{"id":4948,"date":"2026-03-13T11:00:28","date_gmt":"2026-03-13T11:00:28","guid":{"rendered":"https:\/\/medivox.ai\/?p=4948"},"modified":"2026-03-13T21:23:00","modified_gmt":"2026-03-13T21:23:00","slug":"what-you-need-to-know-about-patient-data-and-gdpr","status":"publish","type":"post","link":"https:\/\/medivox.ai\/en\/hva-du-ma-vite-om-pasientdata-og-gdpr\/","title":{"rendered":"Can you use AI for record keeping without violating GDPR?"},"content":{"rendered":"<p data-start=\"632\" data-end=\"759\">A GP finishes a consultation and asks ChatGPT to write a short journal note:<\/p>\n<p>\u201cSummarize this: 54-year-old man, chest pain last 3 days, using atorvastatin, previous MI.\u201d<\/p>\n<p>In a matter of seconds, the doctor receives a tidy journal note back.<\/p>\n<p>It seems effective - but what many people don't consider is that the patient data may have been sent to an external AI service.<strong> without a data processing agreement<\/strong>.<\/p>\n<p>In many cases, this may be in violation of the privacy policy.<\/p>\n<p>Many people are surprised by this - because AI itself is not illegal in healthcare.<br data-start=\"949\" data-end=\"952\" \/><strong data-start=\"954\" data-end=\"1044\">The challenge is what happens to the patient data after it is sent to an AI tool.<\/strong><\/p>\n<p data-start=\"632\" data-end=\"759\">More and more doctors and therapists are testing AI tools to write journal entries, dictate referrals or summarize consultations.<\/p>\n<p data-start=\"761\" data-end=\"808\">Tools like ChatGPT do this impressively well.<\/p>\n<p data-start=\"810\" data-end=\"845\">But here an important question arises:<\/p>\n<p data-start=\"847\" data-end=\"888\"><strong data-start=\"847\" data-end=\"888\">Is it legal to use AI on patient data?<\/strong><\/p>\n<p data-start=\"890\" data-end=\"948\">Short answer:<br data-start=\"900\" data-end=\"903\" \/><strong data-start=\"903\" data-end=\"948\">Yes - but only if certain requirements are met.<\/strong><\/p>\n<p data-start=\"950\" data-end=\"1113\">The problem is that many general AI services <strong data-start=\"995\" data-end=\"1026\">is not designed for health data<\/strong>, and can therefore violate the privacy policy if used directly for record keeping.<\/p>\n<p data-start=\"1115\" data-end=\"1138\">This guide explains:<\/p>\n<ul data-start=\"1140\" data-end=\"1276\">\n<li data-section-id=\"byqttu\" data-start=\"1140\" data-end=\"1165\">\n<p data-start=\"1142\" data-end=\"1165\">what the GDPR actually requires<\/p>\n<\/li>\n<li data-section-id=\"d0jgc8\" data-start=\"1166\" data-end=\"1219\">\n<p data-start=\"1168\" data-end=\"1219\">why general AI tools can be problematic<\/p>\n<\/li>\n<li data-section-id=\"1s5z9k4\" data-start=\"1220\" data-end=\"1276\">\n<p data-start=\"1222\" data-end=\"1276\">what an AI system must have to be safe in clinical use<\/p>\n<\/li>\n<\/ul>\n<hr data-start=\"1278\" data-end=\"1281\" \/>\n<h1 data-section-id=\"o8uow3\" data-start=\"1283\" data-end=\"1330\">Why health data is extra protected<\/h1>\n<p data-start=\"1332\" data-end=\"1435\">The General Data Protection Regulation classifies health data as <strong data-start=\"1393\" data-end=\"1434\">special categories of personal data<\/strong>.<\/p>\n<p data-start=\"1437\" data-end=\"1508\">This means that they have <strong data-start=\"1459\" data-end=\"1507\">Stricter protection than regular personal data<\/strong>.<\/p>\n<p data-start=\"1510\" data-end=\"1541\">Examples of health information:<\/p>\n<ul data-start=\"1543\" data-end=\"1752\">\n<li data-section-id=\"7awabr\" data-start=\"1543\" data-end=\"1580\">\n<p data-start=\"1545\" data-end=\"1580\">diagnoses and treatment history<\/p>\n<\/li>\n<li data-section-id=\"ah70cz\" data-start=\"1581\" data-end=\"1620\">\n<p data-start=\"1583\" data-end=\"1620\">symptoms and clinical observations<\/p>\n<\/li>\n<li data-section-id=\"w78bk\" data-start=\"1621\" data-end=\"1639\">\n<p data-start=\"1623\" data-end=\"1639\">drug use<\/p>\n<\/li>\n<li data-section-id=\"5vimmv\" data-start=\"1640\" data-end=\"1653\">\n<p data-start=\"1642\" data-end=\"1653\">test results<\/p>\n<\/li>\n<li data-section-id=\"1f0hkm6\" data-start=\"1654\" data-end=\"1685\">\n<p data-start=\"1656\" data-end=\"1685\">discharge summaries and journal notes<\/p>\n<\/li>\n<li data-section-id=\"rvmwmt\" data-start=\"1686\" data-end=\"1718\">\n<p data-start=\"1688\" data-end=\"1718\">information about mental health<\/p>\n<\/li>\n<li data-section-id=\"1f97smf\" data-start=\"1719\" data-end=\"1752\">\n<p data-start=\"1721\" data-end=\"1752\">genetic and biometric data<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"1754\" data-end=\"1853\">The regulations can be found in <strong data-start=\"1775\" data-end=\"1794\">GDPR article 9<\/strong>, which regulates the processing of sensitive personal data.<\/p>\n<p data-start=\"1855\" data-end=\"1910\">Source:<br data-start=\"1861\" data-end=\"1864\" \/>GDPR art. 9<br data-start=\"1875\" data-end=\"1878\" \/><a class=\"decorated-link\" href=\"https:\/\/gdpr-info.eu\/art-9-gdpr\/\" target=\"_new\" rel=\"noopener\" data-start=\"1878\" data-end=\"1910\">https:\/\/gdpr-info.eu\/art-9-gdpr\/<\/a><\/p>\n<hr data-start=\"1912\" data-end=\"1915\" \/>\n<h2 data-section-id=\"hn2pnq\" data-start=\"1917\" data-end=\"1958\">Can doctors use ChatGPT for record keeping?<\/h2>\n<p data-start=\"1960\" data-end=\"2003\">Many doctors and therapists have tested this.<\/p>\n<p data-start=\"2005\" data-end=\"2059\">But in practice, it can create more privacy issues.<\/p>\n<p data-start=\"2005\" data-end=\"2059\"><strong data-start=\"1223\" data-end=\"1245\">Rule of thumb:<\/strong><br data-start=\"1245\" data-end=\"1248\" \/>If you have not signed a data processing agreement with your provider, you should not send patient data to the system.<\/p>\n<h3 data-section-id=\"ngze8t\" data-start=\"2061\" data-end=\"2096\">1. Lack of data processing agreement<\/h3>\n<p data-start=\"2098\" data-end=\"2188\">When you enter patient information into an AI tool, you are sending data to an external service.<\/p>\n<p data-start=\"2190\" data-end=\"2229\">In GDPR this is called <strong data-start=\"2210\" data-end=\"2228\">data processing<\/strong>.<\/p>\n<p data-start=\"2231\" data-end=\"2330\">To make this legal, there must be a <strong data-start=\"2273\" data-end=\"2329\">data processing agreement between the clinic and the provider<\/strong>.<\/p>\n<p data-start=\"2332\" data-end=\"2395\">If this does not exist, the processing may be in violation of the GDPR.<\/p>\n<p data-start=\"2397\" data-end=\"2454\">Source:<br data-start=\"2403\" data-end=\"2406\" \/>GDPR art. 28<br data-start=\"2418\" data-end=\"2421\" \/><a class=\"decorated-link\" href=\"https:\/\/gdpr-info.eu\/art-28-gdpr\/\" target=\"_new\" rel=\"noopener\" data-start=\"2421\" data-end=\"2454\">https:\/\/gdpr-info.eu\/art-28-gdpr\/<\/a><\/p>\n<hr data-start=\"2456\" data-end=\"2459\" \/>\n<h3 data-section-id=\"1huvocc\" data-start=\"2461\" data-end=\"2494\">2. Data can be stored outside the EEA<\/h3>\n<p data-start=\"2496\" data-end=\"2556\">Several AI services store data in the US or other third countries.<\/p>\n<p data-start=\"2558\" data-end=\"2645\">The transfer of health data outside the EEA requires special legal mechanisms, such as:<\/p>\n<ul data-start=\"2647\" data-end=\"2731\">\n<li data-section-id=\"1uek1dj\" data-start=\"2647\" data-end=\"2682\">\n<p data-start=\"2649\" data-end=\"2682\">EU Standard Contractual Clauses<\/p>\n<\/li>\n<li data-section-id=\"1heykvr\" data-start=\"2683\" data-end=\"2710\">\n<p data-start=\"2685\" data-end=\"2710\">Binding Corporate Rules<\/p>\n<\/li>\n<li data-section-id=\"1uvdmd0\" data-start=\"2711\" data-end=\"2731\">\n<p data-start=\"2713\" data-end=\"2731\">Adequacy decisions<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"2733\" data-end=\"2806\">This makes the use of general AI services legally more complex in the healthcare sector.<\/p>\n<hr data-start=\"2808\" data-end=\"2811\" \/>\n<h3 data-section-id=\"e9l7c4\" data-start=\"2813\" data-end=\"2862\">3. Limited control over storage and deletion<\/h3>\n<p data-start=\"2864\" data-end=\"2931\">When patient data is sent to an external AI service, you need to know:<\/p>\n<ul data-start=\"2933\" data-end=\"3003\">\n<li data-section-id=\"maephx\" data-start=\"2933\" data-end=\"2953\">\n<p data-start=\"2935\" data-end=\"2953\">where data is stored<\/p>\n<\/li>\n<li data-section-id=\"1j57owx\" data-start=\"2954\" data-end=\"2978\">\n<p data-start=\"2956\" data-end=\"2978\">how long they are stored<\/p>\n<\/li>\n<li data-section-id=\"gk2q8a\" data-start=\"2979\" data-end=\"3003\">\n<p data-start=\"2981\" data-end=\"3003\">who has access<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"3005\" data-end=\"3094\">If this is not clearly regulated, it may violate information security requirements.<\/p>\n<hr data-start=\"3096\" data-end=\"3099\" \/>\n<h2 data-section-id=\"kq8fkf\" data-start=\"1679\" data-end=\"1729\">What happens if patient data ends up in the wrong system?<\/h2>\n<p data-start=\"1731\" data-end=\"1787\">Breaches of data protection rules in the healthcare sector can lead to:<\/p>\n<ul data-start=\"1789\" data-end=\"1976\">\n<li data-section-id=\"186jz4s\" data-start=\"1789\" data-end=\"1816\">\n<p data-start=\"1791\" data-end=\"1816\">Supervision from the Danish Data Protection Agency<\/p>\n<\/li>\n<li data-section-id=\"l81qm7\" data-start=\"1817\" data-end=\"1888\">\n<p data-start=\"1819\" data-end=\"1888\">fines of up to <strong data-start=\"1835\" data-end=\"1886\">20 million euros or 4 % of global turnover for businesses<\/strong><\/p>\n<\/li>\n<li data-section-id=\"1n2a86g\" data-start=\"1889\" data-end=\"1922\">\n<p data-start=\"1891\" data-end=\"1922\">compensation claims from patients<\/p>\n<\/li>\n<li data-section-id=\"3hgr0r\" data-start=\"1923\" data-end=\"1976\">\n<p data-start=\"1925\" data-end=\"1976\">in serious cases, supervisory proceedings against healthcare professionals<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"1978\" data-end=\"2062\">This does not mean that AI is dangerous - but that <strong data-start=\"2080\" data-end=\"2139\">The tool must be developed for handling health data.<\/strong><\/p>\n<hr data-start=\"3096\" data-end=\"3099\" \/>\n<h2 data-section-id=\"1ki7apz\" data-start=\"3101\" data-end=\"3143\">When can AI be legally used in healthcare?<\/h2>\n<p data-start=\"3145\" data-end=\"3183\">AI is <strong data-start=\"3151\" data-end=\"3182\">not illegal in healthcare<\/strong>.<\/p>\n<p data-start=\"3185\" data-end=\"3238\">But the processing must have a valid processing basis.<\/p>\n<p data-start=\"3240\" data-end=\"3256\">The most common are:<\/p>\n<h3 data-section-id=\"1vr32qz\" data-start=\"3258\" data-end=\"3289\">1. Necessary for health care<\/h3>\n<p data-start=\"3291\" data-end=\"3365\">Healthcare professionals can process health information if it is necessary for:<\/p>\n<ul data-start=\"3367\" data-end=\"3415\">\n<li data-section-id=\"p5dnbg\" data-start=\"3367\" data-end=\"3382\">\n<p data-start=\"3369\" data-end=\"3382\">diagnostics<\/p>\n<\/li>\n<li data-section-id=\"7fbo4g\" data-start=\"3383\" data-end=\"3397\">\n<p data-start=\"3385\" data-end=\"3397\">treatment<\/p>\n<\/li>\n<li data-section-id=\"s9iddx\" data-start=\"3398\" data-end=\"3415\">\n<p data-start=\"3400\" data-end=\"3415\">record keeping<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"3417\" data-end=\"3463\">This is regulated by <strong data-start=\"3436\" data-end=\"3462\">GDPR article 9 (2)(h)<\/strong>.<\/p>\n<hr data-start=\"3465\" data-end=\"3468\" \/>\n<h3 data-section-id=\"ydhpex\" data-start=\"3470\" data-end=\"3504\">2. Fulfillment of duty of care<\/h3>\n<p data-start=\"3506\" data-end=\"3567\">In Norway, healthcare professionals have <strong data-start=\"3533\" data-end=\"3566\">statutory duty to keep records<\/strong>.<\/p>\n<p data-start=\"3569\" data-end=\"3612\">This follows from <strong data-start=\"3585\" data-end=\"3611\">Health Personnel Act \u00a739<\/strong>.<\/p>\n<p data-start=\"3614\" data-end=\"3731\">If AI is used as a tool to fulfill this obligation, it may be legal - provided that privacy is safeguarded.<\/p>\n<p data-start=\"3733\" data-end=\"3807\">Source:<br data-start=\"3739\" data-end=\"3742\" \/>Health Personnel Act \u00a739<br data-start=\"3764\" data-end=\"3767\" \/><a class=\"decorated-link cursor-pointer\" href=\"https:\/\/lovdata.no\/lov\/1999-07-02-64\/\u00a739\" target=\"_new\" rel=\"noopener\" data-start=\"3767\" data-end=\"3807\">https:\/\/lovdata.no\/lov\/1999-07-02-64\/\u00a739<\/a><\/p>\n<hr data-start=\"3809\" data-end=\"3812\" \/>\n<h2 data-section-id=\"g8ptyb\" data-start=\"3814\" data-end=\"3855\">What requirements must an AI tool meet in healthcare?<\/h2>\n<p data-start=\"3857\" data-end=\"3926\">To be used safely in clinical work, an AI system must normally have:<\/p>\n<h3 data-section-id=\"1a3xwil\" data-start=\"3928\" data-end=\"3954\">1. Data processing agreement<\/h3>\n<p data-start=\"3955\" data-end=\"3995\">Regulates how patient data is processed.<\/p>\n<h3 data-section-id=\"10jn4r9\" data-start=\"3997\" data-end=\"4024\">2. Storage within the EEA<\/h3>\n<p data-start=\"4025\" data-end=\"4073\">To avoid complicated third country transfers.<\/p>\n<h3 data-section-id=\"nvk6dk\" data-start=\"4075\" data-end=\"4092\">3. Encryption<\/h3>\n<p data-start=\"4093\" data-end=\"4116\">Data must be encrypted both:<\/p>\n<ul data-start=\"4118\" data-end=\"4152\">\n<li data-section-id=\"b2jv5u\" data-start=\"4118\" data-end=\"4138\">\n<p data-start=\"4120\" data-end=\"4138\">during transfer<\/p>\n<\/li>\n<li data-section-id=\"1q7y87b\" data-start=\"4139\" data-end=\"4152\">\n<p data-start=\"4141\" data-end=\"4152\">during storage<\/p>\n<\/li>\n<\/ul>\n<h3 data-section-id=\"hfiia\" data-start=\"4154\" data-end=\"4177\">4. Access control<\/h3>\n<p data-start=\"4178\" data-end=\"4220\">Only authorized personnel should have access.<\/p>\n<h3 data-section-id=\"oojcym\" data-start=\"4222\" data-end=\"4236\">5. Logging<\/h3>\n<p data-start=\"4237\" data-end=\"4278\">All accesses to patient data must be logged.<\/p>\n<p data-start=\"4280\" data-end=\"4354\">These are requirements that follow from <strong data-start=\"4308\" data-end=\"4353\">GDPR article 32 on information security<\/strong>.<\/p>\n<p data-start=\"4356\" data-end=\"4398\">Source:<br data-start=\"4362\" data-end=\"4365\" \/><a class=\"decorated-link\" href=\"https:\/\/gdpr-info.eu\/art-32-gdpr\/\" target=\"_new\" rel=\"noopener\" data-start=\"4365\" data-end=\"4398\">https:\/\/gdpr-info.eu\/art-32-gdpr\/<\/a><\/p>\n<hr data-start=\"4400\" data-end=\"4403\" \/>\n<h2 data-section-id=\"1rhpm8z\" data-start=\"4405\" data-end=\"4443\">How MediVox handles privacy<\/h2>\n<p data-start=\"4445\" data-end=\"4506\">AI in health requires solutions that are designed for clinical use.<\/p>\n<p data-start=\"4508\" data-end=\"4672\">Developed specifically for healthcare professionals, Medivox is designed to meet the legal and technical requirements that apply to the processing of patient data in the healthcare sector.<\/p>\n<p data-start=\"4674\" data-end=\"4693\">Among the measures are:<\/p>\n<ul data-start=\"4695\" data-end=\"4869\">\n<li data-section-id=\"1is1nd3\" data-start=\"4695\" data-end=\"4734\">\n<p data-start=\"4697\" data-end=\"4734\">data processing agreement with all customers<\/p>\n<\/li>\n<li data-section-id=\"vyeiq7\" data-start=\"4735\" data-end=\"4762\">\n<p data-start=\"4737\" data-end=\"4762\">Storage of data in Norway<\/p>\n<\/li>\n<li data-section-id=\"rw4vnh\" data-start=\"4763\" data-end=\"4797\">\n<p data-start=\"4765\" data-end=\"4797\">encrypted transmission and storage<\/p>\n<\/li>\n<li data-section-id=\"1ebcb2l\" data-start=\"4798\" data-end=\"4829\">\n<p data-start=\"4800\" data-end=\"4829\">access control and logging<\/p>\n<\/li>\n<li data-section-id=\"1b7l3k6\" data-start=\"4830\" data-end=\"4869\">\n<p data-start=\"4832\" data-end=\"4869\">clear routines for deleting data<\/p>\n<\/li>\n<\/ul>\n<hr data-start=\"5067\" data-end=\"5070\" \/>\n<h2 data-section-id=\"p1w6f6\" data-start=\"5072\" data-end=\"5115\">Want to see how it works in practice?<\/h2>\n<p data-start=\"5117\" data-end=\"5251\">We're also hosting a webinar where we'll demonstrate how AI can be used for record keeping, letters and documentation in clinical work.<\/p>\n<p data-start=\"5253\" data-end=\"5284\">You can see more about the webinar here:<\/p>\n<p data-start=\"5286\" data-end=\"5434\">Streamlining medical notes - how AI can free up doctors' time<br data-start=\"5360\" data-end=\"5363\" \/><a class=\"decorated-link\" href=\"https:\/\/events.medivox.ai\/#events\" target=\"_new\" rel=\"noopener\" data-start=\"5363\" data-end=\"5396\">https:\/\/events.medivox.ai\/<\/a><\/p>\n<hr data-start=\"5436\" data-end=\"5439\" \/>\n<h2 data-section-id=\"u53moq\" data-start=\"5441\" data-end=\"5498\">Checklist: Is the AI tool you use GDPR compliant?<\/h2>\n<p data-start=\"5500\" data-end=\"5529\">Go through these questions:<\/p>\n<p data-start=\"5531\" data-end=\"5765\">- Is there a data processing agreement?<br data-start=\"5567\" data-end=\"5570\" \/>- Do you know where your data is stored?<br data-start=\"5596\" data-end=\"5599\" \/>- Is data stored within the EEA?<br data-start=\"5629\" data-end=\"5632\" \/>- Is data encrypted during transmission and storage?<br data-start=\"5679\" data-end=\"5682\" \/>- Is there access control and logging?<br data-start=\"5723\" data-end=\"5726\" \/>- Are patients informed about the use of AI?<\/p>\n<p data-start=\"5767\" data-end=\"5878\">If you can't answer yes to these questions, you should consider the solution further before applying it to patient data.<\/p>\n<hr data-start=\"5880\" data-end=\"5883\" \/>\n<h2 data-section-id=\"11dr0jn\" data-start=\"5885\" data-end=\"5909\">FAQ - frequently asked questions<\/h2>\n<h3 data-section-id=\"1jwtawj\" data-start=\"5911\" data-end=\"5962\">Do I need patient consent to use AI?<\/h3>\n<p data-start=\"5964\" data-end=\"5982\">Not necessarily.<\/p>\n<p data-start=\"5984\" data-end=\"6119\">If AI is used as a tool for diagnostics, treatment or record keeping, the treatment basis may be <strong data-start=\"6094\" data-end=\"6118\">necessary health care<\/strong>.<\/p>\n<p data-start=\"6121\" data-end=\"6183\">But patients should be informed about how their data is processed.<\/p>\n<hr data-start=\"6185\" data-end=\"6188\" \/>\n<h3 data-section-id=\"ny63d7\" data-start=\"6190\" data-end=\"6228\">Can the AI provider see patient data?<\/h3>\n<p data-start=\"6230\" data-end=\"6255\">It depends on the system.<\/p>\n<p data-start=\"6257\" data-end=\"6385\">Access may be necessary in certain cases, for example when troubleshooting.<br data-start=\"6333\" data-end=\"6336\" \/>Then the access should be <strong data-start=\"6359\" data-end=\"6384\">restricted and logged<\/strong>.<\/p>\n<hr data-start=\"6723\" data-end=\"6726\" \/>\n<h3>Are AI journals legal in Norway?<\/h3>\n<p data-start=\"3011\" data-end=\"3014\">Yes.<\/p>\n<p data-start=\"3016\" data-end=\"3158\">AI can be used as a tool for writing journal notes, as long as healthcare professionals remain professionally responsible for the content of the journal.<\/p>\n<p data-start=\"3160\" data-end=\"3220\">The journal must still meet the requirements of the Health Personnel Act.<\/p>\n<hr data-start=\"6387\" data-end=\"6390\" \/>\n<h3 data-section-id=\"dejwc9\" data-start=\"2301\" data-end=\"2348\">Can I use ChatGPT if I remove names?<\/h3>\n<p data-start=\"2350\" data-end=\"2368\">Not necessarily.<\/p>\n<p data-start=\"2370\" data-end=\"2489\">Even without a name, information such as age, diagnosis, symptoms or rare conditions can make a patient identifiable.<\/p>\n<p data-start=\"2491\" data-end=\"2585\">This means that also <strong data-start=\"2511\" data-end=\"2584\">Partially anonymized information can be personal data under GDPR<\/strong>.<\/p>\n<hr data-start=\"6185\" data-end=\"6188\" \/>\n<h3 data-section-id=\"1aj8j10\" data-start=\"6392\" data-end=\"6418\">Does data have to be stored in Norway?<\/h3>\n<p data-start=\"6420\" data-end=\"6424\">No, you don't.<\/p>\n<p data-start=\"6426\" data-end=\"6511\">But they normally need to be stored <strong data-start=\"6451\" data-end=\"6470\">within the EU\/EEA<\/strong> if they contain personal data.<\/p>\n<hr data-start=\"6513\" data-end=\"6516\" \/>\n<h3 data-section-id=\"1oazn04\" data-start=\"6518\" data-end=\"6572\">Can AI tools use patient data for model training?<\/h3>\n<p data-start=\"6574\" data-end=\"6636\">Only if this is explicitly regulated in the data processing agreement.<\/p>\n<p data-start=\"6638\" data-end=\"6721\">In many cases, this will require <strong data-start=\"6672\" data-end=\"6720\">pseudonymization or anonymization of data<\/strong>.<\/p>\n<hr data-start=\"6723\" data-end=\"6726\" \/>\n<h3 data-section-id=\"oc645y\" data-start=\"6728\" data-end=\"6773\">What happens if a patient requests deletion?<\/h3>\n<p data-start=\"6775\" data-end=\"6827\">Patients have the right to erasure in many situations.<\/p>\n<p data-start=\"6829\" data-end=\"6927\">But in the health service <strong data-start=\"6858\" data-end=\"6886\">journal retention obligation<\/strong>, which often takes precedence over the right to erasure.<\/p>\n<hr data-start=\"6929\" data-end=\"6932\" \/>\n<h2 data-section-id=\"1zehoy\" data-start=\"279\" data-end=\"327\">A situation many doctors recognize themselves in<\/h2>\n<p data-start=\"329\" data-end=\"567\">In a busy clinical environment, it's easy to test new tools to save time.<br data-start=\"405\" data-end=\"408\" \/>As a result, many doctors have tried pasting a journal entry or epicrisis into an AI tool to help improve the wording or create a summary.<\/p>\n<p data-start=\"569\" data-end=\"648\">It's understandable - the need for better tools in clinical documentation is great.<\/p>\n<p data-start=\"650\" data-end=\"842\">However, when patient data is sent to general AI services without a data processing agreement or control over where the data is stored, it can also create legal and privacy challenges.<\/p>\n<hr data-start=\"6929\" data-end=\"6932\" \/>\n<h2 data-section-id=\"ug6tuu\" data-start=\"6934\" data-end=\"6946\">Conclusion<\/h2>\n<p data-start=\"6948\" data-end=\"6998\">AI can be a powerful tool for healthcare professionals.<\/p>\n<p data-start=\"7000\" data-end=\"7073\">But when patient data is involved, the solution must meet strict requirements:<\/p>\n<ul data-start=\"7075\" data-end=\"7125\">\n<li data-section-id=\"17wkt5e\" data-start=\"7075\" data-end=\"7089\">\n<p data-start=\"7077\" data-end=\"7089\">privacy<\/p>\n<\/li>\n<li data-section-id=\"tmbve4\" data-start=\"7090\" data-end=\"7107\">\n<p data-start=\"7092\" data-end=\"7107\">data security<\/p>\n<\/li>\n<li data-section-id=\"s308dc\" data-start=\"7108\" data-end=\"7125\">\n<p data-start=\"7110\" data-end=\"7125\">legal responsibility<\/p>\n<\/li>\n<\/ul>\n<blockquote data-start=\"3728\" data-end=\"3854\">\n<p data-start=\"3730\" data-end=\"3854\">The most important question is therefore not <strong data-start=\"3770\" data-end=\"3789\">if you use AI<\/strong>, but <strong data-start=\"3795\" data-end=\"3853\">whether the tool is designed for handling patient data<\/strong>.<\/p>\n<\/blockquote>\n<hr data-start=\"7212\" data-end=\"7215\" \/>\n<h1 data-section-id=\"btdgez\" data-start=\"7217\" data-end=\"7225\">Sources<\/h1>\n<p data-start=\"7227\" data-end=\"7291\">GDPR - General Data Protection Regulation<br data-start=\"7268\" data-end=\"7271\" \/><a class=\"decorated-link\" href=\"https:\/\/gdpr-info.eu\" target=\"_new\" rel=\"noopener\" data-start=\"7271\" data-end=\"7291\">https:\/\/gdpr-info.eu<\/a><\/p>\n<p data-start=\"7293\" data-end=\"7371\">Norwegian Data Protection Authority - Artificial intelligence and privacy<br data-start=\"682\" data-end=\"685\" \/><a class=\"decorated-link\" href=\"https:\/\/www.datatilsynet.no\/regelverk-og-verktoy\/rapporter-og-utredninger\/kunstig-intelligens\/\" target=\"_new\" rel=\"noopener\" data-start=\"685\" data-end=\"779\">https:\/\/www.datatilsynet.no\/regelverk-og-verktoy\/rapporter-og-utredninger\/kunstig-intelligens\/<\/a><\/p>\n<p data-start=\"1166\" data-end=\"1381\">Norwegian Data Protection Authority - Privacy and artificial intelligence (recommendations)<br data-start=\"1233\" data-end=\"1236\" \/><a class=\"decorated-link\" href=\"https:\/\/www.datatilsynet.no\/regelverk-og-verktoy\/rapporter-og-utredninger\/kunstig-intelligens\/anbefalinger\/\" target=\"_new\" rel=\"noopener\" data-start=\"1236\" data-end=\"1343\">https:\/\/www.datatilsynet.no\/regelverk-og-verktoy\/rapporter-og-utredninger\/kunstig-intelligens\/anbefalinger\/<\/a><\/p>\n<p data-start=\"7373\" data-end=\"7430\">Health Personnel Act<br data-start=\"7391\" data-end=\"7394\" \/><a class=\"decorated-link\" href=\"https:\/\/lovdata.no\/lov\/1999-07-02-64\" target=\"_new\" rel=\"noopener\" data-start=\"7394\" data-end=\"7430\">https:\/\/lovdata.no\/lov\/1999-07-02-64<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>The use of AI in healthcare requires strict privacy management. Learn about GDPR requirements and how to ensure compliant processing of patient data.<\/p>","protected":false},"author":9,"featured_media":5003,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[78,72,75,73],"tags":[],"class_list":["post-4948","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ledere","category-leger","category-opplaering","category-sykepleiere"],"_links":{"self":[{"href":"https:\/\/medivox.ai\/en\/wp-json\/wp\/v2\/posts\/4948","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/medivox.ai\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/medivox.ai\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/medivox.ai\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/medivox.ai\/en\/wp-json\/wp\/v2\/comments?post=4948"}],"version-history":[{"count":2,"href":"https:\/\/medivox.ai\/en\/wp-json\/wp\/v2\/posts\/4948\/revisions"}],"predecessor-version":[{"id":5002,"href":"https:\/\/medivox.ai\/en\/wp-json\/wp\/v2\/posts\/4948\/revisions\/5002"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/medivox.ai\/en\/wp-json\/wp\/v2\/media\/5003"}],"wp:attachment":[{"href":"https:\/\/medivox.ai\/en\/wp-json\/wp\/v2\/media?parent=4948"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/medivox.ai\/en\/wp-json\/wp\/v2\/categories?post=4948"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/medivox.ai\/en\/wp-json\/wp\/v2\/tags?post=4948"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}