This DPIA is published by Project Line, the data processor of Intelligent Clinic Management Platform. Per Art. 35(3)(b) GDPR, processing of special-category health data on a large scale meets the mandatory-DPIA threshold. The EDPB criteria for a mandatory DPIA (WP248 rev.01, criteria 1, 4 and 7) are met: special-category data, automated decisions that inform the service, and innovative technology (the AI voice agent).
| Item | Description |
|---|---|
| Nature | Hosting of clinic + patient health records, AI voice receptionist (real-time; calls not recorded), AI visit-scribe transcription, automated SMS/WhatsApp reminders. |
| Scope | Patients of clinics that license the Service. Volume scales with clinic count. |
| Context | B2B SaaS; clinic = controller, Project Line = processor. |
| Purposes | Appointment scheduling, electronic health records, billing, reminders, AI clinical-decision-support (non-binding). |
| Data categories | Name, contact, date of birth, identity document numbers, medical history, prescriptions, payment metadata (tokenized — no PAN). |
| Data subjects | Patients (including minors, whose data is processed only with verified parent / legal-guardian consent), clinic staff, clinic owners. |
| Retention | Active duration of the license + 30 days grace + minimum statutory retention (7–30 years, depending on the country). |
Each processing operation is mapped to a specific clinical or administrative purpose. Data minimization: only fields required for that purpose are collected. Pseudonymisation in audit logs. Granular access controls at the per-clinic boundary; cross-clinic data access is technically impossible.
| Risk | Likelihood | Severity | Mitigation |
|---|---|---|---|
| Unauthorized access to medical data | Low | High | Per-tenant SQL isolation, TLS 1.2+, AES-256 at rest, optional MFA (TOTP) available for clinical roles, PIN lockout, audit log with hash chain, outbound budget guard. |
| AI hallucination influencing clinical decision | Medium | High | Voice agent prompts present suggestions as documentation only; the treating clinician retains all clinical authority. Disclaimers are set out in the agreement. |
| Undisclosed AI interaction | Low | High | Mandatory AI-disclosure announcement in the patient's language at call start (EU AI Act Art. 50); per-patient AI-processing consent captured + versioned. Calls are not recorded. |
| Sub-processor incident | Low | Medium | Core sub-processors: Azure / OpenAI / Twilio / Meta / Zoho (transactional e-mail). Optional payment + invoicing (clinic opt-in): Stripe / PayPal / Cardcom / Tranzila / PayPlus / Meshulam / GreenInvoice / iCount. Optional OAuth (clinic opt-in): Google / Microsoft. Optional US insurance-claims clearinghouse (clinic opt-in, US clinics only): Stedi. Each has binding DPA. 30-day notice on changes. |
| Cross-border transfer | Low | Medium | EU SCCs for transfers; Azure Israel Central region by default. |
| Lengthy retention | Low | Medium | Termination workflow hard-deletes data after 30-day grace; statutory retention windows enforced. |
| Processing of minors' data | Low | High | Patients under 18 are flagged; consent is blocked server-side unless a parent / legal guardian signs (guardian name + relationship recorded, encrypted). Minors' data receives the same per-tenant isolation, AES-256 encryption and AI-disclosure as all patient data. |
Each clinic, as controller, is invited to review and add jurisdiction-specific risks before processing. Feedback channel: support@projectlineil.com.
After application of the mitigations the residual risk is assessed as LOW. Consultation with the supervisory authority under Art. 36(1) is not required at present; Project Line will consult the supervisory authority again if a future processing operation materially increases the risk.
This DPIA is reviewed annually and whenever a sub-processor changes, a new data category is added, or applicable supervisory-authority guidance is updated.
© 2026 Project Line. All rights reserved.