Help Center
Short answers to the questions clinicians and hospital administrators ask most often when starting with My Health Online.
How do I pseudonymize patient data before uploading?
Replace the patient's name, national ID, and insurance number with your hospital's local case identifier before saving the case. The platform stores only that local identifier; it never sees the direct identifiers.
DICOM attachments should be de-identified at the modality or via the hospital PACS export before being uploaded. My Health Online does not strip DICOM tags on the server — the responsibility for de-identification lies with the uploading hospital.
Why are DICOM, MRI, HbA1c not translated when I switch languages?
Medical vocabulary is kept identical across every locale on purpose — translating it has been shown to introduce clinical-safety risk. A Turkish radiologist and an Uzbek radiologist read the exact same string when they look at a study.
The platform enforces this with a build-time check: any medical term that appears in English must appear verbatim in every other locale. The UI marks these terms with the Latin language attribute so screen readers pronounce them consistently.
How do I enable multi-factor authentication (MFA)?
Open your Account page, click 'Set up MFA', and scan the QR code with an authenticator app (Google Authenticator, 1Password, Authy). Confirm by entering the six-digit code the app generates.
You will receive ten one-time recovery codes — save them in a password manager. Lose your phone? Sign in with one recovery code, then enroll again with a new device.
I am locked out. What now?
The platform locks an account for 15 minutes after five consecutive failed login attempts. Wait it out and try again, or ask your hospital administrator to clear the lockout manually.
If you've forgotten your password, use the 'Forgot password?' link on the sign-in page. The reset link is sent to your registered hospital email and is valid for one hour.
How do I change the time zone used for timestamps?
Open your Account page and pick a time zone from the curated dropdown (grouped by pilot region). The setting takes effect immediately on every timestamp the platform renders for you.
Audit logs always store events in UTC internally — the time zone preference only affects how the platform displays times to you.
How do I get a copy of my data (DSAR)?
Authenticated clinicians can fetch their data export immediately at /api/auth/dsar/export. The response is portable JSON containing your account record and the cases you have authored.
Under KVKK Art. 11, GDPR Art. 15-22, and UZ PDL Art. 22 you may also request rectification, erasure, restriction, or portability. Contact your hospital administrator first — they are the data controller — or write to privacy@cccp.health.
What happens to case content when our hospital leaves the platform?
On termination of the hospital contract, all case content and clinician account data is exported back to the hospital in a portable format and deleted from My Health Online within thirty days.
The audit log is retained for the statutory minimum period — this is required to demonstrate compliance and cannot be waived. See the Data Processing Agreement at /dpa for details.
Still stuck?
Reach your hospital administrator first — they can resolve account, MFA, and access issues directly. For platform-level questions, email support@cccp.health (responses within one business day on weekdays).