Access to Medical Records
A Guide for Providers
Access to medical records is strictly regulated, so healthcare providers must verify both the identity and legal entitlement of anyone requesting access. Patients may inspect their own records and receive the first extract or copy free of charge, while other persons may access them only under statutory conditions. The article explains access rights, deadlines, police requests and the risks of unauthorised disclosure.

Key takeaways
Legal framework for access to documentation
The rules for access are primarily set out in Sections 65 and 66 of the Health Services Act. Furthermore, the duty of confidentiality under Section 68 and the GDPR regulation (Act No. 110/2019 Coll.) must be respected. The healthcare provider is obliged to secure the documentation against unauthorised access – the law explicitly requires measures to be taken so that unauthorised or accidental access to personal data cannot occur. A breach of confidentiality or unauthorised disclosure of data results not only in disciplinary consequences but also in criminal liability.
Who has the right to inspect documentation
The law distinguishes between several categories of persons who may—under precisely defined conditions—inspect a patient's medical records or make extracts from them:
The patient themselves – can view their own documentation at any time, but always in the presence of a facility employee and with regard to the record being kept. The patient has the right to inspect their documentation and to make an extract or copy of it free of charge for the first request.
Legal representative/guardian – for example, the parent of a minor patient or a court-appointed guardian of an adult. They also have the right to inspect and obtain extracts just like the patient. The patient's consent is not required for this.
Persons designated by the patient, legal representative, or guardian (power of attorney) – the patient (or their representative/guardian) can name, for example, a family member or legal representative in the medical records. Such designated persons have the same rights to inspection and copies as the patient.
Persons close to the deceased patient – family members or other persons close to the deceased may inspect the documentation, but only to the extent specified in Section 33 of the Act (they have the right to information about the health status of the deceased patient and information about the results of an autopsy, if performed, including the right to inspect the medical records kept about them or other records relating to their health status and to make extracts from them). If the patient, during their lifetime, expressly forbade the disclosure of data to certain close persons, this prohibition also applies after death (information can be provided to these persons only if it is in the interest of protecting their health or the health of another person, and only to the necessary extent.
Attending medical staff – doctors, nurses, physiotherapists, etc., who are involved in the patient's care, have the right (and duty) to inspect the patient's documentation without their consent. This is necessary to ensure high-quality and safe care. In practice, this means that any doctor or nurse on the patient's team can read and write in the documentation.
Healthcare professionals in facilities – e.g., in laboratories, radiology, rehabilitation, etc., if they are providing a service to the patient, they may view the documentation (again, to the necessary extent and in the patient's interest).
Other authorised parties, especially state authorities and supervisory bodies – a number of persons authorised by these institutions may inspect the documentation without the patient's consent, to the extent necessary for the exercise of their powers:
persons involved in the exercise of the powers of administrative authorities – e.g., persons entrusted with handling a complaint at a regional authority
Reviewing physicians of health insurance companies – authorised persons of health insurance companies may inspect documentation to check the legitimacy of payment for a service. However, their rights are not unlimited – they see the documentation only to the extent necessary for the check (e.g., confirmation of diagnosis and procedures)
Assessing physicians and other health status assessors - healthcare professionals who assess health status for social security purposes (e.g., sickness benefits, pensions, unemployment benefits)
SÚKL (State Institute for Drug Control) - SÚKL employees authorised to carry out inspections
IHIS (Institute of Health Information and Statistics) - persons recording and checking data in the National Health Information System
Court experts – to the extent specified by law enforcement authorities or the court
Physicians of the State Office for Nuclear Safety
Public health protection authorities – hygiene physicians, epidemiological service in the investigation of infectious diseases.
persons qualified to practice a healthcare profession conducting quality and safety assessments under this Act and persons qualified to practice a healthcare profession conducting external clinical audits of medical radiation under the Specific Health Services Act,
The Public Defender of Rights (Ombudsman) – to ensure the protection of sensitive data of third parties,
inspectors authorised to carry out inspections related to the clinical evaluation of medicinal products for human use in accordance with EU regulations
EU Member States – doctors abroad – if a patient moves to care elsewhere in the EU and an electronic version of the "patient summary" exists, the new doctor can take it over unless the patient has expressed disagreement
International preventive bodies against torture
Archivists
Disciplinary bodies of professional chambers – authorised member of the Czech Medical Chamber (ČLK)
What about the Police of the Czech Republic?
According to the provisions of Section 8(5) of the Criminal Procedure Code, if a special law does not specify the conditions under which information that is classified under such a law, or to which a duty of confidentiality applies (Section 68 of the Health Services Act), can be disclosed for the purposes of criminal proceedings, such information may be requested for criminal proceedings with the prior consent of a judge.
If the Police of the Czech Republic requests medical documentation from you for the purposes of criminal proceedings, it can only be released with the written consent of the patient (whether the patient is the victim or a suspect in a criminal offence) or with the consent of a judge.
Suspicion of abuse:
A healthcare provider may restrict access to the medical records (refuse to disclose information about the health status) of a minor patient to their legal representative, foster parent, or other caregiver if there is a reasonable suspicion that this person is involved in their abuse, mistreatment, or otherwise endangering their healthy development. Such withholding of information is possible if providing it could further endanger the patient. The same procedure applies to patients with limited legal capacity.
How to inspect and make extracts
Inspection of documentation always takes place in the presence of an authorised employee of the facility. The patient or other authorised person may not take the documentation away – they can only read it on-site and, if necessary, have an extract or copy made. The procedure usually includes:
Request: The patient or other authorised person submits a written request for inspection or a copy (often there is a specific form). They must state whose documentation and what scope is being requested.
Identity verification: The provider verifies the applicant's identity (with an ID card) and their authorisation (power of attorney, child's birth certificate, court decision, etc.). For persons from authorities or insurance companies, an official ID or authorisation is required.
Setting a deadline: Within 15 or 30 days of submitting the request (depending on the type of applicant), the provider must comply with the request. The patient themselves (and persons under Section 65(1)) will usually receive the extract within 30 days, while authorities and external entities have 15 days. A different deadline may be set by mutual agreement.
Option for electronic access: If the documentation is in electronic form, the patient can request remote access or a record on a data carrier. If technology allows, a digital copy can be provided (unless a paper document is explicitly required).
If it is not possible to arrange an in-person inspection (e.g., the patient cannot come to the facility), the provider may send a copy of the documentation. In such a case, the law sets a deadline of 5 days from the time the patient/directive announced that inspection cannot be arranged. Again, you can agree on a different deadline; we recommend a written agreement. The copy is sent via the requested medium (e-mail, CD/DVD, regular mail).
Deadlines and fees
The law guarantees the patient and other persons under Section 65(1) of the Health Services Act that the first preparation of an extract/copy is free of charge. The provider therefore cannot charge any fee for a one-time preparation of the documentation (payment for postage or packaging still applies if it is being sent).
Repeated requests can be charged for – up to the amount of the actual costs incurred for printing and sending. But beware, the provider cannot condition the provision of an extract or copy of the medical records on prior payment – you must release the copy and only then request payment.
Persons under Section 65(1)(b) and (c) of the Health Services Act (e.g., legal representative, guardian) can also make the first extract free of charge. For a repeated request, the same applies as for the patient.
Organisational measures: The patient must follow the instructions of the healthcare professional (to avoid endangering the care of another patient or breaching confidentiality). A record of who inspected the documentation and when is always made in the records.
Common mistakes and risks of unauthorised access
In practice, situations arise where an employee or person in good faith "just wants to quickly check" a patient's medical record. However, the law does not permit this without meeting the conditions. Unauthorised access is a breach of the duty of confidentiality and can have serious consequences:
Criminal penalty: The Criminal Code (Section 180) defines the criminal offence of unauthorised handling of personal data, in cases where it causes serious harm to the rights of the person to whom the documentation relates. If no serious harm is caused, it is an administrative offence.
Administrative sanctions: The Office for Personal Data Protection (ÚOOÚ) can impose a fine in the order of hundreds of thousands to millions of crowns for insufficient protection of sensitive data.
Professional liability: A healthcare professional who breaches confidentiality commits a disciplinary offence for which a disciplinary measure may be imposed.
Lawsuits and compensation: The patient or their survivors may claim damages for the leakage of personal and health data – this is a violation of personal rights.
Loss of trust: A patient whose data has "gotten out" may lose trust in the doctor and the facility. In healthcare, trust is key to successful treatment.
Example from case law: In one case, an employee illegally viewed patients' electronic documentation without reason. The ÚOOÚ criticised the facility for a lack of access control, and one of the patients even faced a penalty for breach of confidentiality. This situation led to a high fine and a crucial lesson for the entire team.
Summary and recommendations
Follow procedures: Handle every inspection or copy of medical records according to the law and internal regulations. Always ask for the applicant's identity and authorisation.
Be a guardian of privacy: Realise that the documentation is the patient's privacy. Do not allow access to unauthorised persons, even if they "just come for the results" without a proper request.
Educate yourself: Study the provisions of Sections 65-66 of the Health Services Act and the obligations regarding personal data protection precisely. Adhere to internal guidelines.
Follow clear requirements: In some cases (administrative or criminal offences), special authorisation or a formal request is required. Never copy documentation just on "common sense" – follow the documented procedure.
Be careful when sharing information: Even sharing information about patients (e.g., between nurses and social workers) must be kept to the minimum necessary under the law.
In conclusion
Respecting the rights to inspect documentation is not bureaucracy for bureaucracy's sake (although it may sometimes seem so) – it is a fundamental ethical and legal rule for the protection of patients and yourselves. Medical documentation is a sensitive legal and ethical topic – and any mistake can have serious consequences. If you are unsure who exactly has access to documentation in your facility, how to correctly handle requests, or how to set up internal guidelines, do not hesitate to contact us.
Our Prague-based law firm has extensive experience in healthcare law – we can help you not only resolve a specific situation but also prevent unnecessary risks and sanctions. Because in law, just as in medicine, the rule is: prevention is always better than cure.
About the author
Read also:
- Managing Medical Device Supplier Contracts: Key Risks Under Czech Law
- Czech Healthcare Providers in 2026: NIS2, Digitalisation and Compliance
- Compliance in Healthcare Procurement in the Czech Republic: How to Avoid Criminal Liability
- Digital Inspections and AI in 2026: New EU Compliance Duties for Firms
- Preparing for Labour Inspections in the Czech Republic: Training and Fines
- Handling Negative Online Reviews Under Czech and EU Law: Compliance Guide
- ARROWS helped the client pass the SÚKL inspection
- Representing a disinfectant manufacturer in a dispute with a health authority regarding the suspension of operations and extensive reconstruction
- GDPR
Disclaimer:
The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.

