Obligations in Maintaining Medical Records
Current Legal Framework and Sanctions
Medical documentation must be maintained completely, verifiably, and securely, as errors in content, access, or electronic security can jeopardize both the patient and the provider's legal standing. The documentation also serves as key evidence in a dispute or audit. In this article, you will learn what the records must contain, who is permitted to access them, and how to set up electronic record-keeping and data protection.

Key takeaways
Need advice on this topic? Contact the ARROWS law firm by email at consultation@arws.cz or by phone at +420 245 007 740. Your query will be gladly answered by "Mgr. Dita Zbožínková, LL.M.", an expert on this topic.
Why is proper maintenance of medical records a strategic necessity, not just an administrative task?
Maintaining medical records is often seen as an administrative burden. However, this view is dangerously outdated. In today's legal environment, meticulously kept documentation becomes an active risk management tool and a key strategic asset that protects the financial stability and reputation of your facility. It's not just about fulfilling a legal obligation, but about building your primary line of defence.
Medical documentation, defined by Act No. 372/2011 Coll., on Health Services, as a set of information kept for the purpose of providing health services, is not only the foundation for ensuring continuity and quality of care. It also becomes a crucial piece of evidence in potential legal disputes with patients, during inspections by administrative authorities, or in proceedings for compensation for harm.
Judicial practice is uncompromising in this regard. Any ambiguity, incompleteness, or formal error in the documentation always works against the healthcare provider. Furthermore, a major legislative change will take effect on 1 January 2025 – the current Decree No. 98/2012 Coll. will be replaced by the new, significantly stricter Decree No. 444/2024 Coll.. Investing in systems and processes for proper documentation management is therefore no longer an expense, but an investment in the legal protection of your business.
New Legal Framework from 1 January 2025: What You Need to Know About Decree No. 444/2024 Coll.?
The new Decree No. 444/2024 Coll., effective from 1 January 2025, is not just a cosmetic change. It represents a comprehensive revision of the rules, responding to advancing digitalisation and clarifying many previously ambiguous areas. Relying on established practices is now extremely risky. Providers must conduct an in-depth review of their internal processes.
The new legislation specifies in detail the content requirements for records, the methods of their processing, the requirements for the so-called patient summary, the deadlines for making and authorising records, and, last but not least, the precise rules for the retention period and subsequent shredding of documentation.
The decree introduces or further specifies the obligation to keep records, for example, on suspicion of domestic violence or abuse, clarifies the documentation requirements when using restrictive measures, or sets a regular frequency for writing a summary report (epicrisis) for inpatient care. This detailed specification means that procedures previously considered sufficient may no longer meet the new requirements.
The new legislation brings dozens of changes that must be reflected in your daily practice. Our lawyers at ARROWS have already conducted a detailed analysis of Decree No. 444/2024 Coll. and are ready to prepare internal directives for you that will ensure 100% compliance with the new rules. For an immediate solution to your situation, write to us at consultation@arws.cz.
Content and Form: Are Your Records Compliant with the Law?
Even medically perfect care loses its legal backing if it is not properly and demonstrably documented. Formal requirements are not bureaucracy – they are the pillars of your legal certainty. Even the slightest formal error, such as a missing date or an illegible signature, can invalidate an entire record at a crucial moment and fatally weaken your position in court.
Key Requirements for Content and Form
According to the Act on Health Services, documentation must be kept in a demonstrable, truthful, legible, and understandable manner. Entries must be made without undue delay. Each record must be dated and identified (signed) by the person who made it. Corrections are made exclusively by a new entry in such a way that the original text remains legible, and the correction must also be dated and signed.
Documentation can be kept in paper, electronic, or combined form. However, the electronic form, in particular, requires robust technical measures, including security against unauthorised access, detailed logging of all access, and the use of a guaranteed electronic signature for the so-called authorisation of the record.
FAQ – Legal Tips on Formal Requirements
Must every record be signed?
Yes, every entry must be authorised – in paper form with a signature and date, in electronic form with a recognised electronic signature or another legal standard.How to correctly fix an error in the documentation?
Never overwrite, white-out, or cross out in a way that makes the original text illegible. Make a new, dated, and signed entry that clearly corrects the error, and leave the original text fully legible.
Ensuring the formal correctness of hundreds of records daily is operationally demanding. ARROWS can help you implement a systemic solution by preparing clear internal directives and practical training for your staff. Connect with us at consultation@arws.cz and get a tailor-made legal solution.
Electronic Documentation and GDPR: A Ticking Time Bomb on Your Server?
The transition to electronic medical records brings efficiency, but at the same time opens the door to new, highly serious risks. Patient health data belongs to the "special categories of personal data" under the GDPR and is subject to the strictest protection regime. A failure in this area can lead to crippling fines from the Office for Personal Data Protection (ÚOOÚ).
It is crucial to realise that the legal basis for processing data in medical records is not the patient's consent. The processing is carried out based on the fulfilment of a legal obligation imposed on providers by the Act on Health Services. Therefore, the patient cannot request the erasure of their data and exercise the so-called "right to be forgotten".
However, this legal obligation does not relieve you of the responsibility for data security. On the contrary. You must adopt demonstrable technical and organisational measures, such as encryption, access rights management, regular backups, and maintaining records of processing activities. In the event of any security incident, such as a cyber-attack, you are obliged to report it to the ÚOOÚ within 72 hours.
Risks and Sanctions | How ARROWS Helps |
Cyber-attack, encryption, or leakage of patient data. A fine from the ÚOOÚ in the range of hundreds of thousands to millions of CZK (see the case of Poliklinika IPP, fine of CZK 309,000). | Preparation of documentation that protects against fines. We will conduct a GDPR audit and help set up robust technical and organisational measures. Need legal assistance? Contact us at consultation@arws.cz. |
Failure to report a security incident to the ÚOOÚ within 72 hours. A separate fine for non-compliance with the notification obligation, even if no fine would be imposed for the attack itself. | Legal consultations that protect against fines. We will create a crisis plan for you in case of a security incident, including the procedure for timely reporting. Need advice? Write to consultation@arws.cz. |
Unauthorised access to data by employees. Loss of patient trust, lawsuits for protection of personal rights, fine from the ÚOOÚ. | Expert training for employees. We will train your staff on how to handle sensitive data securely and minimise the risk of human error. Want to arrange training? Connect with us at consultation@arws.cz. |
Insufficient contractual arrangements with IT system suppliers (processors). You, as the controller, are liable for the supplier's failures. | Preparation and review of contracts. We will review or prepare your data processing agreements with IT suppliers to ensure they fully comply with GDPR requirements. Need a contract review? Write to consultation@arws.cz. |
Access to Documentation: Who Can View It and When Must You Say "No"?
Managing access to medical records is a legal minefield. An error by an administrative worker in releasing a copy of the documentation can have consequences for the entire facility as devastating as an IT security failure. The weakest link in the system is often human, which is why clear internal procedures and regular training are absolutely essential.
The Act on Health Services (§ 65) precisely defines the circle of authorised persons. The primary right to view belongs to the patient, their legal representative, guardian, or a person demonstrably designated by the patient. Without the patient's consent, only persons explicitly listed in the law may view the documentation to the extent strictly necessary, such as healthcare professionals ensuring continuity of care, court-appointed experts, insurance company review doctors, or law enforcement authorities – who, however, usually require prior consent from a judge.
Before allowing any access, you are obliged to verify the identity of the requesting person. Furthermore, every viewing (with the exception of the attending staff in the course of providing care) must be carefully recorded directly in the patient's medical records. A breach of the duty of confidentiality is one of the most strictly punished offences, with a penalty of up to CZK 1,000,000.
International Element: Care for Foreigners and Data Sharing within the EU
The globalisation of healthcare is not just about patients travelling for care, but primarily about the cross-border flow of sensitive data. Any provider whose information system is or will soon be connected to the national digital infrastructure becomes an international player with international obligations. This requires legal advice that goes beyond knowledge of only Czech law.
When providing care to foreigners, for example, within occupational health services, it is necessary to correctly handle documentation from their foreign doctors, including ensuring officially certified translations. However, a much greater challenge is joining the European system for health data exchange, MyHealth@EU.
This system already allows Czech patients to pick up their ePrescriptions in countries like Poland, Croatia, and Spain, and vice versa. The basis is the sharing of the so-called patient summary – a structured extract of key information (allergies, diagnoses, surgeries) that provides a doctor in another EU country with a quick overview of the patient's health status. Although sharing is currently voluntary, from 2029, sharing the patient summary and ePrescription will be mandatory, and from 2031, laboratory results and discharge summaries will also be included.
Do you provide care to foreigners or are you preparing for full digitalisation? Thanks to our ARROWS International network, we handle cases with an international element daily. We will help you navigate the obligations of cross-border data sharing and ensure that your procedures comply with both Czech and EU law. Do not hesitate to contact our office – consultation@arws.cz.
When a Mistake Becomes Reality: Sanctions, Lawsuits, and a Damaged Reputation
The consequences of errors in maintaining medical records are threefold: high administrative fines, lost lawsuits, and irreparable damage to reputation. The biggest risk in court proceedings is the principle established by the case law of the Constitutional and Supreme Courts – the so-called reversal of the burden of proof.
This principle means that if a provider violates their duty to keep proper records (they are incomplete, illegible, or records are missing), and a patient claims to have suffered harm, the burden of proof shifts to the provider. In practice, this means that it is not the patient who must prove the doctor's error, but the doctor (or the healthcare facility) who must prove that they acted correctly. Without complete and flawless documentation, this is practically impossible.
In addition to this procedural risk, there are also direct financial penalties. For failing to keep documentation or handling it contrary to the law, an administrative authority (typically the regional authority) can impose a fine of up to CZK 500,000. The ÚOOÚ can then impose sanctions in the range of hundreds of thousands to millions of crowns for GDPR violations.
Risks and Sanctions | How ARROWS Helps |
Incomplete or illegible record of a procedure. In case of a dispute, the court will apply the principle of reversal of the burden of proof – you will have to prove that you did not make a mistake. | Representation in courts and before administrative authorities. We analyse your documentation and prepare a defence strategy that minimises the impact of formal shortcomings. Need representation in court? Write to consultation@arws.cz. |
Missing or defective informed consent. The procedure may be deemed unlawful, even if performed correctly from a medical standpoint. A claim for compensation arises. | Preparation and review of documentation. We will create model informed consent forms for you that will stand up in court and protect you from lawsuits. Want a review of your documentation? Contact us at consultation@arws.cz. |
Failure to keep or loss of documentation. A fine from the administrative authority of up to CZK 500,000 and a virtually certain loss in any related court case. | Legal opinions and crisis consulting. We will assess your situation and propose steps to minimise damages and sanctions. Need quick legal advice? Write to consultation@arws.cz. |
Violation of rules for retention and shredding. Fines from administrative authorities, risk of misuse of old data after the shredding period has expired. | Preparation of internal directives. We will prepare a shredding policy for you in accordance with the new decree and the Act on Archiving. Need to set up processes? Connect with us at consultation@arws.cz. |
Comprehensive Legal Protection from ARROWS: More Than Just Statutes
At ARROWS, we understand that your priority is to provide top-quality healthcare, not to study legal regulations. Our task is to create a legal framework for you so that you can fully concentrate on your professional activities. We are not just "firefighters" for problems; we are the architects of your legal certainty. We provide comprehensive 360° protection that includes both proactive prevention and effective defence.
Our key services in this area include preparing internal directives in accordance with the new legislation, reviewing contracts with IT suppliers, conducting GDPR audits, and providing expert training for your management and staff. In case of trouble, we provide representation in courts and before administrative authorities, such as regional authorities or the ÚOOÚ, and we deliver fast and understandable legal opinions for your crisis decision-making.
Our experience is proven by long-term cooperation with more than 150 joint-stock companies, 250 limited liability companies, and 51 municipalities and regions. We pride ourselves on speed, high quality, and a business-oriented approach. For our clients, we are not only legal advisors but also partners whom we are happy to connect for interesting business or investment opportunities.
Don't want to handle this problem alone? The ARROWS law firm is trusted by more than 2,000 clients and we have been awarded Law Firm of the Year 2024. See HERE our references, and it will be our honour to help you solve your problem. The inquiry is free of charge.
About the author
Disclaimer:
Disclaimer: The information contained in this article is for general informational purposes only and serves as a basic guide to the subject matter. While we strive for maximum accuracy, please be aware that legal regulations and their interpretation evolve over time under Czech legislation. To verify the current status of regulations and their application to your specific situation, it is therefore essential to contact the Prague-based ARROWS law firm directly at (consultation@arws.cz). We assume no liability for any damages or complications arising from the use of information from this article without our prior individual legal consultation and professional assessment. Each case requires a tailored solution, so please do not hesitate to contact us.

