The Croatian authority clarifies patients' rights to access their personal data in the hospital information system

The Croatian Data Protection Authority (AZOP) has clarified the scope of a patient's right to access the identity of hospital staff who have consulted their medical record via the hospital information system.

Addressing a question on the disclosure of access logs to medical records, the authority distinguishes two categories of staff. For staff who have directly provided healthcare, the institution is required to disclose names, first names, and specializations under Article 12 of the Law on the Protection of Patients' Rights. This disclosure constitutes a legal obligation within the meaning of Article 6, paragraph 1, point c) of the GDPR and cannot be refused by invoking the rights and freedoms of employees. For other staff members (administrative, IT, etc.) who have accessed the record, their identity is not automatically disclosable under Article 15 of the GDPR, relying on the Court of Justice of the European Union ruling in case C-579/21. These are not considered recipients.

The disclosure of the identity of these other employees must be assessed on a case-by-case basis to determine if it is indispensable for the effective exercise of the patient's rights, while taking into account the rights and freedoms of these employees. The hospital must provide sufficient information about accesses (date, time, purpose) to allow the patient to verify their legality. As the data controller, it must implement technical and organizational measures to ensure that only authorized personnel access the data, documenting authorizations and controlling access. Any unauthorized access must be treated as a potential data breach within the meaning of Articles 33 and 34 of the GDPR. The response to the access request must be provided within one month, and any partial or total refusal must be justified.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire