Published on 06.07.2026
This compliance document applies to Aurelia Private Health (also referred to as “Aurelia”, “we”, “our”) in relation to AureliaPrivateHealth.com, its educational content, downloadable resources, newsletters, social media channels, digital communications, complimentary strategy sessions and related services.
Establish a governance framework supporting lawful, ethical and secure delivery of physician-led concierge preventative medicine.
Identify key legislation and guidance including the Health Professions Act, HPCSA ethical rules and guidelines, POPIA, National Health Act, Consumer Protection Act, Electronic Communications and Transactions Act, Promotion of Access to Information Act where applicable, Medicines and Related Substances Act where applicable, and other relevant South African legal requirements.
Assign accountability to practice leadership and an Information Officer. Maintain documented policies, periodic compliance reviews and staff training.
Ensure all practitioners maintain current registration, practise within scope, obtain informed consent, preserve confidentiality, maintain accurate records, avoid misleading advertising, manage conflicts of interest, and comply with ethical guidance relating to telehealth, referrals and professional conduct.
Process personal and special personal information lawfully, transparently and only for defined healthcare purposes. Maintain security safeguards, processing records, operator agreements, breach procedures and mechanisms for data-subject rights.
Classify information, implement role-based access, strong authentication, audit logging, encryption where appropriate, secure backups, retention schedules, secure disposal and incident response procedures.
Maintain evidence-informed protocols, documented care pathways, referral standards, quality assurance activities, adverse-event reporting, peer review where appropriate and continuous quality improvement.
Clearly define the scope of concierge membership, preventative services, executive health assessments, complimentary strategy sessions and exclusions including emergency care.
Document governance for the proprietary framework, physician oversight, validation processes, version control, transparent communication of limitations and prohibition on presenting outputs as guaranteed outcomes.
Adopt secure communication platforms, verify patient identity, document consent, recognise limitations of remote assessment and escalate where in-person or emergency care is required.
Use appropriately qualified independent providers, maintain referral documentation, manage receipt of results, communicate clinically significant findings and document follow-up responsibilities.
Implement endpoint protection, software updates, vulnerability management, phishing awareness, password standards, multi-factor authentication where feasible and business continuity planning.
Maintain accurate website content, privacy policy, terms of service, cookie policy, medical disclaimer and processes for handling enquiries while avoiding creation of unintended doctor-patient relationships.
Ensure public communications are accurate, evidence-informed and consistent with applicable HPCSA ethical guidance. Respect marketing consent requirements under POPIA.
Provide onboarding, confidentiality agreements, recurring compliance education and documented acknowledgement of policies.
Maintain documented processes for complaints, privacy incidents, cybersecurity events, clinical incidents, corrective actions and continuous improvement.
Conduct periodic reviews of policies, risk assessments, supplier contracts, record retention, access controls and regulatory developments.
Maintain controlled versions of the Privacy Policy, Terms of Service, Cookie Policy, Medical Disclaimer, Membership Agreement, Telemedicine Consent, POPIA Consent, Information Security Policy and related SOPs.