Skip to content

Operations and Patient Journey

Patient Data Security: What GDPR and KVKK Actually Require of Your CRM

Health data is a special category under both GDPR and KVKK. The controls your CRM must have, what to ask a vendor, and the habits that cause breaches.

Why health data is treated differently

Both the GDPR (Article 9) and Turkey's KVKK (Article 6) place health data in a special category, subject to stricter conditions than ordinary personal data. Medical tourism companies hold exactly this: diagnoses, photographs, medical reports, treatment histories.

The practical consequence is that "we're careful" is not a position. You need a lawful basis you can point to, controls you can demonstrate, and records that show who accessed what.

What follows is a practical checklist, not legal advice. Take proper advice for your jurisdiction and circumstances.

The controls your CRM must have

ControlWhat it means in practice
Role-based accessA consultant sees their own patients, not the whole database
Field maskingPhone and email hidden from restricted roles — data masking
Audit loggingWho opened which record, when, and what changed
EncryptionIn transit and at rest
Retention rulesData not kept indefinitely; deletion requests satisfiable
Export controlBulk export restricted and logged

The last row is the one most often missing and most often exploited: an unrestricted export button is how databases walk out of companies. See security.

Questions to ask a vendor

  • Where is the data hosted, and in which jurisdiction is it processed?
  • Is there a data processing agreement, and does it name sub-processors?
  • How are backups protected, and how long are they kept?
  • What is the breach notification process and its timeline?
  • Can I delete a specific patient's data on request, including from backups over time?
  • What certifications exist, and when were they last audited?

A vendor who cannot answer these plainly is not a vendor whose security you can vouch for to a regulator.

The habits that cause breaches

In this sector, incidents rarely come from sophisticated attacks. They come from ordinary working habits:

  1. Patient photos in personal WhatsApp. Medical images on a personal phone, backed up to a personal cloud account.
  2. Spreadsheet exports. "Just to work on at home" — then on a personal laptop indefinitely.
  3. Shared logins. One account used by three people destroys the audit trail entirely.
  4. No offboarding. Access left open for weeks after someone leaves.

All four are organisational, and all four are fixed by routing communication through CRM-connected channels and closing access on the day someone departs. See sales team management.

What to put in place this quarter

A realistic starting sequence for a company that has none of this:

  1. Write the privacy notice and consent text; make consent capture part of the enquiry flow rather than an afterthought.
  2. Turn on role-based access and user groups; remove blanket admin rights.
  3. Move patient messaging onto connected channels so nothing new accumulates on personal devices.
  4. Define a retention period and apply it to closed records.
  5. Write a one-page offboarding checklist and use it every time.

None of these require a project. All of them reduce your exposure more than any single technical purchase.

Frequently asked questions

Does GDPR apply if my company is in Turkey?

If you offer services to people in the EU, yes — GDPR applies based on where the individual is, not where you are. Most medical tourism companies serving European patients are therefore subject to both GDPR and Turkey's KVKK, which are similar but not identical.

Is explicit consent always required for health data?

Explicit consent is the most commonly used lawful basis, but not the only one; both regimes allow processing necessary for healthcare provision under conditions. In practice, obtaining clear, documented explicit consent is the simplest defensible route. This is general information, not legal advice — take advice for your own situation.

What is the most common cause of a breach in this sector?

Not hacking. It is patient data living in personal WhatsApp accounts and personal devices, and departing employees taking exports with them. The controls that matter most are organisational, not technical.

MetoCRM modules mentioned in this article

SecurityData MaskingUser GroupsPatient RecordAll modules

MetoCRM is a business management platform built for medical tourism companies. From patient records and quotes to partner hospitals and accounting, it runs the whole operation on one screen.

Request a demo See pricing