Guide24 August 20264 min read792 words

Law 5651 Compliant Guest Wi-Fi and Logging for Hospitals

Explains how hospitals meet Law 5651 user authentication and signed-log duties for patient and visitor guest Wi-Fi, handling high turnover and patient-data privacy with SignLogger.

#hospital law 5651#hospital guest wifi#captive portal#law 5651 logging#patient data

When hospitals offer guest Wi-Fi to patients, companions, and visitors, that access falls under the Law No. 5651 obligation to authenticate users and keep signed logs. SignLogger authenticates users through a captive portal in high-turnover healthcare environments, retains internet access (connection) logs, and seals those logs every day with an authorized certificate authority timestamp and e-signature. SignLogger processes only connection records; it never touches clinical content such as patient files, medical images, or hospital information system data.

This content is for general information only and does not constitute legal advice. Consult your legal counsel and current legislation for your institution's specific obligations.

Why Hospital Guest Wi-Fi Is Different

Healthcare institutions differ from other public-internet venues in several ways. Outpatient waiting areas, inpatient floors, emergency departments, and cafeterias host thousands of short-lived connections throughout the day. This dense, constantly changing user base demands both uninterrupted access and lawful recording of every connection.

  • High turnover: Patients and visitors come and go quickly; the system must authenticate each new user fast.
  • Multi-zone campus: Access across different buildings and floors must be managed from a single point.
  • Patient privacy: The guest network must be logically separated from the clinical network and patient data.
  • Continuity: Care never pauses, so the logging infrastructure must run 24/7.

Law 5651 Obligations: Authentication and Signed Logs

Law No. 5651 requires hosting providers that offer public internet access to authenticate users and retain access logs, unaltered, for a defined period. A hospital enters this scope the moment it offers internet to patients and visitors. In practice two requirements stand out: verifying who connected, and being able to prove the integrity of that record.

SignLogger authenticates users through the captive portal, and RADIUS identity checks use the PAP method only. The retained logs are sealed every day with a TÜBİTAK Kamu SM timestamp and e-signature, making it provable that a record existed on the stated date and was not altered afterward. The Kamu SM service works on a credit (kontör) basis, so planning matters to keep signing from being interrupted when credits run out. The exact retention period and accepted authentication methods should be based on current legislation.

User Authentication Options

In the hospital scenario, the goal is to satisfy the identity match the law requires while preserving privacy. SignLogger supports several authentication flows that can be chosen by institutional load and policy.

MethodHow It WorksHospital Use
SMS verificationLogin via a code sent to a phone numberPractical for visitors and companions
Portal formSelf-service registration with identity detailsWaiting areas, cafeteria
Predefined accountAccount for staff or long-stay inpatientsInpatient floors

To plan the network design and captive portal flow end to end, explore our hotspot management solution.

Patient Data and Privacy: What SignLogger Does Not See

Health data is a special category of personal data requiring the highest level of protection. The critical distinction here is this: SignLogger is a logging and authentication layer, not a clinical system. It retains only connection metadata about which device went online and when; it does not process the body of visited content, medical records, or hospital information/imaging system data.

  • The guest network is designed separately from the clinical network; guest traffic cannot reach internal systems.
  • The collected log is limited to the minimum connection information the law requires.
  • All data runs on the hospital's own infrastructure (VMware/Hyper-V); records never leave the institution and stay on-prem.

SignLogger is not tied to any specific firewall brand; it works with any RADIUS-capable firewall and sits on top of your existing network investment.

Frequently Asked Questions

Does hospital guest Wi-Fi fall under Law 5651?

Yes. The moment a hospital offers public internet access to patients and visitors, hosting-provider obligations apply, requiring user authentication and signed log retention.

Does SignLogger access patient data or medical records?

No. SignLogger retains only connection logs. It never touches clinical data such as patient files, medical images, or hospital information and imaging systems.

Can the system handle heavy patient turnover?

Yes. The captive portal is designed for multi-zone, high-volume campuses; new users are authenticated quickly and every connection is recorded.

How are logs made tamper-evident?

SignLogger seals logs every day with a TÜBİTAK Kamu SM timestamp and e-signature, making it provable that a record existed on the stated date and was not altered afterward. Kamu SM works on a credit basis.

Does our data leave the institution?

No. SignLogger runs on the hospital's own virtualization infrastructure (VMware/Hyper-V); logs stay on-prem and are not sent to any third-party server.

Do we have to replace our existing firewall?

No. SignLogger is brand-independent and works with any RADIUS-capable firewall; it is added on top of your existing infrastructure.

Last updated: 25 August 2026

See SignLogger Law 5651 compliance for yourself

Request a free demo