April 29, 2026 · 10 min read
KVKK and Clinical Software: A Compliance Guide
Law No. 6698, the Personal Data Protection Law (KVKK) entered into force in 2016. Since then, one of the most frequent questions from clinic managers has been: "What should I pay attention to when using software that stores sensitive information such as patient data?" This guide provides practical answers.
Why Is Health Data "Special Category"?
Under Article 6 of the KVKK, health data is special category personal data. This requires far stricter protection than ordinary data:
- Explicit consent is MANDATORY for processing (except for legal exemptions)
- The data controller is obliged to take additional security measures
- Mandatory registration with the Data Controllers' Registry (VERBİS)
- Penalties increased up to fivefold in the event of a breach
Your Responsibilities as a Clinic
A clinic is a data controller. Even if you use software, you are responsible for protecting patient data. Here is what you need to do:
- VERBİS Registration: Mandatory for clinics with annual revenue above 1 million TL. Registration is free via the KVKK website.
- Privacy Notice: You must inform your patient about the purpose and method of data processing and their rights (on the intake form).
- Explicit Consent Form: A separate, written (or electronic) explicit consent must be obtained for health data. KRATS offers a digital explicit consent form.
- Data Processing Inventory: It must be documented which data is stored where and who accesses it.
- Trained Staff: KVKK training for clinic employees (annually recommended).
- Data Breach Notification: In the event of a breach, notify the Personal Data Protection Board within 72 hours.
What to Expect from the Software
A KVKK-compliant clinical software should include the following features:
- Encryption: Data traffic TLS 1.2+, storage AES-256.
- Access Control: Role-based authorization (receptionist, physician, and administrator access different data).
- Audit Log: A record of who accessed which data and when (a KVKK Art. 12 requirement).
- Multi-Factor Authentication (MFA): SMS/TOTP verification in addition to the password.
- Data Backup: Regular, encrypted backups (KRATS: daily, 7-day retention).
- Data Erasure: Complete erasure of data upon the patient's request (KVKK Art. 7).
- Data Export: The right to download patient data in a standard format (PDF, JSON) (KVKK Art. 11/d).
KRATS's KVKK Compliance
KRATS has taken KVKK requirements into account from the very design stage:
- Data Locality: Health data stays on your device or your own server. KRATS cloud access is optional and encrypted only.
- Two-Way Encryption: Communication TLS 1.2+, storage AES-256-GCM.
- Audit Log: All access and changes are logged with date, user, and IP. Retained for 10 years.
- Role Management: The receptionist cannot see the patient's medical records, only the appointment information.
- Explicit Consent Module: Digital explicit consent is signed at patient admission and stored as a PDF.
- Data Erasure: GDPR-compliant erasure with a single click at the patient's request. A record of the operation remains in the audit log.
- Backup: Daily encrypted backups with AWS Backup (eu-central-1 Frankfurt — a certified region outside Turkey).
- Breach Detection: CloudWatch alarms on anomalous access patterns (SOAR-ready).
Practical Tips for VERBİS Registration
- Registration Obligation Check: Is your annual revenue above 1 million TL? Or do you process sensitive (health) data? If yes, registration is mandatory.
- Data Processing Purposes: Define clear categories such as "patient appointment management", "medical records", and "billing".
- Data Transfers: List all third parties — SGK, e-Prescription, bank, KRATS software, AWS, Cloudflare.
- Retention Periods: The statutory period for health data (generally 20 years, 10 years for a deceased patient).
- Security Measures: If you use software such as KRATS, add the items "encryption, audit, MFA, backup".
Penalties and Breach Scenarios
In recent years, the KVKK Board has imposed serious penalties on clinics and hospitals:
- Storing patient data in software exposed to unauthorized access: 500,000 - 2,000,000 TL
- Sending SMS without obtaining explicit consent: 50,000 - 200,000 TL
- Lack of a privacy notice: an administrative fine starting from 50,000 TL
- Failing to report a data breach: active penalty + an additional 1 million TL
Conclusion
KVKK may seem complex, but with the right tools and processes, achieving compliance is not difficult. By automating this process, KRATS gives you the opportunity to focus solely on your clinical work. You can also see the KVKK compliance module when you request a demo.
KVKK-Compliant Clinical Software
Start with KRATS and make your KVKK compliance automatic.
Request a Demo