The Electronic Patient Record
Since January 2025, an electronic patient record has been created automatically for almost all statutorily insured persons — without their active consent. That may sound like a mere administrative matter. For people in psychotherapy, it is not. This page explains what rights you have and how to exercise them in practice.
Automatically generated with Google NotebookLM — a “conversation” between two AI voices. It may occasionally be inaccurate, but offers a good first overview.
The essentials at a glance
A central digital health record in which findings, doctors’ letters and medication data are stored. It is meant to improve care — and you decide what goes into it and who sees it (§ 341 SGB V, German Social Code Book V).
Most likely yes. Since 15 January 2025, the opt-out principle applies: the record was created automatically for all insured persons who did not actively object — even if you were unaware of it.
Use the ePA fully · Specifically shield your psychotherapy data · Reject the ePA entirely and have it deleted. All of this is possible at any time — and can be undone.
Step-by-step instructions
You do not need any technical knowledge to exercise your rights. If you already know what you want, go straight to the option that suits you.
The complete objection — if you do not want an ePA at all
For everyone who fundamentally does not consent to the central storage of their health data and prefers to keep their data decentralised with their individual providers.
This is the most consistent path. You simply inform your health insurance fund that you do not want an ePA. This is your legally enshrined right (§ 342 SGB V, German Social Code Book V) — with no obligation to give reasons. Almost all health insurance funds offer several simple ways to do this:
- Digitally via app or website: The insurers’ ePA apps usually have a menu item such as “Delete ePA” or “Objection”. Online forms are also often available on their websites (AOK-Bundesverband, 2025b).
- By phone or in writing: A call to the service hotline is enough. Or an informal letter with your name, insurance number and the sentence: „Hiermit widerspreche ich der Einrichtung und Nutzung einer elektronischen Patientenakte für meine Person.“ (“I hereby object to the creation and use of an electronic patient record for my person.”)
The result: Your ePA is deleted completely and irrevocably (gematik GmbH, 2025a). No new data will be stored centrally. Should you change your mind later, you can withdraw your objection at any time — your insurer will then create a new, empty record.
The protected space — use the ePA, shield your psychotherapy
Probably the most important path for patients in psychotherapy. Keep the practical benefits of the ePA — while keeping highly sensitive therapy data fully confidential.
You can use the ePA in such a way that, for example, your cardiologist can view your latest hospital report while the contents of your psychotherapy remain absolutely protected. For maximum protection, I recommend a combination of three measures — a triple-lock principle:
With this triple safeguard, you can use the ePA for other medical appointments while being certain that the sensitive contents of your psychotherapy remain confidential.
Fine-tuning — adjust exactly what bothers you
For everyone who wants to use the ePA in principle but would like to handle certain aspects differently.
The ePA offers various levers. Three common concerns — and your options:
“I don’t want other doctors to see my medications.”
In the ePA app, you can either completely deactivate the automatic medication list, which is fed by e-prescriptions, or set it to “visible only to me”. That keeps this information private (KBV, 2025).
“Under no circumstances should my data be used for research.”
You can object to the planned use of data for research (from around 2026) at any time (§ 363 SGB V, German Social Code Book V). This setting has no effect whatsoever on your treatment or your other use of the ePA.
“This one doctor’s letter is too sensitive — no one but me should see it.”
In the ePA app, you can “hide” any individual document. It then remains visible to you personally, but for all doctors, hospitals and pharmacies it is as if it did not exist (KBV, 2025).
No smartphone? The ombuds office is your personal service.
You do not need an app or any technical knowledge to exercise your rights. Every health insurance fund is legally required to set up an ombuds office that serves as a neutral point of contact and advice (§ 342a SGB V, German Social Code Book V). You can call or write to it and ask for all the settings mentioned here to be made on your behalf: delete the ePA, block practice access, stop billing data, deactivate the medication list, object to research use. You will find the contact details on your insurer’s website.
Background, opportunities, risks
The ePA is not a neutral technical tool. If you want to make a truly self-determined decision, you should know the background. An honest assessment — without trivialising, without scaremongering.
Legal framework: How did the ePA come about?
The ePA is the result of a years-long political process aimed at fundamentally modernising the German healthcare system. The driving vision: a digitally connected system in which medical information is available securely, quickly and completely wherever it is needed for your treatment. The legal foundations are anchored in §§ 341 ff. SGB V (German Social Code Book V) and the Digitale-Versorgung-Gesetz (DVG, German Digital Healthcare Act).
In a first phase from 2021 to 2024, the ePA was based purely on voluntary participation — the “opt-in” principle. As uptake was extremely low, the legislature reversed the principle: since 15 January 2025, the “opt-out” procedure applies, under which an ePA is created automatically for every person with statutory health insurance unless they have actively objected (BMG, 2025c). Legally, this silence is treated as informed consent. This is precisely the crux that data protection advocates and patient representatives strongly criticise: many people may not have understood the full implications of their insurers’ information letters. The result: millions of people have an ePA without consciously knowing it.
Since 1 October 2025, all healthcare providers have been legally obliged to use the ePA and store relevant treatment data (AOK-Bundesverband, 2025a). This obligation ceases as soon as you object as a patient. For highly sensitive data, providers are explicitly required to inform you of this right (§ 347 SGB V, German Social Code Book V).
What goes into the ePA — and where does it come from?
The ePA is a dynamic system fed from three different sources:
- Your healthcare providers: Medical reports, doctors’ letters (especially hospital discharge letters), digital health documents such as your vaccination record or maternity record.
- Your health insurance fund — the often invisible, automatic data flow: Unless you object, your insurer automatically transfers billing data (ICD-10 diagnosis codes) and e-prescription data for the medication list into your ePA (gematik GmbH, 2025a). This data stream runs in the background — without you actively noticing.
- You yourself: The ePA is legally defined as a record “managed by the insured person”. You can upload your own documents at any time — scanned old doctors’ letters, a pain diary, information about an advance directive.
What speaks for the ePA? Opportunities and benefits
Despite all legitimate concerns, there are understandable arguments in favour of the ePA. Policymakers promise increased patient safety in emergencies, as vital information such as allergies or current medication is quickly available. Duplicate examinations can be avoided. And for the first time, you gain a complete overview of your own health history and can take an active part in the treatment process (BMG, 2025c).
For people without serious data protection concerns and without ongoing psychotherapy, the ePA can be a sensible instrument. The decision is yours.
Risks and criticism — an honest assessment
At the end of 2024, the Chaos Computer Club demonstrated serious conceptual security flaws in the telematics infrastructure — including the theoretical possibility of mass access to third-party records (Kastl & Tschirsich, 2024). gematik responded with fixes. The fundamental problem remains: absolute security is an illusion. Once health data has been stolen, it cannot be “reset” — the damage is permanent.
The “all-or-nothing” permission modelBy default, every practice you grant access to can view, for 90 days, all documents you have not actively hidden. An orthopaedist could theoretically read the discharge report from your psychosomatic clinic. The entire burden of control rests on your shoulders. Professional bodies such as the Bundespsychotherapeutenkammer (BPtK, Federal Chamber of Psychotherapists) sharply criticise this model because it contradicts the basic principle of data minimisation (BDP, 2024). As early as 2020, the Federal Commissioner for Data Protection (BfDI) warned of precisely this scenario.
Research use from 2026The Gesundheitsdatennutzungsgesetz (GDNG, German Health Data Use Act) creates the basis for using ePA data in pseudonymised form for research from around 2026 onwards (BMG, 2025b). Here too, an opt-out applies. Critics warn of the risk of re-identification: with a combination of rare diseases, specific treatment histories and demographic data, it could theoretically be possible to trace records back to individual persons. It is a fundamental trade-off between the collective benefit for research and your individual right to informational self-determination.
Loss or misuse of the health cardThe eGK (electronic health card) is the key to the ePA. If it falls into the wrong hands and is used in a card reader, someone could gain unauthorised access — precisely because the PIN is often waived in treatment contexts. The CCC experts showed that practice ID cards can be obtained fraudulently. The probability for any individual is low, but not zero. Practical advice: treat your eGK like a credit card, report any loss to your insurer immediately, and check the access log in the app from time to time (Netzpolitik, 2025).
Stigmatisation and social risksHealth data — especially psychotherapeutic data — is among the most personal information there is. If such data becomes known against your will, it can be detrimental to those affected. Think of professional contexts: if a company doctor were to see confidential mental health data, it could affect the employment relationship. Or in your private life: not everyone wants a co-treating doctor from their closer social circle to learn which diagnoses they have. To some extent, it is your responsibility to prevent this — by consciously hiding sensitive content. The former Federal Data Protection Commissioner Ulrich Kelber warned that lowered security standards could permanently damage citizens’ trust — and trust is the very precondition for the system to work at all (Netzpolitik, 2025).
Your tools: the 90-day rule, hiding, deleting, the access log
The 90-day rule and how to master it: By default, a practice is granted access to your ePA for 90 days. Via the app or the ombuds office, you can shorten or extend this period individually for each practice, or revoke access at any time (KBV, 2025).
Hiding vs. deleting — the strategic difference:
- Hiding is the most flexible method: a hidden document remains stored in your ePA but is visible exclusively to you. For everyone else, it is as if it did not exist.
- Deleting is the definitive step: a deleted document is removed irrevocably. A practice is not obliged to upload a document you have deleted a second time.
The access log — your personal monitoring instrument: Every single access to your ePA is fully logged. In the app, you can see at any time which practice accessed which data and when (gematik GmbH, 2025b). If anything seems wrong, contact your health insurance fund immediately.
The ePA operates in a permanent tension between the benefits for healthcare and the risks to your privacy. The “opt-out” system has clearly shifted the responsibility onto you — it demands that you actively inform yourself and act.
Please understand this page as an invitation to exercise your rights with confidence. Whether you reject the ePA entirely, use it without restriction or take a differentiated middle path — the choice is yours alone. Feel free to raise any questions with me in our personal conversations at any time. Together we can find the path that is right and safe for you.
This text is provided for general information (as of October 2025) and does not replace individual legal advice. For specific legal questions, please contact your health insurance fund or an independent advice service.
References
- AOK-Bundesverband. (2025a, 1. Oktober). Seit 1. Oktober 2025: ePA ist Pflicht für Ärztinnen und Ärzte. aok.de
- AOK-Bundesverband. (2025b). Elektronische Patientenakte ePA: Widerspruch. aok.de
- Berufsverband Deutscher Psychologinnen und Psychologen (BDP). (2024, 20. November). Stellungnahme: Die ePA für alle schützt sensible Befunde nicht ausreichend. bdp-verband.de
- Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI). (2020, 25. August). BfDI zum Patientendaten-Schutz-Gesetz. bfdi.bund.de
- Bundesministerium für Gesundheit (BMG). (2025b). Gesundheitsdatennutzungsgesetz (GDNG). bundesgesundheitsministerium.de
- Bundesministerium für Gesundheit (BMG). (2025c). ePA für alle. bundesgesundheitsministerium.de
- gematik GmbH. (2024, 27. Dezember). Stellungnahme zum CCC-Vortrag zur ePA für alle. gematik.de
- gematik GmbH. (2025a). ePA für alle — Widerspruchsmöglichkeiten. gematik.de
- GKV-Spitzenverband. (2025, 3. Juni). Informationen zur elektronischen Patientenakte nach § 343 SGB V. gkv-spitzenverband.de
- Kassenärztliche Bundesvereinigung (KBV). (2025, September). Elektronische Patientenakte. kbv.de
- Kastl, T., & Tschirsich, M. (2024, 27. Dezember). CCC: Das Narrativ der sicheren ePA ist nicht mehr zu halten. Netzpolitik.org. netzpolitik.org
- Orth, A. (2025, 5. Februar). EPA-Daten für die Forschung. Pharmazeutische Zeitung. pharmazeutische-zeitung.de
- Sozialgesetzbuch (SGB) Fünftes Buch (V) — Gesetzliche Krankenversicherung. Bundesamt für Justiz. gesetze-im-internet.de
- Techniker Krankenkasse (TK). (2025, 20. Februar). Forschungsdatenspende in der ePA. tk.de
