Expert knowledge for digital decisions
Can Health Data Be Processed in the Cloud?
Short answer
What to Check
Data Processing. Contract according to Article 28 GDPR with the provider – and with its subcontractors in the chain.
Confidentiality Obligation. According to § 203 StGB, service providers with access must be separately obligated to confidentiality. This point is often missing in standard contracts.
Processing Location. It is significantly easier to justify within the EU. For third countries, a suitable basis is required – and for health data, a careful consideration.
Encryption. During transmission and storage. Ideally, in such a way that the provider cannot read the contents themselves.
Roles and Logging. As in any system with patient data.
Additional Requirements
In the area of statutory health insurance, there are special requirements for certain processing activities, including regarding the processing location. These must be examined depending on the configuration.
Cloud Is Not Automatically Less Secure
A professionally operated data center is generally better secured than a server in a practice basement that no one updates. The question is not whether to use the cloud or not, but what contractual assurances are in place.
Practical Advice
Have the provider confirm in writing: processing location, subcontractors, encryption, obligation under § 203 StGB, and what happens to the data at the end of the contract.
This text does not replace legal advice.
Key facts
- Always Required
- Data processing agreement and obligation under § 203 StGB
- Significantly Easier
- Processing within the EU
- No Automatism
- Cloud is not inherently less secure
Sources
All external claims are backed by traceable sources.-
01
Strafgesetzbuch (StGB) Bundesministerium der Justiz
-
02
Datenschutz-Grundverordnung (Verordnung (EU) 2016/679) Amt für Veröffentlichungen der EU