Electronic Patient Records & Data Privacy: How secure is the ePA?

- Centralized storage of health data in the ePA, with access granted only upon patient consent.
- Storage of sensitive health data such as diagnoses, medical reports, and medication plans.
- Data protection risks due to the lack of partial access options for physicians.
- Legal basis: GDPR Art. 9 Para. 1, SGB V §§ 341 et seq.
- Public skepticism: only 0.2% use the ePA despite a 66% theoretical approval rate.
The idea is sound: all patient records on one digital platform, always at your fingertips. Test results, medical history, and much more – nothing gets lost when switching doctors or when a comprehensive diagnosis is required. But how secure is the ePA digital platform? And what are its pros and cons?
What is the electronic patient record?
Like the electronic health card or video consultations, the digital patient record is intended to boost telemedicine in Germany. The electronic patient record (ePA), also known as the digital health record, essentially consists of all of an insured person's medical files, bundled into a single digital platform. The information combined digitally is referred to as health data. This health data is encrypted and stored on a central platform. Patient data is accessed via the telematics infrastructure, which is a highly secure, closed network. Information can only be viewed by selected doctors – and patients decide which ones. Those theoretically authorized to access it include:
- Doctors and dentists
- Therapists
- Pharmacists
- Other healthcare providers involved in treatment, such as hospitals
Important: Health insurance companies are not authorized to access the electronic patient record!
In theory, patients have full control over their ePA. Via an app, the electronic patient record can be populated with prognoses, medication plans, and similar information. For those without a smartphone or tablet, there is also the option to have the complete patient file uploaded digitally to the electronic health record at a doctor's office. This is done using the practice management system (PVS) used by medical practices. But what exactly is the data being uploaded to the ePA?
Data protection in the healthcare sector
In the healthcare and nursing industry, there is more to consider regarding data protection than in other sectors. This is primarily because the work involves sensitive information such as health data. We specialize in providing data protection advice for this industry.
What data is stored in the digital patient record?
The ePA stores health data. This is a category of personal data that requires a particularly high level of protection, and special security measures must be taken during its collection, processing, and storage (Art. 9 (1) GDPR). Specifically, this includes data such as:
- Diagnoses, test results
- Maternity records and child health check-up booklets (the latter from 2022 onwards)
- Blood counts and blood test results
- X-rays
- Medication plans, treatment measures, and therapies
- Vaccinations and vaccination records
- Pre-existing conditions and allergies
- Medical reports and physician correspondence
Because this data can easily identify an individual and, in the worst-case scenario, leave them vulnerable in the event of a data breach, it is stored in encrypted form. Access is restricted to the insured person and anyone they have explicitly authorized.
Legal basis for the electronic patient record
There are various legal foundations for the electronic patient record:
- Art. 9 (1) GDPR: This article classifies stored health data as requiring special protection. This necessitates specific regulations for both storage and access to ensure the security of this data, such as encryption.
- Sections 341 et seq. of the German Social Code (SGB V): These sections of the Social Code establish that an electronic patient record (ePA) may be maintained.
- Section 305 of the German Social Code (SGB V): According to this newly regulated basis, it must be ensured that no unauthorized third party can gain access to the digitally transmitted data of insured persons. As previously mentioned, access is only possible with the explicit consent of the patients.
- Art. 9 (2) lit. b GDPR: This article provides the necessary legal basis for data transmission and refers to the consent mentioned above.
And finally, there is a court ruling regarding the electronic patient record: Following a constitutional complaint in 2021, the Federal Constitutional Court addressed the issue and classified the ePA as a voluntary service that insured persons cannot be forced to use (Decision of Jan. 4, 2021, Ref. 1 BvR 619/20).
Electronic patient record: Pros and cons
All health data at your fingertips – is this a digitalization booster or a data protection nightmare? The advantages are clear:
- Duplicate treatments can be avoided
- Even when changing doctors, physicians can see all relevant information at a glance
- In an emergency, hospitals can access important background information, such as details about allergies or drug interactions
- Insured persons decide for themselves what should be stored in the ePA
Ultimately, the ePA is intended to ensure better and smoother treatment. However, as with any issue, there is a trade-off.
- The ePA may be incomplete if insured persons only include part of their medical history
- If a doctor is granted access to the electronic patient record, they gain access to everything stored within it. Partial access is not possible – yet, for example, a psychotherapist's findings are of little relevance to a dentist. This situation is expected to change in 2022
- No accessible access: Managing the ePA without the app is possible, but only under difficult conditions
- Health data is stored centrally. However, decentralized storage would significantly increase security. If hackers were to gain access to the digital platform, they would not be able to view all the digital health records stored there.
Conclusion: Is data protection guaranteed with the electronic patient record?
Medical practices are now busy upgrading; practice management systems are being updated to handle digital patient records. Is the much-heralded digitalization of the healthcare system finally arriving? It remains difficult: At the beginning of 2021, the Federal Commissioner for Data Protection and Freedom of Information (BfDI), Prof. Ulrich Kelber, stated regarding the ePA and data protection: "In its current form, I personally would not use the ePA." He based this statement primarily on the fact that it is not possible to grant doctors partial access. The problem: the "fine-grained" authorization that Kelber demands is not technically possible with the current telematics infrastructure.
A large part of the population seems to agree with the BfDI's opinion: The digital association Bitkom published figures on the ePA in May 2021 – and they speak volumes. While 66% of Germans would theoretically like to use the digital patient record, in practice, only 0.2% of all Germans are actually doing so. The reservations are (still) too great. This may change once insured persons are granted more self-determination over their data in the ePA.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.













