MediDesk policies
Acceptable Use Policy
Rules for lawful, authorised, and secure use of MediDesk by practices and their users.
This Acceptable Use Policy ("AUP") forms part of the MediDesk Terms of Service. Customers are responsible for ensuring all their users comply.
1. Permitted Use
MediDesk may only be used for lawful practice management purposes by authorised staff of a subscribing private healthcare practice, in compliance with all applicable South African law, POPIA, HPCSA guidelines, and professional obligations.
2. General Rules
All users must:
- use only their own individually named account — credential sharing is prohibited;
- access only the data and features their role permits;
- keep login credentials confidential and report suspected compromise to security@desklabs.co.za immediately;
- comply with these Terms and this AUP at all times.
Customer administrators are responsible for managing user access, assigning appropriate permissions, and removing access for departed or unauthorised staff promptly.
3. Prohibited Uses
Data access and disclosure
- Access, view, export, or disclose patient or practice data without authorisation.
- Browse patient records for any purpose other than a legitimate practice function.
- Copy or export patient data to personal devices, personal email, or unapproved systems.
Security and system integrity
- Share, sell, or transfer credentials to any other person.
- Attempt to bypass authentication, role permissions, Row Level Security, rate limits, or feature flags.
- Access or attempt to access another practice's data.
- Conduct security testing, penetration testing, or vulnerability scanning without DeskLabs' prior written approval.
- Upload malware, ransomware, exploit payloads, or any harmful code.
Communications and payments
- Send patient communications without the required authority or consent.
- Send spam or messages that violate POPIA's direct marketing provisions.
- Send fraudulent payment requests, false invoices, or misleading billing information.
- Configure payment or bank details fraudulently.
- Abuse SMS credit allocations, purchase credits fraudulently, or attempt to circumvent monthly SMS limits.
- Misuse walk-in queue check-in pages, consent forms, or appointment detail links for purposes other than managing patient arrivals and notifications.
AI Voice Receptionist
- Use the AI Voice Receptionist for emergency calls, clinical triage, or medical advice.
- Configure the AI Voice Receptionist to provide clinical guidance, diagnoses, or treatment recommendations.
- Enable call recording without configuring an appropriate consent message for callers.
- Rely on AI-generated transcripts or summaries as accurate medical or legal records without independent review.
- Misrepresent the AI Voice Receptionist as a human receptionist or medical professional.
Clinical misuse
- Use MediDesk as the sole basis for clinical decisions without independent professional review.
- Use MediDesk for emergency medical advice, triage, or emergency dispatch.
- Enter fabricated patient data in production without DeskLabs' prior written approval.
Support and bug reports
- Attach screenshots or files containing patient personal information or health records to support tickets unless strictly necessary to demonstrate the reported issue.
- If patient information is included in a support submission, notify DeskLabs immediately and minimise the scope of the disclosure.
- Paste or share patient personal information in external tools (Slack, email, GitHub, ChatGPT, or other AI tools) when seeking help with MediDesk issues.
- Use AI tools or external services to process patient data exported from MediDesk without a valid legal basis and appropriate data protection agreements.
Platform and IP
- Send requests in volumes that adversely affect platform performance.
- Reverse engineer, copy, or attempt to derive MediDesk's source code.
- Resell or sublicense access to MediDesk.
4. Healthcare-Specific Rules
MediDesk must never be used in emergency situations or where a system failure could endanger patient safety. Practices must maintain independent emergency procedures.
Treating practitioners remain solely responsible for all clinical decisions, diagnoses, prescriptions, treatment plans, patient care, informed consent, billing codes, and professional obligations. MediDesk does not replace professional judgement and has no clinical role of any kind.
The AI Voice Receptionist is an administrative call-handling tool only. It must not be used for clinical triage, emergency dispatch, or medical advice. Practices must ensure callers with emergencies are directed to appropriate emergency services.
Practices must have authority to contact patients, guardians, or caregivers via any channel used through MediDesk, and must manage opt-out requests promptly.
5. Reporting
Suspected AUP violations, security vulnerabilities, or unauthorised data access must be reported to:
- Support: support@desklabs.co.za
- Security: security@desklabs.co.za
6. Enforcement
DeskLabs may, without prior notice where urgency requires, take any of the following actions in response to a suspected or confirmed AUP violation:
- warn or require remediation;
- restrict or disable features such as SMS sending, AI Voice Receptionist, file uploads, or public links;
- reset passwords or suspend user accounts;
- suspend the Customer's entire account;
- preserve and retain relevant evidence;
- report unlawful activity to relevant authorities;
- terminate the subscription for serious or repeated violations.
DeskLabs is not liable for any loss arising from enforcement action taken in good faith.
Contact: legal@desklabs.co.za | security@desklabs.co.za | desklabs.co.za
