Our Approach
Mosdent considers the protection of every personal data it collects from its guests, especially special category health data, as one of the fundamental responsibilities of running a health center. This responsibility is observed at every stage, from the design of digital systems to daily clinical practice.
Technical Measures
The following technical measures are actively implemented for data security:
- All in-house communication is encrypted with TLS 1.3
- Field-level encryption at database level (for special category data)
- Two-factor authentication (2FA) · for all personnel
- Role-based access control (RBAC) · doctor, assistant, administration hierarchy
- Regular security tests and penetration tests
- Encrypted backups and disaster recovery plan
- All server accesses are logged and audited
Administrative Measures
Our administrative measures, as important as technical ones:
- Annual KVKK/GDPR training for all personnel
- Confidentiality agreements and digital ethics commitments
- Data breach response plan (notification within 72 hours)
- KVKK compliance officer position and regular internal audits
- Risk assessment for third-party software services
Data Breach Notification
In case of a possible data breach, notification is made to affected data subjects and the KVKK Authority within 72 hours, pursuant to Article 12 of KVKK. Mosdent takes every possible breach seriously and maintains transparent communication.