucracy
- Your plan as internal operational guide and external reference document
- Keeping it a living document: review dates, named custodians, and the events that trigger an unscheduled review
- Governance for solo practices, group practices, shared premises and outsourced services
Module 3 β The Ethics Pillar
- Autonomy, beneficence and non-maleficence applied to patient data
- Informed consent as a process, not a signature, and how to design one that works
- Broad consent versus tiered consent, and when each is appropriate
- Consent in complex situations: minors and assent, impaired capacity, proxy consent, deceased patients
- The clinical data and research boundary, one of the most consequential distinctions in the course
Module 4 β The Legislation Pillar
- Six categories of legislation relevant to health practitioners
- POPIA, PAIA, the National Health Act, ECTA and the Cybercrimes Act
- Comparisons with GDPR, the UK Data Protection Act and HIPAA
- Why anonymised data usually cannot be used freely and what real de-identification requires
- Building a legislative reference repository your whole team can use
Module 5 β Structural Protections
- The tangible, technical measures that prevent unauthorised access
- Password protection, firewalls, encrypted storage, and physical security of devices and servers
Module 6 β Procedural Protections
- Structural protections lock the data; procedural protections decide who holds a key
- Documented access conditions and how to eliminate personality-driven systems
Module 7 β The Equity Pillar
- Applying identical storage, protection, and access standards across your entire dataset
- Guarding against bias entering data management systems
Module 8 β The Sustainability Pillar
- Governance across the full data lifecycle
- Storage, backup and recovery, staff transitions, and what happens if the practice closes or changes hands
Module 9 β Accountability & Enforcement
- Breach response protocols: who is notified, what steps follow, what the repercussions are
- Data provenance and audit trails, how you demonstrate compliance rather than claim it
Module 10 β Bringing It All Together
- Assembling your drafted sections into one master governance plan
- The completeness and consistency review that catches what individual modules miss
- Sign-off, approval, and setting up your annual review cycle
The course also includes a separate Data Governance Plan Template, a fully worked sample plan for a fictional solo practice, and downloadable summaries for every module.
Who This Is For
This course is for health practitioners and practice owners who:
- Collect, store or handle patient data in any form, paper or digital
- Have never written a formal data governance plan, or have one that has gone stale
- Want to understand their POPIA and National Health Act obligations in practical terms
- Are responsible for staff, locums or contractors who access patient records
- Are setting up, restructuring, merging or winding down a practice
- Have wondered whether they can ethically or legally use their own patient data for research
It works for solo practitioners and multi-site group practices alike. The six pillars apply equally β what changes with scale is the complexity of their application, not the principles.
What Makes This Different
This is not a compliance checklist or a legal summary you file and forget.
The course is built around a single practical outcome: a finished governance plan for your specific practice. Every module ends with a worksheet, every worksheet drafts a section, and Module 10 assembles them. You are writing your plan as you learn, which is why practitioners finish this course with something usable rather than something noted.
It is also grounded in South African reality β POPIA, PAIA, the National Health Act, HPCSA guidance β while providing GDPR, UK and US comparisons so the framework travels if you do.
Meet Your Instructor
Nicki Tiffin
Nicki works at the intersection of health data, ethics and governance, with published research on protecting health data through de-identification of structured datasets.
This course reflects that dual perspective: rigorous about the ethical and legal obligations attached to health data, and practical about what a working practice can realistically implement and maintain.
Frequently Asked Questions
"Who is this course for?"
Any health practitioner or practice owner responsible for patient data β biokineticists, physiotherapists, and allied health professionals in solo or group practice. If patient information passes through your hands, this applies to you.
"Do I need a legal or IT background?"
No. The course explains what you need in plain language and points you toward professional advice where it is genuinely required. The legislation module teaches you how to identify and summarise the laws that apply to you, not how to interpret law like a lawyer.
"Is this only relevant in South Africa?"
South African legislation is used as the primary worked example β POPIA, PAIA, the National Health Act, ECTA and the Cybercrimes Act. Comparisons with GDPR, the UK Data Protection Act and HIPAA are included throughout, and the six-pillar framework itself is jurisdiction-neutral. If you practise elsewhere, the course prompts you to identify your local equivalents.
"How practical is it, really?"
Very. You work from a Data Governance Plan Template that mirrors the course structure section by section. Worked examples show what a completed entry looks like, and a fully worked sample plan for a fictional solo practice is included for whenever you are unsure what βdoneβ looks like.
"How long does it take?"
It is self-paced with lifetime access. Most practitioners work through it over a few weeks, module by module, drafting as they go. Doing it in one sitting is possible but not the point β the writing is where the value is.
"Does this cover using patient data for research?"
It covers the boundary clearly β and the answer is that a practice governance plan does not authorise research use. The course explains what research use actually requires: specific informed consent, independent ethics approval, and a separate governance framework. That is deliberately outside this course's scope, but knowing where the line sits protects you.
"Will I get my CPD points?"
This course is accredited by the HPCSA for 6 CPD points. On completion you will receive your certificate and the documentation to submit to HPCSA, at no extra cost.
"Is there a payment plan?"
Currently, it is one payment of R999 R499. If that is a barrier, reach out β we can explore options.
"How do I access the course after I buy it?"
You will get immediate access to your Kajabi account. All you need is an email address and a password: simple setup, instant access.
Still have questions?
Email us at [email protected]. We are here to help.
CPD & Recognition
Accredited for 6 HPCSA CPD points | POPIA and National Health Act aligned | Lifetime access
Ready to start? Build your governance plan for R999 R499
Good intentions are not a governance framework. Systems are.