You are here: Infothek - Blood pressure apps and digital tools - What is the ePA (electronic patient record)?

What is the ePA (electronic patient record)?

Since 29 April 2025 at the latest, everyone with statutory health insurance in Germany has automatically received an electronic patient record (ePA), unless they objected to its creation by opting out. However, many people are still unclear about what it is and what purpose it is intended to serve.

Until now, in the best-case scenario, the family doctor collected all of a patient's medical reports. This meant that they referred the patient to the relevant specialists when needed and received the findings from the examinations carried out there. The same applied to reports on hospital stays. In some cases, patients were given the reports directly with instructions to hand them in to their GP; often, the reports were also sent directly. This resulted in a more or less complete collection in the patient file kept by the GP.

ePa (electronic patient record)
Medical findings needed for treatment by a specialist, a hospital stay, rehabilitation, etc. had to be requested from the GP. However, if emergency treatment was necessary, these findings were usually unavailable, meaning that important information was missing.

Among other things, the electronic patient record is intended to fix that. The ePA enables the secure storage and sharing of important health data like reports, diagnoses, doctors' letters, medication data, lab results, possibly nursing information, electronic sick notes (eAU), DMP data, advance directives, organ donation records, etc. These are available at any time in the free app or on the health insurance card. In addition, an emergency data set (NFD) can be stored in the ePA, recording all information relevant in an emergency, such as diagnoses, allergies, the current medication list, pregnancy, and so on. You can also note the person to be contacted in an emergency.

The ePA is a patient-managed record. The Federal Ministry of Health's „ePA for everyone“ concept is considered a key element of digitalization. Since January 2025, the ePA rollout has been taking place through an opt-out process, meaning that insured persons can object if they do not want an ePA. Previously existing ePAs that insured persons requested through the opt-in process have been updated to the new version. The features are also intended to become available only gradually. During the initial phase, the ePA is to be introduced as a so-called "basic record", with its scope of use then expanding over time.
The free app provided by health insurance providers can be downloaded to and used on a patient's smartphone or tablet. Alternatively, the ePA is also available on the health insurance card.  

Patients can use the ePA app to decide which content is stored and who gets access. They retain control over their data and set access rights. An objection to the ePA (opt-out) is possible at any time, even after the ePA has been set up.

They can also decide which documents should be deleted again, if necessary, or whose access to the data should be revoked. In the long term, findings and other records should be archived here throughout a person's life. So there should only be one ePA per patient. 
However, even without actively using the app, healthcare providers can technically access the data when the electronic health card is read.

Specifically, storing the emergency data set (NFD) on the health card is an important improvement over previous practice. In an emergency, it avoids searching, saves valuable time and gives rescue personnel immediate access to important information about the patient's medical history and current medication.

Since October 2025, doctors and other healthcare providers have been required to use the ePA to enter certain data unless the patient has objected.

Besides physicians, providers also include therapists, pharmacies and other people or institutions involved in treatment. Data are not transferred automatically here either; the desired files must be deliberately copied onto the health card or into the ePA available there. The originals remain with the respective doctor, therapist, etc., as before.

In general, only those who have been authorized by the patient have access to the ePA.

Neither the operators of the ePA nor the health insurer can access the collected data. One special case is the NFD: in an emergency, doctors, rescue personnel and other people who have an electronic health professional ID card can access it even without the patient's consent (the patient may no longer be able to give consent in an emergency). Every access is recorded on the health card and can therefore be traced afterwards.

Data protection is taken very seriously: the servers for the ePA are located in Germany. The ePA is therefore subject to European data protection regulations. Providers must also go through extensive certification processes before they can offer the ePA.
Nevertheless, data protection and data security remain central topics of discussion, since some citizens still have concerns.

What should be stored in the electronic patient record (ePA)?

As mentioned above, the ePA should ideally accompany us for life. Starting with U-examinations for children and adolescents, vaccinations, allergies and blood type, you can also store, for example, the maternity record, the dental bonus booklet and, of course, all other findings. Services claimed from the health insurer, data from health apps and nursing care information - even the electronic sick note and e-prescriptions documenting medication history - should also be included in the ePA. For example, you can also upload your PDF report from Tensana to your ePA.

Overall, the electronic patient record (ePA) is a very useful innovation. However, it also requires the patient to act as a partner in their own medical care. After all, the best record is useless if it is not maintained. It is therefore the patient's responsibility to keep it up to date and, if necessary, to give the respective doctor access to the findings relevant to them.

Data protection for the ePA is also repeatedly discussed. Sensitive data are being stored and should not fall into unauthorized hands. To make the ePA secure, as mentioned above, everything possible is being done.

Sources:



This article is from Tensana – the leading app since 2011, helping hundreds of thousands of people monitor their blood pressure every day. Our content is based on carefully researched, evidence-based data and is continuously updated (as of 02/2025).

Author Sabine Croci is a qualified medical assistant with many years of experience in internal medicine and cardiology practices as well as outpatient care, and has headed the specialist editorial team at Tensana since 2015. Thanks to her extensive additional qualifications as an emergency medical technician, first responder, and in various areas of therapy and emergency care, she provides well-founded, practical, and reliably verified information.


Similar articles:
Search for more information

Translation Disclaimer:
This content has been automatically translated. We strive for accuracy, but errors may occur. Please contact us if you find any inconsistencies or have questions.