AI in Medical Practices: Patient Data and the Duty of Confidentiality
Can doctors use AI tools like ChatGPT? What GDPR Art. 9, criminal confidentiality law, and professional codes require — and how to protect patient data in practice.
In short: never enter identifiable patient data into a regular AI like ChatGPT, Copilot, or Gemini. Health data is specially protected under GDPR Art. 9. On top of that, medical confidentiality binds you — in Germany under StGB § 203 and the model professional code. AI can help in a practice, but only if you first remove or replace anything that points back to a patient.
Why patient data is specially protected
Health data belongs to the special categories of personal data. That is set out in GDPR Art. 9. Processing it is prohibited in principle and allowed only under a narrow exception, such as treatment itself. On top of that comes medical confidentiality. It obliges you to keep patient secrets. Breaking it is a criminal offense in Germany under StGB § 203.
- GDPR Art. 9: health data is a special category with strict protection.
- StGB § 203: unlawfully disclosing a patient secret is a criminal offense — up to one year of imprisonment or a fine.
- Model professional code (MBO-Ä): confidentiality is also anchored in professional law and applies beyond a patient's death.
- A name, a date of birth, or a rare diagnosis alone can make a person identifiable.
Important: even if you replace a name with a placeholder, it often stays personal data. Under GDPR Recital 26, pseudonymized data is still personal data. Pseudonymization lowers the risk, but it does not remove your obligations.
What happens when you enter data into an AI
When you type text into a consumer AI, that text leaves your computer. It is processed on the vendor's servers and may be stored there. What happens to the content depends on the service and the plan. These policies change often, so always check the current documentation.
- According to OpenAI, inputs from its free consumer services may be used for training under certain conditions unless you opt out — check the current terms.
- According to Microsoft and Google, business and enterprise products follow different rules than the free consumer versions.
- Without a data processing agreement (DPA), you usually lack the legal basis to hand personal data to the vendor at all.
- Once content is sent, it cannot be reliably recalled.
For you this means: as soon as a patient secret leaves your computer and lands with a vendor without a DPA, that can be an unlawful disclosure under StGB § 203. This holds even if you only entered it quickly for help with wording.
Which AI use is allowed in a practice
Not every AI use is off limits. It depends on whether identifiable data is involved and what safeguard you apply. The table below shows typical cases from daily practice. It is guidance, not a free pass — when in doubt, the stricter principle wins: no patient data in the AI.
| Use case | Allowed? | Safeguard |
|---|---|---|
| Write a general appointment template with no patient reference | Yes | Use placeholders instead of real names and data |
| Summarize a doctor's letter with a real name | No | Pseudonymize first; only with a DPA and a vetted service |
| Research an anonymous, common condition | Yes, with care | No identifying details; never name a rare combination |
| Check a bill with an insurance number | No | Use local practice software, not a consumer AI |
| Draft a patient email template | Yes | Replace name, diagnosis, and contact with placeholders |
Remember the rule of thumb: the more precise the details, the easier a person is to identify. A common condition in a large city is less sensitive than a rare diagnosis in a small town. In the second case, the context alone can sometimes reveal the person.
Pseudonymize before every AI use
The most effective safeguard is data minimization: reveal as little as possible. Whatever remains, replace it with placeholders before the text leaves the practice. This is exactly where ONYRI Sanitize helps. The tool detects sensitive details in the text and replaces them with reversible tokens — for example, a name becomes a neutral placeholder.
A note on the mechanics: the detection engine runs entirely in your browser. The mapping from token to real value always stays local on your device and is never sent to a server. When you use the built-in Chat, only the already anonymized text goes to the AI model. The answer is then filled back in with the real values inside your browser.
- Data minimization under GDPR Art. 5: process only what is necessary.
- Pseudonymization clearly lowers the risk of disclosure.
- The token-to-value mapping never leaves the browser.
- To stay honest: pseudonymized data is still personal data (Recital 26). Your obligations remain.
ONYRI does not guarantee GDPR compliance and does not make your output legally anonymous. The tool reduces the amount of data that reaches the outside at all. This minimization supports your obligations — it does not replace them.
Checklist: DPA and documentation
If you want to use AI in a practice, you need more than care while typing. You need a documented framework. Work through these points in order before the first tool goes live.
- 1Check whether the vendor offers a data processing agreement (DPA) and sign one.
- 2Clarify where the data is processed and whether it is used for training — based on the vendor's current documentation.
- 3Put in writing which AI use is allowed and which is not.
- 4Pseudonymize or remove all patient data before it reaches an AI tool.
- 5Train your team: who may do what, and what must never go into an AI?
- 6Keep a record of processing activities and document your decisions.
If you are unsure, bring in your supervisory authority or your medical chamber. Germany's Data Protection Conference (DSK) has published guidance on artificial intelligence and data protection. It is a good starting point for practice.
Frequently asked questions
- Can I use ChatGPT for patient data as a doctor?
- Not with identifiable data. Health data is specially protected under GDPR Art. 9, and confidentiality under StGB § 203 binds you as well. Without a DPA and without pseudonymization, entering real patient data into a consumer AI is high-risk.
- Is removing just the name enough?
- Often not. A date of birth, a location, or a rare diagnosis can also make a person identifiable. And even pseudonymized data stays personal data under GDPR Recital 26. Remove as much as you can.
- Does a tool like ONYRI make my use GDPR-compliant?
- No. ONYRI pseudonymizes your text and lowers the amount of data that reaches the outside. That supports data minimization under GDPR Art. 5, but it does not replace a DPA, documentation, or a legal review.
- What do I need to use AI safely in a practice?
- A data processing agreement, a clear internal rule, pseudonymization before every input, team training, and documentation. When in doubt, review the case with your supervisory authority or medical chamber.
Sources & references
- GDPR Art. 9 – Processing of special categories of personal data — EUR-Lex (Publications Office of the EU)
- German Criminal Code § 203 – Violation of private secrets — German Federal Ministry of Justice (gesetze-im-internet.de)
- DSK guidance on artificial intelligence and data protection — German Data Protection Conference (DSK)
- Model Professional Code for Physicians (MBO-Ä) — German Medical Association (Bundesärztekammer)
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.