Privacy. Security. Experts United.

Data protection in the medical practice

As important as medical confidentiality. Data protection made easy.

Robin Data stands for highest
Quality and safety standards.

TÜV-certified data protection ISO 9001 certified quality management system
TÜV-certified data protection ISO/IEC 27001 certified information security management system

DATA PROTECTION IN THE MEDICAL PRACTICE: AS NATURAL AS MEDICAL CONFIDENTIALITY

The observance of medical confidentiality goes without saying for every doctor. Adhering to this obligation presents special challenges for doctors in their daily work and involves risks under criminal law.

The systematic implementation of the General Data Protection Regulation (GDPR) is the ideal basis for safeguarding medical confidentiality in your practice. The laws of the GDPR aim to organise data protection in the medical practice in such a way that patient data does not fall into the hands of unauthorised third parties. Legally prescribed security measures significantly reduce the risks of a data leak.

The implementation of the GDPR appears complex and is an additional challenge for doctors. The data protection experts at Robin Data have many years of industry expertise in the field of medical practices, OBAGs and MVZs. We guarantee that we will implement the data protection in your practice in a simple and secure way.

With Robin Data, data protection easily becomes part of your daily routine. No longer worry about fines and criminal consequences.

WE SUPPORT YOUR MEDICAL PRACTICE IN THE IMPLEMENTATION OF DATA PROTECTION

SERVICES FOR THE IMPLEMENTATION OF DATA PROTECTION IN YOUR MEDICAL PRACTICE

Data Protection Officer

Data protection officer Data protection in the medical practice

Our external Data Protection Officer are at your disposal as regional contact persons. Together with the Data Protection Officer, you implement the data protection documentation for your medical practice.

  • Review and, if necessary, amend the privacy policy of the website

  • Inclusion of necessary data protection impact assessments

  • and much more.

Data Protection Management Software

Data protection software for the medical practice

Robin Data has a Data Protection Management Software specially developed for medical practices. Profit from an already preconfigured Record of processing activities. Suitable templates, e.g. for information duties, are available free of charge on request.

Also included in the data protection software:

  • Erasure concept

  • Technical and organisational measures

  • Data Protection Impact Assessments

  • and much more.

Information security based on ISO/IEC 27001

Information security according to ISO/IEC 27001 for the medical practice

Especially when processing sensitive patient data in medical practices, there are processing activities, such as the reception of patients or the stay of patients in the treatment room, which require special security measures.

In this case, special technical and organizational measures of information security are required. In this case we analyse and design an information security management system (ISMS) based on the information security standard ISO/IEC 27001 together with you.

Internal audits

Internal audits for the medical practice

In consultation sessions we often hear that medical practices have already implemented initial data protection measures, but are unsure whether these are correct. With internal audits you can check the status of data protection implementation in your medical practice. These audits are carried out by our Data Protection Officers, after which you will receive information about improvements.

Staff training

Data protection staff training

The sensitization of employees is essential for the implementation of sustainable data protection in the medical practice. Our data protection officers will be happy to train your employees.

Implementation of the GDPR

Your Data Protection Officer at Robin Data

We would be pleased to send you a non-binding offer for the deployment of an external Data Protection Officer in your medical practice.

  • regional
  • sector-specific
  • individual

TECHNICAL AND ORGANISATIONAL MEASURES

COMMON MISTAKES IN DATA PROTECTION IN MEDICAL PRACTICES

How secure are the PC passwords of your employees?

Access to personal data of patients processed on a computer must be protected. This applies equally to the patient reception area and the treatment room.

Medical practices must instruct their employees to use secure passwords. At best, a password policy is created for this purpose.

Do you protect your patients' files sufficiently?

Data protection medical practice files

Patient files are to be locked up immediately after use in file cabinets provided for this purpose.

If patients are in the treatment room or reception area, the doctor's practice must ensure that no foreign patient files are left lying around.

The process around the patient flow must be structured in such a way that no third party has the opportunity to view a patient's file or document.

Do you validate personal information over the phone?

Data protection medical practice

Before providing sensitive personal patient data over the phone or by e-mail, medical practice staff must ensure that the requestor is authorized to receive the data.

Do you know what the technicians in your practice do in the area of IT security?

IT Security Data Protection Medical Practice

Encrypted data storage, regular backups and a secure firewall protect your patients' data. Medical practices must ensure sufficient IT security when processing patient data.

Privacy self-check for medical practices

Does your practice meet the minimum requirements for technical data protection when connecting IT systems? Test yourself and answer the following questions.

  1. Is the communication of your practice encrypted in the network? For this purpose, state-of-the-art procedures are to be used.
  2. Can you guarantee that unauthorised access to the internal networks of the practice or institution is impossible?
  3. Are the effects of misconfigurations in the internal network effectively limited?
  4. Do the endpoints of communication in your medical practice authenticate each other through state-of-the-art procedures?
  5. Is the maintenance of the hardware and software components used for network access controllable? It must be possible to enable maintenance by an active action; all maintenance activities are logged.
  6. Do you use certified hardware and software components for network access?
  7. Does your practice adhere to basic standards - such as auditing acceptability?

LEAVE DATA PROTECTION TO THE PROFESSIONALS!

WE TAKE OVER YOUR DATA PROTECTION

Our data protection officers are:

  • Already in use for years in medical practices
  • Near you and direct contact person
  • Experienced in dealing with IT and technology

Steps towards a data protection compliant medical practice

1

Analysis of existing data protection measures

2

Analysis of the processes in the medical practice

3

Structure of the data protection management system

4

Employee sensitisation

STEP 1 TO THE DATA PROTECTION COMPLIANT MEDICAL PRACTICE

Analysis of existing data protection measures

1

Privacy compliance of the website

2

Obligation of data secrecy

3

Existing documents in the course of patient communication (consent, information, etc.)

4

Existing legally required documents (TOMs, deletion concept, etc.)

5

Service instructions and privacy policy

LEAVE DATA PROTECTION TO THE PROFESSIONALS

Save time, costs and nerves in the daily practice routine!

Robin Data implements the data protection measures for your medical practice. In a non-binding meeting we will discuss which concrete measures we will take to make your medical practice compliant with data protection.

STEP 2 TO THE DATA PROTECTION COMPLIANT MEDICAL PRACTICE

Analysis of the data protection processes in the medical practice

1

Patient registration process

2

Patient call process

3

Process of patient file flow

4

Process of telephony with patients

5

Administration and archiving of patient files

6

Administration of consent, information to patients

7

Conversion of deletion periods

8

Dealing with patients' requests for information and deletion

9

Use of the management system in practice

10

Dealing with data breaches

STEP 2 TO DATA PROTECTION COMPLIANT MEDICAL PRACTICE: PRACTICAL TIPS

DATA PROTECTION AND PATIENTS

Declarations of consent

Patients are treated on a legal basis for routine treatments. It is not necessary to obtain consent for data processing. However, if patients' health data is further processed by third parties, a declaration of consent may be necessary.

We will be happy to advise you in which cases declarations of consent are useful and provide you with the appropriate templates.

Information requirements

Medical practices must inform their patients that their data are processed by the medical practice. For this purpose, forms can be displayed in the medical practice. The information duties of the GDPR are defined in Art. 12-14 listed.

We provide our customers with forms for information requirements.

Right of access to information

Medical practices are obliged to allow patients to view patient files or to provide information on personal data. The right of inspection is defined in § 630g BGB (treatment contract), the right of information in Art. 15 GDPR is regulated.

We offer our customers to create an appropriate processing activity for the internal privacy policy. In this way, you can respond to requests for information quickly and in compliance with data protection regulations.

Right of cancellation

The right of cancellation is defined in Art. 17 GDPR and states that the patient concerned has the right to ask the doctor's office to delete personal data immediately. Again, it is advisable to prepare appropriate processing activities in order to respond quickly to requests.

We would be happy to work with you to develop appropriate instructions and processing activities for the staff of your medical practice.

STEP 3 ON THE DATA PROTECTION COMPLIANT MEDICAL PRACTICE

Structure of the data protection management system

1

Recording of locations (e.g. for ÜBAGs)

2

Recording the relevant employees of the data protection organisation

3

Acquisition of external contacts

4

Checking contractual bases for data exchange (e.g. laboratories, insurance companies)

5

Structure of the procedure directory

6

Structure of the extinguishing concept

7

Carrying out data protection impact assessment

8

Implementation of necessary technical-organisational security measures

9

Implementing the documents for patients and staff (consent, information)

10

Optimization of the processes from 2 regarding conformity to data protection

PHYSICAL PRACTICES

Violation of data protection and professional secrecy

In addition to the consequences in the event of a breach of the applicable basic data protection regulation, medical practices must also observe professional confidentiality. If medical practices violate § 203 of the German Criminal Code, a fine or one year imprisonment is to be expected.

Frequently asked questions about data protection in medical practices

No. Medical treatment is provided on a contractual basis.

This basis entitles the medical practice to process patient data in accordance with Art. 9 paragraph 2(h) and paragraph 3 in conjunction with Article 6 (paragraph 1 sentence 1 letter b) of the GDPR.

This legal basis covers all processing necessary for the treatment of the patient.

Excluded from this legal basis are processing operations that are not necessary for the treatment. For example, the transfer of personal patient data by private billing agencies. Consent must be obtained from the patient for this processing.

In general, the basic data protection regulation provides for the appointment of a Data Protection Officer when a medical practice regularly employs 20 persons to process personal data.

However, it should be noted that a Data Protection Officer must also be appointed when sensitive health data are processed. As a rule, the processing of health data poses a high risk to patients and their rights and freedoms. Under data protection law, a data protection impact assessment must be carried out when processing health data.

We recommend the appointment of a Data Protection Officer even if the practice size is less than 20 employees.

Medical practices must inform patients about the extent to which their personal data are processed. For this purpose, a notice in the practice is sufficient, a signed notice is not required. We recommend that patients also provide the information duties in writing upon request.

Personal data of patients are to be deleted if they are no longer needed to fulfil the treatment contract and if there is no legal retention period that prevents deletion. In principle, patient files must be deleted after 10 years, even if the patient does not expressly request this.

Patient files can be kept longer, insofar as

  • There are reasons to believe that the deletion is not in the legitimate interest of the patient.
  • The medical record is required for the assertion, exercise or defence of legal claims.

No. Firstly, we recommend that the DPO should be independent of the doctor or medical practice in order to avoid an internal conflict of interest.

Assigning the role of Data Protection Officer to medical practitioners is also not recommended, as implementation is not compatible with the actual tasks due to time constraints.

Request a quote for Robin Data ComplianceOS®

We will be happy to provide you with an offer that suits your needs.

© Copyright - Robin Data GmbH
en_GB