Patient Data Privacy in a Pakistani Clinic: What You Owe Your Patients
A patient record is the most sensitive thing a clinic holds, and most practices have never decided who may open it. Confidentiality duties, the law as it stands, and the controls that make a leak unlikely rather than merely unpunished.
A dental record contains a person's name, phone number, address, medical history, medications, allergies, photographs of their face and mouth, and what they paid. In one file. It is more revealing than most banking data, and in a great many clinics it sits in a register anyone behind the desk can lift, or on a PC whose password is the clinic's phone number.
This piece is not about fear. It is about the small number of decisions that separate a clinic that would survive an incident from one that would not.
Where the law stands, plainly
Pakistan does not currently have a comprehensive data protection statute in force. A Personal Data Protection Bill has gone through repeated drafts without enactment; PECA 2016 addresses unauthorised access to information systems; and practitioners carry professional confidentiality obligations independent of any of it.
Two things follow. First, "there is no law" is not a defence a patient, a regulator or a court would find persuasive when the duty of confidence is professional and ancient. Second, the direction of travel is one way — every draft has been stricter than the last. Building for the stricter version costs little now and saves a scramble later.
The five controls that actually matter
1. Individual logins, and roles that match the job
The receptionist needs the schedule, the patient's contact details and the bill. She does not need the clinical notes, and she certainly does not need the ability to delete a payment. One shared "clinic" login destroys accountability: when something is wrong, nobody can say who did it, and every honest member of staff is under suspicion.
2. An audit trail you cannot edit
Who opened this chart, who changed this fee, who deleted this appointment, and when. It protects patients from misuse and staff from accusation. A clinic that can answer those questions in seconds handles an incident calmly; one that cannot is guessing about its own business.
3. Consent that is recorded, not remembered
Consent for treatment, and separately for photographs — especially before-and-after images used in marketing. A patient agreeing verbally to a procedure has not agreed to appear on Instagram. Record both, with a date, against the patient. Digital consent forms make this a by-product of the visit rather than a folder nobody can find later.
4. Backups that have been restored at least once
An untested backup is a rumour. The failure mode is not dramatic — no hacker, just a dead disk, a stolen PC, or ransomware from a pirated download — and the loss is total: histories, radiographs, balances, everything. Automatic, off-site, encrypted, and rehearsed. The wider argument is in clinic data security.
5. A rule about phones
Clinical photographs taken on a personal phone end up in a gallery that syncs to a family cloud account. Either photographs are taken inside the clinic system and attached to the patient, or you have accepted a risk you have not thought about. This is the single most common quiet breach in dentistry.
WhatsApp, honestly
Patients here want their prescription and receipt on WhatsApp, and refusing on privacy grounds would be theatre — they will simply photograph the paper anyway. Do it deliberately instead:
- Send to the number on the record, confirmed with the patient, not to whatever number messaged you
- Send only what that patient asked for — a document, to one person
- Use the clinic's number and the official Business API where you can, not a staff member's personal phone
- Honour opt-outs, and keep marketing separate from clinical messages
The dangerous version is a receptionist's own handset holding two thousand patients' details, leaving with her when she changes job.
What to ask a software vendor
If your records sit in someone else's system, these questions are reasonable and the answers should be immediate:
| Ask | Why it matters |
|---|---|
| Is my clinic's data isolated from other clinics? | Multi-tenant systems must enforce this in the data layer, not in the interface |
| Who on your side can read my patient records? | "Everyone in support" is a real answer at some vendors |
| Are backups automatic, encrypted and off-site? | And when did you last restore one? |
| Is there an audit log of access and changes? | Without it, nothing above can be verified |
| What happens to my data if I leave? | Export format, deletion timeline, in writing |
A vendor that cannot answer these clearly has told you something useful.
The half-day version
Give every staff member their own login and remove the shared one. Set roles so people see what their job needs. Turn on automatic backups and restore one to prove it works. Write two lines of clinic policy about phones and photographs. Record photo consent from today onwards.
None of that requires a law to compel it, and all of it is what you would want from the clinic treating your own family.
Frequently asked questions
Is there a data protection law in Pakistan?
There is no comprehensive personal data protection act in force. A Personal Data Protection Bill has been through several drafts without being enacted, PECA 2016 covers unauthorised access to information systems, and professional bodies impose confidentiality duties on practitioners. The practical position: a clinic is bound professionally and ethically regardless of what the statute book eventually says — and the drafts that keep appearing suggest planning for stricter, not looser.
Can I send a prescription or report on WhatsApp?
It is what patients expect and it is defensible when done deliberately: send to the number the patient gave you and confirmed, send only what they asked for, and never send one patient anything belonging to another. The real risks are a mistyped number and a staff member using a personal phone with a shared gallery.
Should staff share one login?
No, and this is the most common failure in small clinics. A shared login means no record of who opened a chart or deleted a payment, and it makes every internal investigation impossible. Individual logins, roles that match the job, and an audit trail — a receptionist has no business reading clinical notes.
Where should records live — the clinic PC or the cloud?
A single clinic PC with no tested backup is the highest-risk option, whatever it feels like. What matters is not location but control: isolated storage per clinic, encrypted automatic backups, access limited by role, and a record of who saw what.
See DentalPro in your own clinic
Charting, treatment plans, billing, accounting, WhatsApp reminders, a patient app and online booking, from one login. Start a 3-day free trial, no card needed.
Start free trial