
Being open with the patient: article 50 of the AI Act
The patient has a right to know they are not talking to a person. How to do that without turning the conversation into a legal notice.
GDPR, encryption, permissions and transparency: what a clinic needs to know to protect patient data when it uses WhatsApp and AI.

The patient has a right to know they are not talking to a person. How to do that without turning the conversation into a legal notice.

Saying “we encrypt the data” says almost nothing. What each kind of encryption protects, where the keys live, and what it still does not cover.

Who answers to the law when a machine replies, what legal basis you need, and why using AI does not change what the clinic owes its patients.

The whole journey of a message: where it comes in, how it travels, where it is kept, and who can end up reading it.

Once everything lives on one screen, deciding who sees what stops being a technical detail and becomes a clinical decision.