Why Is Health Data Considered Special Category?
Health data falls under the "special categories of personal data" in KVKK. This is because disclosure of such data carries a risk of discrimination, stigma or harm to the data subject. A patient's diagnosis, medication history, laboratory results or genetic information is among the most sensitive personal data, and the law therefore provides reinforced protection for it.
This guide addresses, in a principle-based way, how health data should be managed under KVKK for hospitals, clinics, laboratories, pharmacies and health technology companies.
The Basic Rule for Processing Special Category Data
As a rule, special categories of data cannot be processed without the data subject's explicit consent. However, for health data the law grants narrow exceptions. Foremost among these is processing for the purpose of providing and managing health services, carried out by persons or authorised institutions under a duty of confidentiality. That is, a hospital processing health data through a physician for treatment purposes can rely on this exception.
This exception does not mean health data can be freely processed for any purpose. For marketing, research sharing or non-treatment purposes, explicit consent generally comes into play.
Explicit Consent or Exception?
Health organisations often confuse the two grounds. The table below summarises which approach fits typical activities.
| Activity | Likely Ground | Note |
|---|---|---|
| Appointment and patient records | Contract / exception | Limited to the purpose |
| Billing and social-security processes | Legal obligation | Mandatory records |
| Non-treatment marketing | Explicit consent | Withdrawable |
| Scientific research sharing | Explicit consent / anonymisation | Anonymous data where possible |
| Storing clinical data in the cloud | Exception + security + transfer condition | Extra condition if abroad |
Reinforced Security Obligations
For special categories of data, the Board expects additional security measures beyond the standard ones. The measures that stand out in health organisations are:
- Limiting access to health data to authorised staff under a duty of confidentiality
- Keeping access records (logging) and monitoring them regularly
- Storing and transmitting data in encrypted form
- Regular KVKK and confidentiality training for staff
- Securing physical archives and devices
Cross-Border Transfer and Health Technologies
Modern healthcare involves telemedicine platforms, cloud-based patient record systems and laboratory integrations. When these tools host data abroad, a cross-border transfer arises. When special category data is involved this transfer is even more sensitive; the provider's obligations as a data processor must be clarified by contract and the transfer conditions set out in law must be met.
Retention, Destruction and Patient Rights
Health records are kept for the periods stipulated by the relevant legislation; these periods can be longer than for other data types. However, once the retention period expires or the processing purpose disappears, data must be erased, disposed of or anonymised via periodic destruction.
As data subjects, patients have the rights to access their data, have it rectified and, under certain conditions, request its erasure. Requests must be answered within a maximum of 30 days. However, records subject to a legal retention obligation may be kept for the relevant period despite an erasure request.
Common Mistakes
When working with special category data, health organisations should watch for these mistakes:
- Collecting explicit consent unnecessarily where the health-service exception could apply, or conversely processing for non-treatment purposes without obtaining consent
- Granting broad access to health data to staff whose job does not require it
- Failing to keep access logs, or never reviewing them
- Storing and transmitting data without encryption
- Neglecting contracts and transfer conditions with health technologies that use servers abroad
- Keeping patient records indefinitely without defining retention periods
These mistakes can have far heavier consequences when special category data is involved.
Compliance Steps for Health Organisations
- Prepare a data inventory covering all health data you process.
- Clarify, for each activity, whether you rely on the health-service exception or explicit consent.
- Limit access to health data to authorised staff under a duty of confidentiality.
- Apply additional measures such as access logging, encryption and physical security.
- Conduct a data impact assessment (DPIA) for high-risk processing.
- Identify all health technologies involving cross-border transfers and arrange the contracts.
- Define a retention period for each record type and establish a periodic destruction process.
- Create a process that answers patient requests within 30 days.
- Prepare a plan to notify the Board within 72 hours in a data breach.
Example Scenario
A private clinic keeps its patients' diagnosis and treatment data in an electronic patient record system. In diagnosis and treatment processes, the data is processed by physicians under a duty of confidentiality, relying on the health-service exception; no separate explicit consent is sought. When the clinic wishes to send non-treatment campaign emails to its patients, it collects separate, freely given explicit consent for this. Because the patient record system is hosted on a server abroad, this constitutes a cross-border transfer and the required contract and security conditions are met. If the system suffers unauthorised access, it is a data breach affecting special category data and is notified to the Board reasonably within 72 hours.
Frequently Asked Questions
Is explicit consent always required to process patient data?
No. For health data processed by staff under a duty of confidentiality within the provision of a health service, such as diagnosis and treatment, the exception set out in law can be relied on. However, non-treatment purposes generally require explicit consent.
Is it possible to store health data in the cloud?
It is, but reinforced security measures, data processor agreements and, if the provider is abroad, meeting the transfer conditions are required. Because it is special category data, the duty of care is higher.
How long should I keep patient data?
For the periods stipulated by the relevant legislation. When those periods expire and the processing purpose ends, data must be erased, disposed of or anonymised via periodic destruction.
What happens if a patient makes an erasure request?
You must assess the request within a maximum of 30 days. However, records subject to a legal retention obligation may continue to be kept for the duration of that obligation; you are expected to explain this to the patient.
This content is for general informational purposes only and does not constitute legal advice.
With JUS. you can request a free demo to securely manage your health data inventory, access permissions and patient requests.