Telemedicine and remote healthcare provision
current legislative requirements
Telemedicine means that you can provide healthcare remotely, which brings new opportunities and obligations for companies. You need to know how to use this service safely and legally without the risk of penalties. The article describes how to correctly implement remote care and what to watch out for.

Key takeaways
Telemedicine as a Legal Concept and the Current State of Legislation
You can only provide it in the field for which you are licensed. If you are licensed for internal medicine, you can provide some of your services remotely, but only if you meet the legal conditions and adhere to the *lege artis* standard of care. The specific technical requirements arise not only from the Act on Health Services but also from related regulations on cybersecurity and personal data protection.
The lawyers at ARROWS law firm regularly handle telemedicine projects as part of their specialization in Health Law. They know the specific challenges providers face when implementing these services and can save you months of work navigating the legislation. Need advice on this matter? Contact us at consultation@arws.cz.
Basic Technical Requirements for the Communication Channel
Every telemedicine service must meet the necessary technical standards to ensure data confidentiality and integrity. The first of these is securing the communication channel. Legislation and regulatory opinions require that communication between the provider and the patient be adequately protected. For video consultations or the transmission of sensitive data, it is essential to use solutions that support encryption (ideally end-to-end).
You must be able to reliably verify that you are communicating with your actual patient (e.g., using NIA, BankID) and not an unauthorized person. Recording a call requires the patient's consent to the capture of their personal expressions under the Civil Code. From a GDPR perspective, the patient must be transparently informed about the recording, and the recording becomes part of the medical documentation.
All these requirements are mandatory, and a breach of the duty to secure patients' personal data can lead to high penalties from the Office for Personal Data Protection (ÚOOÚ). In practice, it has been shown that common commercial platforms may not meet the requirements for protecting health data unless their enterprise versions are used.
Software as a Medical Device and Its Certification
One of the most frequently overlooked complexities of telemedicine is the fact that the software you use may qualify as a Medical Device Software (MDSW). This is governed by the European MDR (Medical Device Regulation 2017/745) and the Czech Act No. 375/2022 Coll., on Medical Devices. If the software assists with diagnosis, treatment, or monitoring, it falls under this strict regulation.
If the software is classified as a medical device, the manufacturer must ensure a conformity assessment, technical documentation, clinical evaluation, and a quality management system. Providers who use uncertified software for purposes requiring certification expose themselves to the risk of penalties, which can reach up to CZK 30 million.
Many application developers are unaware of this requirement and believe their application is merely a "wellness" tool. The Prague-based legal team at ARROWS law firm has already handled numerous such situations and can assist you with the legal qualification and classification. We will determine whether your software needs CE certification and how to proceed in compliance with the MDR.
Requirements for Personal Data Protection and Cybersecurity
Telemedicine works with a so-called special category of personal data (data concerning health), which is subject to the strictest requirements of the GDPR (EU Regulation 2016/679). The provider must implement robust technical and organizational measures to secure this data. The new Act on Cybersecurity, which implements the NIS2 Directive, will also have a significant impact.
Under the new Act on Cybersecurity, responsibility for ensuring cybersecurity lies directly with top management (statutory bodies). In the event of an incident, it will no longer be possible to simply delegate responsibility to the IT department.
In practical terms, you must ensure data encryption, access rights management, access logging, and Disaster Recovery plans. A GDPR breach can lead to fines of up to €20 million or 4% of the total worldwide annual turnover. The ÚOOÚ conducts inspections in the healthcare sector, and penalties are not just a theoretical threat.
Patient's Informed Consent and Legal Aspects of the Contract
Telemedicine cannot function without a proper legal basis. The relationship between a doctor and a patient is primarily governed by the Act on Health Services, while also containing elements of a contractual relationship under the Civil Code, especially in the area of self-payment. The obligation to provide the patient with comprehensible information applies even in remote care. Informed consent does not always have to be in writing, but for legal certainty, a recorded form is highly advisable in telemedicine, particularly regarding information about the limits of remote care and consent to its provision in this form.
The patient must be informed that the care is being provided remotely, what its limitations are (e.g., the impossibility of a physical examination), what technologies are being used, and how their data is secured. If the patient's health is harmed as a result of an improperly chosen form of care, the provider will be liable for a procedure that is not *non lege artis*.
The medical records must justify why a remote approach was chosen, unless it is self-evident from the nature of the matter. The Prague-based legal team at ARROWS law firm has experience in preparing and reviewing documentation for telemedicine, including General Terms and Conditions (GTC). Need secure legal documents? Contact us at consultation@arws.cz.
Maintaining Medical Records in Digital Form
The Act on Health Services sets out the rules for maintaining records, including in electronic form. If you keep records purely electronically, which is standard in telemedicine, you must meet specific requirements. The documentation must be kept in a verifiable, truthful, and legible manner.
Entries must be provided with a record identifier and the electronic signature of the person who made the entry, or another verifiable method of authorization within the information system. The information system must guarantee that records cannot be retroactively altered without leaving a trace (so-called versioning).
The Act on the Electronization of Healthcare (No. 325/2021 Coll.) also plays a significant role, gradually introducing the obligation to use master data and sectoral identifiers. Furthermore, the implementation of the European regulation on the European Health Data Space (EHDS) is being prepared, which will in the future introduce an obligation to share defined categories of data in an interoperable format.
Telemedicine and Reimbursement for Health Services
The issue of reimbursement in telemedicine is still evolving. Although telemedicine is a legal form of care, the right to reimbursement from public health insurance is not automatic. Reimbursements are governed by the reimbursement decree and contracts with health insurance companies.
Currently, there are specific codes for remote care services (e.g., remote consultations in some specializations), but their use has its own rules and limits. Some insurance companies (e.g., VZP) have their own programs or bonuses for telemedicine.
If a service is not covered by public insurance, the patient can pay for it themselves, provided they are informed of the price in advance and agree to it. Here, it is necessary to be mindful of the rules for contracted providers, who must not request payment from a patient for care that is covered by insurance. The lawyers at ARROWS law firm have experience in setting up self-payment models. Write to us at consultation@arws.cz.
Liability Insurance for Telemedicine Services
The Act on Health Services requires providers to have liability insurance for damages. However, many standard insurance policies were concluded at a time when telemedicine was not common. They may not explicitly cover it, or they may contain exclusions for care provided outside a healthcare facility.
The risks associated with telemedicine are specific:
Diagnostic error caused by the absence of physical contact or poor quality data transmission.
Cybersecurity risks (data breaches, ransomware).
Technical software failures.
It is essential to verify with your insurance company whether your policy also covers remote care and whether it includes cybersecurity risks. The experts at ARROWS law firm can help you review your insurance policy. Contact us at consultation@arws.cz.
Artificial Intelligence in Telemedicine and New Regulation
Artificial intelligence (AI) is increasingly entering the healthcare sector. With the entry into force of the new European Artificial Intelligence Act (AI Act), new obligations are being imposed on providers and manufacturers. If software uses AI for diagnosis, determining therapy, or triaging patients, it will likely be classified as a high-risk AI system.
This means an obligation to meet strict requirements for accuracy, robustness, cybersecurity, quality of training data, and human oversight. If the AI is also a medical device, it must meet the requirements of both regulations (MDR and the AI Act). The lawyers at ARROWS law firm specialize in the legal analysis of AI systems and can advise you on compliance.
Risks and Penalties | How ARROWS Helps (consultation@arws.cz) |
Unsecured communication: Risk of data breach, fines from the ÚOOÚ, administrative offenses. | Audit and contractual documentation: We will review your contracts with IT suppliers and set up Data Processing Agreements (DPAs) according to GDPR. |
GDPR breach: Fine of up to €20 million or 4% of turnover; reputational damage; claims from patients for non-material damages. | GDPR compliance: We will design a comprehensive data protection system, information duties, and incident response processes. |
Software without certification (MDR): Fine of up to CZK 30 million under the Act on Medical Devices; prohibition of use; liability for damages. | MDR consulting: We will perform a legal qualification of the software and assist with the market placement process or communication with the SÚKL. |
Missing informed consent: Legal uncertainty; risk of disputes over the *lege artis* standard of care; administrative penalties. | Documentation preparation: We will create template informed consents and instructions specifically for remote care. |
Insufficient insurance: In the event of damage, the provider pays for everything from their own resources, which can be ruinous. | Insurance policy review: We will assess whether your existing policy covers the risks of telemedicine and cybersecurity. |
Implementing Telemedicine: A Practical Plan
For a safe implementation of telemedicine, we recommend following these steps:
Legal and medical audit – Define which services can be safely provided remotely.
Technology selection – Choose a solution that meets security standards and allows for a DPA.
Security and GDPR – Set up data protection processes, access rights, and encryption.
Contractual documentation – Update informed consents and internal regulations.
Insurance – Extend your insurance coverage.
Staff training – Ensure that doctors and nurses know how to work with the technologies safely.
Pilot operation and reimbursement – Clarify the funding model (insurance company vs. self-payer).
The lawyers at ARROWS law firm handle telemedicine projects comprehensively. We can communicate with your IT specialists and management to create a plan that is legally secure and practically applicable. Write to us at consultation@arws.cz.
Cross-Border Telemedicine and EHDS
Providing telemedicine across borders (with the patient in another EU country) is a legally complex discipline. Generally, the doctor must meet the conditions for providing care in the country where the patient is located (which often means needing to have their qualifications recognized or being registered in that country). However, there are certain exceptions within the freedom to provide services.
The upcoming regulation on the European Health Data Space (EHDS) aims to reduce these barriers and enable the effective sharing of health data. Once the regulation fully comes into effect, electronic health systems will have to meet interoperability standards for cross-border data exchange.
The lawyers at ARROWS law firm handle cases with an international element daily, thanks to the ARROWS International network. If you are planning to expand abroad, a legal analysis is essential. Contact us at consultation@arws.cz.
Executive Summary for Management
The legislative framework is in place: Telemedicine is a legal part of healthcare, but it is bound by strict rules (security, record-keeping, identification).
Cybersecurity is management's responsibility: With the arrival of the NIS2 Directive and the new Act on Cybersecurity, the statutory body will be directly responsible for security.
Risk of software as a medical device (MDR): Using uncertified diagnostic software carries a risk of a fine up to CZK 30 million.
Funding is not automatic: It is necessary to have a clear reimbursement strategy (contracts with insurance companies or direct payments).
Complexity requires expertise: The legal, IT, and medical aspects must be aligned.
Conclusion
Telemedicine is both the future and the present of Czech medical practice. Its legislative framework gives providers certainty but also places high demands on compliance. You must meet requirements for cybersecurity, personal data protection, proper maintenance of electronic records, and potentially the regulation of medical devices.
The lawyers at ARROWS law firm have been focusing on telemedicine for a long time. We have experience in setting up processes, preparing contractual documentation, and negotiating with regulators (SÚKL, ÚOOÚ) and insurance companies.
ARROWS law firm provides legal services to hundreds of companies, we are insured for damages up to hundreds of millions of crowns, and we have an international reach. Write to us at consultation@arws.cz.
About the author
Disclaimer:
The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.

