Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

Sector

Data protection in hospitals and at their suppliers

Alongside Art. 9 GDPR stands section 203 of the Criminal Code, a separate duty backed by criminal sanction. Under its paragraph 4, first sentence, it reaches the service provider itself and the data protection officer. Under paragraph 4, second sentence, no. 1 it reaches the hospital where it has not bound the provider to secrecy. Whether outsourcing is permissible at all is decided in addition by state law, and state law diverges.

One provider in two federal states

A provider with hospitals in North Rhine-Westphalia and in Bavaria puts a document management system out to tender. The supplier attaches its processing agreement, the data protection team reviews it, and the roll-out is planned identically for both sites. Two things have not been examined in the process.

Professional secrecy creates a criminal liability of its own

What applies in a hospital alongside the Regulation is regularly missed during contract review, because it does not sit in data protection law. Section 203(1) no. 1 of the Criminal Code makes the unauthorised disclosure of a patient secret a criminal offence, and that duty exists next to Art. 9 GDPR rather than inside it.

Three sentences of section 203 that bear on outsourcing

When disclosure to a supplier is permitted

Under paragraph 3, second sentence, secrets may be disclosed to persons assisting in the professional activity in so far as this is necessary in order to make use of their services. Necessity is the yardstick here too, and it is determined per access rather than per contract.

When the supplier itself is criminally liable

Under paragraph 4, first sentence, an assisting person commits an offence by disclosing without authorisation a secret that became known to them. The same provision expressly names the data protection officer working for the hospital.

When the hospital is criminally liable

Under paragraph 4, second sentence, no. 1, the hospital commits an offence where it has not ensured that the assisting person was bound to secrecy and that person then discloses. That obligation is something other than the contract under Art. 28(3) GDPR.

Every engagement of a supplier therefore calls for two documents, not one. Where only the first is in place, there is a data protection basis and an open criminal exposure beside it.

The same project, two states, two outcomes

Why a project turns out differently in two states comes down to a layer standing alongside the Regulation and the Criminal Code. The states have enacted their own rules on patient data, and these differ precisely on outsourcing.

Outsourcing patient data in two states

North Rhine-WestphaliaMerkmalBavaria
Processing within the institutionSection 7(1) GDSG NW makes processing within the institution the rule and processing on behalf the exception.The starting pointPermittedArticle 27(4), fifth sentence, BayKrG allows it where the special protective measures are observed.
Disruption or costUnder section 7(2) GDSG NW only where operational disruption could not otherwise be avoided or partial operations become significantly cheaper.ConditionNo indicationsSo long as nothing indicates that patients' protected interests would be impaired.
Physically separateUnder section 7(3), second sentence, GDSG NW medical patient data have to be processed in physically separate files.Separation at the supplierNot prescribed
From 1994The wording has not been adapted to the Regulation and refers to provisions since repealed.Vintage of the provisionAdaptedParagraph 6 expressly refers to Art. 28 and Art. 32 GDPR.

For a provider with hospitals in both states it follows that a single uniform outsourcing arrangement is not readily available. The assessment is made state by state, and the outcome may be separate storage or a second supplier.

A supplier becomes an assisting person and is criminally liable itself

What this means for a supplier usually shows up only during the tender. Anyone supplying into a hospital becomes an assisting person within the meaning of section 203(3), second sentence, of the Criminal Code and is thereby subject under paragraph 4, first sentence, to a duty of their own, backed by criminal sanction. The processing agreement does not capture that.

What a supplier should settle before its first tender

Liste zu erledigender Punkte

  • Who inside the organisation actually gets access to patient data, and whether each of those people is bound
  • Whether sub-processors are used, because under section 203(4), second sentence, no. 2 the duty to bind them then falls on the supplier as well
  • Whether operations can deliver separation by client and, for North Rhine-Westphalia, physical separation of medical data
  • In which states the customer’s hospitals lie, because permissibility depends on it
  • Whether remote maintenance and the evaluation of log data are covered by contract, because both are access

How we support you in healthcare

The scope of the assessment is smaller than it looks, provided it is worked through in the right order. First it is established which state rules apply to which hospital. Then it is settled, supplier by supplier, whether they are an assisting person and who has to be bound at their end. Only after that is work on the contract worthwhile, because the contract reflects the result rather than producing it.

Frequently asked questions

Is consent sufficient as a legal basis?

For treatment itself it is likely the weaker route. Art. 9(2)(h) GDPR permits processing for the purposes of care and treatment without any consent being needed. Consent can be withdrawn, and a withdrawal in the middle of treatment creates a problem that would not exist without it.

Does a processing agreement satisfy section 203 of the Criminal Code?

No. The contract under Art. 28(3) GDPR and the obligation to secrecy under section 203(4), second sentence, no. 1 of the Criminal Code are two different things with two different consequences. Where the obligation is missing and the provider discloses, the hospital is criminally liable alongside it.

Is the data protection officer personally bound by secrecy?

Yes, and on pain of criminal sanction. Section 203(4), first sentence, of the Criminal Code expressly names the data protection officer working for one of the persons listed in paragraphs 1 and 2. That applies to internal and external appointments alike.

May treatment data be reused for research?

Subject to conditions. Art. 9(2)(j) GDPR together with section 27 BDSG or with state law comes into consideration, as does the German health data use act. The research clauses in state law partly date from before the Regulation and have to be examined state by state.

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.