In a therapy practice, almost every piece of data is health data — not after some analysis, but from the first phone call. That is why the riskiest AI application is not the booking bot, but the innocent-looking habit of pasting a patient report into a general-purpose AI tool: professional secrecy rules can be breached the moment the data sits on a provider's server, whether or not a human ever reads it.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
Physiotherapy, occupational therapy and speech therapy practices already use AI: dictation and transcription, draft texts for referral reports, exercise apps for patients, booking bots, social media content. Legally, these applications differ sharply — and the AI Act is not the strictest rule involved.
| What you do | What applies | Order of magnitude |
|---|---|---|
| Drafting findings or referral reports in a general-purpose AI tool | Professional secrecy + Art. 9 GDPR | criminal/professional law · up to €20m or 4 % |
| Dictation/transcription via a cloud service | Professional secrecy + Art. 9 GDPR | criminal/professional law · up to €20m or 4 % |
| Exercise app that assesses performance | Medical-device law (a manufacturer question) | depends on the provider |
| Booking bot on your website or Instagram | Art. 50 AI Act — disclosure | up to €15m or 3 % |
| AI images and copy for marketing | Art. 50 AI Act + advertising law | labelling · injunctions |
| Your team uses AI tools | Art. 4 AI Act — literacy | no standalone fine |
For small and medium-sized enterprises, the lower of the two AI Act values applies (Art. 99(6)). Under the GDPR, the higher one does.
In a beauty salon, health data comes into existence through the analysis. In a therapy practice it is there from the start: the diagnosis on the referral, the findings, the treatment record — even the bare fact that someone is your patient. All of this is health data under Article 4(15) GDPR and therefore a special category under Article 9: processing is prohibited unless an exemption applies.
For the treatment itself you do not need consent: Article 9(2)(h) permits processing for the provision of health care by, or under the responsibility of, persons subject to professional secrecy. But that permission carries only the treatment context. A general-purpose text tool, a marketing assistant or a chatbot are not part of it — there you need your own legal basis, in practice almost always explicit consent. And every provider whose tool sees patient data needs a data processing agreement under Article 28 GDPR.
Across Europe, health professionals are generally bound by professional secrecy — under criminal law, professional regulation, contract, or a combination — with the exact scope set by national law. The operative point for AI is the same everywhere:
Secrecy can be breached the moment patient data sits on a server that the provider's staff could access. It does not depend on whether a human ever reads the prompt. It is not the reading that constitutes the disclosure — the possibility of it does. A report pasted into a general-purpose AI tool for "polishing" can cross that line even if the output never leaves your practice.
If your practice is in Germany: physiotherapists, occupational therapists and speech therapists are secrecy holders under § 203 of the Criminal Code, with criminal liability of up to one year's imprisonment — and since the 2017 reform, § 203(3)–(4) allows involving IT and AI providers only if they are contractually bound to secrecy (a data processing agreement alone is not enough; it covers data protection, not criminal law). Non-medical practitioners (Heilpraktiker) fall outside § 203 on the prevailing view, but remain fully bound by the GDPR and by contractual confidentiality. Outside Germany, check your national rules — the cut of these provisions differs by country, and the safe baseline is the same everywhere: patient data goes into no tool whose provider is not contractually bound.
No patient reference in the prompt. "Draft a friendly paragraph about progress in shoulder rehabilitation" is unproblematic. "Write the report for Mrs M., 54, post rotator cuff repair" is not. Strip names, dates of birth and attributable diagnoses before the input and re-insert them in your own system — same tools, without the trap.
Apps that merely show exercises are unproblematic. As soon as a system assesses execution or derives recommendations from health data, the question arises whether it is a medical device — then medical-device law and CE marking apply, and the AI Act can classify such systems as high-risk via Annex I where the product must undergo third-party conformity assessment. That is the manufacturer's duty, not yours — but you should have the answer in writing: "Is your system placed on the market as a medical device?" The answer decides what you may rely on.
If a bot answers on your website or in your direct messages, people must be able to tell they are talking to a machine — one sentence is enough: "You are chatting with an automated assistant." Since 2 August 2026, Article 50 of the AI Act also requires labelling AI-generated or materially AI-edited images, audio and video. And health-related advertising claims are regulated in every member state — an AI that writes sweeping promises of healing writes you a legal problem; keep claims to what you can evidence.
Since 2 February 2025, Article 4 of the AI Act has obliged you to take measures to foster AI literacy among your staff — the three-person practice as much as the therapy centre. Since the Digital Omnibus you no longer have to guarantee any particular level of competence; the duty to act remains. To be honest about it: there is no standalone fine for Article 4; Article 99(4) lists the sanctioned duties exhaustively, and Article 4 is not among them.
Why the record still matters: if a report with patient data ends up in the wrong tool, the first question — from the regulator, the professional body, the other side's lawyer — is always the same: did your staff know what they were doing? A dated training record answers it. Nothing else does.
Not with a patient reference in a general-purpose tool: once a name, date of birth or attributable diagnosis sits on a provider's server that staff could access, professional secrecy can be breached — actual reading is not required. It becomes workable with a provider that signs a contractual secrecy undertaking and a data processing agreement — or with no patient reference in the prompt at all.
Yes. Article 50 of the AI Act requires that people can tell when they are interacting with an AI system, unless it is obvious. One sentence is enough: “You are chatting with an automated assistant. For a personal conversation, call us.”
It depends on what it does: merely showing exercises is unproblematic; assessing execution or deriving recommendations from health data can make it a medical device, with the manufacturer bearing CE obligations. Get it in writing whether the system is placed on the market as a medical device — the duty is the provider's, the reassurance is yours.
For the GDPR, yes. For professional secrecy, usually not: in Germany, § 203(4) of the Criminal Code additionally requires an express contractual secrecy undertaking by the service provider, and other member states attach their own conditions to involving service providers — check your national rules. A provider unwilling to sign a secrecy undertaking is telling you something.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free