An AI colleague for your clinic: appointments, aftercare and repeat questions
In a clinic, Nova takes over the scheduling and repeat questions: booking and rescheduling appointments, practical aftercare questions, availability outside opening hours. Anything concerning someone's health or treatment goes to a human — not because it is technically impossible, but because health data is a heavier category and a wrong answer costs more there than elsewhere.
Published on · Last updated on
The problem in this sector
Questions about price and timeline keep coming back. The secretariat types the same answer over and over.
| Aspect | For this sector |
|---|---|
| Channels | E-mail · WhatsApp |
| Own knowledge | Treatment info, prices and conditions as the source for the answer |
| Deployment | Nova Vault |
| Expected outcome | Price and timeline questions covered by the treatment info go back right away. The rest lands with the secretariat. |
How far your sector has come
A clinic does not fall under a sector for which CBS publishes a separate AI figure. What we do know: healthcare is not in the leading group — information and communication leads at 54 percent — and not in the lowest either, where hospitality, transport and construction sit at 6 to 7 percent. For a clinic that means: you are not behind your sector, but there is no beaten path to follow either.
Where the limit sits
Health data is special category data and requires a stricter regime than ordinary customer data. On top of that comes article 22 GDPR: a decision that significantly affects someone may not be taken solely by automated means. In practice: the AI schedules and informs, the practitioner assesses.
Concretely, these are the things Nova does not do on its own here:
- Assessing complaints or symptoms, not even to judge urgency — triage stays human work.
- Sharing results, record data or treatment information, not even when the patient asks themselves.
- Refusing an appointment or moving someone down the waiting list; proposing is fine, deciding is not.
That limit does not live in a setting someone can flip by accident; it is established up front. That is the difference between a system you know the behaviour of and one you find out about afterwards.
Why in healthcare it starts with the duty of secrecy
In a practice it does not start with a legal basis but with the duty of secrecy. Article 88 of the Wet BIG covers everything you learn while practising your profession. A message at eleven at night about a painful tooth already falls under it, before anyone copies it into the record.
Article 457 of Book 7 of the Civil Code admits only people directly involved in the treatment who genuinely need the data for their work. That is a narrow door. So the question is not whether your supplier is trustworthy, but whether this system may see this message for this task.
On top of that, article 9 GDPR prohibits health data in principle and ties the healthcare exception to the duty of secrecy. Article 30 of the Dutch GDPR Implementation Act allows someone to be bound to secrecy by contract. That confidentiality is therefore not an annex to the contract but the condition under which a supplier may touch the data at all.
Set out in AI in healthcare and the duty of secrecy, including the twenty-year record retention period from article 454 of Book 7 and a table per type of message.
The general rules on automated decision-making and transparency are set out in AI and the GDPR for SMEs and the AI Act for SMEs.
What we need from you
This differs per sector, so it sits here rather than in a generic checklist:
- Your appointment system, and clarity on which appointment types Nova may and may not schedule.
- Who within the practice may see what — a receptionist has a different scope than a practitioner.
- The questions you now get by phone and always answer the same way; that is the core of what moves over.
How a project runs — intake, analysis of your existing communication and a shadow week in which nothing is sent yet — is set out on the approach page.