Register of Medical Records Disclosures - a Template

An insurance company called Anna's practice asking for a patient's records after an injury. Anna emailed a copy of the file, thinking "the patient wants the…
An insurance company called Anna's practice asking for a patient's records after an injury. Anna emailed a copy of the file, thinking "the patient wants the compensation anyway, so it's fine". She didn't check the authorisation, and didn't record who she disclosed what to, or when. A few months later, the patient filed a complaint that his data had been sent to an entity he hadn't authorised. Anna had no evidence of the legal basis for the disclosure, or of what exactly she'd shared.
Disclosing medical records is an area where it's easy to breach both the Patient Rights Act and the GDPR (General Data Protection Regulation). The key to staying compliant is keeping a register of disclosures. In this article, we'll explain who can receive medical records, how to disclose them, and how to keep the mandatory disclosure register -- with a ready-made structure template.
Legal basis -- what the law says
The rules on disclosing medical records are set out in the Polish Act of 6 November 2008 on Patient Rights and the Patient Rights Ombudsman, and in the Regulation of the Minister of Health on the types, scope and templates of medical records and how they are to be processed. The Act imposes an obligation to keep a register (log) of disclosed medical records.
On top of this comes the GDPR -- medical data is a special category, so every disclosure must have a legal basis.
Who can be given access to medical records?
Medical records may be disclosed to:
- the patient or their legal representative
- a person authorised by the patient (based on an authorisation held in the records)
- other healthcare providers continuing the patient's treatment
- authorised bodies (courts, the prosecutor's office, the National Health Fund (NFZ), the Social Insurance Institution (ZUS), ombudsmen, KIF) within the scope of their duties
- insurance companies -- with the patient's consent
- after the patient's death -- a person authorised during the patient's lifetime, or a close relative, provided there is no objection
Key rule: never disclose data "over the phone" without verifying the authorisation and the legal basis.
Forms of disclosure
Medical records can be disclosed:
- for inspection (at the practice, in the presence of staff)
- by making a copy, printout or transcript
- by handing over the original (exceptionally, against a receipt, when delay would risk causing harm)
- on an electronic data carrier
- via electronic means of communication (with security safeguards in place)
The first disclosure within the requested scope is usually free of charge; a fee within statutory limits may be charged for subsequent ones.
The disclosure register -- what it must contain
This is at the heart of compliance. The register of disclosed medical records should contain:
| Element | Description |
|---|---|
| Serial number | the next entry number |
| Patient data | first name, surname, identifier (e.g. PESEL, Poland's national identification number) |
| Who received it | the person / entity / authority |
| Legal basis for disclosure | patient consent, request from an authority, continuation of treatment |
| Scope of the disclosed records | what exactly was handed over |
| Method of disclosure | inspection, copy, carrier, electronic |
| Date of disclosure | the day it was handed over |
| Signature / person responsible | who carried out the disclosure |
Example entry:
```
No. 12 | Jan Kowalski, PESEL ...
Disclosed to: PZU S.A. (insurance company)
Basis: written patient consent dated 10.05.2026
Scope: therapy record for the period 03-04.2026, copy
Method: paper copy, issued against a receipt
Date: 14.05.2026 | Carried out by: A. Nowak
```
Deadlines for handling a request
Medical records must be disclosed without undue delay. In practice, this means handling the request immediately, or within a reasonably short time for more complex requests. A refusal to disclose (e.g. lack of authorisation) should be documented together with the reason.
CTA: Don't have a template for the disclosure register or a request form? The FizjoReady STANDARD package includes a ready-made template for the medical records disclosure register, a request form and authorisation form, and a GDPR compliance checklist. Handle every case without risk. See FizjoReady packages →
Authorisation for records access -- collect it from the patient at the start
Best practice is to obtain a statement on authorisation (or lack thereof) for access to the records and health information from the patient at the first visit. This means:
- you know exactly who is allowed to access the data
- you have a basis for disclosure to a close relative
- you avoid dilemmas in urgent situations
Keep the statement in the patient's records and update it whenever the patient requests.
GDPR and disclosure -- what to keep in mind
- every disclosure must have a legal basis (consent, a statutory provision, a request from an authority)
- verify the identity of the person collecting the records
- apply the principle of minimisation -- disclose only the scope covered by the request
- when transferring electronically, ensure encryption / a secure channel
- record the disclosure in the register (this is also evidence of accountability towards UODO, the Polish Data Protection Authority)
The most common mistakes
- disclosing data without verifying authorisation ("over the phone")
- no disclosure register, or an incomplete one
- handing over the entire record instead of the requested scope
- sending data by ordinary, unencrypted email
- no patient authorisations in the records
Disclosure versus inspection -- not the same thing
It's worth distinguishing disclosure of a copy from disclosure for inspection. When a patient or an authorised body reviews the records on site, this is still a form of disclosure, and you must record it in the register. The same applies when you issue a copy, a transcript, an electronic carrier, or send data via a secure channel. Each of these situations is an event that must have a legal basis, a verified recipient, and an entry in the log. Consistently recording every form of disclosure builds accountability towards the President of UODO and protects you if a patient complains that their data ended up with an unauthorised person.
The most common mistakes when disclosing records
- disclosing data without verifying authorisation and identity
- a missing or incomplete disclosure register
- handing over a wider scope than the request covered
- sending sensitive data by ordinary, unsecured email
Frequently asked questions
Do I have to keep a disclosure register even though hardly anyone asks for records?
Yes. The obligation to keep a log of disclosed medical records arises from the Act and doesn't depend on the number of requests. Even if disclosures are rare, you must record each one. An empty but ready register also demonstrates that you have a system in place and are fulfilling the obligation.
Can I send a patient's records by email?
You can disclose records electronically, but you must ensure data security, e.g. file encryption and recipient verification. Sending sensitive data by ordinary, unsecured email risks breaching the GDPR. Always confirm identity and the legal basis, and record the disclosure in the register.
Can an insurance company get the records without the patient's consent?
As a rule, disclosing records to an insurance company requires the patient's consent. Don't hand over data just because an insurer calls. Verify the patient's written consent and the scope of the request, then record the disclosure. Without consent and a legal basis, you breach confidentiality and the GDPR.
Who can collect the records after a patient's death?
After a patient's death, the records may be disclosed to a person the patient authorised during their lifetime, and, under the terms set out in the Act, to a close relative -- provided that no other close relative or the patient themselves objected. It's worth having the patient's statement on this matter in the records, which removes doubt at a difficult moment.
CTA: Want to disclose records in line with the law and the GDPR? The FizjoReady STANDARD package is a disclosure register template, forms and a checklist in a single file. See FizjoReady packages →
Related articles:
- GDPR in a physiotherapy practice
- Medical records in physiotherapy
- How to correctly keep a patient record in physiotherapy?