Question Clearly sourced

Expert knowledge for digital decisions

How is patient data processed legally?

Short answer

Health data may only be processed under strict conditions according to Article 9 of the GDPR – in practice, usually based on the treatment itself. Encryption, a role and rights concept, comprehensive logging of access, and a data processing agreement with each service provider are required. Additionally, the medical confidentiality obligation under § 203 of the Criminal Code also binds external service providers.

For health data, two regulations apply concurrently:

GDPR. Article 9 generally prohibits the processing of special categories and only allows it in exceptional cases – for treatment, for example, according to Article 9 (2) (h).

§ 203 of the Criminal Code. Breaching confidentiality is a criminal offense. Since 2017, professionals bound by confidentiality may involve service providers but must explicitly require them to maintain confidentiality. A data protection agreement alone is not sufficient for this.

What is Technically Required

  • Encryption during transmission and storage
  • Roles and Rights – the medical assistant at the reception does not need the same access as the treating physician
  • Logging of every access to patient data, audit-proof
  • Deletion Concept considering retention periods
  • Backups that are as protected as the main system

What is Most Often Missing in Practice

Access Logging. Without it, it cannot be clarified in case of suspicion who opened a file – and that is exactly when it is needed.

The Obligation of Service Providers under § 203 of the Criminal Code. Many practices have a data processing agreement but lack a separate confidentiality obligation.

Retention

For patient records, according to § 630f of the Civil Code, a retention period of ten years generally applies after the treatment is completed. Other regulations may provide for longer periods. This is an obligation to retain – not a right to further use.

This text does not replace legal advice.

Key facts

Two Regulations
Article 9 of the GDPR and § 203 of the Criminal Code
Service Providers
also need a confidentiality obligation
Patient Record
generally 10 years (§ 630f of the Civil Code)
Most Often Missing
audit-proof access logging

Sources

All external claims are backed by traceable sources.
  1. 01
  2. 02

Ready for your next project?

Free initial consultation - no sales pressure, just clear answers.

Request consultation