Healthcare providers process health data, the most protected category of personal data under the GDPR. A website with a contact form, an online appointment system, or a patient portal must be set up correctly from a technical standpoint. That’s not an option; it’s a legal requirement.
Why GDPR carries more weight for healthcare providers than for other sectors
The General Data Protection Regulation, better known as the GDPR, applies to every organization that processes personal data. But not all personal data is equal. The GDPR makes an explicit distinction between ordinary personal data and special categories of personal data that deserve increased protection.
Health data falls under that special category, along with genetic data, biometric data, and a limited number of other categories. Article 9 of the GDPR essentially prohibits the processing of health data unless specific conditions are met. For healthcare providers, an exception applies for the provision of healthcare, but that exception is tied to strict technical and organizational requirements.
In concrete terms, for a healthcare provider’s website, this means: every technical component that processes personal data—a contact form, an online appointment system, a chat function, a patient portal—must be set up in a way that meets the heightened protection requirements of the GDPR.
A website that fails to do so exposes the healthcare provider to real risks: fines from the Data Protection Authority, reputational damage, and a loss of patient trust that is difficult to repair.
The most common GDPR mistakes on healthcare provider websites
LOFT 33 regularly analyzes websites of medical practices and healthcare institutions. These are the most frequent GDPR-related issues:
A cookie notice that isn’t correctly configured.
A cookie notice that only informs but offers no real choice, or where analytical and marketing cookies are already loaded before the visitor has given consent, does not comply with the GDPR. This is one of the most common technical shortcomings on medical websites, and one of the easiest for the Data Protection Authority to check.
A privacy policy that doesn’t match the actual data processing.
A generic privacy policy copied from another website or generated via an online tool rarely correctly describes which data the practice actually processes, on what basis, and for what purpose. An incorrect privacy policy is not just a GDPR violation; it’s also a reputational risk if patients read it.
No data processing agreement with third-party service providers.
Every third-party service provider that processes personal data on behalf of the practice—a hosting provider, an appointment system provider, an email marketing platform—must have a data processing agreement in place. Without that agreement, the practice is in violation as the data controller, even if the third-party provider acts correctly themselves.
A contact form without a correct legal basis.
A contact form on a medical website processes personal data. The basis for that processing must be clear—consent, performance of a contract, or legitimate interest—and must be correctly communicated to the visitor. A form without that communication does not meet GDPR transparency requirements.
An online appointment system without adequate security.
An online appointment system processes names, contact details, and in many cases, information about the reason for the visit, which is health data. That system must be technically secured, data must not be kept longer than necessary, and the connection security must be correctly configured.
No procedure for data breaches.
The GDPR requires organizations to report data breaches to the Data Protection Authority within 72 hours if they pose a risk to the rights and freedoms of those involved. For healthcare providers, the chance of a data breach via the website—a hacked contact form, an unsecured database—is more real than often assumed. A website without technical security measures significantly increases that risk.
What LOFT 33 implements technically
LOFT 33 delivers websites for healthcare providers with a technically correct GDPR structure as a standard part of every project. This includes the following technical elements.
Correct cookie configuration. A cookie management system that offers visitors a real choice, blocks analytical and marketing cookies until consent is given, and correctly registers and respects the visitor’s choice. No pre-ticked boxes, no dark patterns that manipulate consent.
Technically correct forms. Contact forms and other input forms configured with the right GDPR fields, consent checkbox, link to the privacy policy, clear description of the processing purpose, and that send and store data securely.
Secure connection and hosting. HTTPS configuration, a correctly installed SSL certificate, and a hosting environment that meets the technical security requirements of the GDPR. For medical websites, the server location is relevant: personal data should essentially not be stored outside the European Economic Area without additional safeguards.
Data processing agreements with third-party service providers. LOFT 33 identifies which third-party service providers process personal data on behalf of the practice and guides the conclusion of the required data processing agreements. This includes the hosting provider, the appointment system, the email platform, and other external tools integrated into the website.
Limiting data processing to what is necessary. A medical website doesn’t need to collect more data than strictly necessary for the purpose of processing. LOFT 33 applies the principle of data minimization when configuring forms, analysis systems, and other data-processing components.
Technical security against unauthorized access. Security measures at the website level, strong authentication for the management panel, regular security updates, and monitoring for suspicious activity to minimize the chance of a data breach via the website.
What LOFT 33 does not do
LOFT 33 provides technical implementation, not legal advice. Drafting a legally watertight privacy policy, maintaining a processing register, appointing a data protection officer, or assessing the lawfulness of specific processing: these are tasks for a legal advisor or a qualified DPO.
LOFT 33 works with the healthcare provider and their legal advisor to align the technical implementation correctly with legal requirements. This collaboration is particularly valuable for more complex projects, such as a website with a patient portal or a multilingual platform with international users.
For healthcare providers who don’t have legal guidance for their GDPR compliance yet, LOFT 33 advises having that part handled by a qualified legal advisor or DPO before the website goes live.
References: GDPR-compliant websites in the medical sector
EuroMedix in Herent is an international medical technology company active in point-of-care diagnostics. LOFT 33 developed a multilingual, AI-ready website with a GDPR-compliant structure that aligns with the organization’s international activities and the heightened requirements of the medical technology sector.
CHARMcm in Herent develops point-of-care diagnostic solutions for the international medical market. LOFT 33 developed a website with a blog, personalized medical surveys, and a GDPR-compliant structure—a project where the technical complexity of data processing required special attention.
Doktershuis Antwerpen is a premium medical practice where LOFT 33 restructured and rewrote the entire website, including a correct GDPR configuration for the contact forms and the custom Engagement Score Engine that processes patient interactions.
“My website already has a privacy policy and a cookie notice, is that enough?”
Not necessarily. The presence of a privacy policy and a cookie notice is a minimum requirement, but the content and technical implementation are at least as important.
A cookie notice that is there but where analytical cookies are already loaded before the visitor has given consent does not comply with the GDPR, even if the notice is visible. A privacy policy that doesn’t match the actual data processing of the practice doesn’t protect the healthcare provider, even if it’s present.
LOFT 33 can perform a technical GDPR audit of an existing website and map out which elements are correct and which require adjustment, without rebuilding the entire website.
GDPR-compliant website for healthcare providers: what you can expect from LOFT 33
An initial 30-minute conversation. LOFT 33 asks questions about the practice, the current website, and the specific components that process personal data. Based on that, a clear picture is formed of what is technically needed.
A technically correct implementation that aligns with GDPR requirements for the medical sector, as part of a new website project or as a targeted adjustment to an existing website.
Transparent communication about what LOFT 33 delivers technically and where legal guidance by an advisor or DPO is recommended.
Frequently asked questions about GDPR-compliant websites
Health data falls under the special categories of personal data in Article 9 of the GDPR—the most protected category. A healthcare provider’s website that includes contact forms, appointment systems, or other data-processing components often indirectly processes health data. This requires a higher level of technical diligence than a website that only processes standard personal data.
A data processing agreement is a contract between the data controller—the healthcare provider—and any third party that processes personal data on the provider’s behalf. For a medical website, these typically include the hosting provider, the appointment system, the email platform, and other external tools. Without these agreements, the healthcare provider is in violation of GDPR, even if the third party itself acts correctly. LOFT 33 identifies which processing agreements are necessary and guides you through the process of closing them.
A cookie notice is the visible banner or pop-up that informs visitors about the use of cookies and asks for their consent. A cookie policy is a comprehensive document that describes which cookies the website uses, for what purpose, and for how long. Both are required for a GDPR-compliant website. The cookie notice must be technically configured correctly—cookies may only be loaded after the visitor has given consent.
That depends on the scale and nature of the data processing. Healthcare providers that process health data on a large scale are required to appoint a DPO in some cases. For individual practices, it is rarely mandatory, but it may be recommended. LOFT 33 does not provide legal advice on this—that is a question for a qualified legal advisor or DPO.
Yes. LOFT 33 can perform a technical GDPR audit of an existing website to identify which elements are correctly configured and which require adjustment. This audit covers the cookie configuration, forms, secure connection, hosting environment, and the presence of processing agreements with third-party service providers. The legal assessment of the privacy policy and the processing register falls outside the scope of this technical audit.
LOFT 33 provides a technically correct GDPR structure as a standard part of every medical website project. However, full GDPR compliance involves more than technical implementation—it also includes legal elements such as the processing register, the assessment of processing grounds, and the internal organization of data processing. This legal dimension falls outside the scope of LOFT 33 and requires guidance from a qualified legal advisor or DPO.