medicalgrow.aiTR

Storage best practices

Organise patient photos and X-rays per patient, store them in line with KVKK/GDPR and get consent for before/after images.

3 min read

A medical-tourism clinic collects thousands of X-rays, photos and documents a year. These files are critical for both the patient experience and your legal obligations: KVKK in Turkey and GDPR for patients from Europe protect health data as special-category data. This article sets out our recommendations for keeping Media Storage organised, secure and audit-ready.

Note

This article is general guidance, not legal advice. Work with a legal adviser on your clinic's privacy notice, explicit consent forms and retention periods.

Organising per patient

MedicalGrow

Media Storage

Patients1
2026
P-1042 Sarah Mitchell2
01_X-rays
02_Photos-Before
03_Photos-After
04_Treatment-Plan
05_Consent-Forms3
P-1043 Jonas Weber
Clinic Assetsprice list, hotel, transfer4

File naming format

YYYY-MM-DD_type_detail_STAGE.ext

  • 2026-10-02_panoramic-xray.jpg
  • 2026-10-02_smile-front_BEFORE.jpg
  • 2026-10-09_smile-front_AFTER.jpg

Before sharing

Photo-use consent signed
Face / identifying details hidden
Share only with who needs it
KVKK · GDPR
Recommended structure: a Patients folder, subfolders per patient ID, file-type folders and a general Clinic Assets folder.
  1. Use a single root folder: all patient-specific files live under Patients, grouped by year.
  2. Create one folder per patient and name it patient ID + full name (P-1042 Sarah Mitchell). Keep the patient ID in a custom field on the contact record too, so the record and the folder are linked. See Recommended custom fields.
  3. Use fixed subfolders in every patient folder: 01_X-rays, 02_Photos-Before, 03_Photos-After, 04_Treatment-Plan, 05_Consent-Forms. The same structure for every patient means you find anything in seconds.
  4. Keep general files sent to everyone (price list, aftercare instructions, hotel/transfer) separate from patient files, in a Clinic Assets folder.

For naming conventions and how to create folders, see Uploading and organising files.

KVKK and GDPR essentials

PrincipleHow it applies to Media Storage
Data minimisationOnly store files needed for treatment. Don't upload unnecessary documents such as passports, IDs or card details.
Purpose limitationDon't use photos taken for treatment in ads or on social media without separate consent.
Access controlLimit access to patient files to the roles that need it; every staff member has their own user and no shared passwords. See Roles and permissions.
RetentionRegularly review and delete files whose retention period has expired, and keep a record of deletions.
Patient rightsIf a patient asks for a copy of their files or for them to be deleted, the patient folder lets you find, hand over or delete everything quickly. See Data privacy: KVKK and GDPR.
International transfersFor European patients, state in your privacy notice that cloud services are used to process their data.

Important

Don't keep patient files on personal phones, personal WhatsApp accounts or USB sticks. Every copy outside the panel is a data risk you can't control. When someone leaves, deactivate their user straight away: Adding users.

Before/after images are the most powerful marketing content in medical tourism — and the most sensitive.

  • Taking photos for treatment and using them in marketing are different purposes; for the latter, get separate, explicit, written consent from the patient.
  • Save the signed consent form in the patient's 05_Consent-Forms subfolder. Don't move an image to Marketing (approved) without consent.
  • Where possible, crop out or hide anything that identifies the patient (face, tattoos, jewellery, distinctive marks).
  • If a patient withdraws consent, remove the image from the marketing folder and from wherever it was published.
  • Ad platforms have their own restrictions on health-related before/after images; check the platform's policy before using them in ads.

Tip

Keep a "Photo consent: Yes/No" custom field on the contact record and add a tag (photo-consent) once consent is given. Your marketing team can then see every consenting patient in one Smart List. See Smart lists.

Monthly housekeeping checklist

Once a month, an Admin user should check:

  • Are there patient-specific files outside Patients? (e.g. X-rays uploaded to the root folder)
  • Have files that don't follow the naming convention been renamed?
  • Have patient folders past their retention period been reviewed?
  • Are the users of former staff deactivated?
  • Does every image in Marketing (approved) have a consent form?

To see who deleted or changed which file, use Audit logs.

Didn't solve your problem?

Ask the assistant or message our support team.

WhatsApp support