Czech healthcare 2026
Recommendations for Facility Management
The era of gradual and voluntary digital innovation is definitively ending. From January 1, 2026, an amendment to Act No. 325/2021 Coll., on the Digitalization of Healthcare, enters into full nationwide effect in the Czech Republic. This step marks the end of fragmented and individual IT solutions. It introduces centrally defined rules, standards, and security protocols to which all healthcare service providers must adapt without exception.

Key takeaways
Digital Transformation Is an Obligation, Not a Choice: What Does the Act on the Electronization of Healthcare Bring?
This change is not just a technological upgrade, but primarily a new legal framework that brings new obligations and high risks for non-compliance. Preparing for this digital obligation is crucial for management to ensure the smooth operation and legal protection of the facility after 2026. If you need to analyze the impacts of these changes on your organization, our Prague-based lawyers are ready to help.
From ePrescriptions for Medical Devices to eReferrals: What New Processes Must You Implement?
The amendment to the act introduces several key digital tools that will become a daily part of your practice. Their implementation requires not only technical readiness but also adjustments to internal processes and staff training.
ePrescriptions for Medical Devices (ePoukaz): From 1 January 2026, it will be mandatory to issue prescriptions for medical devices (glasses, wheelchairs, incontinence aids, etc.) exclusively in electronic form. The paper form will be discontinued, except for statutory exceptions. This means your facility must have functional access to the eRecept system and apply for access credentials in time for all relevant staff, including non-medical professions such as opticians or dispensary workers.
eReferrals (eŽádanka): Paper-based requests for laboratory, imaging, or specialized examinations will be replaced by an electronic system. The doctor will issue an eReferral, the patient will receive a unique identifier, and the target facility will download the referral electronically. Although the patient can request a paper copy, the primary process must be digital.
Shared Health Record: This is one of the most fundamental elements of the entire reform. This central record will be divided into two parts: an emergency record (vital data such as blood type, allergies, key medication) and a record of the results of preventive and screening examinations. Your facility will be obliged to contribute to this system and also to draw information from it, which fundamentally changes the rules for sharing medical documentation.
Cybersecurity under NIS2: Does Company Management Face Personal Liability?
In parallel with electronization, the new European NIS2 directive is also coming into force, implemented into the new Act on Cybersecurity. This dramatically expands the range of regulated entities in the healthcare sector and significantly tightens the requirements for protecting networks and information systems. It is no longer just about the IT department – NIS2 introduces direct and personal liability for statutory bodies and top management for ensuring cybersecurity.
New obligations include conducting regular risk analyses, implementing robust security measures, mandatory incident reporting, and, above all, securing the entire supply chain. This means you will have to legally and technically verify the security standards of your suppliers of IT systems and medical devices. The lawyers at ARROWS specialize in preparing supplier contracts and internal directives that reflect the requirements of NIS2. For an immediate solution to your situation, write to us at consultation@arws.cz.
The penalties for non-compliance are unprecedented. Fines of up to EUR 10 million or 2% of the total worldwide annual turnover are threatened, and in extreme cases, a ban on holding office for the responsible members of management. Management is thus under dual pressure: they must invest considerable resources in technology and processes, and at the same time, they are personally liable for their functionality.
Risks and Penalties | How ARROWS Helps (consultation@arws.cz) |
A fine of up to EUR 10 million (or 2% of turnover) and personal liability of management for non-compliance with NIS2 requirements. | Preparation of complete documentation and internal directives for compliance with NIS2 – do you need to protect company management? |
Financial penalties for GDPR breaches when sharing data within the new eHealth systems (e.g., Shared Health Record). | Legal audit (DPIA) and review of data handling processes to comply with both GDPR and the Act on Electronization. |
Operational collapse and reputational damage due to a cyberattack (the average cost of a data breach in healthcare is USD 7.42 million). | Expert training for employees and management focused on cybersecurity and legal obligations. |
Contractual disputes with suppliers of IT systems or medical devices who do not meet the new security standards. | Preparation and review of supplier contracts with an emphasis on cybersecurity guarantees and liability. |
Financial Shocks in 2026: How to Prepare for the New Reimbursement Decree and Reorganization of Care?
In addition to the technological revolution, healthcare facilities in 2026 also face a fundamental reset of financial flows. The draft of the new reimbursement decree and the reorganization of emergency care present serious strategic challenges for management, which can directly threaten the economic stability and operational capabilities of your organization.
"Destructive" Reimbursement Decree: What Is the Real Threat to Your Budget?
Professional unions and hospital associations are calling the draft reimbursement decree for 2026 "destructive." The reason is the planned changes intended to save the system approximately CZK 2 billion, but at the expense of providers. It is crucial for management to understand the specific impacts of these changes and proactively prepare for them.
Among the riskiest measures is the reduction of the basic CZ-DRG rate, which means less money for standard hospitalizations. A major threat is also the financial pressure on short-term hospitalizations, where some procedures will only be reimbursed as one-day surgery, regardless of the patient's actual health condition. This could have a fatal impact on the financing of care for polymorbid and chronic patients requiring longer postoperative care.
Furthermore, the introduction of price competitions, for example in orthopedics, brings the risk that the main criterion for reimbursement will become price, not the quality of care. These changes come at a time when many facilities are still coping with insufficient cost coverage from previous years. ARROWS provides legal analyses of the impacts of the reimbursement decree and represents clients in negotiations with health insurance companies.
Reorganization of Emergency Services and New Contracts with Insurance Companies: What to Watch Out For?
From 1 January 2026, a fundamental systemic change will occur: the responsibility for ensuring the network and availability of emergency services will shift from the regions directly to health insurance companies. For providers, especially hospitals with emergency departments and pediatric beds, this means the need to negotiate entirely new contractual relationships and define the scope of services provided.
Emergency care will be newly divided into four segments (for adults, for children, dental, and pharmacy) and financed by a combined capitation-fee-for-service reimbursement model. The exact parameters will be set by the reimbursement decree, but the contractual terms you negotiate with the insurance companies will be key. A passive approach and acceptance of standard proposals can lead to unfavorable terms and insufficient cost coverage.
In this new situation, legal support becomes a strategic tool for defending financial stability. It is no longer just about a formal review of contracts, but about active negotiation, preparation for administrative proceedings, and protection of your economic interests. Our Prague-based lawyers are ready to represent you in these key negotiations. Connect with us and get a tailor-made legal solution.
Risks and Penalties | How ARROWS Helps (consultation@arws.cz) |
Significant drop in revenue due to reduced reimbursements for hospitalizations and the introduction of price competitions. | Legal analysis of the impacts of the reimbursement decree and preparation of documents for negotiations with health insurance companies. |
Unfavorable contractual terms with insurance companies for providing emergency services, leading to unreimbursed costs. | Representation in negotiating contracts with health insurance companies and review of contract amendments. |
Penalties for incorrect reporting of care under the new, more complex rules for reimbursements and preventive programs. | Legal opinions and expert training for management and the care reporting department. |
Risk of reimbursement denial for care provided beyond one-day surgery for high-risk patients. | Representation in administrative proceedings with health insurance companies in disputes over reimbursement for provided care. |
A New Era of Patient Rights and Provider Obligations
The legislative changes for 2026 do not only concern technology and finance, but also touch the very core of the relationship between doctor and patient. New obligations in the area of prevention and payment transparency require adjustments to daily processes, precise documentation, and increase the legal risks associated with the human factor.
Expanded Preventive Check-ups: How to Adjust Documentation and Reporting?
The amendment to the Decree on Preventive Check-ups (No. 70/2012 Coll.) significantly expands their content from 1 January 2026. Doctors will now perform ECG examinations from the age of 30, more frequently take blood for cholesterol tests, and regular liver and kidney tests, as well as screening for the risk of heart failure, are being introduced. Emphasis is also placed on mental health in the family history and the creation of an individual treatment and prevention plan for each patient.
For providers, this entails a crucial task: to adjust internal procedures and medical documentation systems so that all these new procedures are properly recorded and reported. Particularly important is the new active duty of the doctor to verify the patient's participation in oncological screening programs (mammography, colonoscopy, etc.). If the patient refuses the examination, the doctor must demonstrably inform them of the risks and carefully record this instruction.
This change increases the administrative burden, but above all, it creates a new field for potential disputes. Insufficient documentation can lead not only to problems with reimbursement from the insurance company but, in extreme cases, to liability disputes. ARROWS will help you prepare internal directives and template forms that ensure legal certainty.
Ban on Hidden Fees and Mandatory Price Lists: How to Avoid Million-Crown Fines?
Another significant change is the amendment to the Act on Health Services, which from 2026 explicitly prohibits the collection of any fees for services fully covered by public health insurance. This also applies to previously tolerated practices such as registration fees, fees for scheduling an appointment at a specific time, or sponsorship donations conditional on admission to care.
At the same time, the law introduces an obligation to have a visibly displayed, transparent, and binding price list for all above-standard and non-reimbursed services. If the patient is not informed of the price in advance and does not agree to it, the provider has no legal right to demand payment. The penalties for violating these rules are strict: an unauthorized fee can result in a fine of up to CZK 1 million, while formal errors in the price list can lead to a fine of up to CZK 50,000.
Successfully managing these changes does not just lie in the technical setup of systems, but primarily in working with people. It is the human factor – overworked and inadequately trained staff – that is the most common source of errors that can lead to high penalties. Therefore, it is essential to invest in high-quality internal regulations and certified training that minimize the risk of error.
International Dimension: European Health Data Space (EHDS) and AI in Healthcare
The legislative changes of 2026 do not have only a local impact. They are part of a broader European trend towards creating a single digital market in healthcare. For the management of Czech facilities, it is crucial to understand the two main pillars of this transformation: the European Health Data Space (EHDS) and the regulation of artificial intelligence (AI). The EHDS is at the beginning of its journey, and by 2027, the Commission must adopt important implementing acts so that the EHDS, and its key parts, can fully enter into force in 2029.
Data Sharing within the EU: What Does the European Health Data Space (EHDS) Bring?
EHDS is an ambitious project of the European Union aimed at creating a single space for the secure sharing of health data. It has two main levels: primary use, which is intended to facilitate the provision of healthcare to EU citizens across borders, and secondary use, which is intended to open up anonymized and pseudonymized data for the purposes of science, research, innovation, and healthcare policymaking.
For Czech hospitals and clinics, this means they become "data holders" with a new obligation. They will have to make data accessible upon request and under strictly defined conditions through newly established national access points. This brings enormous opportunities for involvement in international research projects, but at the same time, new legal risks, especially in the area of protecting intellectual property and trade secrets contained in your datasets.
Artificial Intelligence (AI) as a Medical Device: Who Bears Responsibility for an Algorithm's Error?
The use of artificial intelligence in medicine, for example, for diagnosis from imaging examinations or predicting disease progression, is no longer science fiction. However, the legal framework for these technologies is rapidly tightening. Software using AI is regulated as a medical device (under the MDR regulation) and, at the same time, if classified as "high-risk," it falls under a new, very strict European regulation – the AI Act.
The key question for any facility deploying AI is liability for damages in the event of a faulty algorithm decision. The legal reality is complex, and liability is shared: the AI manufacturer is liable for a product defect, the hospital as the user is liable for correct deployment and ensuring human oversight, and finally, the doctor bears professional responsibility for the final clinical decision, as they must not blindly accept AI outputs. ARROWS specializes in preparing contracts with AI suppliers and setting up internal processes that clearly define this complex liability and minimize your risks.
By providing their data for training AI models, hospitals are changing their role from a mere "data controller" (under GDPR) to a "data curator." This brings new responsibility not only for data protection but also for its quality and relevance. Providing poor-quality data that leads to faulty AI performance can establish the hospital's co-liability for the resulting damage.
Do You Provide Care with an International Element? Rely on the ARROWS International Network
The complexity of regulations like EHDS, the AI Act, and GDPR in the context of cross-border care requires deep knowledge not only of Czech but also of European law. This is where the unique strength of our firm becomes apparent. Thanks to our ten-year-built ARROWS International network, we handle cases with an international element almost daily and can ensure legal certainty across EU jurisdictions.
Risks and Penalties | How ARROWS Helps (consultation@arws.cz) |
Loss of trade secrets or intellectual property when providing data for research within EHDS. | Preparation of Data Sharing Agreements and license agreements that protect your intellectual property. |
Co-liability for damage caused to a patient by a faulty AI system decision. | Legal analysis and setup of contracts with AI suppliers that clearly define liability relationships. |
Fines for violating the EU AI Act for high-risk systems (up to EUR 35 million or 7% of turnover). | Creation of internal directives and processes for the safe and legal deployment of AI in clinical practice. |
Legal uncertainty when providing care to foreign patients and sharing their data across borders within EHDS. | Legal advice using the ARROWS International network to ensure compliance with the legislation of multiple EU states. |
How ARROWS Turns Legislative Threats into Your Competitive Advantage
The year 2026 brings a whirlwind of legislative changes that affect all areas of a healthcare facility's operation – from IT and finance to daily patient care and strategic planning. Mastering this transformation requires an integrated legal approach that connects technical law, finance, labor law, and intellectual property protection.
At ARROWS, we understand that it's not just about legal clauses. Thanks to our many years of experience and a portfolio that includes more than 150 joint-stock companies, 250 limited liability companies, and dozens of municipalities and regions, we also understand the business and operational reality of our clients. Our job is not just to point out risks, but to provide practical solutions that protect your organization and enable it to grow.
For our clients in the healthcare sector, we provide comprehensive legal services covering all the key challenges of 2026:
Drafting internal directives that ensure compliance with NIS2, GDPR, the AI Act, and the new rules for price lists and informed consent.
Preparation and review of contracts with suppliers of IT and medical technology, health insurance companies, AI developers, and research partners.
Expert training for employees and management, which is key to managing the human factor, minimizing errors, and demonstrating due diligence in the event of an inspection or dispute.
Representation in courts and administrative bodies in disputes over reimbursements, during inspections by authorities, or in cases of liability for damages.
We pride ourselves on speed, high quality, and added value. We actively connect our clients when we see interesting business or investment opportunities, and we are always open to discussing new business ideas.
Your Strategic Partner for Certainty in 2026
The legislative changes in 2026 are inevitable, complex, and ignoring them is not an option. For the unprepared, they represent a serious threat; for the prepared, they are an opportunity to gain an edge. Properly set up processes, watertight contracts, and trained staff will not only save you millions in fines but also streamline operations and strengthen your market position.
Don't wait for problems to arise. Gain a strategic advantage and legal certainty today. Arrange a no-obligation consultation and let's discuss how we can prepare your facility for a successful entry into 2026.
About the author
Read also:
- AI in a Game Studio: A Checklist for Contracts, Licensing, Data, and Liability
- Using Artificial Intelligence in Software and App Development – Legal Questions
- Cybersecurity and Drone Hijacking Threats
- GDPR inspections in practice: how investigations by the Office for Personal Data Protection are conducted
- Compliance audits: How to conduct an internal audit before the authorities arrive
Disclaimer:
The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.

