Storage best practices
Organise patient photos and X-rays per patient, store them in line with KVKK/GDPR and get consent for before/after images.
3 min read
A medical-tourism clinic collects thousands of X-rays, photos and documents a year. These files are critical for both the patient experience and your legal obligations: KVKK in Turkey and GDPR for patients from Europe protect health data as special-category data. This article sets out our recommendations for keeping Media Storage organised, secure and audit-ready.
Note
This article is general guidance, not legal advice. Work with a legal adviser on your clinic's privacy notice, explicit consent forms and retention periods.
Organising per patient
- Use a single root folder: all patient-specific files live under
Patients, grouped by year. - Create one folder per patient and name it patient ID + full name (
P-1042 Sarah Mitchell). Keep the patient ID in a custom field on the contact record too, so the record and the folder are linked. See Recommended custom fields. - Use fixed subfolders in every patient folder:
01_X-rays,02_Photos-Before,03_Photos-After,04_Treatment-Plan,05_Consent-Forms. The same structure for every patient means you find anything in seconds. - Keep general files sent to everyone (price list, aftercare instructions, hotel/transfer) separate from patient files, in a
Clinic Assetsfolder.
For naming conventions and how to create folders, see Uploading and organising files.
KVKK and GDPR essentials
| Principle | How it applies to Media Storage |
|---|---|
| Data minimisation | Only store files needed for treatment. Don't upload unnecessary documents such as passports, IDs or card details. |
| Purpose limitation | Don't use photos taken for treatment in ads or on social media without separate consent. |
| Access control | Limit access to patient files to the roles that need it; every staff member has their own user and no shared passwords. See Roles and permissions. |
| Retention | Regularly review and delete files whose retention period has expired, and keep a record of deletions. |
| Patient rights | If a patient asks for a copy of their files or for them to be deleted, the patient folder lets you find, hand over or delete everything quickly. See Data privacy: KVKK and GDPR. |
| International transfers | For European patients, state in your privacy notice that cloud services are used to process their data. |
Important
Don't keep patient files on personal phones, personal WhatsApp accounts or USB sticks. Every copy outside the panel is a data risk you can't control. When someone leaves, deactivate their user straight away: Adding users.
Before/after photos and consent
Before/after images are the most powerful marketing content in medical tourism — and the most sensitive.
- Taking photos for treatment and using them in marketing are different purposes; for the latter, get separate, explicit, written consent from the patient.
- Save the signed consent form in the patient's
05_Consent-Formssubfolder. Don't move an image toMarketing (approved)without consent. - Where possible, crop out or hide anything that identifies the patient (face, tattoos, jewellery, distinctive marks).
- If a patient withdraws consent, remove the image from the marketing folder and from wherever it was published.
- Ad platforms have their own restrictions on health-related before/after images; check the platform's policy before using them in ads.
Tip
Keep a "Photo consent: Yes/No" custom field on the contact record and add a tag (photo-consent) once consent is given. Your marketing team can then see every consenting patient in one Smart List. See Smart lists.
Monthly housekeeping checklist
Once a month, an Admin user should check:
- Are there patient-specific files outside
Patients? (e.g. X-rays uploaded to the root folder) - Have files that don't follow the naming convention been renamed?
- Have patient folders past their retention period been reviewed?
- Are the users of former staff deactivated?
- Does every image in
Marketing (approved)have a consent form?
To see who deleted or changed which file, use Audit logs.
Related articles

Didn't solve your problem?
Ask the assistant or message our support team.