FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Customer Support
  4. Medchat

Medchat

PreferencesWebsite

Related services

11Sight

11Sight is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 11Sight supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 11Sight ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

42Chat

42Chat is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42Chat integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42Chat helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

8x8

8x8 is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 8x8 supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 8x8 ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences
A

Acquire Live Chat

Acquire Live Chat is a live chat and customer messaging platform that enables businesses to engage with website visitors in real time. It provides instant messaging, chatbot automation, and team collaboration tools to deliver fast, personalized customer support. Acquire Live Chat supports multi-channel communication, conversation routing, and canned responses to improve response times. With built-in analytics and CRM integration, Acquire Live Chat helps convert visitors into customers.

Preferences

ActivEngage

ActivEngage is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. ActivEngage integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, ActivEngage helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

Ada

Ada is a web accessibility solution that helps websites comply with ADA, WCAG, and accessibility standards. It provides automated scanning, remediation tools, and compliance monitoring to ensure content is accessible to all users, including those with disabilities. Ada offers screen reader optimization, keyboard navigation support, and color contrast adjustment. With regular audits and reporting, Ada helps create inclusive digital experiences for everyone.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does MedChat do?

MedChat is a US-based HIPAA-compliant live chat platform specifically designed for healthcare organisations including hospitals, clinics, and telehealth providers. Because healthcare chat conversations may contain protected health information (PHI), MedChat faces dual compliance requirements: HIPAA in the US and GDPR for European patients. Explicit consent is required for health data collected via chat, and all data is processed on US infrastructure requiring Standard Contractual Clauses.

What is MedChat?

MedChat is a live chat platform designed specifically for healthcare organisations, built to comply with HIPAA requirements in the United States. It serves hospitals, clinics, dental practices, telehealth providers, and medical billing companies that need to engage patients via chat while protecting protected health information (PHI). MedChat provides patient intake forms, appointment scheduling, and post-visit follow-up chat functionality.

GDPR and health data: a dual compliance challenge

For European healthcare organisations using MedChat, both GDPR and HIPAA principles apply. Under GDPR, health information is special category data under Article 9, requiring explicit consent (Art. 9(2)(a)) or another specific legal basis such as medical treatment (Art. 9(2)(h)). The ePrivacy Directive requires consent before chat scripts load. The combination of special category health data, large-scale processing, and US data transfer makes MedChat one of the highest-risk tools in terms of GDPR compliance requirements.

What data does MedChat collect?

MedChat collects chat conversation content (which may include health symptoms, diagnoses, medications, appointment reasons, and other PHI), patient names and contact details, session identifiers, IP addresses, and browser information. When integrated with appointment systems, it may also process scheduling data linked to the patient''s health record.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements for health chat

Explicit consent under GDPR Article 9(2)(a) is required before health data is collected via MedChat. This goes beyond standard ePrivacy consent and requires a clear, specific statement that health information may be shared and processed. Patients must be specifically informed that chat conversations are processed in the US, that health data requires special protection, and must actively agree before the chat begins.

Data transfers outside the EU

MedChat processes all data in the US. Standard Contractual Clauses apply, but the sensitivity of health data makes the transfer particularly significant. A Transfer Impact Assessment should be conducted as part of the mandatory DPIA to evaluate whether SCCs effectively protect health data in the US context.

Practical compliance steps

Obtain explicit Article 9 consent before MedChat loads. Conduct a mandatory DPIA including a Transfer Impact Assessment. Sign a DPA and BAA with MedChat. Update your privacy notice to describe health data processing and the US transfer. Configure conversation log retention to align with healthcare data retention requirements. Implement a mechanism for patients to request deletion of their chat data. Consider EU-hosted healthcare chat alternatives if the US transfer risk cannot be adequately mitigated.

GDPR consent category

Preferences

Websites using MedChat must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) and explicit consent (Art. 9(2)(a)) for health data collected via chat. Legitimate interest may apply to basic session management, but health-related conversation content requires explicit consent and heightened protection.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, UK GDPR, HIPAA (US), special category data (Art. 9)

DPIA considerations

A DPIA is mandatory for MedChat deployments. Healthcare chat conversations constitute processing of special category health data under GDPR Article 9, combined with large-scale processing and US data transfer. The DPIA must specifically address the health data processing basis, the US transfer safeguards, and data minimisation for healthcare conversations.

Sample consent text

We use MedChat to provide live chat support for healthcare enquiries. MedChat may process health information you share during the chat. This data is processed on servers in the United States. As health data receives special protection under GDPR, your explicit consent is required. Please accept to enable the healthcare chat service.

Technical details

Tracking methodJavaScript healthcare chat widget, first-party cookies, HIPAA-compliant server-side conversation logging
Server locationUnited States (MedChat infrastructure, HIPAA-compliant hosting)
Data transferred outside the EUMedChat is a US-based healthcare-specific live chat platform designed for HIPAA compliance. All patient and conversation data is processed on US infrastructure. Transfers rely on Standard Contractual Clauses under GDPR Article 46.

Third-party domains contacted

medchat.comcdn.medchat.comapi.medchat.com

Cookies placed

NameTypeDurationPurpose
mc_sessionsessionSessionSession identifier for the MedChat live chat widget — may process protected health information
mc_uidpersistent1 yearVisitor identifier used to recognise returning patients in the MedChat widget

MedChat uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What data does MedChat collect?

MedChat collects chat conversation content which may include health symptoms, diagnoses, medications, appointment reasons, and other protected health information. It also collects patient names, contact details, session identifiers, IP addresses, and browser information.

Does MedChat require consent under GDPR?

Yes, and more than standard consent. Healthcare chat conversations may contain special category health data under GDPR Article 9, requiring explicit consent beyond standard ePrivacy consent. Patients must be specifically informed that health data may be shared and processed in the US before any health information is entered.

What legal basis applies to health data in MedChat?

Explicit consent under Article 9(2)(a) is the most appropriate basis for health data collected via chat. Article 9(2)(h) may apply for healthcare professionals providing medical treatment. Standard contract performance or legitimate interest cannot be used as the basis for special category health data.

Does MedChat transfer data outside the EU?

Yes. MedChat is a US company processing all data on US infrastructure. Standard Contractual Clauses apply. Given the sensitivity of health data, a Transfer Impact Assessment must be conducted as part of the mandatory DPIA to assess whether SCCs provide adequate protection.

Do I need a DPIA for MedChat?

Yes, a DPIA is mandatory. MedChat processes special category health data at scale, involving large-scale processing, automated conversation handling, and US data transfer. All three of these factors independently trigger the DPIA requirement under GDPR Article 35.

How do I implement MedChat compliantly for EU patients?

Obtain explicit Article 9 consent before MedChat loads. Conduct a mandatory DPIA with Transfer Impact Assessment. Sign both a DPA and a BAA with MedChat. Update your privacy notice to specifically describe health data processing and US transfer. Configure retention limits for chat logs aligned with healthcare data requirements.

Are there EU-hosted healthcare chat alternatives to MedChat?

For EU-hosted healthcare chat, consider Cliniko (Australian, GDPR-conscious), Ninchat (Finland) with healthcare configuration, or custom implementations using EU-hosted messaging infrastructure. Doctolib (France) provides GDPR-compliant patient communication tools specifically designed for European healthcare providers.

How do I update my privacy notice for MedChat?

Add a dedicated section on patient chat communication. Explain that MedChat processes health information from chat conversations on US servers, that this constitutes processing of special category health data, that explicit consent is required and can be withdrawn, that data is transferred to the US under SCCs, and provide a contact point for data subject rights including chat data deletion.