Until 2017 doctors in Germany had a legal problem: strictly speaking they couldn’t let an external IT service provider near their systems, because §203 of the German Criminal Code (StGB) — the professional confidentiality rule — criminalises disclosing patient secrets. The fact that a modern practice simply can’t run without IT maintenance was ignored by the law. The reform of 9 November 2017 closed that gap — not with a blanket exemption, but with a clearly defined framework. Anyone working with a practice today as an IT service provider should know that framework.
What §203 StGB regulates
§203 StGB criminalises the unauthorised disclosure of others’ secrets by certain professionals — namely doctors, dentists, psychotherapists, lawyers, tax advisers, and the people working alongside them in a professional capacity. What’s protected isn’t just “medical” content: even the fact that someone is in your care falls under it. Before 2017, practice IT sat squarely in that grey zone.
What the 2017 reform changed
With the German law on the protection of secrets when third parties are involved in professional activity, the revised §203(3)(2) StGB explicitly covers so-called participating persons. In short:
- A doctor may engage an external IT service provider and grant them access to data — as long as it’s necessary for the service being provided.
- In return she must contractually oblige the provider to confidentiality and put them on notice of §203 StGB.
- The provider is brought into the scope of criminal liability: under §203(4) StGB they too are criminally liable if they breach confidentiality.
Following the amended §203 StGB, doctors in private practice, hospital doctors and hospitals may grant external service providers access to confidential data insofar as that is necessary for the external service.
Why that’s good — and why it creates obligations
The reform makes legal what was unavoidable in practice anyway. But it draws a clear line between “allowed, because documented and contractually regulated” and “it just happened”. Concretely, for your practice that means:
- With every IT service provider who could have access to personal patient data (even theoretically — via remote support, for example), you need a written confidentiality obligation.
- You need a data-processing agreement (DPA) under Art. 28 GDPR that regulates purposes, scope, technical safeguards, and any sub-processors.
- You should limit access to what’s technically required — no blanket admin access where a targeted service account does the job.
- You should document the activity (maintenance logs, ticket records). In an audit, this is the most important defence line.
What the reform does not settle — and where it can still pinch
The reform doesn’t relieve you of the responsibility for picking a serious service provider. And it doesn’t reach into cross-border situations: a US cloud service you place patient data on isn’t automatically permitted just because of the reform. GDPR, eHealth legislation, and (for social data) §75b SGB V continue to apply.
How to spot a good DPA
A good DPA for IT maintenance in a practice typically includes:
- a clear description of the activity (remote support, backup, monitoring, …);
- a list of sub-processors (e.g. hosting providers) and the right to object to new ones;
- technical and organisational measures (TOMs) — held by the provider, available on request;
- confidentiality obligations of the provider’s staff under §203 StGB;
- rules on handing over and deleting data when the contract ends;
- notification obligations on security incidents, with concrete deadlines.
Sounds like a lot. A solid template is four to six pages — and once it’s in place, it becomes routine.
What we do
We work exclusively on the basis of a DPA under Art. 28 GDPR and an obligation under §203 StGB. Our staff (which currently means the owner) are properly briefed; every sub-processor (e.g. Hetzner as host) has its own DPA. If you onboard us as a new provider we bring the contract templates with us; if you already use a standard we adapt to yours.
Note: this article is an orientation, not legal advice. For binding statements please consult your legal adviser or the relevant medical association.
Sources
- German Medical Association / KBV: Medical confidentiality (2025). bundesaerztekammer.de · PDF
- Deutsches Ärzteblatt: Confidentiality — Legislator regulates engagement of external service providers. aerzteblatt.de
- activeMind: Data processing for professional secret holders. activemind.de