Medical Data Confidentiality: The Georgian Regime
The Georgian special regime for the confidentiality of medical data is written into the Law on Medical Practice: it contains the core confidentiality duty, the rules of access to and correction of documentation, the specificity of telemedicine, and the conditions for producing records. The categories of the United States HIPAA and of European Union data-protection law — protected health information, special-category data — are non-Georgian concepts: the page is carried by the Georgian law, with the Georgian Law on Personal Data Protection adding the general background.
Article 48 of the law sets the core duty: the subject of independent medical activity must, save for cases provided by legislation, keep confidential the information about the patient's state of health and private life — both while conducting the activity and after its cessation, both during the patient's life and after death. These two "afters" set the severity of the regime: the duty is not lifted either by closing the practice or by the patient's death.
The Permissible Cases of Disclosure
The law itself supplies the list of disclosures. The subject may disclose confidential information where: the patient gives the right to disclose; non-disclosure threatens the health or life of a third person whose identity is known; a substantiated suspicion of a disease subject to mandatory registration exists; the information is supplied to other medical personnel participating in the service; disclosure is necessary for a forensic medical examination; law-enforcement bodies demand it under a court decision; the information concerns a possible fact of violence against women or domestic violence and a risk of repetition exists — in which case it is communicated only to the relevant state body; the information is supplied to state bodies for establishing social benefits — where the patient's consent is required; and, for teaching and scientific purposes, the data are presented so that identification is impossible.
This list is a working instrument: every disclosure must rest on one of its items, and when responsibility is at issue it is the subject who shows which item covers the act. Outside it, disclosure is a violation — though the patient's grant of the right to disclose and the protection of a third person are the most frequent grounds.
Access to Documentation and Its Correction
Article 41 governs access: on request, the subject must acquaint the patient — or, for a minor or a person unable to take an informed decision, the relative or legal representative — with the information in the medical documentation on the state of health, including diagnostic results, data on treatment and care, and records of consultations by another subject. In cases provided by law the subject may withhold information from a capable patient or restrict its scope — but where the patient insistently demands it, acquaintance becomes a duty. A relative or representative of a capable patient may be acquainted only with the patient's consent.
Article 42 supplies the correction machinery: on the patient's substantiated request, the subject must enter a correction, addition or explanation into the medical documentation and update the personal and medical data; for a minor or incapable patient, the request may come from the relative or representative. At the same time, where the recording of information is required by legislation, the subject may decline to change it — the necessity of a record and the right of correction balance each other.
Telemedicine and the Production of Records
Article 91 governs telemedicine: where telemedicine means are used, protecting the confidentiality of information about the patient is incumbent on the subject, and, on the patient's request, data on identity, health and private life may be transferred anonymously. Article 56 sets the quality conditions for records: they must be kept in the state language, clearly and comprehensibly; be complete; be recorded in time; adequately reflect every detail of the service; and each new part must be certified by a signature. Records are communicated to a third person only in the cases provided by the law — the confidentiality regime continues on paper as well.
Frequently Asked Questions
Below we summarize the questions most often asked about medical data confidentiality.
When does the duty end?
Never fully: confidentiality must be protected both during the activity and after its cessation, during the patient's life and after death.
May a patient be refused acquaintance with documentation?
Only in cases provided by law, and on an insistent demand refusal no longer works — acquaintance becomes a duty.
How are records corrected?
On the substantiated request of the patient or their representative — unless the recording is required by legislation.
What is specific to telemedicine?
Confidentiality is likewise incumbent on the subject, and on the patient's request data are transferred anonymously.
How We Help on Legal.ge
On Legal.ge we build confidentiality regimes for clinics and physicians and defend patients: we audit the grounds of disclosure, structure the access and correction procedure, and assess telemedicine risks. Contact us — your data regime will stand on lawful rails.
