The confidential medical records of around 3,000 South African Police Service (SAPS) officers are circulating after a leak in the Western Cape, and they hold the kind of detail nobody hands over lightly: PTSD diagnoses, cancer treatment, alcoholism, full surgical histories. SAPS first tried to call it an administrative error before acknowledging it as a reportable breach under the Protection of Personal Information Act (POPIA). If you employ anyone, you hold the same category of data about your own staff, and POPIA treats it as the most sensitive information you can process.
What happened
The Cape Argus reported on 9 June 2026 that the records of roughly 3,000 officers had been exposed, with the data spanning 2024 to 2026 and the leak itself appearing to have happened in May. Those files were health records: diagnoses, treatment notes, and surgical history, the sort of information an officer shares with a doctor and expects to go no further.
SAPS Western Cape management's first instinct was to play it down as an administrative slip. That framing did not survive contact with the facts, and the service has since formally acknowledged it as a reportable POPIA breach involving the unlawful disclosure of sensitive medical and personal data. The Police and Prisons Civil Rights Union (POPCRU) has demanded a full review of the medical, absenteeism, and leave management systems that hold this information, and the SAPS medical aid scheme is separately checking whether its own data was caught up in it.
The detail that should stay with any business owner is where the data lived. It came out of the everyday HR-adjacent systems that track who is off sick, who is on leave, and who has a condition that affects their work, the same systems almost every business runs in some form, on a shared drive or in an HR inbox or a spreadsheet.
Why this matters more under POPIA
Under POPIA, health information sits in a category of its own. Section 26 classifies it as special personal information, the same protected tier as religious beliefs, race, and biometric data, and processing it is prohibited by default unless you meet a specific legal ground. The reasoning is plain. A leaked phone number is a nuisance, but a leaked cancer diagnosis or a record of treatment for addiction can cost someone a promotion or their standing among colleagues, and none of it can be pulled back once it is out.
Most SA business owners do not picture themselves as holders of medical data, yet nearly all of them are. The sick note in an employee's file is medical information. So is the medical aid form, the injury-on-duty record kept for the Compensation for Occupational Injuries and Diseases Act (COIDA), and the HR note about an accommodation for a chronic condition. Businesses in healthcare, education, and law hold far more of it again. The moment that information sits on a device or in an account you control, POPIA's duty to apply reasonable safeguards (Section 19) sits with you, and so does the duty to notify the Information Regulator and the affected person when it leaks (Section 22).
The "administrative error" reflex is itself a warning. When sensitive data leaks, the first move is often to shrink the language and hope it passes, and under POPIA that does not pause the clock on your notification duties. For a Durban SME holding staff medical files in a folder half the office can open, the distance between "we had a filing mix-up" and "we unlawfully disclosed special personal information" is one disgruntled employee or one misdirected email wide.
What to do this week
- Find every place employee health information lives. Sick notes, medical certificates, medical aid forms, COIDA injury records, and any HR note that mentions a diagnosis or an accommodation. Most businesses have never mapped this, which is exactly why they cannot protect it.
- Cut down who can reach it. Medical and HR records should not sit in a drive the whole team can open or a shared inbox that several people log into. Restrict access to the one or two people whose job needs it, and confirm everyone else is locked out.
- Separate health data from your other records. POPIA puts it in a higher tier, so store it that way, in a protected location with its own access controls, not folded into general staff folders.
- Stop moving this information through WhatsApp, personal email, and loose spreadsheets. Every forward and every download is another copy you no longer control, and every copy is somewhere it can leak from.
- Write down what you would do if it leaked. Name who contacts the Information Regulator, who tells the affected staff member, and how quickly. POPIA expects notification as soon as reasonably possible, and the middle of an incident is the wrong time to be inventing the process.
Where Ubuntu Guard fits
If you have never checked where your staff's medical and HR data sits, who can open it, or what POPIA expects of you as the responsible party, that is the ground our cybersecurity assessment covers. We map what you hold, work out who can reach it, and show you where the gaps are, then give you a plain-language report and a prioritised list of what to fix first.
Not sure where your employees' medical and personal information is sitting, or who can get to it? Our assessment tells you. WhatsApp us to book: wa.me/27791595040
Cybersecurity Made Simple
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za