Healthcare / practices & clinicsSolution · Draft doctor's letters and research medically — under medical confidentiality (§ 203 StGB) and health-data rules (Art. 9 GDPR)

AI for medical practices & clinics: § 203 StGB, patient data, Art. 9 GDPR | meinGPT

How medical and dental practices, psychotherapists and clinics use AI while preserving medical confidentiality (§ 203 StGB) and handling health data (Art. 9 GDPR): drafting doctor's letters, patient communication, medical research with sources, practice knowledge management — with real workflows, an example prompt and strict review limits.

For Doctors, dentists, psychotherapists, practice owners, practice and clinic management, and practice teams.

Who it is for
Doctors, dentists, psychotherapists, practice owners, practice and clinic management, and practice teams
Impact
Less time in documentation and correspondence — every medically relevant statement stays reviewed and owned by the doctor; no diagnosis or treatment decision by the AI
Task
Draft doctor's letters and research medically — under medical confidentiality (§ 203 StGB) and health-data rules (Art. 9 GDPR)
Short answer

AI in healthcare means using generative AI for the preparatory, recurring tasks of a practice or clinic — drafting doctor's letters and findings from verified information, drafting patient communication, researching medically with sources, and making internal practice knowledge accessible. Two frames are decisive. First, medical confidentiality: doctors, dentists and psychotherapists in Germany are professionals bound by secrecy under § 203 (1) no. 1 StGB and may only pass patient data to external IT or AI providers if those providers are bound in writing to confidentiality as a 'contributing person' within the meaning of § 203 (3) StGB. Second, the special data-protection regime: health data are special categories of personal data under Art. 9 GDPR and may only be processed on a separate legal basis (Art. 9 (2) GDPR) and with strict care — as a rule pseudonymised. For the first frame, meinGPT offers practices and clinics exactly this separate confidentiality undertaking under § 203 StGB: in it, SelectCode commits in writing to secrecy as a contributing person under § 203 (3) sentence 2 StGB. The AI handles the preparatory work — every medically relevant statement, diagnosis and treatment decision is reviewed and owned by the doctor.

How it works

From the task to productive AI use

For practices and clinics the core question is not "can AI do this?" but "may I put patient data into it?" — and the answer hangs on two things. First, medical confidentiality: § 203 StGB expressly allows professionals bound by secrecy to make use of 'contributing persons' in exercising their profession — external IT and AI providers, for instance — provided their involvement is necessary and they are bound to secrecy. meinGPT reflects exactly that construction in a separate confidentiality undertaking under § 203 StGB — its own signable contract, not part of the standard terms: in it, SelectCode commits in writing to secrecy as a contributing person under § 203 (3) sentence 2 StGB, keeps entrusted third-party secrets confidential (continuing beyond the end of the contract), obtains only the knowledge necessary to perform the contract, and binds all deployed staff and any sub-contractors (and their staff) to confidentiality in writing in advance; the undertakings are to be produced to the professional on request. Second, the special data-protection regime: health data are special categories under Art. 9 GDPR — processing them requires a separate legal basis under Art. 9 (2) GDPR and particular care; where possible, patient details should be pseudonymised before processing. Technically this runs on a platform that bundles several models behind one interface with central permission management, is operated in the EU, provides for a DPA and does not use input for training. The doctor therefore stays master of the secret and of the data: the AI prepares doctor's letters, patient letters and research; the medical assessment, diagnosis, treatment decision and sign-off stay with them.

Who it is for
Doctors, dentists, psychotherapists, practice owners, practice and clinic management, and practice teams
Impact
Less time in documentation and correspondence — every medically relevant statement stays reviewed and owned by the doctor; no diagnosis or treatment decision by the AI
Task
Draft doctor's letters and research medically — under medical confidentiality (§ 203 StGB) and health-data rules (Art. 9 GDPR)
Use cases

What Healthcare / practices & clinics gets done with AI

Concrete, repeatable flows — from the first prompt to a dependable result.

01

Draft doctor's letters and findings summaries

From verified information supplied by the doctor, the assistant drafts a structured doctor's letter or findings summary in the desired form and tone. The doctor reviews every medical statement and approves — the AI takes over the drafting, not the medical assessment. No findings and no diagnosis are produced by the AI; special categories under Art. 9 GDPR are processed only on a separate legal basis and, where possible, pseudonymised.

02

Draft patient communication

From bullet points, the assistant drafts factual text for recurring patient communication — appointment reminders, organisational notes, general information. The doctor or practice team checks content and accuracy before sending; the AI supplies the draft, not the binding medical statement to the patient.

03

Medical research with sources as preparation

As preparation, the assistant researches publicly available professional information and summarises it with source references. The result is a working basis, not a diagnosis or treatment recommendation from the AI — the medical assessment, diagnosis and decision are made and owned by the doctor. Models can misquote or invent sources, so every source must be checked against the primary literature.

04

Make practice and clinic knowledge accessible

An assistant connected to internal guidelines, SOPs and handbooks answers the team's recurring organisational and professional questions (procedures, internal standards, responsibilities) with a source reference — for the team, with permissions, without protected patient data leaving the practice or clinic boundary. Access follows the permissions granted.

05

Take the load off documentation and administration

The assistant helps structure recurring documentation and administrative tasks — producing templates, checklists and internal notes from verified guidance, for instance. The medical documentation itself, its accuracy and completeness remain the doctor's responsibility and run through the audited practice and clinic systems, not through the AI.

06

Build a practice assistant with a fixed review rule

Without programming, the practice or clinic assembles an assistant with its own templates and a fixed review reminder ('Draft — to be reviewed and owned by the doctor; no diagnosis or treatment decision by the AI') and releases it to the team. Human control is thereby anchored in the workflow rather than optional; no processing of special categories without a separate legal basis and, as a rule, pseudonymisation.

Open example

A real prompt, a real answer

Nothing hidden — you see the input and the result before you sign up.

Prompt

I am a doctor preparing a letter to a patient. From my verified bullet points, draft a polite, factual text and output it as a table per section: section, draft text, review note for me. Make no diagnosis, no treatment recommendation and no binding medical statement; flag every point where I need to check or add something medically. Use no real patient names. Bullet points: reminder of the follow-up appointment, documents to bring to the appointment, general note on an open question.

How meinGPT works on your task
meinGPT's answer
SectionDraft text (proposal)Review note
Salutation & reference"Dear …, we would like to remind you of your upcoming appointment."Check salutation/reference, no real names in the draft
Appointment reminder"Your follow-up appointment takes place on … at …."Check the appointment against the calendar
Documents needed"Please bring … so that we can discuss …."⚠ Check medically: which documents are needed in this specific case
Open question"Regarding your question about …, we will come back to you separately after medical review."⚠ No diagnosis/treatment recommendation in the draft — to be answered by the doctor
Closing"Kind regards, your practice team"Sign-off by the doctor before sending
Ready to use

Put it to work in your own company

In a short live demo we show how this solution runs in your company with meinGPT, GDPR-compliant — using your own use cases.

Book a live demo

Or download the AI for professionals bound by secrecy — the § 203 selection criteria (PDF, German) as a PDF:

AI for professionals bound by secrecy — the § 203 selection criteria (PDF, German)By email

A work email is enough — processed in line with the GDPR.

GDPR & security

Built for enterprise compliance

Practices and clinics process professional secrets and special categories of personal data, and the operation is designed accordingly. meinGPT is operated by SelectCode GmbH, which is ISO 27001 certified and has its security reviewed regularly through independent penetration tests (most recently SySS, 2025); the certificate and evidence are available through the Trust Center. Processing takes place in the EU, a data processing agreement (DPA) is standard, and input is not used to train the models. Access to patient data, drafts and the knowledge base follows strict permissions through central permission management with SSO, is limited by least-privilege scopes and is traceable through audit logs. For professionals bound by secrecy the decisive building block is added: meinGPT offers practices and clinics a separate confidentiality undertaking under § 203 StGB — its own signable contract, not part of the standard terms. In it, SelectCode commits in writing to secrecy as a contributing person under § 203 (3) sentence 2 StGB — keeping entrusted secrets confidential (including beyond the end of the contract), obtaining only the knowledge necessary to perform the contract, and binding all deployed staff and any sub-contractors (and their staff) to confidentiality in writing as well, contractually; the undertakings are to be produced to the professional on request. Unauthorised disclosure by a contributing person is a criminal offence under § 203 (4) StGB. Disclosure occurs only where an official or judicial duty requires it, with prior notice where permissible. Because health data are special categories under Art. 9 GDPR, the following applies additionally: processing only on a separate legal basis and with particular care, as a rule pseudonymised. Together with EU processing, a DPA and the exclusion of training on input, that is the basis for using AI while preserving medical confidentiality and the special data-protection regime; meinGPT provides the confidentiality undertaking on request. Patient data therefore stays under control in the practice or clinic environment rather than being processed through private AI accounts (shadow AI).

What matters when choosing
  • § 203 StGB: Does the provider commit in writing to confidentiality as a contributing person — with a separate confidentiality undertaking (§ 203 (3) sentence 2 StGB) — and does it undertake contractually to bind its staff and any sub-contractors in writing too, with undertakings to be produced to the professional on request?
  • Art. 9 GDPR — health data: Are special categories of personal data processed only on a separate legal basis (Art. 9 (2) GDPR), and does the setup support pseudonymising patient details?
  • EU processing & DPA: Is patient data processed within the EU and is there a data processing agreement (Art. 28 GDPR) governing instruction-bound processing, technical measures and deletion duties?
  • No training on input: Is it contractually assured that prompts, uploads and patient data are not used to train the models?
  • Roles, permissions & logging: Is there central user and permission management, SSO, least-privilege access and audit logs to evidence access to patient data?
  • Patient-data separation: Can cases and patient data be kept cleanly apart instead of being mixed in one shared, uncontrolled context?
  • Adoption & enablement: Is there training and are there champions, so the practice or clinic uses AI correctly, with review and without detouring through private shadow AI?
Limits & failure modes

What this solution cannot (yet) do

Honesty is part of the solution. These limits are known — and therefore plannable.

01

AI is preparation and relief, not the practice of medicine: drafts, summaries and research are working materials. The AI makes no diagnosis, takes no treatment decision and does not practise medicine — every medical assessment and decision is made and owned by the doctor.

02

Health data are special categories under Art. 9 GDPR: processing them is only permissible on a separate legal basis (Art. 9 (2) GDPR) and requires particular care; as a rule patient details must be pseudonymised, and in case of doubt a separate data-protection assessment of the individual case is called for.

03

Confidentiality under § 203 StGB and responsibility for preserving the secret always remain with the doctor; contractually involving the provider as a contributing person does not relieve them of their own duty of care and review. Patient data must never be processed through private AI accounts (shadow AI).

04

AI models can misrepresent or invent content, sources or details; no draft, summary or piece of research may be used or passed on externally without review. A four-eyes or sign-off principle is strongly recommended.

05

meinGPT is not a medical device and makes no medical intended-purpose claim; the boundary to the Medical Device Regulation (MDR) must be observed, and the AI does not replace medical, legal or data-protection advice. Whether and how AI may be used in a specific case should be clarified with the competent medical association, the data protection officer and/or legal counsel.

FAQ

Frequently asked questions

Yes — but only while preserving medical confidentiality. Doctors, dentists and psychotherapists are professionals bound by secrecy under § 203 (1) no. 1 StGB. External IT and AI providers count as 'contributing persons'; patient data may be disclosed to them under § 203 (3) StGB insofar as this is necessary for the professional activity and the provider is bound to confidentiality in writing. meinGPT provides practices and clinics with a separate confidentiality undertaking under § 203 StGB, in which SelectCode commits in writing to secrecy as a contributing person under § 203 (3) sentence 2 StGB. On top of that you need EU processing, a DPA, the assurance that input is not used for training, and — because health data are special categories under Art. 9 GDPR — a separate legal basis. Patient data must not be processed through private AI accounts without such a binding commitment.

Related solutions

AI in accounting & finance: receipts, invoices, reporting | meinGPTHow accounting and finance teams use AI GDPR-compliantly: pre-capture receipts and invoices, extract data, prepare reporting — with real workflows, an example prompt, strict review limits and selection criteria.Creating AI agents: build your own agents without code | meinGPTWhat an AI agent is (and how it differs from an assistant and a chatbot) and how companies build their own AI agents without programming: goal, instruction, knowledge (RAG), tools & actions, guardrails and approval — with a build guide, an example, governance, a checklist and GDPR.AI in customer service: enquiries, knowledge base, tickets | meinGPTHow customer service teams use AI GDPR-compliantly: answer enquiries faster, search the knowledge base, summarise tickets and reply consistently — with real workflows, an example prompt, honest limits and selection criteria.