Telemedicine from a Lawyer's Perspective
Telemedicine enables healthcare to be provided remotely, but it requires secure communication, identity verification, protection of health data and properly managed patient consent. It may be provided only by an authorised healthcare provider, while the software used may fall under medical-device rules. The article summarises the main legal and regulatory duties providers should address.

Key takeaways
What is telemedicine?
Remote consultations: The most well-known form, involving telephone or video consultations with a doctor, which can lead to recommendations for procedures, prescription of medications (ePrescription), or planning further care.
Telemonitoring: Regular remote monitoring of health data, such as blood pressure, glucose levels, heart activity, or sleep patterns. This data is transmitted to the provider for long-term monitoring and early intervention in chronic diseases.
Data/Image Transmission (Store-and-Forward): Allows for the sharing of imaging documentation (X-rays, dermatological photographs) and other clinical data with specialists for assessment outside of real time.
Inter-provider consultations: Doctors and other healthcare professionals consult and coordinate patient care remotely, which improves the multidisciplinary approach.
Legal pillars of telemedicine in the Czech Republic
Czech legislation is dynamically adapting to the development of telemedicine, but the pace of technological change is often faster than legislative processes. An amendment to Act No. 372/2011 Coll., on Health Services, newly defines telemedicine and sets out the basic conditions for its provision.
Crucially, telemedicine can be provided even outside a healthcare facility, but only with strict compliance with technical requirements for the quality and security of communication. It is important to realise that telemedicine is not a separate type of health service, but rather a form of its provision. This means that it can only be provided by a healthcare provider with a valid authorisation for the given type of care.
The amendment to the Act (No. 240/2024 Coll., effective from 1 October 2024) is accompanied by implementing Decree No. 30/2025 Coll., which regulates the quality and security of communication and encryption of the communication channel, the method of proving the identity of the communicating parties, and the method of expressing and recording the patient's consent or dissent to the recording of communication between the provider and the patient.
One of the most common legal uncertainties is the assessment of the software used in telemedicine. Software that enables even partial decisions or actions in healthcare (e.g., diagnosis, treatment, monitoring) is classified as a medical device. Such software is then subject to the strict European Regulation (EU) 2017/745 (MDR), which is implemented by the Czech Act on Health Services.
Manufacturers of such software must meet demanding requirements for safety, quality, documentation (including instructions for use in the Czech language), clinical evaluation, and post-market surveillance. They must be registered in the European database EUDAMED or in the national Register of Medical Devices (RZPRO) maintained by the State Institute for Drug Control (SÚKL). Many developers of telemedicine applications or platforms may not be aware of these demanding requirements, which can lead to unforeseen certification costs and, in extreme cases, legal liability for non-compliance.
Key legal challenges for providers
Providing telemedicine services involves several fundamental legal areas that need to be managed.
1. Personal data protection and GDPR
Sensitivity of health data: Why is patient data a gold mine for cyber-attacks?
Healthcare works with a huge amount of a special category of personal data, which includes sensitive information about the health status, diagnoses, treatment, and medical history of patients. This data is extremely valuable on the black market and is becoming an attractive target for cyber-attacks, including ransomware, phishing attacks, and unauthorised access.
A leak of such data poses a significant risk to patient privacy and can irreversibly damage the credibility of providers. Provider obligations: How to ensure technical and organisational measures, data minimisation, and pseudonymisation
Providers must implement robust technical and organisational measures to protect personal data in accordance with the GDPR. Key measures include:
Communication encryption: All transmitted data must be encrypted.
Identity verification: Reliable verification of the identity of the communicating parties (patient and provider).
Data minimisation: Processing only the data necessary for the given purpose.
Data pseudonymisation: Replacing directly identifiable data with a code to reduce the risk of re-identification.
Internal policies and staff training: Clearly documented processes for handling data and regular training for all employees.
Understandable information for patients: Transparently and clearly informing patients about how their data is processed.
2. Patient's informed consent
Informed consent is the cornerstone of the relationship with the patient, and its role in telemedicine is even more significant. Specifics of informed consent in telemedicine: What it must contain and how to obtain it correctly
In telemedicine, the clarity and comprehensibility of information are key to ensuring that the patient fully understands the nature of digital care. The consent should be easy to understand and should include:
The purpose and nature of the telemedicine service.
The expected benefits and possible risks/consequences (e.g., limitations of a physical examination).
Alternative care options (e.g., an in-person examination).
The patient's rights, including the right to refuse care or withdraw consent.
Detailed information on personal data protection.
The method of verifying the identity of both the patient and the provider.
Recording of communication: How to ensure legal compliance and patient trust
Recording telemedicine communication (e.g., video calls) is possible only with the explicit consent of the patient. This consent must be recorded in the medical documentation. Transparency and the option to refuse recording are key to building patient trust.
3. Liability insurance: Essential protection for every provider
The Act on Health Services requires providers to conclude an insurance contract for liability for damage caused during the provision of health services. Given the new risks of telemedicine (e.g., errors in remote diagnosis, cyber-attacks leading to data leaks, software errors), adequate insurance is necessary to protect against the financial consequences of potential disputes and compensation claims. It is important to verify whether existing insurance covers the specifics of telemedicine.
4. Cross-border telemedicine
The development of telemedicine also raises the issue of cross-border provision of services within the European Union. The EU is actively promoting the digitalisation of healthcare and is striving to create a European Health Data Space (EHDS), which is intended to facilitate the exchange of data across member states and support digital health services. The Czech Republic is actively involved in European interoperability projects.
When providing cross-border services, it is crucial to address complex issues of jurisdiction, applicable law (the law of which country applies), and the mutual recognition of qualifications of healthcare professionals. The provider must carefully analyse the legal regulations of both the country from which the service is provided and the country where the patient is located in order to avoid unintentional violation of laws.
Risk and potential problems | How ARROWS helps |
Use of non-certified software (MDR) | We will assess the legal classification of your application, verify compliance with MDR requirements, and set up contractual relationships with software developers. |
Leakage of sensitive health data and fines from the DPA (ÚOOÚ) | We will prepare GDPR documentation tailored to telemedicine, set up security policies, and verify compliance with the technical requirements of the implementing decree. |
Lack of informed consent and illegal recording | We will prepare informed consent templates and a procedural methodology for recording communication to make it fully bulletproof in the event of an inspection. |
Errors in lege artis care and licence revocation | We will set up internal processes for providing care in accordance with lege artis standards, review your liability insurance, and represent you in proceedings before the authorities. |
Risks and sanctions: What are the penalties for non-compliance?
Non-compliance with legal regulations in telemedicine can have serious consequences for healthcare providers, threatening their operations and reputation.
Administrative offences and fines
The Act on Health Services allows the competent administrative authority (regional authority, Prague City Hall) to suspend or even revoke the authorisation to provide health services. The reasons include, in particular, a serious or repeated breach of the obligations laid down for the provision of health services or failure to keep proper medical records. Revocation of the authorisation means the effective end of the provider's activity.
Financial penalties for GDPR violations
A breach of the GDPR, especially in the area of sensitive health data, carries the risk of very high financial penalties. The sanctions are "two-tiered": up to EUR 10 million or 2% of the total worldwide annual turnover for a less serious breach, and up to EUR 20 million or 4% of the total worldwide annual turnover for a more serious breach. The DPA (ÚOOÚ) actively supervises compliance with the GDPR and imposes fines that are not just a theoretical threat.
Conclusion: The key to safe telemedicine
Telemedicine is the undeniable future of healthcare, offering enormous potential to improve the accessibility and efficiency of services. However, for this potential to be fully and safely realised, it is essential to carefully navigate a complex and ever-evolving legal environment.
It is crucial for healthcare providers to focus on these areas:
Strictly comply with legislation: Especially the Act on Health Services and the new implementing decrees, which detail technical requirements, communication encryption, and identity verification.
Protect personal data: Implement technical and organisational measures in accordance with the GDPR, minimise data collection, and ensure its pseudonymisation. There is a risk of high fines from the DPA (ÚOOÚ).
Obtain informed consent: Ensure that patients always give clear and understandable informed consent to telemedicine care and the recording of communication.
Adhere to the "lege artis" standard: Carefully assess whether the telemedicine form of care is appropriate and safe in the given case, and have adequate liability insurance in place.
Address software regulation: Make sure your software does not fall under the Medical Device Regulation (MDR) and meet all related certification and documentation requirements.
Failure to comply with these rules can lead to serious sanctions, including the revocation of the authorisation to provide health services, high financial penalties, and the obligation to compensate the patient for harm. To ensure legal certainty and minimise risks, it is essential to have an experienced legal partner at your side.
About the author
Read also:
- Managing Medical Device Supplier Contracts: Key Risks Under Czech Law
- Czech Healthcare Providers in 2026: NIS2, Digitalisation and Compliance
- Digital Inspections and AI in 2026: New EU Compliance Duties for Firms
- Compliance in Healthcare Procurement in the Czech Republic: How to Avoid Criminal Liability
- Dietary Supplements vs Medicinal Products in Czech Law: Key Compliance Steps
- Handling Negative Online Reviews Under Czech and EU Law: Compliance Guide
- ARROWS helped the client pass the SÚKL inspection
- Representing a disinfectant manufacturer in a dispute with a health authority regarding the suspension of operations and extensive reconstruction
- Mgr. MUDr. Veronika Králíková, an expert consultant at ARROWS, has successfully defended her doctoral thesis and earned the title Ph.D.
- MEDICAL LAW
Disclaimer:
The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.

