Single Blog Title

This is a single blog caption

GDPR Obligations for Hospitals and Clinics: Protection of Patient Data

Entrance

Hospitals, clinics, doctor's offices, dental clinics, cosmetic centers, laboratories, imaging centers, psychological counseling centers, physical therapy centers, and similar healthcare providers are among the institutions where personal data is processed most intensively and sensitively. A patient's name, surname, Turkish Republic identity number, telephone number, address, appointment information, payment information, insurance information, prescription, test results, radiology images, diagnosis, surgical history, medications used, allergy information, psychiatric evaluation record, pregnancy information, genetic data, or biometric data may be processed by a healthcare institution.

A significant portion of this data is not only "personal data" but also special categories of personal data . Health data, if disclosed, is subject to stricter protection under the Personal Data Protection Law (KVKK) because its disclosure could lead to discrimination, harm to the individual within their social environment, damage to their professional life, or violation of their privacy. The Personal Data Protection Authority also states that special categories of personal data, if disclosed, could cause discrimination or harm to the data subject and therefore require stricter protection than other personal data.

Therefore, GDPR compliance for hospitals and clinics is not simply about adding a "GDP text" to their website. It must be clearly defined for what purpose patient data is processed, what legal basis it is based on, which units have access to this data, and whether the data is shared with Ministry of Health systems, laboratories, insurance companies, physicians, pharmacies, suppliers, or service providers abroad. The Regulation on Personal Health Data, published by the Ministry of Health, was also published in the Official Gazette on June 21, 2019, to regulate the procedures and principles to be followed in processes related to personal health data in the Ministry's central and provincial organizations and affiliated healthcare providers.

What is Patient Data?

Patient data refers to any information relating to a person seeking or receiving healthcare services. This includes not only records related to illness, but also patient identification information, contact information, appointment records, admission documents, consent forms, laboratory results, radiology images, discharge summaries, prescriptions, payment information, private health insurance information, call center records, and security camera footage.

The most sensitive group of patient data is health data. Health data is any information relating to a person's physical or mental health. This includes test results, blood type, information on chronic diseases, history of psychiatric treatment, surgical information, pregnancy information, HIV test results, genetic disease risk, cancer diagnosis, medication use, disability reports, and treatment plans. Under the Personal Data Protection Law (KVKK), health data is considered special categories of personal data. The law specifies a limited number of special categories of personal data, including a person's health, sexual life, biometric, and genetic data.

Therefore, healthcare organizations need to handle patient data with more care than ordinary commercial businesses. Processing a customer's delivery address on an e-commerce site is not as sensitive as processing a patient's oncology report on a hospital. Sending patient data to the wrong person, disclosing it to unauthorized personnel, sharing it in WhatsApp groups, using it on social media, or processing it for advertising purposes can have serious legal consequences.

Under what legal grounds can health data be processed?

Hospitals and clinics often process health data for purposes such as diagnosis, treatment, care, appointments, patient admission, laboratory tests, imaging, surgery, prescriptions, billing, and healthcare planning. However, the correct legal basis must be determined for each data processing activity.

The Personal Data Protection Law (KVKK) regulates specific conditions for the processing of special categories of personal data. Law No. 7499 amended Article 6 of Law No. 6698, expanding the conditions for processing special categories of personal data. Following this amendment, the Personal Data Protection Authority published a "Guide on the Processing of Special Categories of Personal Data" to ensure that data controllers processing special categories of personal data have the correct legal basis.

Explicit consent is not always the sole legal basis for processing health data. Under the Personal Data Protection Law (KVKK), health data may be processed without explicit consent in certain cases. In particular, for purposes such as protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning and managing health services and their financing, health data may be processed by individuals or authorized institutions and organizations bound by an obligation of confidentiality. The KVKK explicitly states that health data is special categories of personal data and can only be processed in the limited circumstances specified in the Law.

However, data processing necessary for the provision of healthcare services is not the same as advertising, marketing, social media sharing, using patient testimonials, clinical promotion, or unnecessary sharing with third parties. While showing a patient's test results to a doctor for treatment may be legally permissible, mistakenly sending the same test results to another patient or disclosing them to unrelated individuals constitutes an unlawful transfer of data.

When is explicit consent required?

One of the most common mistakes in the healthcare sector is the belief that obtaining general explicit consent from the patient for each procedure renders all data processing activities legally compliant. However, explicit consent must be given freely, based on informed knowledge, and related to a specific matter. General statements such as "I consent to the processing and sharing of my health data for any purpose" carry legal risks.

Explicit consent may be required, particularly in data processing activities that are not a mandatory element of healthcare services. For example, sharing a patient's photo as a "before-and-after" image on a social media account, using the treatment process for advertising purposes, publishing patient testimonials with names and images, processing health data for scientific research or marketing purposes, sending campaign messages to patients, or certain international data transfer activities for which there is no legal basis other than explicit consent may all require explicit consent.

However, even with explicit consent, data processing activities must be proportionate. A healthcare institution cannot store a patient's entire medical history indefinitely, share it with unrelated personnel, or use it extensively for advertising purposes simply because the patient has given consent. Explicit consent does not negate the principles of lawfulness, fairness, specific and legitimate purpose, proportionality, and retention for the necessary period stipulated in the Turkish Personal Data Protection Law (KVKK).

How Should Hospital and Clinic Privacy Notices Be Prepared?

One of the most fundamental obligations of hospitals and clinics is the obligation to inform. The information notice should explain to the patient who is processing their data, for what purpose, on what legal grounds, by what methods, to whom it may be transferred, and their rights under the Personal Data Protection Law (KVKK). The KVKK Authority's public announcement dated June 8, 2026, stated that information notices should use clear, concise, and simple language; general, vague, incomplete, or misleading information should not be included. The same announcement also specifically emphasized that "processing purpose" and "legal grounds" are separate elements.

In healthcare facilities, a single general information text is often insufficient. Patient admission information, employee information, visitor/camera information, website cookie information, call center information, job application information, and specific processes requiring explicit consent should be evaluated separately. For example, identity and contact data during patient admission are processed for the purpose of providing healthcare services; camera recordings are processed for security purposes; data from contact forms on the website are processed for appointment or request management; and the use of patient images for social media promotion may require separate explicit consent.

The privacy policy should clearly indicate the data transfer processes. Health data may be shared with physicians, laboratories, imaging centers, pharmacies, private insurance companies, public institutions, contracted service providers, lawyers, or financial advisors. However, the purpose of each transfer and the recipient group must be clearly stated. The Personal Data Protection Authority (KVKK) states that when personal data transfers are involved, the purpose of the transfer and the recipient groups must be specifically included in the privacy policy.

Sharing Patient Data with Third Parties

Patient data should only be shared with those who need access based on their duties and authorization. Different individuals, such as doctors, nurses, admissions staff, laboratory personnel, accounting, or insurance departments, may have access to a patient's health data; however, this access should not be unlimited. Each staff member should only have access to the data necessary for their duties.

Sharing information with family members, in particular, should be done carefully. Being a relative, spouse, parent, or child of the patient does not automatically grant access to all health data. Different assessments may be made if the patient has lost consciousness, requires emergency intervention, or there is a legal obligation; however, under normal circumstances, there must be a legal basis for disclosing the patient's health information to their relatives.

In its decision dated May 20, 2020, numbered 2020/407, the Personal Data Protection Board determined that patient test results are sensitive personal data related to health and that transferring them to a third party without legal basis constitutes a violation of the Personal Data Protection Law. This decision shows that even sending test results, reports, prescriptions, epicrisis, or imaging results to the wrong person can lead to serious liability.

Therefore, hospitals and clinics should establish authentication mechanisms in SMS, email, patient portal, WhatsApp, call center, and physical document delivery processes. If test results are sent via email, address verification should be performed, and encryption should be used if necessary; if delivery is to a patient's relative, authorization should be checked.

Sharing Patient Information via WhatsApp, SMS, and Email

In healthcare settings, appointment scheduling, test results, photos, prescriptions, and payment information are often shared via WhatsApp due to practicality. However, the uncontrolled sharing of health data through WhatsApp or similar applications carries serious risks. The platforms' international connections, end-to-end encryption, device security, screen capture risks, the possibility of sending data to the wrong person, and data storage policies should be evaluated separately.

If health data is to be sent via email, the adequate precautions specified in the Board's decision no. 2018/10 regarding the transfer of sensitive personal data must be taken into account. According to this decision, if sensitive personal data needs to be transferred via email, it must be transferred using encrypted corporate email addresses or KEP (Registered Electronic Mail) accounts; encryption must be applied using cryptographic methods when transferring data via portable memory devices, CDs, or DVDs; and methods such as VPN or sFTP must be used when transferring data between different servers.

Caution should also be exercised with SMS notifications. An appointment reminder message is not the same as a message containing diagnosis, test results, or treatment details. While limited information can be sent for appointment reminders, a message like "Your oncology test results are ready" could violate privacy if seen by someone else on the phone. Therefore, healthcare organizations should regulate message content in accordance with the principle of data minimization.

Camera Recordings and Visitor Data in Healthcare Facilities

Hospitals and clinics may use cameras for security purposes. However, camera recordings also constitute personal data. Furthermore, camera footage can become even more sensitive for healthcare institutions; because even seeing a person enter a particular clinic, psychiatric center, IVF center, oncology ward, or cosmetic clinic can indirectly provide information about their health status.

Therefore, camera systems should be installed in a measured way. Camera use may be justified in entrances, corridors, waiting areas, and places where security risks exist; however, camera use in examination rooms, treatment rooms, patient rooms, breastfeeding rooms, restrooms, changing areas, or places where privacy is highly anticipated poses serious legal risks.

Layered lighting should be implemented in areas where cameras are located. Visible warning signs should include information about the data controller, the purpose of recording, and access to detailed information text; the duration for which camera recordings are stored and who has access to them should also be regulated. The Personal Data Protection Authority states that the lighting should be easily accessible and noticeable, and that methods that make it difficult for data subjects to access the lighting should be avoided.

Technical and Administrative Measures to be Taken for Special Categories of Data

Because health data is considered sensitive personal data, hospitals and clinics must implement higher security standards. The Personal Data Protection Board's decision No. 2018/10 states that separate policies and procedures must be established for sensitive personal data, regular training must be provided to personnel working with this data, confidentiality agreements must be in place, access rights must be clearly defined, periodic access controls must be conducted, and access must be immediately revoked in case of job changes or termination of employment.

For health data stored electronically, measures such as cryptographic methods, secure logging, security updates, regular testing, user authorization, and at least two-factor authentication for remote access are important. For patient files stored physically, precautions should be taken against archive security, fire, flood, theft, unauthorized access, and the transmission of classified documents.

One of the most common risks in clinics is excessive staff access to patient files. While reception staff may only need access to appointment and contact information, having access to all test results can be disproportionate. Accounting staff may need access to payment and billing information; however, access to detailed patient diagnostic records is often unnecessary. Therefore, task-based access authorization should be implemented.

Patient Data Storage and Destruction Process

Patient data cannot be stored indefinitely. However, due to the nature of healthcare services, some records may need to be retained for extended periods. When determining the retention period, healthcare legislation, medical record obligations, statutes of limitations, potential malpractice claims, billing and accounting records, insurance processes, and notification obligations to public institutions should all be considered.

Hospitals or clinics must establish retention periods for each data category. Appointment records, patient files, informed consent forms, test results, radiology images, payment records, call center records, security camera footage, and marketing releases do not all need to be retained for the same period. While retaining security camera footage for extended periods may be disproportionate in many cases, medical records may require even longer retention.

Data whose retention period has expired must be deleted, destroyed, or anonymized. Keeping all patient data indefinitely with the thought of "it might be needed later" may violate the Personal Data Protection Law (KVKK). Destruction processes should be recorded, and electronic and physical archives should be regularly checked.

What should hospitals and clinics do in case of a data breach?

Data breaches in healthcare organizations can have very serious consequences. Theft of patient files, cyberattacks on hospital information management systems, sending laboratory results to the wrong person, theft of patient photos from a doctor's personal phone, email hacking, or the online publication of patient records can all constitute data breaches.

According to the Personal Data Protection Law (KVKK), if personal data processed is obtained by others through unlawful means, the data controller is obliged to notify the data subject and the Board as soon as possible. The KVKK Authority states that, in accordance with the Board's decision dated January 24, 2019, and numbered 2019/10, the data controller must notify the Board without delay and within a maximum of 72 hours from the date they become aware of the breach.

The reporting process for breaches involving health data should be handled with greater care. The number of individuals affected, the data categories, when the breach began and was detected, the measures taken, and the channels through which affected individuals can obtain information should be disclosed. A 2026 data breach announcement by the Personal Data Protection Authority (KVKK) stated that data belonging to patients involved in medical device complaints was subject to breaches, and that health information was among the affected data categories.

Therefore, hospitals and clinics should have a data breach response plan. IT, legal, quality, patient relations, management, and relevant medical units must work together during a crisis. The breach should not be concealed; evidence must be preserved, technical analysis must be conducted, and notification to the Board and relevant parties must be evaluated.

Use of Health Data in Advertising and Social Media

Clinics, particularly in fields such as aesthetics, dentistry, hair transplantation, dermatology, and obesity surgery, may wish to use patient photos for promotional purposes. However, a patient's "before-and-after" image, treatment results, facial photos, or procedure videos may be linked to health data. Such sharing carries serious risks regarding GDPR and patient privacy.

Even if a patient's face is obscured in the photograph, they may be identifiable through tattoos, scars, voice, clinical history, type of procedure, or other distinguishing information. Therefore, explicit, separate, specific, and verifiable consent must be obtained for social media sharing. The patient must know which image will be published on which platform, for what purpose, and for how long. They should not be denied access to healthcare services if they do not give their consent.

Healthcare organizations should also be cautious when using patient testimonials and success stories. Posts such as "Our patient X successfully completed cancer treatment" or "Our patient Y after rhinoplasty…" can pose risks even if they don't reveal the individual's identity, as they contain health information. Advertising and promotional activities should be evaluated not only under the Personal Data Protection Law (KVKK) but also in terms of healthcare legislation and professional ethics.

Employee Data and Healthcare Organizations

Hospitals and clinics process not only patient data but also employee data. Records may be kept for physicians, nurses, technicians, admissions staff, cleaning staff, security guards, and administrative personnel, including identity, contact information, payroll, personnel files, medical reports, professional qualifications, diplomas, certificates, shifts, performance, and disciplinary records.

Healthcare workers may also have their health data or sensitive personal data processed. Examples include pre-employment medical reports, periodic examination records, vaccination information, workplace accident records, and occupational risk assessments. This data should be explained separately in the employee information notice and processed only to the extent necessary for occupational health and safety or employment obligations.

Employees' access to patient data should also be controlled. Every employee should not have access to all patient data. In particular, the access of former employees to the Hospital Information System (HIS), laboratory system, email, and archives should be immediately blocked. The Personal Data Protection Board's decision No. 2018/10 regarding sensitive personal data clearly states that the access of employees who change roles or leave the company should be immediately revoked.

International Data Transfer and Cloud Systems

If healthcare organizations use patient tracking software, cloud backup, telemedicine infrastructure, call center systems, appointment scheduling software, email services, image archiving, or AI-powered analytics tools, the possibility of transferring data abroad should be examined separately. The transfer of health data abroad should be evaluated more strictly due to its sensitive nature.

The Personal Data Protection Authority (KVKK) has previously emphasized in its announcements that data centers used through cloud service providers may mostly be located abroad, and in such cases, compliance with the KVKK's provisions regarding data transfer abroad is required.

Therefore, it is not enough for clinics to say, "We obtained the program externally, we don't know where the data is stored." The location of the software server, the sub-service providers, the country from which the support team accesses the data, whether the data is encrypted, where backups are stored, and the mechanism used for international data transfer should all be regulated by contract.

The Most Common GDPR Mistakes Made by Hospitals and Clinics

The most common initial mistake in healthcare settings is assuming that simply having a patient sign a general form automatically renders all data processing legally compliant. However, informed consent, explicit consent, and medical consent are distinct legal procedures.

The second mistake is allowing too much access to patient data. Admissions staff, accounting, physicians, nurses, and laboratory personnel should all have different levels of access.

The third mistake is the uncontrolled sharing of test results, reports, or photos via WhatsApp and personal email. Secure transfer methods should be used for sensitive data.

The fourth mistake is using patient images for social media promotion without their explicit consent. Patient photographs, treatment processes, or procedure results cannot be used as advertising material without explicit consent.

The fifth mistake is failing to define data retention periods. Camera footage, call logs, appointment logs, patient files, and payment records should not be stored for the same duration.

The sixth mistake is not having a data breach plan. Rapid notification and crisis management are vital in a health data breach.

The seventh mistake is failing to analyze the use of foreign servers or cloud software in terms of Article 9 of the Turkish Personal Data Protection Law (KVKK). This is particularly risky in systems containing health data.

Conclusion

For hospitals and clinics, compliance with the Personal Data Protection Law (KVKK) is a fundamental requirement for patient privacy and trust in healthcare services. Since health data is considered special categories of personal data, its processing, storage, transfer, and destruction are subject to stricter rules than ordinary personal data. Healthcare organizations must process patient data only for specific, clear, and legitimate purposes; based on sound legal grounds; and in a proportionate and secure manner.

Information texts should be prepared clearly and understandably, situations requiring explicit consent should be separately defined, and medical consent should not be confused with explicit consent under the Personal Data Protection Law (KVKK). Extreme caution should be exercised when sharing test results, health reports, prescriptions, imaging records, and patient photographs with third parties. The Board's decision No. 2020/407 regarding the unlawful transfer of test results demonstrates that sending health data to the wrong person or to a third party without legal basis can lead to serious liability.

Healthcare organizations must also implement the technical and administrative measures specified in the Board's decision no. 2018/10 for sensitive data; restrict access rights, provide personnel training, obtain confidentiality commitments, store data in encrypted and secure environments, carry out data transfer using secure methods, and take into account the 72-hour Board notification period in case of a data breach.

In conclusion, GDPR compliance for hospitals and clinics is essential not only to protect against legal sanctions but also to safeguard patient trust, ensure the confidentiality of healthcare services, and strengthen institutional reputation. A properly established GDPR system makes all healthcare processes, from patient admission to test results, camera recording to social media sharing, employee access to data breach management, secure, transparent, and compliant with the law.

Leave a Reply

Call Now Button