skipToContent
ArkeonTech Logo
Back to all posts

AI Phone Assistants in Medical Practices: What the Law Requires

August 24, 2026
Updated September 18, 2026
Label: content created with AI assistance This article was created with AI assistance

The text and images in this article were generated with the help of AI systems. Labelled in accordance with Art. 50(4) of the EU AI Act. Responsible for publication: ArkeonTech.

AI Phone Assistant Medical Practice Professional Secrecy GDPR EU AI Act
A telephone handset with a data stream passing through three closed seal rings, the first glowing markedly brighter than the two behind it

Most practices test the wrong question when they evaluate an AI phone assistant. They ask whether the provider is GDPR-compliant. The rule that applies first is not in the GDPR at all. It sits in the German Criminal Code, and it is aimed not at the provider but at the practice owner personally.

In brief: An AI phone assistant that takes calls from patients processes health data. Three sets of rules apply at once. Section 203(3) sentence 2 of the German Criminal Code has expressly permitted the use of external service providers since the 2017 reform, but requires them to be bound to secrecy. A practice that omits this commits an offence itself under Section 203(4) sentence 2 no. 1, punishable by up to one year of imprisonment or a fine. The GDPR adds a data processing agreement under Article 28 and a legal basis under Article 9(2)(h). The EU AI Act comes on top: disclosure under Article 50 has been mandatory since 2 August 2026, while the high-risk obligations under Annex III only apply from 2 December 2027 following the Digital Omnibus. If the assistant sorts calls by urgency, it can fall under Annex III no. 5(d). Plain appointment booking does not; advance triage does.

May a medical practice use an AI phone assistant at all?

Yes. Since the 2017 reform of Section 203 of the German Criminal Code, engaging external service providers has been expressly permitted. Before that the legal position was unsettled, and practices operated in a grey area with every IT provider. That uncertainty is gone.

The governing sentence reads:

"The persons named in subsections 1 and 2 may disclose third-party secrets to other persons who assist in their professional or official activity, insofar as this is necessary in order to make use of the activity of those other assisting persons."

Four words carry the entire weight: "insofar as this is necessary". They limit what the assistant is allowed to hear. A system that books appointments needs a name, contact details and a rough indication of the matter. It does not need a diagnostic history. Transmitting more than necessary leaves the scope of the permission, even where the contract is sound.

The same provision applies to tax advisers, supplemented there by Section 62a of the Tax Advisory Act. We have described how the assessment works out in a tax firm bound by professional secrecy separately. What an assistant takes on organisationally in a practice, and what that achieves day to day, is covered in our article on the AI phone assistant for medical practices. This text deals solely with the legal side.

Why does liability fall on the practice rather than the provider?

Because Section 203(4) contains two separate offences. Sentence 1 targets the assisting person, meaning the provider, where its staff disclose a secret. Sentence 2 no. 1 targets the practice, and it targets an omission: failing to ensure that the service provider was bound to secrecy.

This is the point that provider documentation rarely highlights. Binding the provider is not a service the provider performs; it is a duty of the practice. It cannot be delegated, and it arises regardless of whether anything has gone wrong.

ProvisionWho is liableTriggerPenalty
s. 203(1) no. 1doctordisclosing a secretup to 1 year or fine
s. 203(4) s. 1provider and its staffdisclosure as an assisting personup to 1 year or fine
s. 203(4) s. 2 no. 1practicefailure to bind, provider disclosesup to 1 year or fine
s. 203(4) s. 2 no. 2providersubcontractor not boundup to 1 year or fine
s. 203(6)all of the abovefor payment or enrichment intentup to 2 years or fine

The fourth row deserves attention. Where the provider itself engages subcontractors, for instance a cloud operator for speech recognition, it must bind those too. The statute extends the chain expressly: "the same applies to other assisting persons where they make use of further persons". Practices should ask to see the whole chain, not just the first contract.

What must the contract contain to satisfy Section 203?

Four elements, drawn from case law and the commentary on the reform. They are quickly checked, and their absence is immediately apparent.

First, a concrete contractual relationship describing the assistance with the medical activity. A general software licence does not qualify. Second, a limitation of the activity to that purpose. Third, a written undertaking by every person at the provider who may access the data, binding them to secrecy under Section 203 specifically, not merely to data confidentiality under the GDPR. These are two different things, and confusing them is the most common defect. Fourth, continuation of that undertaking along the entire subcontracting chain.

A practical test: ask to see the undertaking that a developer or support agent at the provider has actually signed. If it refers only to "data confidentiality" or cites Article 28 GDPR, the criminal-law layer is missing.

Health data is in principle excluded from processing by Article 9(1) GDPR. Practices rely on the exception in Article 9(2)(h): processing for the purposes of health care, resting on the treatment contract. That exception is tied to Article 9(3), which requires the data to be processed by professionals subject to an obligation of professional secrecy.

This is where the circle closes back to criminal law. The GDPR basis holds only if the duty of secrecy has been passed through to the service provider. A clean Article 28 processing agreement without the Section 203 undertaking leaves a gap that affects both regimes.

A common error is to invoke patient consent under Article 9(2)(a). That does not work for a phone assistant: consent would have to exist before processing begins, but the call begins with processing. Anyone consenting on the phone has already spoken by that point.

When does the assistant become a high-risk system under the AI Act?

The obligations for high-risk systems under Annex III of the EU AI Act were originally due to apply from 2 August 2026. The Digital Omnibus (Regulation (EU) 2026/1744) moved that date to 2 December 2027. The classification itself is unchanged, and anyone choosing a system today should know it. Annex III no. 5(d) covers AI systems intended to evaluate and classify emergency calls, to dispatch or prioritise emergency response services, and systems for emergency healthcare patient triage.

An assistant that books appointments and takes prescription requests does not fall within this. An assistant that sorts calls by urgency and decides who still gets an appointment today moves closer to the wording. The boundary runs along the intended purpose, not the product name.

FunctionClassificationReasoning
Booking and moving appointmentsnot high-riskno assessment of health status
Taking prescription requestsnot high-riskintake only, decision stays in the practice
Noting and forwarding callbacksnot high-riskpreparatory task under Art. 6(3)(d)
Sorting matters by urgencyassessment requiredproximity to Annex III no. 5(d)
Deciding who receives an urgent slotlikely high-riskprioritisation within the meaning of the rule

Article 6(3) of the AI Act offers an exemption: an Annex III system is not high-risk where it poses no significant risk, because it performs a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing the human assessment, or performs a preparatory task.

One qualification removes that exemption again: where the system performs profiling of natural persons, it remains high-risk in every case. An assistant that categorises callers on the basis of earlier contacts should be examined on this point.

Anyone relying on the exemption must document the assessment before the system goes into operation. The documentation is not a formality; it is the basis on which market surveillance authorities review the classification.

Does the caller have to be told they are speaking to an AI?

Yes, and this duty applies regardless of the high-risk question. Article 50(1) of the AI Act requires people to be informed that they are interacting with an AI system unless this is obvious from the circumstances. On the phone it is precisely not obvious, because modern voice systems sound natural.

The information belongs at the start of the call, not in a privacy notice on the website. One sentence is enough, and it should be plain rather than legalistic. Practices that address it openly report less irritation than those that try to conceal it.

For a deeper treatment, we have covered the Article 50 disclosure duty in a separate article, along with the AI literacy duty under Article 4 in force since February, which also covers the practice staff who look after the assistant.

How does the assistant reach the practice management system?

This is where many projects fail, and not for legal reasons but technical ones. The 2025 survey by the Central Research Institute of Ambulatory Health Care, covering more than 3,100 practice owners and medical care centre directors, paints a clear picture of the starting position: usability across the 32 practice management systems examined averages 63.1 out of 100 points, a third of practices are considering a switch, and 40 percent complain about poor support availability.

For the phone assistant this has a sober consequence. An interface to the practice management system is the precondition for appointments landing in the calendar without double entry. Whether one exists is decided by the maker of the management system, not by the provider of the assistant.

Three questions settle this before any contract is signed. Is there a documented interface for appointments? Is it supported by the maker, or addressed through an unofficial route? And is the interface operator likewise bound under Section 203, if it gets to see data?

Where no interface exists, the assistant remains an intake system: it records the matter and hands it over to the team in structured form. That is less than marketing claims promise, but it relieves the load measurably and is legally straightforward, because nothing is written back.

What differs for medical care centres and hospital outpatient clinics?

The criminal-law position is the same; the organisational one is not. Section 203(1) no. 1 attaches to the person of the doctor, not to the legal form. In a medical care centre the duty under subsection 4 sentence 2 no. 1 therefore falls on the medical director, not on the holding company.

From this follows a practical point that is often overlooked: a framework contract between the holding company and the provider does not automatically discharge the binding duty for every employed doctor. The undertaking has to reach the people to whom the secret was entrusted.

Hospital outpatient clinics are additionally subject to the relevant state hospital act, which may contain its own rules on data processing and varies in strictness between federal states. For multi-site group practices, it must be clarified whether the assistant merges data across locations, because that is a disclosure in its own right and must again be measured against necessity.

Which documents should the practice keep on file?

Six. They can be assembled in an afternoon if the provider cooperates, and their absence is the first thing an audit notices.

DocumentLegal basisWho provides it
Undertaking under s. 203 StGBs. 203(4) s. 2 no. 1 StGBprovider, requested by the practice
Data processing agreementArt. 28 GDPRprovider
List of subcontractors with undertakingss. 203(3) s. 2 StGBprovider
Entry in the record of processing activitiesArt. 30 GDPRpractice
Data protection impact assessmentArt. 35(3)(b) GDPRpractice, often with advice
AI Act classification with reasoningArt. 6(3) AI Actpractice, based on provider information

The impact assessment is regularly required for health data, because Article 35(3)(b) GDPR expressly names large-scale processing of special categories. It must exist before deployment, not after.

What applies to practices in Austria and Switzerland?

The three layers stay the same: criminal law, data protection and AI regulation. Only the provisions have different names.

Austria. The medical duty of confidentiality is laid down in Section 54 of the Medical Practitioners Act 1998 (Ärztegesetz) and expressly binds auxiliary persons as well. Under criminal law Section 121 of the Austrian Criminal Code protects secrets about a person's state of health; assistants are treated like the professionals themselves, and the offence is prosecuted only with the authorisation of the injured party. For data protection the GDPR applies as in Germany, that is Article 9 for health data and Article 28 for the data processing agreement, supplemented by the Austrian Data Protection Act. The AI Act applies directly and with the same dates: disclosure under Article 50 has been mandatory since 2 August 2026, the high-risk obligations under Annex III apply from 2 December 2027.

Switzerland. Doctors are in the catalogue of Art. 321 of the Swiss Criminal Code, and their auxiliary persons are expressly included. A breach of professional secrecy is punished on complaint with a custodial sentence of up to three years or a monetary penalty. Under Art. 5 of the Federal Act on Data Protection (FADP) health data are sensitive personal data. Art. 9 FADP permits outsourcing to a processor only if no statutory or contractual duty of confidentiality prohibits it, and requires the practice to satisfy itself that the provider can guarantee data security. If the server is located abroad, Art. 16 FADP applies in addition.

Switzerland does not yet have an AI statute with a disclosure duty like Article 50. On 12 February 2025 the Federal Council decided to ratify the Council of Europe's AI Convention, and a consultation draft is due by the end of 2026. A practice that nevertheless tells callers at the outset that they are speaking to a digital assistant acts with foresight and can combine the notice with the information on data processing under Art. 19 FADP.

Whether an external provider counts as an auxiliary person within the meaning of Art. 321 in Switzerland should be settled with the professional body or a specialist lawyer before deployment. This section provides orientation and does not replace advice under Austrian or Swiss law.

Frequently asked questions

May a medical practice use an AI phone assistant? Yes. Since 2017, Section 203(3) sentence 2 of the German Criminal Code has expressly permitted external service providers to assist in medical activity, insofar as this is necessary for their service. The permission comes with a condition: the provider and its subcontractors must be bound to secrecy.

Who is criminally liable if patient data leaks? Both sides, for different reasons. The provider under Section 203(4) sentence 1 where its staff disclose a secret. The practice under Section 203(4) sentence 2 no. 1 where it failed to bind the provider to secrecy. In each case the penalty is up to one year of imprisonment or a fine.

Is a data processing agreement under Article 28 GDPR sufficient? No. The processing agreement satisfies data protection law, not criminal law. The Section 203 undertaking is a separate declaration with its own addressees: everyone at the provider who may access the data. Binding them to general data confidentiality does not meet the requirement.

Is an AI phone assistant a high-risk system under the EU AI Act? It depends on the intended purpose. Appointment booking, prescription intake and callback notes fall outside Annex III. If the assistant sorts calls by urgency or decides on urgent slots, it approaches Annex III no. 5(d) on emergency call assessment and patient triage. The classification must be documented before deployment.

Do I have to tell patients an AI is on the line? Yes. Article 50(1) of the EU AI Act requires the information unless it follows from the circumstances. With natural-sounding voice systems it does not. A plain sentence at the start of the call satisfies the duty; a note in the website privacy policy does not.

Do I need a data protection impact assessment? As a rule, yes. Article 35(3)(b) GDPR expressly names large-scale processing of special categories of data, and health data is one of them. It must exist before deployment and describe the specific processing, not the product in general.

What applies in a medical care centre or hospital outpatient clinic? The same in criminal law, not in organisational terms. Section 203(1) no. 1 attaches to the person of the doctor, not to the holding company. A framework contract signed by the holding company therefore does not automatically discharge the binding duty for every employed doctor. Hospital outpatient clinics are additionally subject to the relevant state hospital act.

May a medical practice in Switzerland or Austria use an AI phone assistant? Yes, under the same basic conditions as in Germany: the provider must be bound into the duty of confidentiality, and the data processing needs a contract. In Austria Section 54 of the Medical Practitioners Act 1998, Section 121 of the Criminal Code, the GDPR and the AI Act apply, including the disclosure duty since 2 August 2026. In Switzerland Art. 321 of the Criminal Code, which expressly includes auxiliary persons, and the Federal Act on Data Protection with Art. 9 on processors apply. Switzerland does not yet have a disclosure duty like Article 50.

Conclusion

Using an AI phone assistant in a medical practice is legally permissible and has been expressly regulated since 2017. The hurdle lies not in the principle but in a duty that is easy to satisfy and easy to overlook: the practice must ensure that the provider and its subcontractors are bound to secrecy under Section 203. Where it fails to do so, it is the practice that commits the offence, not the provider.

On top of that comes the EU AI Act classification, whose high-risk obligations apply from 2 December 2027. For appointment booking it is uncritical; for any form of urgency sorting it is not. A practice that deliberately confines the assistant to intake and forwarding stays on the simple side of both regimes and still gains the relief it is after.

In practice that means: first define the intended purpose in writing, then obtain the undertakings, then settle the interface question. In that order, because each step determines the next.

Sources

Matching ArkeonTech service

AI phone assistant (voice agent)

Answers every call, books appointments and writes CRM notes - natural voice, 24/7.