Last updated: April 2026
MedCascade is committed to protecting your privacy and securing your personal and health information. Our program is aligned with the South African Protection of Personal Information Act 4 of 2013 (POPIA) and, for US healthcare customers, with the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules.
MedCascade supports billing-assist and clinical validation workflows for healthcare providers, medical bureaus and medical schemes. Depending on your jurisdiction, different privacy frameworks apply:
For our own account management, security monitoring and communications, MedCascade is a responsible party (POPIA) and a controller of its own corporate data.
We may collect and process the following categories of information:
We follow the POPIA principles of lawfulness, purpose limitation, minimality, and confidentiality in all our processing activities.
We process personal information for the following purposes:
For special personal information (health), we act primarily as operator for the responsible party (our customer) and process on documented instructions under the applicable POPIA grounds relied upon by that customer (e.g., healthcare provision, legal claims or explicit consent). Customers are responsible for ensuring a lawful basis and necessary notices/consent.
Our controls are designed to meet the POPIA appropriate-safeguards requirement and align with the administrative, physical and technical safeguards of the HIPAA Security Rule (45 CFR Part 164, Subpart C).
As operator, we retain customer data according to the customer's configuration and instructions, and for as long as necessary to provide the Service, meet legal obligations and maintain auditability.
Backups have limited retention windows. Upon termination, we will delete or return data per our agreement and the customer's instructions unless retention is legally required.
Under POPIA, you have the following rights:
To exercise your rights, contact our Information Officer using the details below.
We do not directly target services to children. Where customer data includes information about minors, customers must ensure lawful processing and appropriate authorisations. We process such data as operator on their instructions.
In the event of a security compromise creating a real risk of harm, we will notify the affected customer (responsible party) and, where applicable, the Information Regulator and data subjects in accordance with POPIA and our contractual commitments.
Where PHI is involved and HIPAA applies, MedCascade will report the breach to the affected covered entity without unreasonable delay and in any event within the timeframes required by 45 CFR 164.410, so the covered entity can meet its HHS and individual notification obligations within 60 days.
We may update this policy occasionally to reflect changes in our practices or legal requirements. Material changes will be communicated in-product or by email. Continued use of the Service after such changes indicates acceptance of the updated policy.
Lodge Complaints with the Information Regulator (South Africa)
Website: https://inforegulator.org.za
This privacy policy reflects our commitment to transparency and to meeting applicable privacy and security obligations under POPIA and HIPAA.
For questions about our Terms of Service, please visit our Terms page.