Article 9
Right to obtain information on accessing data
In short: Natural persons shall have the right to obtain information on any access to their personal electronic health for at least the last 3 years.
- Natural persons shall have the right to obtain information, including through automatic notifications, on any access to their personal electronic health
data through the health professional access service obtained in the context of healthcare, including access provided in accordance
with Article 11(5).
- The information referred to in paragraph 1 shall be provided, free of charge and without delay, through electronic health data access services
and shall be available for at least three years from each date of access to the data. That information shall include at least the following:
- (a) information on the healthcare provider or other individuals who accessed the personal electronic health data;
- (b) the date and time of access;
- (c) which personal electronic health data were accessed.
- Member States may provide for restrictions to the right referred to in paragraph 1 in exceptional circumstances, where there are factual
indications that disclosure would endanger the vital interests or rights of the health professional or the care of the natural person.
Recital 16: Access to electronic health records by healthcare providers or other individuals should be transparent to the natural persons concerned.
Electronic health data access services
should provide detailed information on access to data, such as when and which entity or natural person accessed data, and which data were accessed.
Discussion
Note that the requirements is both:
- To receive notifications when someone accesses information.
- To retrieve/search past access information.
It seems likely the
NCP will provide a UI / an API to retrieve the audit log details.
Feedback
Please e-mail
ehds@ringholm.com should the information on this page be incorrect or incomplete; we welcome your suggestions to improve its content.
About Ringholm bv
Ringholm bv is a group of European experts in the field of messaging standards and systems integration in healthcare IT.
We provide the industry's most advanced training courses and consulting on healthcare information exchange standards.