Acceptable Use Policy
This Acceptable Use Policy governs the use of the MedReport platform by all users — including registered healthcare practitioners, practice administrators, report viewers, Med Report Solutions (Pty) Ltd and Smart Station (Pty) Ltd staff.
Purpose and Scope
This Acceptable Use Policy ("AUP") sets out permitted uses, prohibited conduct, security obligations, and the consequences of breach. All users are bound by this AUP as a condition of access to the platform, incorporated by reference into the Subscriber Agreement and Practitioner Agreement.
Permitted Uses
- Generating intelligently processed draft medical reports (including clinical notes, progress notes, discharge summaries, letters, medical certificates, and other practice-configured report types) for patients of the subscribing practice.
- Uploading source clinical documents and using extraction/drafting tools solely for patients of the subscribing practice.
- Recording consults and generating clinical notes where the practice has enabled those features and patient consent requirements are met.
- Reviewing, editing, and approving medical report drafts in the practitioner's professional capacity.
- Accessing approved reports for clinical, administrative, or legal purposes related to the patient's care.
- Permitted users only: HPCSA-registered practitioners, authorised practice administrators, authorised report viewers. Each user must have their own account — sharing login credentials is strictly prohibited.
Prohibited Conduct
All Users
- Using the platform for any purpose other than medical report generation and management for the subscribing practice.
- Sharing login credentials with any other person.
- Attempting to access reports or functions beyond your assigned role.
- Uploading documents about patients who are not patients of the subscribing practice.
- Processing personal information for purposes other than those disclosed in the Privacy Policy.
- Approving reports you have not personally reviewed.
- Introducing malicious software, scripts, or unauthorised automation tools.
- Probing, scanning, or testing the platform’s security.
- Scraping or bulk-downloading patient records beyond normal use.
- Providing false information during account registration, including false HPCSA numbers.
Registered Practitioners
- Approving a report that is clinically inaccurate, incomplete, or misleading.
- Delegating approval responsibility to another person.
- Generating reports for patients you have not treated or for whom you do not have clinical responsibility.
- Removing or altering the intelligent processing disclaimer embedded in approved reports.
- Using medical certificate verification links or QR codes to misrepresent legitimacy or to publish clinical content beyond what the public verify page is designed to show.
- Relying on AI drafts, medication/allergy prompts, or safety signals as a substitute for professional clinical judgement.
Security Obligations
- Use a strong, unique password — minimum 12 characters, mix of character types.
- Enable and maintain multi-factor authentication (MFA) at all times.
- Log out when leaving a workstation unattended.
- Report suspected compromise of credentials immediately.
- Do not access the platform on shared or public computers where session data may be exposed.
Reporting Violations
Any user who suspects a violation of this AUP must report it immediately to:
- Platform support: support@medreport.co.za
- Information Officer: legal@medreport.co.za
Reports will be treated confidentially. Users are encouraged to report suspected violations without fear of retaliation where the report is made in good faith.
Consequences of Breach
| Breach Type | Consequence |
|---|---|
| Minor / first-time breach | Warning; mandatory security awareness session; enhanced monitoring |
| Significant breach | Immediate account suspension pending investigation; notification to subscribing practice; potential permanent account termination |
| Serious breach | Immediate permanent account termination; notification to subscribing practice; notification to HPCSA if applicable; referral to law enforcement if criminal conduct suspected |
Monitoring
All actions on the MedReport platform are recorded in an immutable audit trail. This includes logins, report access, state transitions, approvals, and administrative actions. These logs may be reviewed in the event of a suspected security incident or AUP violation. Use of the platform constitutes consent to this monitoring.
Policy Review
| Version | Date | Approved by |
|---|---|---|
| 1.0 | March 2026 | Information Officer |
| 1.1 | July 2026 | Information Officer — voice, documents, certificates, AI assist |
