GDPR & Data Protection

Register of Medical Records Disclosures - a Template

Author:

An insurance company called Anna's practice asking for a patient's records after an injury. Anna emailed a copy of the file, thinking "the patient wants the…

An insurance company called Anna's practice asking for a patient's records after an injury. Anna emailed a copy of the file, thinking "the patient wants the compensation anyway, so it's fine". She didn't check the authorisation, and didn't record who she disclosed what to, or when. A few months later, the patient filed a complaint that his data had been sent to an entity he hadn't authorised. Anna had no evidence of the legal basis for the disclosure, or of what exactly she'd shared.

Disclosing medical records is an area where it's easy to breach both the Patient Rights Act and the GDPR (General Data Protection Regulation). The key to staying compliant is keeping a register of disclosures. In this article, we'll explain who can receive medical records, how to disclose them, and how to keep the mandatory disclosure register -- with a ready-made structure template.

The rules on disclosing medical records are set out in the Polish Act of 6 November 2008 on Patient Rights and the Patient Rights Ombudsman, and in the Regulation of the Minister of Health on the types, scope and templates of medical records and how they are to be processed. The Act imposes an obligation to keep a register (log) of disclosed medical records.

On top of this comes the GDPR -- medical data is a special category, so every disclosure must have a legal basis.

Who can be given access to medical records?

Medical records may be disclosed to:

  • the patient or their legal representative
  • a person authorised by the patient (based on an authorisation held in the records)
  • other healthcare providers continuing the patient's treatment
  • authorised bodies (courts, the prosecutor's office, the National Health Fund (NFZ), the Social Insurance Institution (ZUS), ombudsmen, KIF) within the scope of their duties
  • insurance companies -- with the patient's consent
  • after the patient's death -- a person authorised during the patient's lifetime, or a close relative, provided there is no objection

Key rule: never disclose data "over the phone" without verifying the authorisation and the legal basis.

Forms of disclosure

Medical records can be disclosed:

  • for inspection (at the practice, in the presence of staff)
  • by making a copy, printout or transcript
  • by handing over the original (exceptionally, against a receipt, when delay would risk causing harm)
  • on an electronic data carrier
  • via electronic means of communication (with security safeguards in place)

The first disclosure within the requested scope is usually free of charge; a fee within statutory limits may be charged for subsequent ones.

The disclosure register -- what it must contain

This is at the heart of compliance. The register of disclosed medical records should contain:

Element Description
Serial numberthe next entry number
Patient datafirst name, surname, identifier (e.g. PESEL, Poland's national identification number)
Who received itthe person / entity / authority
Legal basis for disclosurepatient consent, request from an authority, continuation of treatment
Scope of the disclosed recordswhat exactly was handed over
Method of disclosureinspection, copy, carrier, electronic
Date of disclosurethe day it was handed over
Signature / person responsiblewho carried out the disclosure

Example entry:

```

No. 12 | Jan Kowalski, PESEL ...

Disclosed to: PZU S.A. (insurance company)

Basis: written patient consent dated 10.05.2026

Scope: therapy record for the period 03-04.2026, copy

Method: paper copy, issued against a receipt

Date: 14.05.2026 | Carried out by: A. Nowak

```

Deadlines for handling a request

Medical records must be disclosed without undue delay. In practice, this means handling the request immediately, or within a reasonably short time for more complex requests. A refusal to disclose (e.g. lack of authorisation) should be documented together with the reason.

CTA: Don't have a template for the disclosure register or a request form? The FizjoReady STANDARD package includes a ready-made template for the medical records disclosure register, a request form and authorisation form, and a GDPR compliance checklist. Handle every case without risk. See FizjoReady packages →

Authorisation for records access -- collect it from the patient at the start

Best practice is to obtain a statement on authorisation (or lack thereof) for access to the records and health information from the patient at the first visit. This means:

  • you know exactly who is allowed to access the data
  • you have a basis for disclosure to a close relative
  • you avoid dilemmas in urgent situations

Keep the statement in the patient's records and update it whenever the patient requests.

GDPR and disclosure -- what to keep in mind

  • every disclosure must have a legal basis (consent, a statutory provision, a request from an authority)
  • verify the identity of the person collecting the records
  • apply the principle of minimisation -- disclose only the scope covered by the request
  • when transferring electronically, ensure encryption / a secure channel
  • record the disclosure in the register (this is also evidence of accountability towards UODO, the Polish Data Protection Authority)

The most common mistakes

  • disclosing data without verifying authorisation ("over the phone")
  • no disclosure register, or an incomplete one
  • handing over the entire record instead of the requested scope
  • sending data by ordinary, unencrypted email
  • no patient authorisations in the records

Disclosure versus inspection -- not the same thing

It's worth distinguishing disclosure of a copy from disclosure for inspection. When a patient or an authorised body reviews the records on site, this is still a form of disclosure, and you must record it in the register. The same applies when you issue a copy, a transcript, an electronic carrier, or send data via a secure channel. Each of these situations is an event that must have a legal basis, a verified recipient, and an entry in the log. Consistently recording every form of disclosure builds accountability towards the President of UODO and protects you if a patient complains that their data ended up with an unauthorised person.

The most common mistakes when disclosing records

  • disclosing data without verifying authorisation and identity
  • a missing or incomplete disclosure register
  • handing over a wider scope than the request covered
  • sending sensitive data by ordinary, unsecured email

Frequently asked questions

Do I have to keep a disclosure register even though hardly anyone asks for records?

Yes. The obligation to keep a log of disclosed medical records arises from the Act and doesn't depend on the number of requests. Even if disclosures are rare, you must record each one. An empty but ready register also demonstrates that you have a system in place and are fulfilling the obligation.

Can I send a patient's records by email?

You can disclose records electronically, but you must ensure data security, e.g. file encryption and recipient verification. Sending sensitive data by ordinary, unsecured email risks breaching the GDPR. Always confirm identity and the legal basis, and record the disclosure in the register.

As a rule, disclosing records to an insurance company requires the patient's consent. Don't hand over data just because an insurer calls. Verify the patient's written consent and the scope of the request, then record the disclosure. Without consent and a legal basis, you breach confidentiality and the GDPR.

Who can collect the records after a patient's death?

After a patient's death, the records may be disclosed to a person the patient authorised during their lifetime, and, under the terms set out in the Act, to a close relative -- provided that no other close relative or the patient themselves objected. It's worth having the patient's statement on this matter in the records, which removes doubt at a difficult moment.


CTA: Want to disclose records in line with the law and the GDPR? The FizjoReady STANDARD package is a disclosure register template, forms and a checklist in a single file. See FizjoReady packages →

Related articles:
- GDPR in a physiotherapy practice
- Medical records in physiotherapy
- How to correctly keep a patient record in physiotherapy?

Newsletter

Regulatory changes and practical tips for physiotherapy practices. No spam.