Skip to content

A patient record belongs in front of whoever has business with it.

Personal data does not start with a form, it starts with the record itself. Which information you keep and why, and who gets to see it, is the whole question.

Which information are you actually keeping

A patient record has a clear job: identify the person correctly, find their past treatment and track the money. If you cannot tie a field to one of those three, filling it in does not enrich the record; it grows the load you will have to protect later.

Health data is counted among special categories of personal data in article 6 of Türkiye's personal data protection law, Kişisel Verileri Koruma Kanunu. This page does not interpret what obligation that creates in your clinic; the text of the law is published on the authority's own site, and how it applies is settled with your legal adviser.

  • Every field should have a live task behind it
  • Information with no task is not collected, it is a load to protect
  • A national ID number may not be needed on every record
  • Health data is a special category in the law

Who needs to see the record

A clinic does not have one person looking at records. Whoever opens the appointment, enters the treatment, takes the payment and reads the report are different people, and they do not all need the same information.

So access is built from two questions: what should this person be able to do, and which records should they see. The answer to the first is the role, to the second the branch permission. If neither is chosen up front, everyone sees everything, and when somebody later asks who looked at what, there is no answer to give.

  • The role sets what can be done, the branch permission what can be seen
  • Permission follows the job, not seniority
  • A single shared account erases who was looking
  • A new member of staff gets their permission set from day one

Consent is a record of its own

Consent is not one thing. Informing a patient about their own appointment does not sit in the same box as an announcement, a campaign or a survey message; they rest on different grounds, and which falls under which consent depends on how your clinic operates.

The practical part: consent is not taken verbally, it lives on the record. When a patient withdraws consent, the record has to be updated the same day, or the next message goes out on the old information.

  • An appointment reminder and an announcement are not the same box
  • Consent is kept on the record, not in someone's memory
  • Withdrawn consent is entered the same day
  • Its scope is written with your legal adviser

A group chat is not a record

The most common practice in clinics is the staff group: the patient's name, phone number and what needs doing get discussed in a WhatsApp group during the day. It is quick, but those messages are not a record.

A group has no permissions; everyone in it sees everything. The message is copied to everyone's phone, stays with whoever leaves, and a message you delete is not deleted from their phone. When the same information lives on the record instead, it is clear who saw it and copies do not multiply.

  • A group message does not record who saw it
  • A copy of the information stays on everyone's phone
  • The message you delete stays on the other side
  • Work discussed during the day never reaches the record

When staff leave, so does their access

A change of staff is the most commonly missed part of this. Hands are shaken on the last day, the system login stays open for weeks, and nobody notices.

The right move is to cut access, not delete the record. The appointments that person opened and the treatments they entered should stay on the record with their name visible; what closes is their ability to look at anything from today on.

  • The system login is closed on the last day
  • The record is not deleted, access is cut
  • Any shared passwords change the same day
  • Who did a past treatment stays on the record

The responsibility stays with the clinic

A record-keeping program holds the information, it does not take on the responsibility. Because the clinic is the data controller towards the patient, the privacy notice, the consent arrangement and answering requests that come from patients are the clinic's own work.

A software provider does not carry those out on your behalf; you are also the one setting permissions, consent and access. Write the texts with your legal adviser and base them on the authority's own publications.

  • The data controller's obligation stays with the clinic
  • The privacy notice and request process are built in the clinic
  • The clinic sets the permission and consent options
  • The texts are prepared with your legal adviser

Frequently asked

How is personal data in patient records protected?
Three things run together: never collecting information you do not need, keeping the record in one place, and limiting who sees it with permissions. The fourth is staff changes; the access of anyone leaving is closed on their last day. This page describes practice, it does not give legal advice.
Do I have to keep a national ID number on the patient record?
This page cannot say yes or no to that. What you want the identity information for, and what the legislation says in your situation, vary by clinic. The measure is this: if you cannot tie a field to a live task, do not ask for it. Get the definite answer from your legal adviser.
Is it a problem to discuss patient information in a staff group?
From a record-keeping point of view, yes. A group chat does not keep track of who saw what, the information is copied to everyone's phone and stays with whoever leaves. When the same information is on the record, you can cut access and limit who looks. Assess the legal side with your clinic's adviser.
Do appointment messages and campaign messages fall under the same consent?
They are not the same thing. One informs the patient about their own appointment, the other is a commercial announcement; they rest on different grounds. Settle which message falls under which consent, and how it is obtained, with your legal adviser. Tying both to a single checkbox causes trouble later.
How do I cut a departing employee's access to records?
By closing the system login on their last day. Cut the access rather than deleting the account; deleting it also blurs who did what in the past. If there are shared passwords, change them the same day and close any sessions left open on devices.
How long should I keep patient records?
We do not write a period on this page. Retention depends on the type of record and on the legislation in force; a figure buried in a page turns into wrong information before long. For your own period, look at the publications of Kişisel Verileri Koruma Kurumu, Türkiye's data protection authority, and ask your legal adviser.
Why is health data treated separately?
Because the text of the law says so. Article 6 of Kişisel Verileri Koruma Kanunu, Türkiye's personal data protection law, counts data relating to health among the special categories of personal data. This page does not interpret the article; the current text is published at kvkk.gov.tr, and what it means in your clinic is settled with your legal adviser.

This guide describes record-keeping and is not legal advice. Which data is processed on which ground, and the consent and retention side, vary by clinic; for current texts see the publications of Kişisel Verileri Koruma Kurumu, Türkiye's personal data protection authority, at kvkk.gov.tr, and consult your legal adviser.

So you know where the record sits

In Bi'Klinik the consent to contact appears as Phone consent and Email consent columns in the Patients list; the Notifications and Documents tabs on the patient card are tied to permissions. Who sees what is set by the Roles and Authorised Branches fields on the Staff screen. For departing staff you choose Close Login, and the record stays with the clinic.

See the patient record

Yarın sabah ofisi açmadan önce kurabiliriz.