SciELO - Scientific Electronic Library Online

 
vol.115 número4Prevention of COVID-19 in the workplace índice de autoresíndice de materiabúsqueda de artículos
Home Pagelista alfabética de revistas  

Servicios Personalizados

Revista

Articulo

Indicadores

    Links relacionados

    • En proceso de indezaciónCitado por Google
    • En proceso de indezaciónSimilares en Google

    Compartir


    SAMJ: South African Medical Journal

    versión On-line ISSN 2078-5135versión impresa ISSN 0256-9574

    SAMJ, S. Afr. med. j. vol.115 no.4 Pretoria may. 2025

    https://doi.org/10.7196/SAMJ.2025.v115i5.3101 

    CORRESPONDENCE

     

    Comment on: 'Cyberattack on the National Health Laboratory Service of South Africa - implications, response and recommendations'

     

     

    To the Editor: In their article on the National Health Laboratory Service (NHLS) cyberattack, Cassim and Chapanduka[1] suggest that the use of platforms such as Gmail and WhatsApp to transmit patient data may have violated the Protection of Personal Information Act 4 of 2013 (POPIA).[2] However, this critical legal question is left unresolved in their analysis. More notably, the authors call for new national legal policies without first analysing how the existing legal framework applies to such situations - and indeed offers solutions.

    Section 19 of POPIA requires that a responsible party - in this case, the NHLS - implement appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unauthorised access to personal information, especially sensitive health data. Crucially, POPIA's obligations remain in force during a data breach; if anything, the duty to protect personal information becomes more acute during such events. A security breach cannot justify lower standards; rather, it should trigger an intensified effort to uphold them.

    The NHLS should have had a contingency plan that accounted for this scenario. In its absence, immediate consultation with legal professionals experienced in data protection was imperative. Practical measures, such as password-protecting files sent via Gmail, would have constituted reasonable technical safeguards under POPIA, given the circumstances. The article does not indicate whether any such steps were taken, raising concerns about the adequacy of the NHLS's data protection practices during the incident.

    Furthermore, POPIA's chapter 4 provides for exemptions if these involve 'a clear benefit to the data subject ... that outweighs, to a substantial degree, any interference with the privacy of the data subject...', offering a legal pathway when conventional data protection measures are impractical owing to emergencies.[3] The Information Regulator has issued clear guidance on how to apply for such exemptions.[4] It appears that the NHLS did not pursue this option. An exemption application could have been urgently processed, providing clear, tailored legal conditions for data handling during the crisis. This could have allowed laboratory professionals to communicate results in unorthodox ways to avoid patient harm, without violating the law.

    We respectfully suggest that the call for new national legal policies is misplaced. What is needed is not legal reform, but effective operationalisation: a legally informed contingency plan, the timely use of exemption mechanisms, and practical safeguards - even under pressure.

    Acknowledgment. ChatGPT was used to improve language and readability.

    DW Thaldar

    School of Law, University of KwaZulu-Natal, Durban, South Africa

    thaldard@ukzn.ac.za

    W Preiser

    Division of Medical Virology, Stellenbosch University and National Health Laboratory Service, Tygerberg Hospital, Cape Town, South Africa

     

    References

    1. Cassim S, Chapanduka ZC. Cyberattack on the National Health Laboratory Service of South Africa - implications, response and recommendations. S Afr Med J 2024;114(12):e2549. https://doi.org/10.7196/SAMJ.2024.v114i12.2549        [ Links ]

    2. Protection of Personal Information Act 4 of 2013. https://www.gov.za/sites/default/files/gcis_document/201409/3706726-11act4of2013protectionofpersonalinforcorrect.pdf (accessed 27 February 2025).         [ Links ]

    3. Cassim S, Chapanduka ZC. Cyberattack on the National Health Laboratory Service of South Africa - implications, response and recommendations. S Afr Med J 2024;114(12):e2549. https://doi.org/10.7196/SAMJ.2024.v114i12.2549        [ Links ]

    4. Protection of Personal Information Act 4 of 2013. https://www.gov.za/documents/protection-personal-information-act (accessed 5 February 2025).         [ Links ]