Articles
Swedish law

Patientdatalagen (the Swedish Patient Data Act) governs how healthcare providers process personal data

Patientdatalagen (PDL) — the Swedish Patient Data Act — applies to all healthcare providers, both public and private. It supplements the General Data Protection Regulation (GDPR) with rules on how healthcare providers may process personal data.

Areas regulated by Patientdatalagen include:

  • Direct access, the patient can be given digital access to their own medical records, as well as information on who has processed their personal data at the healthcare provider. Logging in to 1177 with BankID is an example of direct access.
  • Internal confidentiality, only those who need information about the patient for their work in healthcare may access it. Patientdatalagen sets requirements for access rights allocation and access control in order to apply internal confidentiality.
  • Shared medical records ("sammanhållen journalföring"), means that different healthcare providers can have direct access to each other's records. Both parties must meet the requirements of Patientdatalagen.
  • Blocking of information, the patient can block information in an individual healthcare provider's record system, and also from other healthcare providers under shared medical records.

Direct access to the patient's medical record

Healthcare providers are required to keep patient records, even if the patient objects. Furthermore, the patient has the right to access their medical records, either through direct access or by other means, such as a paper printout.

Healthcare providers therefore have the option, but not the obligation, to give the patient direct access to their medical records held by that provider. For direct access, the patient must be securely identified through technical security measures.

The patient also has the right to request information about which care units have had access to their information, and at what time. Here too, direct access can be granted if secure identification is possible.

Healthcare providers must maintain internal confidentiality

Only healthcare staff who, through their work, take part in the care and treatment of the patient may access the patient's information. The healthcare provider is responsible for ensuring that access is limited to those who need the patient's information to carry out their work. Internal confidentiality must be maintained through technical solutions for assigning access rights and controlling access.

Shared medical records give access to patient information held by another healthcare provider

Shared medical records mean that one healthcare provider can give other healthcare providers access to a patient's medical records. Before the information is made accessible to other healthcare providers, the patient must be informed about what shared medical records means, about the option to object to the information being made available, and that in that case the healthcare provider is obliged to block the information.

In the next step, a healthcare provider intending to access patient information made available through shared medical records must meet the following requirements.

The healthcare provider has a current patient relationship with the individual.
The patient information is needed to prevent, investigate, or treat illness or injury in the patient.
The patient has given their consent.
An employee of the healthcare provider may access the patient information after making an active choice in the record system confirming that they have assessed the requirements above as being met. A healthcare provider that gains access to patient information through shared medical records becomes the data controller for the processing of that information within its own operations, and is responsible for ensuring that the information is handled in accordance with Patientdatalagen.

The patient can block information

All patient information can be blocked at the patient's request. This means that other healthcare providers cannot get direct access to the information. What is shown is only that there is blocked information and which healthcare provider applied the block.

The block can be lifted by the healthcare provider that applied it, if the patient requests this. A healthcare provider treating a patient whose life or health is in danger can, through an active choice, see which blocked information exists at other healthcare providers. Through a further active choice, the healthcare provider can request that the block be lifted by the other healthcare provider. Only the healthcare provider that applied the block can lift it. This can be done on a case-by-case basis, and only for the information needed for the patient's essential care.

National and regional quality registers may require the consent of IMY

In certain cases, anyone wishing to process genetic personal data in a national or regional quality register needs the consent of the Swedish Authority for Privacy Protection (IMY). Under the General Data Protection Regulation (GDPR), genetic data is classified as sensitive personal data and is defined in Article 4(13) GDPR as:

"Personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question."

Since health data may be processed in quality registers without the consent of IMY, IMY has determined that genetic data linked to a person's state of health, such as blood samples or other biological samples, may also be recorded in quality registers without the consent of IMY.

Quality registers that have no connection to the person's health must apply for the consent of IMY.

Read more at IMY.

Processing of personal data in connection with crime

When healthcare processes personal data for the purpose of preventing, detecting, investigating, or prosecuting crime, or enforcing criminal penalties, it is the Swedish Criminal Data Act (brottsdatalagen) that applies, not the GDPR and Patientdatalagen. In certain cases, however, both Patientdatalagen and the Criminal Data Act may apply — for example, in forensic psychiatric care, decisions may need to be made concerning both the forensic psychiatric care itself and coercive measures.

Read more:

Patientdatalagen (2008:335)

Patientdataförordningen (2008:360)

The National Board of Health and Welfare's regulations and general guidelines on record-keeping and the processing of personal data in healthcare (HSLF-FS 2016:40)

Keep reading