For medical practices, therapy and healing professions

Receive patient documents securely. Without another patient portal.

Patients open your fixed practice link, upload reports, admission forms, or files, and send them directly in the browser – no personal account or installation needed.

The everyday

Health data are often least secure precisely where the process is meant to be simple.

01
“Send the report by email”

The file remains readable in multiple secure inboxes and backups.

02
Large portals are not used

Registration, password and app download are too much of a hurdle for a single intake form.

03
Representation is managed via pooled accounts

Shared access credentials blur accountability and cannot be cleanly revoked upon departure.

An expiry in three steps

The secure link fits into the existing patient contact.

1

Create practice postbox

For example, "test results", "admission" or "therapy documents." Protection level and retention period are selected per incoming item.

2

Send the link

In appointment confirmation, SMS, email signature, or as a QR code at reception. Patients do not need an account.

3

Open in team

Approved team members see new entries in real time and open them using their own account and security factor.

Typical applications

A link for documents before and after the appointment.

Start pragmatically: Begin by using a secure inbox for receiving documents. Name it neutrally and avoid including diagnoses or treatment reasons in unencrypted subject or name fields.

Before the first appointment

Receive the intake form, referral, and existing findings in advance.

Diagnostics & Laboratory

Deliver documents once or receive them via a secure inbox.

Therapy and aftercare

Exchange confidential documents without permanent email attachments.

Practice organisation

Assign postboxes to selected employees or the entire team; revoke access immediately upon departure.

Protection model

The appropriate protection level per process

One-time code or passkey

Postboxes can be secured using a code, account passkey, combination, second factor, or your own end-to-end passphrase.

Short deadlines

Inboxes are available for 24, 48, 72 hours, or 7 days depending on settings, and are deleted after being read.

Contract documents

Business provides an AVV and a §203 obligation in the account. The specific legal classification remains the responsibility of the practice.

SchlüsselBot is a secure transmission channel, not a practice management system or a medical archive. After retrieval, please store any necessary documents in your designated patient file. Guidance for professional duty holders

Frequently asked

Briefly answered

Does the practice need to provide patients with new login credentials?

No. External senders open the link without an account. The protection check applies to the retrieval by the practice or the direct message recipient.

Can attachments land on a mobile device?

Yes, that's why the retrieval page prompts users to open the link on the device where the file should be saved, before the one-time unlock.

Is the use automatically GDPR-compliant?

SchlüsselBot is prepared for GDPR compliance and provides a Data Processing Agreement (AVV) in Business. Purpose, lawfulness basis, information obligations, and internal permissions are managed by the practice.

A secure patient entry can be as simple as a link.

Without patient app – with clear permissions and contract documents for your practice.