Here at Vizibiliti, we’ve noticed a troubling trend in recent months. Doctors are increasingly being approached by third parties promising better returns, lower costs, or “quick wins” for their practices. These approaches are often framed as informal, exploratory or risk-free — just a quick look at your numbers, a snapshot of your billing data, or a brief review of how your practice is performing.
But what may feel like a harmless conversation can quickly become a serious liability.
Unfortunately, some medical professionals are falling for these approaches and sharing sensitive practice and patient information with people they don’t know, without proper agreements, consent, or safeguards in place.
A recent case we encountered underlines the potential pitfalls. A specialist shared clinical patient data and financial information with a third party who had no formal relationship with the practice and a chequered professional history. No waivers were signed. No indemnities were in place. The risks were substantial.
Once sensitive data leaves your control, you no longer get to decide how it is used, stored, or protected.

Most doctors don’t share information recklessly. In fact, the opposite is true. These situations often arise because specialists are busy, under pressure, and trying to run efficient businesses alongside demanding clinical workloads.
Fly-by-night operators exploit this reality. They present themselves as experts, create urgency, downplay risk, and suggest that paperwork and formal processes are unnecessary obstacles. The promise of improved cash flow or reduced costs can make it tempting to engage quickly.
But shortcuts in this area are rarely harmless.
Sharing patient or practice data is not just a business decision — it is a legal one.
Under the Protection of Personal Information Act (POPIA), doctors are responsible for how personal and clinical data is processed, shared, and safeguarded. This responsibility does not disappear simply because a third party requests the information or claims to know what they’re doing.
Key principles apply:
Even granting “view-only” access can constitute unlawful disclosure if these conditions are not met. Importantly, intent is not a defence. A well-meaning decision can still result in a breach.
Beyond POPIA, there are professional consequences to consider.
The Health Professions Council of South Africa (HPCSA) expects practitioners to safeguard patient confidentiality at all times. Allowing inappropriate access to patient or clinical data — even indirectly — can expose a doctor to complaints, investigations, and disciplinary action.
“I didn’t realise” or “I trusted them” offers little protection once a complaint is lodged. From a regulatory perspective, the responsibility sits squarely with the practitioner.

The risks don’t stop at legal or ethical exposure.
Shared data can surface inconsistencies that invite unwanted scrutiny — including from medical schemes, auditors, or SARS. In some cases, data shared informally has later been used out of context, misinterpreted, or leveraged in ways the doctor never anticipated.
Reputational damage can be just as costly. Once trust is lost with partners, funders, or regulators, rebuilding it takes time and resources.
Reputable service providers approach data access very differently.
They insist on:
If an operator is willing to proceed without documentation, safeguards, or proper consent, that is not efficiency — it is a red flag.
Paperwork in this context is not bureaucracy. It is protection.
There are consistent patterns in risky engagements. Be cautious if someone:
Legitimate professionals welcome scrutiny. Rogues avoid it.

Protecting sensitive information is not about mistrust — it’s about professionalism.
Just as you would never hand over clinical decision-making without proper safeguards, you should never hand over patient or practice data without clear agreements, consent, and accountability in place.
If something feels rushed, informal, or too good to be true, pause. Ask questions. Get advice. The consequences of getting this wrong can be long-lasting and difficult to undo.
Even anonymised data can sometimes be re-identified, especially when combined with other datasets. You should still ensure there is a lawful purpose, appropriate agreements, and clarity on how the data will be used.
In most cases, no. POPIA requires demonstrable, informed consent where applicable. Verbal assurances are extremely difficult to defend if challenged.
Yes. As the data custodian, you retain responsibility for ensuring that any third-party processes information lawfully and securely.
At minimum: a formal agreement, confidentiality clauses, POPIA compliance warranties, defined scope of access, and clarity on data retention and deletion.
Reputable providers welcome reference checks, formal agreements, legal review, and clear governance. Resistance to these steps is a warning sign.
If you’re unsure whether a request for information is legitimate or want to review how your practice handles sensitive data, feel free to reach out to Vizibiliti. We’re here to help you protect your practice — calmly, carefully, and correctly.