Lesson 9.1 · 6 min
§ 17 Records, data security and retention
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- Records others can follow. Document patient data systematically, so that diagnosis and course of treatment can be followed.
- Protect. Screen locks and passwords, for example, against unauthorised access and loss. Prescription forms and stamps kept safe from theft.
- Brief the team. Anyone who assists with medical tasks knows patients' risks and potential complications.
- Ten years, then destroy properly. Keep records at least ten years, consent and patient information included. Destroy data carriers no longer needed as data protection requires.
- On the visit. For the on-site visit, two complete, anonymised patient files are ready, for the peers only.
In detail
What § 17 requires
- Patient data is documented systematically; diagnosis and, where treatment follows, the course of treatment can be followed from the records § 17(1).
- Suitable security measures protect the data against unauthorised access and loss, an automatic screen lock and passwords for example § 17(2).
- All prescription forms and stamps are kept safe from theft § 17(3).
- Staff who assist with medical tasks as auxiliaries under § 49(2) of the Physicians Act, and health professionals to whom medical tasks are delegated under § 49(3), are informed about patients' risks and potential complications § 17(4).
- Records, in particular findings, diagnosis, therapy, patient information and consent forms, are kept for at least ten years § 17(5).
- Data carriers no longer needed, from hard drives and CDs or DVDs to paper records, are destroyed and disposed of properly under data protection rules § 17(6).
On the on-site visit
To check § 17(1), you prepare two patient files in advance, complete and anonymised; they are shown to the peers only. In justified exceptions the peers can ask for further complete, anonymised files § 33(7). More in lesson 1.3.
What works as proof
- the screen-lock setting and a password rule;
- a backup whose restore has been tested;
- a lockable place for prescription forms and stamps;
- proof that assistants were briefed;
- destruction certificates for files and data carriers, from a disposal company for example.
Checklist
- Diagnosis and course of treatment can be followed from the records.
- Screens lock automatically; access is protected by passwords.
- The data is protected against loss.
- Prescription forms and stamps are kept safe from theft.
- Patient records are kept at least ten years, consent and patient information included.
- Old data carriers and paper files are destroyed as data protection requires.
Quiz
For how long, at least, must patient records be kept under § 17(5)?
- Ten years
- Seven years
- Until the next evaluation
- Five years
Show the answer
The answer is A: Ten years. § 17(5): at least ten years, in particular findings, diagnosis, therapy, patient information and consent forms.
Sources
This lesson's statements rest on:
Not legal advice. What counts is the text of the QS-VO 2024 in the Federal Legal Information System (version of 3 October 2026) and the Austrian Medical Chamber's Hygiene Regulation 2014. Not an offer of ÖQMED, the BIQG or the Medical Chamber.