Single Blog Title

This is a single blog caption

The Importance of Health Data Protection and Information Law

Entrance

Health data is one of the most sensitive and critically protected data groups within personal data. A person's illness, diagnosis, treatment history, medications used, laboratory results, genetic characteristics, psychiatric condition, surgical information, pregnancy status, sexual health, disability information, blood type, radiological images, and medical reports are not merely technical information; they are data that can directly impact a person's private life, social standing, work relationships, family life, insurance status, and personal rights.

Therefore, the protection of health data is not merely compliance with the Personal Data Protection Law (KVKK ). It is also directly linked to patient privacy, the right to privacy, medical secrets, medical ethics, patient rights, hospital management, cybersecurity, cybercrimes, and compensation law. If health data is illegally obtained, shared, or leaked, the victim not only suffers a violation of privacy but may also face social stigma, job loss, insurance problems, family problems, psychological harm, and financial losses.

In Turkey, one of the fundamental regulations regarding the protection of health data is the Law No. 6698 on the Protection of Personal Data(KVKK). According to Article 6 of the KVKK, individuals' health data falls under the category of special categories of personal data. Special categories of personal data are those that, if processed unlawfully, can lead to discrimination or serious harm to the data subject. Therefore, health data requires a much higher level of protection than ordinary contact or identity information. Article 6 of the KVKK lists information such as health, sexual life, biometric, and genetic data as special categories of personal data.

What is health data?

Health data is any information relating to a person's physical or mental health. This scope is quite broad. Hospital records, examination information, diagnosis and treatment records, test results, radiology images, surgical notes, discharge summaries, prescriptions, medication usage information, blood tests, genetic test results, psychological evaluation records, medical board reports, disability reports, disability ratings, vaccination records, and information on chronic diseases can all be considered health data.

Health data is not limited to official files kept in hospitals. Data such as heart rate, sleep, steps, calories, blood pressure, blood sugar, menstrual cycle, pregnancy tracking, mood, and sports performance collected in mobile health applications can also qualify as health data depending on the specific situation. Smartwatches, wearable technologies, telemedicine applications, online psychological counseling platforms, and digital appointment systems can also process personal health data.

Therefore, the protection of health data is not solely the concern of hospitals and doctors. Private hospitals, clinics, dentists, psychologists, laboratories, pharmacies, health tourism companies, insurance companies, employers, digital health applications, software companies, cloud service providers, and call centers may also process health data. These individuals and organizations are obliged to comply with the Personal Data Protection Law (KVKK), specific legislation, patient rights, and information technology law rules when processing health data.

Why is health data considered special category personal data?

The reason health data is considered special categories of personal data is that its disclosure could cause serious harm to the individual. For example, if a third party learns that a person is undergoing psychiatric treatment, is HIV positive, receiving cancer treatment, has had an abortion, carries a genetic disease, or is receiving addiction treatment, this could directly affect their social, professional, and family life.

Therefore, a simple explicit consent form or a general privacy policy is insufficient for processing health data. Data processing conditions, obligation to inform, access authorization, data security, retention period, transfer abroad, data breach notification, and data destruction processes for health data must be managed more meticulously.

In the current framework of Article 6 of the KVKK (Law on Protection of Personal Data), the processing of special categories of personal data is generally prohibited; however, it may be processed in the exceptional cases listed in the law. Regarding health data, it is particularly important that processing be carried out by persons or authorized institutions and organizations bound by an obligation of confidentiality, for purposes such as protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of health services and their financing.

Basic Principles in Health Data Processing

When processing health data, the general principles of the Personal Data Protection Law (KVKK) must be adhered to. These principles include: compliance with the law and rules of fairness, accuracy and timeliness when necessary, processing for specific, explicit and legitimate purposes, being relevant, limited and proportionate to the purpose, and retention for the necessary period.

For example, a hospital can process information necessary for a patient's diagnosis and treatment. However, requesting unnecessary information unrelated to treatment, using health data for marketing purposes, sharing patient lists with third parties, or allowing employees unrestricted access to all patient files creates legal risks.

The principle of proportionality is particularly important in health data. A clinic can ask for the name, surname, phone number, and reason for the appointment from someone requesting one. However, if a simple preliminary consultation form requests a detailed medical history, a complete list of medications, family illnesses, and unnecessary personal information, this can create problems in terms of the data minimization principle. The healthcare institution should only request the data necessary for the service and should not use this data for purposes other than those specified.

Regulation on Personal Health Data

One of the specific regulations in the field of health data in Turkey is the Regulation on Personal Health Data. According to the Ministry of Health, the Regulation was published in the Official Gazette dated June 21, 2019, and numbered 30808, and entered into force. The Regulation was prepared to regulate the procedures and principles to be followed in the processes of the Ministry's central and provincial organizations, affiliated health service providers, and related institutions.

The importance of this regulation lies in the fact that health data is regulated not only under the general provisions of the Personal Data Protection Law (KVKK), but also specifically, taking into account the unique nature of healthcare services. Healthcare requires continuity, accessibility, and rapid access to accurate information. However, this need does not negate the patient's privacy. Healthcare providers are obligated to take the necessary technical and administrative measures to protect the privacy of all health data, including test results, examinations, diagnoses, treatments, reports, imaging, and patient files. The Ministry of Health has clarified with this regulation that no one can be forced to share their health data except in cases where it is mandatory for the provision of healthcare services, and that healthcare facilities are obliged to take the necessary measures to protect the privacy of all patient data.

e-Nabız and the Digitalization of Health Data

e-Nabız is one of the most important digital systems in terms of protecting health data . According to the Ministry of Health, e-Nabız is a website that allows individuals to access their own health information through a single portal. The purpose of e-Nabız is to enable citizens and physicians authorized by citizens to access their personal health data effectively and efficiently through information and communication technologies.

The e-Nabız system provides great convenience in healthcare services. Patients can view their past test results, prescriptions, radiology images, reports, and examination records; and physicians can access the patient's past health information during the treatment process. This can improve the quality of treatment, reduce unnecessary tests, and enable quick decision-making in emergency situations.

However, ease of digital access also increases the responsibility for data security. The security of data processed in centralized health record systems such as e-Nabız is critical not only in terms of individual privacy but also in terms of public health and the reliability of healthcare services. The Ministry of Health's information page regarding the e-Nabız personal health record system states that the Ministry of Health of the Republic of Turkey is the data controller with respect to personal data processed in e-Nabız.

Responsibility of Healthcare Institutions Under the Personal Data Protection Law

Hospitals, clinics, doctor's offices, laboratories, medical centers, dental clinics, psychological counseling centers, and health tourism companies often act as data controllers when processing personal health data. The data controller is the person who determines the purposes and means of processing personal data. A healthcare organization is considered a data controller if it decides which patient data will be collected, in which system it will be stored, which personnel will have access to it, and with which laboratory or insurance company it will be shared.

In this context, healthcare institutions must inform patients, avoid collecting unnecessary data, restrict access to health data, impose confidentiality obligations on their employees, enter into contracts with data processors, secure their digital systems, notify the Board and relevant individuals in case of data breaches, and implement storage and destruction processes.

According to the Turkish Personal Data Protection Law (KVKK), data controllers are obliged to take the necessary technical and administrative measures to ensure an appropriate level of security to prevent the unlawful processing and unlawful access to personal data, and to ensure the preservation of personal data. The Authority states that the measures to be taken should be determined according to the structure, activities, and risks of each data controller; the size of the company, as well as the nature of the personal data processed, is also important. Since health data is of a sensitive nature, the level of security measures should be higher in healthcare institutions.

Patient Information and Explicit Consent

Healthcare institutions must explain to patients in a clear and understandable way how their personal data is processed. The patient information document should include the identity of the data controller, the categories of data processed, the purposes of data processing, the legal grounds, the individuals and institutions to whom data may be transferred, the data collection methods, and the patient's rights under the Personal Data Protection Law (KVKK).

The key point here is that explicit consent is not required for every process necessary for the provision of healthcare services. Health data may be processed without explicit consent in certain circumstances if legal conditions exist, such as the provision of medical diagnosis, treatment, and care services, the protection of public health, and the planning of healthcare services and their financing. However, a separate legal assessment should be made regarding the use of health data for marketing purposes, its transfer to third parties for advertising purposes, unnecessary profiling, or processing for purposes unrelated to healthcare services.

The explicit consent obtained from the patient must also be valid. Explicit consent must be given freely, based on informed knowledge, and related to a specific matter. Broad and vague consent forms that are made a mandatory condition for accessing healthcare services may be legally debatable. For example, general statements such as "I agree to the processing of all my health data for any purpose" carry a serious risk in a sensitive data category such as health data.

Hospital Information Management Systems and IT Law

The majority of healthcare data is now stored in digital systems. Hospital Information Management Systems, laboratory information systems, PACS/radiology imaging systems, e-prescription infrastructures, patient portals, online appointment systems, telemedicine applications, and mobile health applications are central to healthcare informatics law.

Maintaining accurate medical records alone is not sufficient for the lawful operation of these systems. It is crucial to know who has access to the system, whether access is logged, whether former employees' privileges have been revoked, whether physician and support staff access rights are limited to their duties, whether patient data is encrypted, whether backups are securely maintained, and whether an incident response plan is in place in case of a data breach.

Unauthorized access to health data constitutes a serious violation under information technology law. For example, a hospital employee accessing the test results of an acquaintance out of curiosity, a doctor accessing the records of a patient with whom they have no treatment relationship, a former employee continuing to access the system, or copying health data to a USB drive can all lead to liability under both the Turkish Personal Data Protection Law and criminal law.

Cybersecurity Aspects of Health Data

The healthcare sector is one of the high-risk areas for cyberattacks. Hospitals and healthcare organizations process a large amount of sensitive data and must provide uninterrupted service. Therefore, ransomware attacks, data breaches, unauthorized access, phishing attacks, weak password usage, outdated software vulnerabilities, and supplier-related security flaws pose serious risks to the healthcare sector.

Encrypting a hospital's patient database is not only a data privacy breach; it can also disrupt healthcare services. The failure of information systems in critical units such as the emergency room, operating theater, laboratory, and intensive care unit can directly impact patient safety. Therefore, the protection of healthcare data is not only a matter of privacy but also of service continuity and patient safety from the perspective of information technology law.

Healthcare organizations need to implement measures such as strong password policies, multi-factor authentication, access restrictions, log management, regular penetration testing, backups, encryption, firewalls, antivirus software, user training, data masking, supplier security, and incident response plans. The "anyone can access any file" mentality is unacceptable, especially in systems that process sensitive healthcare data.

Health Data Breach and 72-Hour Notification

The unlawful acquisition of health data by others constitutes a data breach. For example, leaking patient lists online, sending laboratory results to the wrong person, unauthorized access to systems other than e-Nabız (the Turkish national health information system), a hospital employee disclosing patient data to third parties, a health tourism company sharing patient photos without permission, or a clinic's computer being compromised by ransomware can all be considered data breaches.

According to the decision of the Personal Data Protection Board dated 24.01.2019 and numbered 2019/10, the data controller must notify the Board without delay and within a maximum of 72 hours from the date they become aware of the data breach. After the individuals affected by the data breach are identified, they must also be notified directly or through appropriate methods as soon as reasonably possible. If notification cannot be made within 72 hours, the reasons for the delay must be explained to the Board.

Reporting health data breaches is particularly important. This is because if the data subject learns of a data breach, they can change their passwords, take precautions against fraud risks, protect against social or professional harm, and, if necessary, pursue legal action. Concealing a health data breach can lead to much more severe administrative and legal consequences for the data controller when it is discovered later. The latest announcements from the Personal Data Protection Law (KVKK) also emphasize that data breach notifications must be made within 72 hours.

Access Permissions and Log Records in Health Data

One of the most important issues in protecting health data is access rights. In healthcare organizations, physicians, nurses, technicians, patient admissions staff, laboratory personnel, billing unit staff, archive staff, call center staff, and IT personnel may have access to data at different levels. However, allowing everyone access to all patient data is excessive.

Access authorization should be limited to the task at hand. It may be illegal for staff unrelated to the treatment process to access a patient's psychiatric records, genetic test results, or personal reports. Similarly, it is risky for billing departments to have excessive access to medical details, for call center employees to view medical history, or for IT personnel to have unlimited access to content data.

Therefore, role-based authorization should be implemented in health information systems, access should be logged, log records should be regularly reviewed, and unusual access should be monitored. It should be possible to answer the question, "Who accessed which patient's data, on what date, and for what purpose?" Log records are important for internal audits, data breach investigations, and criminal prosecution.

Transfer of Health Data to Third Parties

Health data may be shared with third parties in certain situations. For example, data transfer may occur in cases such as laboratory services, radiology services, referral processes, insurance provisions, social security procedures, court or prosecutor requests, occupational health and safety processes, billing, health tourism coordination, or medical consultations.

However, every transfer must have a legal basis, purpose, and scope. Patient data should not be shared unnecessarily with third parties. For example, sending a patient's entire medical history to an insurance company may be excessive when only the information necessary for a specific pre-authorization process is sufficient. For a health tourism company to share a patient's before-and-after photos for advertising purposes, explicit, specific, and valid consent is required.

The transfer of health data abroad also requires special attention. If health data is shared with a doctor, insurance company, health tourism agent, cloud provider, CRM system, or foreign laboratory abroad, the conditions for data transfer abroad under Article 9 of the Personal Data Protection Law must also be evaluated.

Health Tourism and Digital Marketing Processes

In the medical tourism sector, the protection of health data is of particular importance. In fields such as hair transplantation, cosmetic surgery, dental treatment, IVF, obesity surgery, eye treatment, and similar areas, patients' photographs, treatment results, reports, and personal information are processed extensively in digital format.

Medical tourism companies often use WhatsApp, social media, CRM, international call centers, online advertising, and cloud systems. During these processes, patients' photos, medical histories, passport information, accommodation details, and treatment plans may be processed. This data may be classified as health data or special categories of personal data.

Sharing "before-and-after" photos for advertising purposes is a very sensitive issue. A patient submitting a photo for treatment does not automatically mean they consent to its use in social media advertising. Consent must be specific, clear, informed, and given freely. It must be clearly stated on which platform, for what purpose, and for how long the photo will be used.

Employers' Processing of Health Data

Employers can also process employees' health data. This may include pre-employment health reports, periodic examinations, work accident records, disability reports, disability information, pregnancy information, occupational disease records, and occupational health and safety documents.

However, the employer's authority to process health data is not unlimited. The employer may only process data necessary within the scope of the employment relationship, occupational health and safety, social security, payroll, leave, and legal obligations. An employee's illness diagnosis, medication use, or private medical information cannot be shared with all managers. Health reports should be processed only to the extent necessary by human resources or the occupational physician; employees' health information should not become a subject of gossip in the workplace.

For example, unnecessarily sharing information about an employee receiving psychiatric treatment with team managers could constitute a breach of sensitive personal data. Similarly, allowing unauthorized access to workplace accident reports, disability information, or pregnancy information creates legal liability.

The Criminal Law Aspects of Health Data

The unlawful acquisition, recording, or dissemination of health data can also have consequences under criminal law. The Turkish Penal Code defines the unlawful recording, disclosure, dissemination, or acquisition of personal data as separate types of crimes. Since health data is of a sensitive nature, the severity of the act is assessed more seriously in the specific case.

For example, a hospital employee sending a patient's medical report to a third party, a doctor accessing the records of someone with whom they have no treatment relationship, a clinic employee sharing patient photos on social media, the disclosure of psychological counseling records, or the unauthorized publication of laboratory results may constitute crimes against personal data and, in some cases, violations of the right to privacy under the Turkish Penal Code.

Health data can sometimes be used as a tool for threats or blackmail. Statements such as "I will tell your family about your illness," "I will send your report to your workplace," or "I will share your treatment photos" may, depending on the specific circumstances, simultaneously constitute threats, blackmail, unlawful dissemination of personal data, and violation of privacy.

Patient Rights

Individuals whose health data is processed have many rights under the Personal Data Protection Law (KVKK). They can learn whether their data is being processed, request information about it if it is, learn the purpose of the processing, inquire whether the data is being used appropriately for that purpose, learn the third parties to whom the data has been transferred, request the correction of incomplete or inaccurate data, request its deletion or destruction if the conditions are met, and request compensation for damages incurred due to unlawful processing.

In healthcare, these rights are also intertwined with patient rights. A patient may wish to access their own health records, request the correction of inaccurate medical records, learn with which institutions their data has been shared, or contact the data controller if they believe their health data has been shared without their permission. The data controller must respond to the request in a timely and reasoned manner.

However, requests for deletion of health data may not always be fulfilled directly. Healthcare institutions may have obligations to retain medical records for specific periods. In this case, the data controller must explain which data is being retained and for what legal reasons.

Liability for Compensation in Cases of Health Data Breach

The unlawful processing or disclosure of health data may give rise to liability for both material and moral damages. Since health data is among a person's most private information, the likelihood of moral harm is high in the event of a breach. For example, the unauthorized disclosure of a patient's information regarding HIV, psychiatric treatment, pregnancy, addiction, cancer, or genetic diseases can cause serious moral harm.

Financial damages may also arise. If the health data breach results in job loss, insurance issues, disruption to treatment, risk of fraud, or economic loss, monetary compensation may be claimed. The healthcare institution's liability may be aggravated if it is proven that they failed to take necessary technical and administrative measures, did not monitor employee access, reported the data breach late, or shared data without the patient's explicit consent.

Compliance Checklist for Healthcare Facilities

Organizations processing healthcare data should first create a data inventory. This includes determining which patient data is collected, for what purpose it is processed, who has access to it, which systems it is stored in, to whom it is transferred, whether any data is transferred abroad, how long it is stored, and what security measures are implemented.

Secondly, patient information texts should be prepared and presented in an understandable way. Separate or layered information may be required for different processes such as online appointments, call centers, examinations, laboratory tests, health tourism, imaging, psychological counseling, and digital health applications.

Thirdly, access rights should be restricted. Each employee should only have access to data necessary for their job. Former employees' accounts should be closed, access should be logged, and unusual access should be monitored.

Fourthly, technical security must be ensured. Measures such as encryption, backup, multi-factor authentication, log management, firewalls, penetration testing, data masking, antivirus software, role-based access, and secure cloud usage should be implemented.

Fifth, a data breach response plan must be prepared. This plan should specify who will do what in the event of a breach, how technical evidence will be protected, how the Board will be notified within 72 hours, how patients will be informed, and whether a criminal complaint needs to be filed with the prosecutor's office.

Conclusion

The protection of health data is one of the most critical areas of information law and personal data protection law in the digital age. Health data is considered special categories of personal data and can directly affect a person's private life, physical integrity, psychological state, social reputation, and economic future. Therefore, the processing, storage, transfer, and protection of health data require high attention and strong security measures.

Hospitals, clinics, laboratories, dentists, psychologists, health tourism companies, insurance companies, employers, and digital health applications must comply with the Personal Data Protection Law (KVKK), the Regulation on Personal Health Data, patient rights, professional confidentiality obligations, and information technology law when processing health data. The Ministry of Health's Regulation on Personal Health Data and the e-Nabız system provide important legal and technical frameworks for the processing and access of health data in a digital environment.

The key to protecting health data is not just preparing documents; it's establishing a secure system, limited access, proper information dissemination, proportionate data processing, regular audits, and effective data breach management. When a data breach occurs, the data controller must notify the Board within 72 hours of becoming aware of the breach and inform the affected individuals as soon as reasonably possible.

In conclusion, the protection of health data is not simply a matter of GDPR compliance; it is a strategic area encompassing patient safety, privacy, quality of healthcare, institutional reputation, cybersecurity, and legal responsibility. It is crucial for all institutions processing health data to manage this process professionally, both to protect patients' fundamental rights and to prevent risks such as administrative fines, compensation claims, criminal investigations, and reputational damage.

Leave a Reply

Call Now Button