Expert knowledge for digital decisions
What is Included in Data Protection in a Medical Practice?
Short answer
The Basics
Record of Processing Activities. What data is processed for what purpose, for how long, and who has access.
Data Processing Agreements. With every service provider that has access – software, IT support, billing office, document destruction.
Additionally § 203 StGB. Service providers must be separately obligated to confidentiality. A data protection agreement alone is not sufficient for this.
Roles and Rights. Reception does not need the same access as the treating staff.
Access Logging. Who has opened which file.
What is Often Missing in Daily Practice
- Screen Lock at reception when absent
- Privacy Screens so that waiting patients cannot see monitors
- Discretion Distance and conversation management at the counter
- Obligation of New Employees, documented
- Regulation for Personal Devices
These points are free and are regularly criticized in audits.
Data Protection Officer
There is an obligation to appoint one if extensive processing of special categories of data is part of the core activities, or from a certain number of persons constantly engaged in processing. Whether a practice is affected depends on the individual case.
In Case of a Data Breach
Notification to the supervisory authority usually within 72 hours. In the case of health data, a high risk is often assumed – then the affected individuals must also be informed.
This text does not replace legal advice.
Key facts
- Two Regulations
- GDPR and § 203 StGB
- Frequently Criticized
- Screen lock, privacy screens, obligations
- In Case of Data Breach
- Usually 72 hours notification period
Sources
All external claims are backed by traceable sources.-
01
Strafgesetzbuch (StGB) Bundesministerium der Justiz