Single Blog Title

This is a single blog caption

Violation of Patient Privacy and Unlawful Sharing of Health Data

What is patient privacy?

Patient privacy refers to the protection of information regarding a person's physical, mental, social, and private life during the provision of healthcare services; ensuring that the examination, diagnosis, treatment, and care process is conducted confidentially; and preventing the sharing of a patient's health information with unauthorized third parties. Information regarding a patient's illness, diagnosis, medications used, surgical history, psychiatric condition, pregnancy information, sexual health data, genetic information, test results, imaging records, disability status, addiction treatment, or infectious disease information is considered within the scope of privacy.

The Patient Rights Regulation covers all public and private institutions and organizations providing healthcare services and aims to ensure that patients receive healthcare services in a manner consistent with human dignity and that they can utilize legal means of protection against rights violations. Therefore, patient privacy is not only an ethical obligation but also a legal obligation for private hospitals, state hospitals, clinics, laboratories, imaging centers, pharmacies, and healthcare professionals.

Violation of privacy can occur not only through the disclosure of a patient's health information to third parties, but also through inappropriate examinations, the loud announcement of a patient's diagnosis within the hospital, unauthorized access to a patient's file, unauthorized access to e-Nabız (the Turkish national health information system), sharing patient information on social media, or unlawfully sharing data with employers, family members, insurance companies, or other institutions.

Why is health data considered special category personal data?

According to the Law No. 6698 on the Protection of Personal Data, personal data is any information relating to an identified or identifiable natural person. The same law designates certain data, such as health data, sexual life data, biometric data, and genetic data, special categories of personal data . Health data is subject to stricter protection because it is directly related to a person's privacy and personal rights.

According to the Turkish Personal Data Protection Law (KVKK), processing special categories of personal data without the explicit consent of the data subject is generally prohibited. Data relating to health and sexual life may only be processed without explicit consent by persons or authorized institutions and organizations bound by an obligation of confidentiality, for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning and managing health services and their financing. This exception does not mean that health data can be freely shared with everyone; it only allows processing limited to the purposes and persons specified in the law.

Therefore, even a hospital, doctor, or healthcare worker simply stating "the patient received treatment here" can constitute a data breach in some cases. This is because the hospital, department, and diagnosis of a person's treatment are considered health data. Protecting privacy is even more crucial in fields such as psychiatry, obstetrics and gynecology, infectious diseases, sexual health, IVF, addiction treatment, cancer, genetic testing, and disability reports.

In what ways does patient privacy manifest itself?

Violation of patient privacy can occur in many different ways. One of the most common examples is when a healthcare professional shares a patient's diagnosis, test results, or treatment information with their family, employer, neighbor, another patient, or third parties without the patient's consent. Being a relative of a patient does not automatically grant the right to access the patient's health data. If the patient has the capacity to understand and has not given explicit permission, even their spouse, mother, father, or child cannot automatically access all health information.

Another type of violation is when hospital staff access a patient's data from the e-Nabız or hospital information system out of curiosity, personal animosity, acquaintance, divorce proceedings, business relationships, or social purposes. Access to health data can only be granted to the extent necessary for healthcare services and by authorized personnel. With the amendments made to the Regulation on Personal Health Data on December 3, 2025, the regulations regarding which physicians can access health data, for what duration, and to what extent have been more clearly defined. For example, access by physicians whom a person consults for healthcare services is restricted until procedures directly related to the healthcare service provided are completed.

Privacy violations can also occur through social media posts. Sharing photos of surgeries, birth images, before and after photos of cosmetic procedures, images of a patient that are still identifiable even if their face is covered, test results, images from a patient's room, or ambulance interventions without permission can result in liability under patient rights, the Personal Data Protection Law (KVKK), and personal rights.

Protecting Privacy Within the Hospital

Patient privacy is not just about data security. Protecting the patient's bodily privacy during examinations, preventing unnecessary people from being in the examination room, not reading patient information aloud, not disclosing diagnoses in hospital corridors, not leaving patient files exposed, and not posting sensitive information along with patient names on notice boards are also part of privacy.

For example, if a patient's sensitive information, such as their HIV status, hepatitis, pregnancy, psychiatric diagnosis, sexual assault, miscarriage, addiction, or cancer, is disclosed in an emergency room or outpatient clinic in a way that others can hear, this could be considered a violation of patient privacy. Similarly, privacy rules should be applied more strictly in delivery rooms, intensive care units, operating rooms, and obstetrics and gynecology wards.

The Patient Rights Regulation governs the patient's right to access information about their health status, as well as their right to examine and obtain copies of their medical files and records directly or through their representative or legal guardian. However, this right belongs to the patient; the healthcare institution cannot disclose the patient's records to unrelated third parties.

Unauthorized Access to e-Nabız Records

The e-Nabız system is an important digital health system that facilitates access to individuals' health records. However, access to e-Nabız and hospital information management systems does not grant healthcare professionals unlimited viewing rights. A healthcare professional cannot examine the health records of a person with whom they do not have a treatment relationship or whose records are not required as part of healthcare services.

The amendments made to the Regulation on Personal Health Data in 2025 redefined the conditions for accessing health data, e-Nabız security settings, and access limits related to the provision of health services. The amendments specifically defined access limits for situations such as the individual's registered family physician, the physician they consulted, the physicians working at the healthcare provider where they were hospitalized, and access via the emergency department.

Therefore, it may constitute unlawful data access if a former spouse, neighbor, relative, employer, or a healthcare professional acquaintance accesses a patient's e-Nabız records. Patients can check their e-Nabız access history and, in case of suspicious access, report it to the Ministry of Health, the relevant hospital, the Personal Data Protection Authority (KVKK), and, if necessary, the prosecutor's office.

Sharing Health Data with the Employer

One of the common violations in practice is the excessive sharing of an employee's health information with the employer. While the employer may, in some cases, obtain information about an employee's sick leave, rest period, or fitness for work, detailed diagnoses, psychiatric history, pregnancy status, test results, medications used, or specific treatment information cannot, as a rule, be shared with the employer.

For example, a hospital informing the employer about the specific illness an employee is taking sick leave for; a human resources department sharing information about an employee's cancer, pregnancy, psychiatric, or infectious disease status with other employees; or an occupational health physician disclosing sensitive health information in violation of their confidentiality obligations can all constitute a privacy breach.

In employment relationships, health data may only be processed for limited purposes such as occupational health and safety, suitability for work, report tracking, or legal obligations. The principle of relevance, limitation, and proportionality is particularly important for health data. The Personal Data Protection Law (KVKK) mandates that personal data be processed lawfully, fairly, for specific and legitimate purposes, and in a manner that is relevant, limited, and proportionate to the purpose for which it is processed.

Providing Health Information to Family Members

Being a relative of a patient does not grant access to all of the patient's health data. If the patient is conscious, capable of making informed decisions, and able to make their own choices, health information should only be disclosed to relatives with the patient's consent. The patient may authorize another person to obtain information about their health condition; documentation of this authorization may be required if necessary.

Conversely, if the patient is a minor, incapacitated, unconscious, or lacks the capacity to make decisions, the parent, guardian, or legal representative may need to be informed. In emergency situations, information sharing necessary to protect the patient's life or physical integrity may be done, provided it is done in a proportionate manner.

For example, disclosing an adult woman's pregnancy test results to her family, revealing a psychiatric patient's diagnosis to their spouse, telling an employer or family member about an HIV test result, or sharing information about abortions or gynecological examinations with third parties can constitute a serious violation of privacy. In such cases, the healthcare institution's defense of "a family member asked" is not sufficient.

Sharing Health Data on Social Media

It has become very common for healthcare professionals or clinics to share patient images on social media. "Before-and-after" photos are frequently used, especially in the fields of cosmetic surgery, hair transplantation, dentistry, childbirth, IVF, obesity surgery, and dermatology. However, sharing such images without the patient's explicit consent is against the law.

Even if a patient's face is obscured, personal data may be considered processed if their identity can be determined through tattoos, voice, body type, date, location, treatment process, or explanatory text. Furthermore, images containing health data are treated with greater sensitivity. A patient's mere consent to treatment does not automatically mean they consent to their image being shared for advertising or promotional purposes.

For social media posts, explicit consent must be specific, informed, and given freely. A vague "my photos may be used" statement added to the general transaction form may not be sufficient in all cases. The patient must know which of their images will be shared, on which platform, for what purpose, and for how long.

Data Controller's Responsibilities

Hospitals, clinics, laboratories, imaging centers, private practices, or institutions providing healthcare services may be considered data controllers or data processors with respect to the personal data they process. According to the Personal Data Protection Law (KVKK), a data controller is a natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.

Article 12 of the KVKK (Law on Protection of Personal Data) obligates data controllers to take necessary technical and administrative measures to prevent the unlawful processing of personal data, to prevent unlawful access to personal data, and to ensure the preservation of personal data. The same article stipulates that data controllers and data processors may not disclose personal data they have learned to others unlawfully or use it for purposes other than the processing purpose; this obligation continues even after they leave their position.

Therefore, a hospital cannot escape responsibility in every case by saying, "Our employee leaked the data, we are not responsible." The hospital is obligated to restrict access rights, maintain log records, train staff, obtain confidentiality commitments, establish data security policies, prevent unauthorized access, and make necessary notifications in case of a data breach.

What Rights Does a Patient Have?

According to Article 11 of the KVKK (Law on Protection of Personal Data), the data subject has the right to inquire with the data controller whether their personal data is being processed, to request information if it is being processed, to learn the purpose of the processing and whether it is being used in accordance with that purpose, to know the third parties to whom the data has been transferred, to request the correction of incomplete or inaccurate data, to request its deletion or destruction if the conditions are met, and to request compensation for damages if they have suffered harm due to the unlawful processing of their personal data.

A patient can contact a healthcare provider and ask the following questions: Who viewed my health data? On what dates was access granted? With whom was my data shared? On what legal basis was it processed? Which of my data is being stored? How will erroneous records be corrected? What measures were taken if there was unlawful data sharing?

The patient may also request corrections to their health records. The Patient Rights Regulation recognizes the patient's right to review and obtain copies of their health records, as well as the principle that records can only be viewed by persons directly involved with the healthcare service. Therefore, both the patient's right to access information and the right to protection of privacy must be considered together.

How to Apply for KVKK (Personal Data Protection Law)?

If a patient believes that their health data has been processed or shared unlawfully, they should first contact the data controller. According to Article 13 of the Personal Data Protection Law (KVKK), the data subject submits their requests in writing or through other methods determined by the Board to the data controller. The data controller is obliged to process the application as soon as possible, and no later than thirty days, depending on the nature of the request.

Applications can be submitted to the hospital's chief physician, private hospital management, data controller representative, KVKK (Personal Data Protection Law) contact address, KEP (Registered Electronic Mail) address, or the institution's official application channel. The application must clearly state the patient's identification information, the date of the breach, the suspicious access or sharing, the information and documents requested, the nature of the damage, and the requested action.

If the data controller rejects the application, provides an inadequate response, or fails to respond within the specified time, the right to complain to the Personal Data Protection Authority (KVKK) arises. According to Article 14 of the KVKK, the data subject may file a complaint with the Authority within thirty days of learning of the response, and in any case within sixty days of the application date. A direct complaint to the Authority cannot be filed without exhausting the application process.

Can a GDPR complaint substitute for compensation?

No. Applying to the Personal Data Protection Law (KVKK) and filing a complaint with the Board are administrative oversight mechanisms. If the Board detects a violation, it may order the data controller to remedy the illegality, take data security measures, or impose administrative sanctions. However, the patient may also need to file a separate compensation lawsuit under general provisions to recover any moral or material damages.

Article 14 of the KVKK (Law on Protection of Personal Data) explicitly states that those whose personal rights have been violated have the right to compensation according to general provisions. Furthermore, Article 11 of the KVKK stipulates that a person who has suffered damage due to the unlawful processing of personal data may demand compensation for that damage.

Therefore, the patient can both file a complaint with the data controller and a GDPR violation complaint, as well as file a lawsuit for compensation due to violation of personal rights, moral damage, loss of reputation, loss of employment, damage to family life, or psychological effects.

Liability under Criminal Law

Unlawful sharing of health data can, in some cases, lead to criminal liability. According to Article 136 of the Turkish Penal Code, a person who unlawfully gives, disseminates, or obtains personal data belonging to another person shall be punished with imprisonment from two to four years.

For example, a hospital employee sending a patient's test results to their ex-spouse, a doctor sharing a patient's psychiatric diagnosis with third parties, a nurse sharing a screenshot of the patient's e-Nabız (electronic health record) on social media, a clinical staff member publishing photos of cosmetic procedures without the patient's consent, or the transfer of health data to third parties for commercial purposes could all be considered under Article 136 of the Turkish Penal Code.

In addition, depending on the nature of the incident, articles 134 (violation of privacy), 135 (recording of personal data), 138 (failure to destroy data), abuse of office, or other types of crimes may also come into play. Criminal investigations and the Personal Data Protection Law (KVKK) process are different. The KVKK focuses on administrative control and data protection, while criminal investigations focus on the criminal liability of the perpetrator.

Can I Claim Material and Moral Damages?

Compensation for material and moral damages can be claimed due to the violation of patient privacy. Moral damages are particularly important because of the sensitive nature of health data. The dissemination of a patient's psychiatric treatment information in the workplace, sharing information about pregnancy or miscarriage with their family, disclosing information about HIV or infectious diseases to third parties, unauthorized publication of cosmetic surgery images, or the announcement of a cancer diagnosis without the patient's consent can all cause significant moral harm.

Monetary compensation comes into play if a data breach has caused tangible economic damage. For example, a patient may claim monetary damages if they have lost their job, had their insurance application rejected, had to undergo psychological treatment due to damage to their privacy, suffered commercial reputation due to clinical photos, or incurred expenses due to unlawful data sharing.

In a compensation lawsuit, the nature of the breach, the sensitivity of the shared data, to whom the data was shared, the prevalence of the sharing, the impact on the patient's social and professional life, whether the breach was intentional or negligent, the data controller's conduct after the breach, and the emotional distress suffered by the patient are all considered together.

Privacy Violation at a Private Hospital

If a privacy violation occurs in a private hospital, private clinic, laboratory, imaging center, aesthetic center, or private practice, private law, consumer law, GDPR, and criminal law avenues may be considered together. Private hospitals are obligated to protect patients' health data, make it accessible only to authorized personnel, keep patient files confidential, and process data for lawful purposes.

A private hospital may be held liable for actions such as a hospital employee viewing a patient's file out of personal curiosity, sharing patient photos for advertising purposes, transferring patient information to intermediary companies or third parties, circulating patient information in WhatsApp groups, or preparing promotional materials without the patient's explicit consent.

In this case, the patient should first submit a written application to the private hospital, requesting access logs, information on who the data was shared with, consent forms (if any), and measures taken regarding the breach. If the hospital does not provide an adequate response, the patient should consider filing a complaint under the Personal Data Protection Law (KVKK), a consumer law application, a compensation lawsuit, and a criminal complaint with the prosecutor's office.

Privacy Violation at State Hospital

If a privacy violation occurs in a state hospital, city hospital, training and research hospital, or public university hospital, administrative appeals, disciplinary proceedings, GDPR complaints, criminal investigations, and full judicial proceedings may be initiated. Healthcare services in state hospitals are considered public services. If patient privacy is violated due to negligence on the part of public personnel or the administration, the administration may be held liable.

For example, if a staff member working at a state hospital accesses a patient's e-Nabız (electronic health record) or hospital records without authorization, shares patient information with a relative, or provides medical documents to a third party, both individual criminal liability, administrative disciplinary liability, and the administration's negligence in providing services can be discussed.

A patient who has suffered harm in a public hospital can apply to the relevant administration to request compensation for their material and moral damages. If the administration rejects the request or fails to respond within the specified time, a full judicial review case can be filed in the administrative court. Parallel to this, avenues under the Personal Data Protection Law (KVKK) and the public prosecutor's office can also be pursued.

How should evidence be collected?

Gathering evidence is crucial in patient privacy and health data breach cases. Since breaches often occur digitally, log records, access logs, screenshots, messages, social media posts, email records, patient file activity, camera footage, and witness statements are all important.

The patient should check their e-Nabız access history; if there is any suspicious access, they should note the dates and times. If there has been any social media sharing, a screenshot should be taken, the sharing link should be saved, and if possible, a notarized record should be made. If health data has been shared via WhatsApp or SMS, the messages should not be deleted, a screenshot should be taken, and a backup of the device should be kept.

The written application to the hospital should request: "information on which staff member accessed my personal health data, on what date, and for what reason; clarification on whether my data has been transferred to third parties; provision of any relevant explicit consent documents; and information on measures taken if unlawful access has been detected.".

What should the patient or their relatives do?

If a patient's privacy is suspected to have been violated, the first step is to document the incident. Shared information, messages, screenshots, social media content, witness testimonies, hospital responses, e-Nabız access records, or other evidence must be preserved. Action must be taken quickly to prevent the deletion of evidence.

The second step is to submit a written application to the data controller. In private hospitals, the application can be made to the hospital management and the GDPR unit; in state hospitals, it can be made to the chief physician, the Provincial Health Directorate, or the Ministry of Health. The application must clearly state the nature of the violation, which data was shared, who shared it, the extent of the damage, and the demands being made.

The third step is to file a complaint with the Personal Data Protection Authority (KVKK) if no response is received or the response is insufficient. It is important to remember that a complaint cannot be filed directly with the Authority without first applying to the KVKK. If no response is given within thirty days of the application, or if the response is insufficient, a complaint should be filed with the Authority, paying attention to the deadlines.

The fourth step is filing a criminal complaint with the prosecutor's office and a compensation lawsuit, depending on the severity of the incident. If the unlawful sharing of health data was intentional, given to third parties, disseminated on social media, or severely affected the patient's private life, criminal law and compensation avenues should be strongly considered.

Conclusion: Health Data is Among the Most Sensitive Personal Data

Patient privacy is a fundamental element of healthcare. A patient's health information can only be processed to the extent necessary for the treatment process and by authorized personnel. Patient diagnoses, test results, surgical history, psychiatric status, pregnancy information, genetic data, sexual health information, or e-Nabız (electronic health record) data cannot be shared with unauthorized individuals.

According to the Turkish Personal Data Protection Law (KVKK), health data is considered special categories of personal data and is subject to stricter protection. Hospitals, clinics, or healthcare institutions acting as data controllers are obligated to prevent unlawful access, ensure data security, supervise their employees, restrict access rights, and make necessary notifications in case of data breaches.

Individuals whose patient privacy has been violated may pursue various legal avenues, including filing a complaint with the data controller, a complaint under the Personal Data Protection Law (KVKK), an application to the Provincial Health Directorate or the Ministry of Health, a criminal complaint with the prosecutor's office, a compensation lawsuit (depending on whether it's a private or public hospital), and, if necessary, administrative legal recourse. The unlawful disclosure, dissemination, or acquisition of personal data may also result in criminal liability under Article 136 of the Turkish Penal Code.

Therefore, in cases where health data is shared illegally or patient privacy is violated, the process should not be limited to a mere "complaint"; evidence must be preserved, written applications must be submitted, GDPR deadlines must not be missed, and both criminal and compensation options must be considered. A strong legal process in health data breaches is only possible by documenting how the breach occurred and concretely demonstrating the material and moral damages suffered by the patient.

Leave a Reply

Call Now Button