Johannesburg: The proposed centralized electronic health record (EHR) system, a cornerstone of South Africa’s ambitious National Health Insurance (NHI), promises to revolutionize healthcare delivery. However, this digital transformation brings with it a formidable challenge: safeguarding the sensitive medical data of millions of citizens from cyber threats.
Experts warn that the NHI’s success hinges on embedding robust cybersecurity measures from the outset. “Cybersecurity needs to be woven into the NHI’s EHR system from the ground up, not treated as an afterthought,” cautions Calin Cloete, Enterprise Security Solutions Lead at ESET Southern Africa.
The interconnected nature of a national EHR system creates vulnerabilities. A single breach could potentially compromise the entire healthcare infrastructure, making a proactive “zero-trust” approach essential. This approach, built on the principle of “never trust, always verify,” mandates stringent security measures like multi-factor authentication and role-based access control for all users, including healthcare providers, administrators, and patients.
“Essentially, the idea is to divide the network into very small segments – each with its own tight access control – and ensure that users only have access to the data they need to perform their duties,” explains Cloete. “This limits the ‘blast radius’ of any potential breach.”
Currently, EHR adoption in South Africa is alarmingly low, with only an estimated 40% of healthcare professionals using digital records. This indicates a steep learning curve for the majority of the country’s healthcare workers, who will need comprehensive training in both technology usage and cybersecurity best practices.
“While implementing a zero-trust architecture can help to reduce the likelihood of basic security errors, it can’t eliminate all human error,” Cloete emphasizes. “Phishing attacks, social engineering, and insider threats still rely on manipulating staff – so cybersecurity training will be crucial.”
The NHI will operate under the stringent Protection of Personal Information Act (POPIA), legally mandating the protection of patient data. Healthcare institutions will therefore have a vested interest in ensuring staff are well-versed in cybersecurity protocols to avoid legal repercussions.
The sheer volume and sensitivity of data stored within the NHI’s EHR system make it a prime target for cybercriminals. “This data is extremely valuable, and for cybercriminals, that means its particularly lucrative,” Cloete warns. “At the same time, any changes to patient data can impact their treatment, which puts lives at risk.”
EHRs, encompassing medical histories, prescriptions, and test results, offer significant benefits, including improved workflow and accelerated decision-making. However, these benefits can only be realized if the system is adequately secured.
“While the implementation of a zero-trust approach will require significant investment in technology, infrastructure, and staff training – the consequences of a data breach could end up costing far more,” concludes Cloete. The message is clear: the NHI’s success, and the security of South Africa’s healthcare data, depend on a robust, proactive cybersecurity strategy.
















