QS-VO 2024 course All courses

Lesson 9.1 · 6 min

§ 17 Records, data security and retention

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

What § 17 requires

  1. Patient data is documented systematically; diagnosis and, where treatment follows, the course of treatment can be followed from the records § 17(1).
  2. Suitable security measures protect the data against unauthorised access and loss, an automatic screen lock and passwords for example § 17(2).
  3. All prescription forms and stamps are kept safe from theft § 17(3).
  4. Staff who assist with medical tasks as auxiliaries under § 49(2) of the Physicians Act, and health professionals to whom medical tasks are delegated under § 49(3), are informed about patients' risks and potential complications § 17(4).
  5. Records, in particular findings, diagnosis, therapy, patient information and consent forms, are kept for at least ten years § 17(5).
  6. Data carriers no longer needed, from hard drives and CDs or DVDs to paper records, are destroyed and disposed of properly under data protection rules § 17(6).

On the on-site visit

To check § 17(1), you prepare two patient files in advance, complete and anonymised; they are shown to the peers only. In justified exceptions the peers can ask for further complete, anonymised files § 33(7). More in lesson 1.3.

What works as proof

Checklist

Quiz

For how long, at least, must patient records be kept under § 17(5)?

  1. Ten years
  2. Seven years
  3. Until the next evaluation
  4. Five years
Show the answer

The answer is A: Ten years. § 17(5): at least ten years, in particular findings, diagnosis, therapy, patient information and consent forms.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the text of the QS-VO 2024 in the Federal Legal Information System (version of 3 October 2026) and the Austrian Medical Chamber's Hygiene Regulation 2014. Not an offer of ÖQMED, the BIQG or the Medical Chamber.