The challenge
A skin and laser clinic in India had three front doors online. Its website handled first inquiries. Its e-commerce store sold products and took orders. Its EMR held patient records. Each had its own way of getting in touch, so questions arrived in three different places.
The clinic wanted a WhatsApp chatbot integration that pulled all three into one channel, with AI answering patients' questions. It also wanted a clear line on privacy. Messages to a skin clinic often carry personal details, and those had no place inside an AI model.
What we built: a WhatsApp chatbot integration for clinics with three front doors
In 2023 the clinic decided to buy a WhatsApp AI bot service rather than build one from scratch. Our job was to help it choose a suitable service and then connect that service to everything the clinic runs online.
Service selection. We advised the clinic on choosing a bot service that fit its needs before any integration began.
Website. Visitors to the clinic's website can move straight into the WhatsApp chat.
Online shop. The e-commerce store, which we had earlier proposed with a chat option on product pages, links into the same channel.
EMR. The patient records system points patients to the same WhatsApp chatbot.
We scoped and delivered the integration as one piece of work, so all three platforms lead to a single chatbot instead of three separate ones.
How it works day to day
A patient browsing the clinic's website has a question, so they tap through to WhatsApp. A customer on a product page does the same. So does a patient who starts from the EMR. All three conversations arrive in one place.
Anything our integration passes to the AI is de-identified first, and no patient records travel with it. The AI answers the question, and the reply returns to the right WhatsApp conversation. When a question falls outside what the clinic has set the bot to handle, the clinic's own team picks it up.
The clinic stays in charge throughout. It owns the bot account, decides what the bot says and sets the topics it covers.
What the AI never sees
Our integration passes only redacted, de-identified data to the AI. That was a design rule, not an afterthought.
Personal details are removed first. Our integration never passes patient records or identifiers from the EMR or the shop to the bot; anything it sends the AI is de-identified first.
No identity from our side. The integration passes context, never names, phone numbers or record numbers.
The clinic holds the controls. It owns the bot account and its settings, including what the bot may ask and keep.
Records stay in the EMR. The integration links people to WhatsApp. It does not copy patient records into the bot.
The bot stays in scope. It answers on the clinic topics the clinic has set, and staff handle the rest.
We designed the integration with India's Digital Personal Data Protection Act, 2023 in mind.
The result
The clinic now has one WhatsApp chatbot that serves its website, its online shop and its EMR. Patients and customers ask in the app they already use, AI answers within the clinic's chosen scope, and patient records and identifiers from its systems stay out of the bot.
There are no usage or outcome numbers on file for this bot, so none appear here. What changed is how people reach the clinic: three separate routes became one.
What the research says
WhatsApp is already in patients' pockets. WhatsApp has more than 3 billion monthly users, Meta's chief executive said on the company's first-quarter 2025 earnings call (Meta Q1 2025 earnings call). Routing the website, shop and EMR to one WhatsApp channel meets patients in an app they already use.
India now enforces data protection. The government notified the Digital Personal Data Protection Rules on 14 November 2025, giving full effect to the 2023 Act. Failing to keep reasonable security safeguards can draw a penalty of up to ₹250 crore (Press Information Bureau).
AI health answers carry risk. The World Health Organization's 2024 guidance on large multi-modal models in health sets out over 40 recommendations and warns of documented risks of false, biased or incomplete statements (WHO). Keeping the bot to clinic-set topics, with staff behind it, is one answer to that.
Breaches keep getting dearer. Security vendor IBM's Cost of a Data Breach Report 2026 puts the global average cost of a breach at US$4.99 million, up 12% on the year before (IBM Cost of a Data Breach). Keeping patient records in the EMR and de-identifying anything sent to the AI shrinks what a breach could expose.
Where AI fits next
The bot does not do this yet; these are options. It could draw its answers on treatments and products from a library of content the clinic approves. Any request to change an appointment, or anything clinical, could be routed straight to a named member of staff.
Planning something similar?
Before you connect a chatbot to your clinic's systems, ask:
Where do patients and customers contact you today, and should they all lead to one channel?
Which personal details must be removed before a message reaches the AI?
Which topics may the bot answer, and who on your team takes the rest?
Should the bot link out from your EMR, or does it truly need access to records?
The same clinic's patient lead CRM shows how its inquiries are followed up. Our AI chatbot development and software consultancy pages explain how we help clinics choose and connect a bot, and our guide to AI data privacy for business covers what to keep out of the model. More examples are on our healthcare software page.



