The health workers, as general medicine doctors, dentists and specialists record health data about their patients in a medical record. The patient rights and health workers duties are established by the law.
File requirements
According to Law on the Contract of Medical Treatment, health workers must store the medical record.
Security
The GDPR requires that the health workers must protect medical records. For example, only authorized people can have access to a patient’s file.
Retention period
The principle rule for health records is written in the WGBO. This law provides that the health worker must store the medical record for 20 years.
Anyway, the GDPR and other specific legislation can be applied for the determination of how long a health worker should store a medical record.
Patient’s rights
The patient’s rights concerning its own medical record are written in part the WGBO and partly in GDPR.Many dispositions are also included in the health legislation.
Patients have the right to view their own medical records, ask for any corrections, or adds or also the destruction. They can also ask for data transfer. (right of data transfer).
Health services provider and GDPR
The GDPR also took on new responsibilities, also for health workers. Rules help them to manage carefully all the sensitive information about privacy of patients, especially now that they are digitized.
Obligation of the GDPR
According to GDPR, new information requirements and new work rules are applied for working with the patient’s consent.
In many case you will be asked to:
– keep your processing activities register;
– keep your Data Protection Impact Analysis;
– appoint a Data Protection Officer
This is important also to manage the patient’s security.
With the enter in force of the GDPR this has not changed, but there is a news: the responsibility.
Responsibility means having the ability to prove that you have adopted all the technical and organizational measures to protect your patient’s data and that the processing is in compliance with the GDPR.
Existing rules that will continue to be applied.
Actual privacy rules are confirmed by GDPR and reinforced in some parts. This is the list of the applicable laws:
- Law on the Contract of Medical Treatment (WGBO);
- Quality, Complaints and Disputes Act (Wkkgz);
- Individual Health Professions Act (BIG Act);
- Health Insurance Act (Zvw);
- Health Market Regulation Act (WMG);
- Additional provisions for the processing of personal data in the Health Act.
The rules of the GDPR also coexist with current rules on medical professional secrecy.
SOURCE: AUTORITA’ PER LA PROTEZIONE DEI DATI DEI PAESI BASSI – AP