Skip to content

Access to Medical Records

A Guide for Providers

Access to medical records is strictly regulated, so healthcare providers must verify both the identity and legal entitlement of anyone requesting access. Patients may inspect their own records and receive the first extract or copy free of charge, while other persons may access them only under statutory conditions. The article explains access rights, deadlines, police requests and the risks of unauthorised disclosure.

Provider reviewing medical records guide at a desk, holding a coffee cup.

Key takeaways

Access to your medical records is strictly regulated. The rules are set forth in Sections 65 and 66 of the Act on Health Services and by the GDPR (Act No. 110/2019 Coll.), with the provider being obliged to secure the data. A breach of confidentiality may lead to disciplinary as well as criminal liability.
As a patient, you have the right to inspect your records at any time. You may always view your own records in the presence of a facility employee, and you will receive the first extract or copy free of charge.
A legal representative or guardian has the same rights as the patient. For example, a parent of a minor patient or a court-appointed guardian of an adult may inspect the records and make extracts without the patient's consent.
You may designate persons who will have access to your records. The patient or their representative may appoint a family member or legal counsel in the medical records, who will then have the same rights to inspection and copies as you do.

DO YOU NEED ASSISTANCE WITH YOUR RIGHTS CONCERNING MEDICAL RECORDS?

Do not hesitate to contact us. We will be pleased to assist you with your case.

ARROWS law firm

Legal framework for access to documentation

The rules for access are primarily set out in Sections 65 and 66 of the Health Services Act. Furthermore, the duty of confidentiality under Section 68 and the GDPR regulation (Act No. 110/2019 Coll.) must be respected. The healthcare provider is obliged to secure the documentation against unauthorised access – the law explicitly requires measures to be taken so that unauthorised or accidental access to personal data cannot occur. A breach of confidentiality or unauthorised disclosure of data results not only in disciplinary consequences but also in criminal liability.

Who has the right to inspect documentation

The law distinguishes between several categories of persons who may—under precisely defined conditions—inspect a patient's medical records or make extracts from them:

  • The patient themselves – can view their own documentation at any time, but always in the presence of a facility employee and with regard to the record being kept. The patient has the right to inspect their documentation and to make an extract or copy of it free of charge for the first request.

  • Legal representative/guardian – for example, the parent of a minor patient or a court-appointed guardian of an adult. They also have the right to inspect and obtain extracts just like the patient. The patient's consent is not required for this.

  • Persons designated by the patient, legal representative, or guardian (power of attorney) – the patient (or their representative/guardian) can name, for example, a family member or legal representative in the medical records. Such designated persons have the same rights to inspection and copies as the patient.

  • Persons close to the deceased patient – family members or other persons close to the deceased may inspect the documentation, but only to the extent specified in Section 33 of the Act (they have the right to information about the health status of the deceased patient and information about the results of an autopsy, if performed, including the right to inspect the medical records kept about them or other records relating to their health status and to make extracts from them). If the patient, during their lifetime, expressly forbade the disclosure of data to certain close persons, this prohibition also applies after death (information can be provided to these persons only if it is in the interest of protecting their health or the health of another person, and only to the necessary extent.

  • Attending medical staff – doctors, nurses, physiotherapists, etc., who are involved in the patient's care, have the right (and duty) to inspect the patient's documentation without their consent. This is necessary to ensure high-quality and safe care. In practice, this means that any doctor or nurse on the patient's team can read and write in the documentation.

  • Healthcare professionals in facilities – e.g., in laboratories, radiology, rehabilitation, etc., if they are providing a service to the patient, they may view the documentation (again, to the necessary extent and in the patient's interest).

Other authorised parties, especially state authorities and supervisory bodies – a number of persons authorised by these institutions may inspect the documentation without the patient's consent, to the extent necessary for the exercise of their powers:

  • persons involved in the exercise of the powers of administrative authorities – e.g., persons entrusted with handling a complaint at a regional authority

  • Reviewing physicians of health insurance companies – authorised persons of health insurance companies may inspect documentation to check the legitimacy of payment for a service. However, their rights are not unlimited – they see the documentation only to the extent necessary for the check (e.g., confirmation of diagnosis and procedures)

  • Assessing physicians and other health status assessors - healthcare professionals who assess health status for social security purposes (e.g., sickness benefits, pensions, unemployment benefits)

  • SÚKL (State Institute for Drug Control) - SÚKL employees authorised to carry out inspections

  • IHIS (Institute of Health Information and Statistics) - persons recording and checking data in the National Health Information System

  • Court experts – to the extent specified by law enforcement authorities or the court

  • Physicians of the State Office for Nuclear Safety

  • Public health protection authorities – hygiene physicians, epidemiological service in the investigation of infectious diseases.

  • persons qualified to practice a healthcare profession conducting quality and safety assessments under this Act and persons qualified to practice a healthcare profession conducting external clinical audits of medical radiation under the Specific Health Services Act,

  • The Public Defender of Rights (Ombudsman) – to ensure the protection of sensitive data of third parties,

  • inspectors authorised to carry out inspections related to the clinical evaluation of medicinal products for human use in accordance with EU regulations

  • EU Member States – doctors abroad – if a patient moves to care elsewhere in the EU and an electronic version of the "patient summary" exists, the new doctor can take it over unless the patient has expressed disagreement

  • International preventive bodies against torture

  • Archivists

  • Disciplinary bodies of professional chambers – authorised member of the Czech Medical Chamber (ČLK)

DO YOU NEED LEGAL HELP?

Get in touch — we're happy to help.

ARROWS law firm

What about the Police of the Czech Republic?

According to the provisions of Section 8(5) of the Criminal Procedure Code, if a special law does not specify the conditions under which information that is classified under such a law, or to which a duty of confidentiality applies (Section 68 of the Health Services Act), can be disclosed for the purposes of criminal proceedings, such information may be requested for criminal proceedings with the prior consent of a judge.

If the Police of the Czech Republic requests medical documentation from you for the purposes of criminal proceedings, it can only be released with the written consent of the patient (whether the patient is the victim or a suspect in a criminal offence) or with the consent of a judge.

Suspicion of abuse:

A healthcare provider may restrict access to the medical records (refuse to disclose information about the health status) of a minor patient to their legal representative, foster parent, or other caregiver if there is a reasonable suspicion that this person is involved in their abuse, mistreatment, or otherwise endangering their healthy development. Such withholding of information is possible if providing it could further endanger the patient. The same procedure applies to patients with limited legal capacity.

Frequently asked questions about the Police of the Czech Republic, exceptions, and fees for documentation

1. Must a healthcare facility release medical records to the Police of the Czech Republic upon request?

  • Only with the written consent of the patient or with the prior consent of a judge under Section 8(5) of the Criminal Procedure Code. A standard police request without the consent of a judge or patient is not sufficient to breach the statutory duty of confidentiality.

2. Can a doctor refuse to show documentation to the parent of a minor child?

  • Yes. If the doctor has a reasonable suspicion that the parent is involved in the abuse, mistreatment, or otherwise endangering the child's development, and providing the information could further endanger the child, they have the right to refuse access to the documentation.

3. Can the release of a copy of medical records be conditioned on prior payment?

  1. No. The first preparation of an extract or copy is completely free of charge for the patient and their legal representatives by law. For repeated requests, only the actual costs incurred can be charged, but the release of the documentation cannot be conditioned on prior payment.

ARROWS law firm

Our specialists will help you

Mgr. MUDr. Veronika Králíková, Ph.D.

Mgr. MUDr. Veronika Králíková, Ph.D.

Counsel

kralikova@arws.cz
Mgr. Dita Zbožínková, LL.M.

Mgr. Dita Zbožínková, LL.M.

advokátka

zbozinkova@arws.cz
ARROWS law firm

How to inspect and make extracts

Inspection of documentation always takes place in the presence of an authorised employee of the facility. The patient or other authorised person may not take the documentation away – they can only read it on-site and, if necessary, have an extract or copy made. The procedure usually includes:

  • Request: The patient or other authorised person submits a written request for inspection or a copy (often there is a specific form). They must state whose documentation and what scope is being requested.

  • Identity verification: The provider verifies the applicant's identity (with an ID card) and their authorisation (power of attorney, child's birth certificate, court decision, etc.). For persons from authorities or insurance companies, an official ID or authorisation is required.

  • Setting a deadline: Within 15 or 30 days of submitting the request (depending on the type of applicant), the provider must comply with the request. The patient themselves (and persons under Section 65(1)) will usually receive the extract within 30 days, while authorities and external entities have 15 days. A different deadline may be set by mutual agreement.

  • Option for electronic access: If the documentation is in electronic form, the patient can request remote access or a record on a data carrier. If technology allows, a digital copy can be provided (unless a paper document is explicitly required).

If it is not possible to arrange an in-person inspection (e.g., the patient cannot come to the facility), the provider may send a copy of the documentation. In such a case, the law sets a deadline of 5 days from the time the patient/directive announced that inspection cannot be arranged. Again, you can agree on a different deadline; we recommend a written agreement. The copy is sent via the requested medium (e-mail, CD/DVD, regular mail).

Deadlines and fees

  • The law guarantees the patient and other persons under Section 65(1) of the Health Services Act that the first preparation of an extract/copy is free of charge. The provider therefore cannot charge any fee for a one-time preparation of the documentation (payment for postage or packaging still applies if it is being sent).

  • Repeated requests can be charged for – up to the amount of the actual costs incurred for printing and sending. But beware, the provider cannot condition the provision of an extract or copy of the medical records on prior payment – you must release the copy and only then request payment.

  • Persons under Section 65(1)(b) and (c) of the Health Services Act (e.g., legal representative, guardian) can also make the first extract free of charge. For a repeated request, the same applies as for the patient.

  • Organisational measures: The patient must follow the instructions of the healthcare professional (to avoid endangering the care of another patient or breaching confidentiality). A record of who inspected the documentation and when is always made in the records.

Common mistakes and risks of unauthorised access

In practice, situations arise where an employee or person in good faith "just wants to quickly check" a patient's medical record. However, the law does not permit this without meeting the conditions. Unauthorised access is a breach of the duty of confidentiality and can have serious consequences:

  • Criminal penalty: The Criminal Code (Section 180) defines the criminal offence of unauthorised handling of personal data, in cases where it causes serious harm to the rights of the person to whom the documentation relates. If no serious harm is caused, it is an administrative offence.

  • Administrative sanctions: The Office for Personal Data Protection (ÚOOÚ) can impose a fine in the order of hundreds of thousands to millions of crowns for insufficient protection of sensitive data.

  • Professional liability: A healthcare professional who breaches confidentiality commits a disciplinary offence for which a disciplinary measure may be imposed.

  • Lawsuits and compensation: The patient or their survivors may claim damages for the leakage of personal and health data – this is a violation of personal rights.

  • Loss of trust: A patient whose data has "gotten out" may lose trust in the doctor and the facility. In healthcare, trust is key to successful treatment.

Example from case law: In one case, an employee illegally viewed patients' electronic documentation without reason. The ÚOOÚ criticised the facility for a lack of access control, and one of the patients even faced a penalty for breach of confidentiality. This situation led to a high fine and a crucial lesson for the entire team.

Summary and recommendations

  • Follow procedures: Handle every inspection or copy of medical records according to the law and internal regulations. Always ask for the applicant's identity and authorisation.

  • Be a guardian of privacy: Realise that the documentation is the patient's privacy. Do not allow access to unauthorised persons, even if they "just come for the results" without a proper request.

  • Educate yourself: Study the provisions of Sections 65-66 of the Health Services Act and the obligations regarding personal data protection precisely. Adhere to internal guidelines.

  • Follow clear requirements: In some cases (administrative or criminal offences), special authorisation or a formal request is required. Never copy documentation just on "common sense" – follow the documented procedure.

  • Be careful when sharing information: Even sharing information about patients (e.g., between nurses and social workers) must be kept to the minimum necessary under the law.

In conclusion

Respecting the rights to inspect documentation is not bureaucracy for bureaucracy's sake (although it may sometimes seem so) – it is a fundamental ethical and legal rule for the protection of patients and yourselves.  Medical documentation is a sensitive legal and ethical topic – and any mistake can have serious consequences. If you are unsure who exactly has access to documentation in your facility, how to correctly handle requests, or how to set up internal guidelines, do not hesitate to contact us.

Our Prague-based law firm has extensive experience in healthcare law – we can help you not only resolve a specific situation but also prevent unnecessary risks and sanctions. Because in law, just as in medicine, the rule is: prevention is always better than cure.

Frequently asked questions about access to medical documentation

1. Who all has the right to inspect documentation even without the patient's consent?

  • Attending medical staff involved in care, and to the necessary extent, reviewing physicians of insurance companies, assessing physicians, public health authorities, SÚKL, IHIS, or court experts.

2. Do relatives have the right to see the medical records of a deceased patient?

  • Close persons have the right to information about the health status, autopsy results, and to inspect the documentation of the deceased, unless the patient expressly forbade this to a specific person during their lifetime.

3. What are the statutory deadlines for processing a request for an extract or copy of documentation?

  • The provider is obliged to comply with a request from the patient or their representative within 30 days. In cases where an in-person inspection cannot be arranged, they must send a copy within 5 days of announcing this fact. Authorities and external bodies have a deadline of 15 days.

4. Can a patient inspect the documentation by themselves and take the original?

  • Inspection always takes place in the presence of an authorised employee of the healthcare facility. The patient cannot take the original documentation home, but they have the full right to obtain an extract or a copy.

5. Can medical records be obtained in electronic form?

  • If the documentation is kept electronically and the facility's technical equipment allows it, the patient can request remote access or the issuance of a digital copy on a data carrier or by e-mail.

6. What penalties are there for unauthorised inspection of documentation?

A healthcare professional faces disciplinary action from their professional chamber, the facility faces high fines from the ÚOOÚ or lawsuits for damages. In the case of a serious infringement of rights, it constitutes the criminal offence of unauthorised handling of personal data.

DO YOU HAVE MORE QUESTIONS? GET IN TOUCH

ARROWS law firm

About the author

Mgr. Dita Zbožínková, LL.M.
Mgr. Dita Zbožínková, LL.M.

Associate

Dita Zbožínková is an attorney at ARROWS, specializing primarily in healthcare law. She provides comprehensive legal support to her clients—primarily doctors, healthcare facilities, and outpatient providers—in all phases of their activities.

Disclaimer:

The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.