Unit 11 / 12

Privacy, KVKK, Data Security and Artificial Intelligence Tool Selection

Gains:

  • Ability to manage data sharing in AI tools within the framework of KVKK, knowing that patient health data is special personal data
  • Ability to turn concepts such as anonymization, data processing agreement, international transfer and storage into a practical checklist
  • Ability to evaluate security, data locality, certification and contractual criteria when choosing an AI tool for the clinic

The data processed in dentistry is not ordinary data. A patient's name, TR ID number, radiography, diagnosis and treatment history; It is considered "special quality personal data" - that is, health data - within the scope of KVKK (Personal Data Protection Law) and requires the highest level of protection. This is the issue that is most often neglected but creates the heaviest liability when introducing AI tools into the clinic. In this unit, we will see how to safely process health data in AI tools, how to choose which tool with what criteria, and how to set up a compliance checklist.

Basic principle: Patient health data is processed only in KVKK compliant, secure and contracted systems. Do not upload any identifying patient information to a tool that you are not sure is secure.

Why is health data private?

KVKK protects personal data; It provides additional safeguards by considering health data as "special quality". Leakage of health data can cause irreversible harm: the patient's privacy is violated, he or she may be subjected to discrimination, the clinic's reputation and legal standing are damaged. Therefore, processing health data requires explicit consent, limitation of purpose and strong security measures.

Caution: Uploading a patient radiograph to a public chat tool "just for comment" may place that data beyond your control. Do not share any identifying information without knowing how the tool stores and uses your data.

Anonymization: the first line of defense

Anonymization means removing all information that identifies the person from the data (name, surname, TR ID, date of birth, contact, file number, recognizable features in the face/mouth image). If you're only going to get a general comment or outline from an AI tool, anonymize the data first. But be careful: some data alone, such as a radiography or facial image, can indirectly identify a person; Make sure the security of the tool before sharing them.

identifying information

What to do

Name, surname, TR

Remove/give code

Date of birth, age

Remove if not needed, age range if necessary

Contact (phone, address)

Definitely remove it

File/patient number

Remove or anonymous code

Radiography/photo

Operate only in a safe, contracted vehicle

Safe vehicle selection criteria

Before bringing an AI tool into the clinic, ask these questions:

  1. Data processing conditions: What does the tool's privacy policy use your data for? Does it use it to train the model?
  2. Data location (storage): Where is the data stored? At home or abroad?
  3. International transfer: If data is transferred abroad, are the conditions stipulated by KVKK met?
  4. Data processing agreement: Is there a written agreement (DPA) with the provider as a data processor?
  5. Security measures: Is there encryption, access control, logging?
  6. Certification / regulation: If used for a medical purpose, does it comply with relevant medical device legislation?
  7. Deletion and storage: How does your request to delete data and retention periods work?
Tip: A “free” tool can use data as a product. Just because it's free doesn't mean it's safe; On the contrary, it requires reading the data processing conditions more carefully.

Mini case 1: Consent and the limit of purpose

A clinic obtains explicit consent from patients for treatment, but this consent does not include processing the data in an AI tool. The clinic is reviewing the purposes of data processing and establishing a separate and clear information/consent process for the use of AI. Lesson: consent for one purpose does not automatically extend to another; AI use must be reported transparently.

Mini case 2: Loading into the wrong vehicle

An assistant uploads the patient panoramic radiograph, along with the name and file number, into a free web tool with no data processing agreement. When the clinic realizes this, it stops the process, records the event, and issues a protocol reminding the entire team that “identifying patient data is processed only in approved, contracted tools.” Lesson: a single careless installation can create a serious data breach; rules must be written and educated.

Mini case 3: Choosing the right tool

A clinic compares two AI dictation tools. One is cheap but does not disclose where the data is stored and does not offer a contract; The other gives a data processing agreement, undertakes not to use the data in model training, and provides encryption. The clinic chooses the second tool, although it is slightly more expensive. Lesson: the criterion for choosing a tool is not price, but data security and compliance.

Copiable templates

Role: Anonymization checker. Task: Mark every expression in the text below that can directly or indirectly identify the person (name, ID, date, contact, file number, rare feature) and suggest how to anonymise. Text: [paste]

Role: AI tool compliance assessor.Task: Generate control questions to evaluate an AI tool for clinical use:data processing conditions, storage location, foreign transfer, data processing agreement, encryption, deletion policy, medical device compliance. Prepare each question in a "yes/no + evidence" format.

Role: Patient information (data) text writer. Task: Write an information draft explaining in plain language that the clinic uses AI tools in certain processes, which data is processed and how, and the patient's rights. The physician/lawyer will verify the legal statements; writing a definitive legal argument.Context: [area of use]

Role: Data breach response drafter. Task: Draft the steps the team will follow in the event of a possible data breach: detection, containment, recording, evaluation, notification obligation control, precaution. Mark legal notice periods with the note "must be verified according to relevant legislation".

Weak prompt / Strong prompt

Weak: "I uploaded this x-ray with the patient's name and ID, let me add all the information for better analysis."

Why it's weak: It exposes sensitive data in an unnecessary and insecure manner; It creates a risk of KVKK violation.

Strong: "Remove and anonymize all patient-identifying information in this text; leave only clinically necessary, de-identified content. I will only process health data in contracted and secure means."

Why it is powerful: It implements the principle of data minimization and anonymization, stipulating the security of the vehicle.

Data minimization and team culture

One of the basic principles of KVKK is data minimization: working with the least data required to do a job. This principle is the golden rule in AI tools. You do not need to provide the patient's name, ID or contact information to have a draft text produced; Clinical content is often meaningful without identity. Ask yourself with each installation: "Is this information really necessary for this task?" If the answer is no, don't provide that information. This simple habit radically reduces the impact of a potential leak.

But even the best rules are useless if the team doesn't follow them. Data security is the culture of the entire clinical team, not a single person. Everyone, from the secretary to the assistant, from the technician to the physician, should know which tool is approved, what information can be uploaded where, and what to do in case of doubt. That's why a written "data use policy", regular short trainings and a "list of approved tools" are essential. A culture that encourages reporting before punishing when an error occurs prevents errors from being hidden and strengthens the system.

Mini case 4: Not giving unnecessary data at all

An assistant pauses as he is about to load the entire patient file into the AI ​​to have it produce an informational text: in fact, only the information "prosthetic options for a single missing molar" is sufficient. Without identity and all the history, without identity and with a minimal desire, it gets the same result. Lesson: the most secure data is data that is never shared; Minimization eliminates risk before it occurs.

Common mistakes

  • Uploading identifying patient information to an insecure/free tool.
  • Assuming that consent for a purpose includes the use of AI.
  • Not checking whether the tool uses the data in model training.
  • Using a provider without a data processing agreement (DPA).
  • Ignoring international data transfer and retention periods.

In summary

Patient health data is special data within the scope of KVKK and requires the highest protection. When processing data in AI tools, anonymize it first; Process identifying information only in secure, contractual and KVKK compliant systems. The criterion for choosing a vehicle is not price or popularity; data processing conditions, storage location, international transfer, contract, encryption and regulatory compliance. The use of AI should be transparently communicated to the patient and the necessary consent should be obtained.

Application task

List all AI and digital tools that come into contact with patient data in your clinic. Answer the questions generated by the “AI tool compliance assessor” prompt for each (data location, contract, encryption, deletion). Flag those that do not comply and create an “approved tools” list and a “banned/suspended tools” list and announce it to your team.

checklist

  • [ ] I process identifying patient data only in approved, contracted tools.
  • [ ] I anonymized data where necessary.
  • [ ] I have established a separate information/consent process for the use of AI.
  • [ ] I evaluated the data location, contract and security status of each tool.
  • [ ] I announced the approved and prohibited vehicle lists to the team.