A Medical Website Is Not an Ordinary Website
As soon as a doctor's website processes personal data, the GDPR comes into play. When certain information reveals a person's health status, the level of protection increases considerably: health data is among the special categories whose processing is in principle prohibited except under exceptions.
Digital compliance is not added after the site is built. It must be integrated into its architecture.
Health Data and Risk Levels
Health data is not limited to a diagnosis recorded in a medical file. It can cover symptoms, medical history, treatments, clinical photographs or care pathway information — including when entered in a simple web form.
The risk level depends on the type of site:
Brochure site (presentation, contact details): limited personal data processing.
Site with a form: as soon as the user can transmit an identity, reason or health information.
Patient portal (authentication, document exchange, prescriptions): a genuine system handling health data, with all associated obligations.
Forms, Minimization and Information
The GDPR does not say every processing must be based on consent. Every processing must have an appropriate legal basis (Article 6) and, for health data, a condition under Article 9.
The minimization principle requires collecting only what is genuinely necessary. A callback form does not need to immediately collect the patient's complete medical history.
Beware of the free "Message" field: a patient may spontaneously write medical information. Processing must be designed accordingly.
Each form must provide clear information: data controller, purpose, legal basis, recipients, applicable rights.
Cookies: Neither All Nor Nothing
Not all cookies require consent. Certain strictly necessary trackers and certain audience measurement tools meeting precise conditions may be exempt.
When consent is required, refusal must be as simple as acceptance. A visible "Accept" button and a hidden "Continue without accepting" link are precisely the type of architecture to avoid.
Advertising pixels and retargeting tools on a medical website require enhanced vigilance: a visited URL may allow inference of health information.
HDS and Security
HDS hosting becomes relevant when personal health data from prevention, diagnosis or care activities is hosted on behalf of the relevant actors. Analysis must be done case by case: host certification is not sufficient to summarize compliance.
A secure medical website requires: HTTPS, access management, strong passwords, backups, updates, logging and incident procedures. Security must be designed end to end, not reduced to an SSL padlock.
Processors, Transfers and Retention
A modern site often uses a host, CDN, appointment tool, analytics, chatbot and AI provider. Each integration creates a new data flow. One must know who receives what, why, where and under what contract (GDPR Article 28).
The location of the main server does not guarantee data remains in the EEA. Sub-processors, support, cloud services and AI tools can create international transfers that must be framed.
Retention periods must be defined by data category and purpose. Data must not be retained indefinitely.
Patient Rights and Governance
Individuals have rights: access, rectification, erasure in situations provided, restriction, objection. The right to erasure has exceptions — avoid the simplistic formula "You can always request deletion of all your data."
Actual processing must be recorded in an internal register. A DPIA may be required when processing is likely to result in high risk. Compliance begins before development: Privacy by Design.
FAQ
Must a medical form include a consent checkbox?
No. Processing must rest on an appropriate legal basis. Consent is not the necessary basis for all processing.
Must a medical website necessarily be HDS?
Not simply because it belongs to a doctor. Application of the HDS regime depends on the data concerned, its origin and hosting context. Case-by-case analysis is necessary.
Do all cookies require consent?
No. Certain strictly necessary trackers and certain audience measurement tools meeting precise conditions may be exempt.
Can an AI chatbot be used on a medical website?
Yes depending on the use case, but one must analyze the data it receives, its providers, hosting, transfers and applicable regulatory frameworks.
Does HTTPS suffice to protect medical data?
No. HTTPS protects transmission, but security must cover the entire system.
Must a doctor always have a DPO?
No. The obligation depends on the organization and the nature and scale of processing carried out.
The Elysium MedTech Approach
At Elysium MedTech, we integrate compliance into the digital architecture: Privacy by Design, Security by Design, data minimization, flow mapping, processor management, controlled cookies, HDS analysis and GDPR integrated into the workflow.
Our goal: build a digital environment that is useful, secure, documented and compliant with its actual use.