Guide8 min read

AI in Medical Practices: Patient Data and the Duty of Confidentiality

Can doctors use AI tools like ChatGPT? What GDPR Art. 9, criminal confidentiality law, and professional codes require — and how to protect patient data in practice.

By Alexis de ONYRI
Worried about your data? Anonymize it before AI

In short: never enter identifiable patient data into a regular AI like ChatGPT, Copilot, or Gemini. Health data is specially protected under GDPR Art. 9. On top of that, medical confidentiality binds you — in Germany under StGB § 203 and the model professional code. AI can help in a practice, but only if you first remove or replace anything that points back to a patient.

Why patient data is specially protected

Health data belongs to the special categories of personal data. That is set out in GDPR Art. 9. Processing it is prohibited in principle and allowed only under a narrow exception, such as treatment itself. On top of that comes medical confidentiality. It obliges you to keep patient secrets. Breaking it is a criminal offense in Germany under StGB § 203.

  • GDPR Art. 9: health data is a special category with strict protection.
  • StGB § 203: unlawfully disclosing a patient secret is a criminal offense — up to one year of imprisonment or a fine.
  • Model professional code (MBO-Ä): confidentiality is also anchored in professional law and applies beyond a patient's death.
  • A name, a date of birth, or a rare diagnosis alone can make a person identifiable.

Important: even if you replace a name with a placeholder, it often stays personal data. Under GDPR Recital 26, pseudonymized data is still personal data. Pseudonymization lowers the risk, but it does not remove your obligations.

What happens when you enter data into an AI

When you type text into a consumer AI, that text leaves your computer. It is processed on the vendor's servers and may be stored there. What happens to the content depends on the service and the plan. These policies change often, so always check the current documentation.

  • According to OpenAI, inputs from its free consumer services may be used for training under certain conditions unless you opt out — check the current terms.
  • According to Microsoft and Google, business and enterprise products follow different rules than the free consumer versions.
  • Without a data processing agreement (DPA), you usually lack the legal basis to hand personal data to the vendor at all.
  • Once content is sent, it cannot be reliably recalled.

For you this means: as soon as a patient secret leaves your computer and lands with a vendor without a DPA, that can be an unlawful disclosure under StGB § 203. This holds even if you only entered it quickly for help with wording.

Which AI use is allowed in a practice

Not every AI use is off limits. It depends on whether identifiable data is involved and what safeguard you apply. The table below shows typical cases from daily practice. It is guidance, not a free pass — when in doubt, the stricter principle wins: no patient data in the AI.

Use caseAllowed?Safeguard
Write a general appointment template with no patient referenceYesUse placeholders instead of real names and data
Summarize a doctor's letter with a real nameNoPseudonymize first; only with a DPA and a vetted service
Research an anonymous, common conditionYes, with careNo identifying details; never name a rare combination
Check a bill with an insurance numberNoUse local practice software, not a consumer AI
Draft a patient email templateYesReplace name, diagnosis, and contact with placeholders

Remember the rule of thumb: the more precise the details, the easier a person is to identify. A common condition in a large city is less sensitive than a rare diagnosis in a small town. In the second case, the context alone can sometimes reveal the person.

Pseudonymize before every AI use

The most effective safeguard is data minimization: reveal as little as possible. Whatever remains, replace it with placeholders before the text leaves the practice. This is exactly where ONYRI Sanitize helps. The tool detects sensitive details in the text and replaces them with reversible tokens — for example, a name becomes a neutral placeholder.

A note on the mechanics: the detection engine runs entirely in your browser. The mapping from token to real value always stays local on your device and is never sent to a server. When you use the built-in Chat, only the already anonymized text goes to the AI model. The answer is then filled back in with the real values inside your browser.

  • Data minimization under GDPR Art. 5: process only what is necessary.
  • Pseudonymization clearly lowers the risk of disclosure.
  • The token-to-value mapping never leaves the browser.
  • To stay honest: pseudonymized data is still personal data (Recital 26). Your obligations remain.

ONYRI does not guarantee GDPR compliance and does not make your output legally anonymous. The tool reduces the amount of data that reaches the outside at all. This minimization supports your obligations — it does not replace them.

Checklist: DPA and documentation

If you want to use AI in a practice, you need more than care while typing. You need a documented framework. Work through these points in order before the first tool goes live.

  1. 1Check whether the vendor offers a data processing agreement (DPA) and sign one.
  2. 2Clarify where the data is processed and whether it is used for training — based on the vendor's current documentation.
  3. 3Put in writing which AI use is allowed and which is not.
  4. 4Pseudonymize or remove all patient data before it reaches an AI tool.
  5. 5Train your team: who may do what, and what must never go into an AI?
  6. 6Keep a record of processing activities and document your decisions.

If you are unsure, bring in your supervisory authority or your medical chamber. Germany's Data Protection Conference (DSK) has published guidance on artificial intelligence and data protection. It is a good starting point for practice.

Frequently asked questions

Can I use ChatGPT for patient data as a doctor?
Not with identifiable data. Health data is specially protected under GDPR Art. 9, and confidentiality under StGB § 203 binds you as well. Without a DPA and without pseudonymization, entering real patient data into a consumer AI is high-risk.
Is removing just the name enough?
Often not. A date of birth, a location, or a rare diagnosis can also make a person identifiable. And even pseudonymized data stays personal data under GDPR Recital 26. Remove as much as you can.
Does a tool like ONYRI make my use GDPR-compliant?
No. ONYRI pseudonymizes your text and lowers the amount of data that reaches the outside. That supports data minimization under GDPR Art. 5, but it does not replace a DPA, documentation, or a legal review.
What do I need to use AI safely in a practice?
A data processing agreement, a clear internal rule, pseudonymization before every input, team training, and documentation. When in doubt, review the case with your supervisory authority or medical chamber.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Read next