77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
External data protection officer for medical practices: obligation to order, costs, reporting line
Data Protection & Privacy

External data protection officer for medical practices: obligation to order, costs, reporting line

30 July 202612 min readBy Lena Vogt
CIVAC

Medical practices process special categories of personal data in accordance with Art. 9 GDPR. Anyone who appoints an external data protection officer needs a clear appointment document, reporting line and 72-hour reporting path. This guide shows duty, costs and workflow in detail.

Medical practices process special categories of personal data in accordance with Art. 9 Para. 1 GDPR, which is why an ordering requirement in accordance with Art. 37 Para. 1 lit. c GDPR in conjunction with Section 38 BDSG applies to almost every practice with employed staff. The practice management is personally liable if this order is missing or only made formally. According to Art. 83 Para. 4 GDPR, fines range up to 10 million euros or 2% of the global annual turnover of the previous financial year. In addition, there are supervisory measures such as orders, activity bans, publications and, in serious cases, professional consequences via the responsible state medical association. From an insurance perspective, the doctor's liability for financial loss is rarely so broad that GDPR fines are covered.

This article explains when the obligation to order applies, what an external data protection officer for medical practices actually does, what costs are realistic and how the reporting line, appointment certificate and 72-hour reporting path are documented in accordance with Art. 33 GDPR in such a way that the examiner of the state data protection authority does not find any gaps. The appointment certificate, signed, filed, verifiable. We show the choice between internal ordering with platform support and external ordering to an officer-as-a-service, both models with identical depth of evidence and uniform reporting line to the practice management. Anyone who wants to transfer the practice from formal fulfilment to verifiable substance will find the complete path in the following nine sections, including legal bases, cost framework, reporting channels and handover rules when changing providers.

Key Takeaways

  • According to Article 37 Paragraph 1 Letter c of the GDPR and Section 38 of the Federal Data Protection Act, a medical practice must order an order as soon as core activities or staffing levels process health data on a regular basis.
  • External order typically costs 180 to 480 euros per month and includes reporting line, templates, audits and 72-hour reporting path.
  • Without an appointment certificate, proof of training and a processing directory, there is no ability to supervise, regardless of whether the order is made internally or externally.

When a doctor's office needs to order

The obligation to order for medical practices results from two regulations at the same time. Art. 37 Para. 1 lit. c GDPR requires a data protection officer if the core activity consists of the extensive processing of special categories of personal data. According to Article 9 Para. 1 GDPR, health data clearly falls under this, as does genetic and biometric data for clear identification. In addition, Section 38 Paragraph 1 BDSG applies, according to which every person responsible with at least 20 people who are constantly involved in the automated processing of personal data must appoint a DPO. In practice, this applies to most group practices, MVZs and professional practice groups, and often also to individual practices with three to four MFAs, as long as each of them works with practice software, billing systems and patient portals. Part-time employees also count fully, provided they regularly carry out automated processing.

The supervisory authorities have assessed medical practices more strictly since the BfDI activity report 2026. The appointment certificate, contact details for the responsible state representative, processing directory in accordance with Art. 30 GDPR, technical and organisational measures in accordance with Art. 32 GDPR and the reporting path in accordance with Articles 33 and 34 GDPR are checked. Anyone who appoints an external data protection officer outsources operational responsibility, but retains ultimate responsibility as the person responsible within the meaning of Art. 4 No. 7 GDPR. CIVAC documents the order via an appointment certificate that can be issued, stores it in the workspace and makes the reporting line to the practice management traceable in the system. The supervisor does not check goodwill, but rather timestamps, versions and signatures. Anyone who understands this builds data protection like software, not like a file folder in the back room. It is precisely this ability to supervise that distinguishes formal appointments from audit-based perceptions. A conscious decision against the order should be made in writing with justification, scope of processing and personnel list, otherwise the formal legal violation is considered proven in case of doubt.

What an external DPO actually does

An external data protection officer in accordance with Art. 39 GDPR informs and advises the practice and its staff, monitors compliance with the GDPR, the BDSG and other data protection regulations, advises on data protection impact assessments in accordance with Art. 35 GDPR and works with the supervisory authority. In a doctor's practice, this specifically means: setting up and maintaining the processing directory, checking order processing contracts with the billing office, practice management system provider, IT service provider and hosting provider, training the practice team at least once a year and processing requests from those affected in accordance with Articles 15 to 22 of the GDPR. In addition, this includes statements on new technologies such as video consultations, online appointment booking, practice apps or AI-supported preliminary recording of findings as well as support for the telematics infrastructure connection.

In an emergency, the DSB will report data breaches in accordance with Art. 33 GDPR within 72 hours of becoming aware of it. Deadline begins as soon as we become aware of it. CIVAC's Workspace contains 490 ready-to-use audit templates, including reporting path, data subject request, AV contract check and risk analysis. The practice licences the workspace for its internal representative or has the order handed over to a CIVAC data protection officer. Licence the workspace for your internal representatives or have our representatives order it. Both models lead to the same appointment certificate, both are managed via the same platform, and both result in an auditable evidence path without breaks between email storage, file folders and software. The platform is a compliance platform and officer-as-a-service with EU data residency and ISO/IEC 27001:2022-ISMS in the background. This means the practice remains operational when the supervisor calls, and the representative can concentrate on the technical assessment instead of searching for templates, versions or addresses of the responsible state authority. In addition, the external DPO takes over the preparation of the annual supervisory communication, so that the practice management only has to approve the process instead of creating texts and attachments themselves.

Obligation to order in detail: individual practice, group practice, MVZ

The supervisory authorities differentiate between forms of practice. A single practice with one doctor and two MFA processes health data regularly, but usually not to an extent that exceeds the threshold of Section 38 BDSG. However, once the entire staff is working with practice management software, each employee is considered to be constantly engaged in automated processing, quickly reaching the 20-person threshold in larger practices. Regardless of this, Art. 37 Para. 1 lit. c GDPR applies to the concept of core activity, since health data forms the core of every medical activity and is not just a by-product. A small individual practice without staff may make an appointment unnecessary, but should document the decision against an appointment.

A group practice according to Section 33 Para. 2 Ärzte-ZV is jointly responsible for data protection according to Art. 26 GDPR. The agreement on shared responsibility must be in writing and regulate the distribution of tasks, in particular the exercise of the rights of those affected. An MVZ in the legal form of a GmbH is regularly obliged to appoint, as the threshold according to Section 38 BDSG is almost always exceeded and the group structure also triggers increased requirements for reporting channels. For each of these constellations, the appointment certificate differs between the contracting parties; the scope of duties in accordance with Article 39 of the GDPR remains identical. CIVAC provides a verified template for each legal form so that the order is formally completed in 48 hours. There are also appendices on the distribution of tasks, the replacement rules in the event of vacation and the documented reporting line. Anyone who carries out the order properly will rule out the most common complaints from the supervisory authorities in the first 14 days and lay the foundation for a reliable data protection management system in everyday practice.

Costs and contract models 2026

Costs for an external data protection officer in a doctor's practice will range between 180 and 480 euros per month plus VAT in 2026, depending on the size of the practice, number of processing activities and depth of service. A single practice without special telematics configuration typically starts at 180 to 240 euros per month, a MFA-strong group practice with online appointments, app connection and video consultations costs 320 to 420 euros, and an MVZ with a branch structure or outpatient operating areas costs 380 to 580 euros. Hourly fees in project business without a permanent mandate are rarely less than 180 euros net per hour, but then do not cover availability, ongoing maintenance or emergency response to a data breach. Flat-rate offers under 100 euros usually cover neither training, processing directory nor reporting path and are ineffective in the audit.

CIVAC handles the mandate at a fixed price and makes all services visible in the workspace: appointment certificate, proof of training, processing directory, AV contract storage, reporting path, data subject request mailbox. Licence the workspace for your internal representatives or have our representatives order it. Both models lead to EU data residency and documented proof of order. Anyone who relies on annual flat rates without audit templates, reporting lines and defined response times is buying formal fulfilment without substance. In case of doubt, the supervisory authority does not ask for the contract, but rather for tickets, certificates and proof of training. The CIVAC SLA guarantees orders within two working days instead of the classic two to six weeks lead time. In addition, there is annual cost clarity without hidden surcharges for additional processes or training repetitions because these components are already included in the fixed price and can be accessed in the workspace. The comparability of offers always requires a look at the hours included, the SLA and the handover rule at the end of the contract.

Reporting line and appointment certificate clearly documented

According to Art. 38 Para. 3 GDPR, the data protection officer must report directly to the highest management level. In the doctor's practice, this means the practice management or the management of the MVZ. The reporting line must be set out in writing and whether it is actually adhered to in everyday life is checked. Anyone who only formally reports to the practice management, but in practice actually reports to the practice manager, risks a complaint about insufficient independence. The appointment certificate regulates the contracting parties, time of order, notice periods, remuneration, liability, obligation of confidentiality in accordance with Section 203 of the German Criminal Code (StGB) and the requirements for professional qualifications in accordance with Article 37 (5) of the GDPR. The express note that the DPO may not be dismissed or disadvantaged because of his duties should also be included in every appointment certificate.

The contact details are reported to the responsible state data protection officer in accordance with Art. 37 Para. 7 GDPR immediately after the order. If the practice fails to take this step, there will be no mandatory proof, even if the DPO has been properly appointed. CIVAC creates the appointment certificate, stores it in the DSB role in the workspace and submits the mandatory reports to the supervisory authority, including status checks. Others run compliance like a filing cabinet. We run it like software. The auditor calls, the evidence is ready. The reporting line is supplemented by a documented response time, a replacement policy in the event of vacation and illness and an annual activity report from the DSB to the practice management, which also serves as an audit template for the supervisory authority. This creates a controllable compliance path from a formal obligation with clearly assigned responsibility, documented escalation logic and verifiable deadlines for training, directory updates and AV contract review. Anyone who keeps the reporting line in writing, technically and factually congruent avoids the most common supervisory question about independence and immediately gains credibility in the event of an audit.

72-hour reporting path for data breaches

Data breaches in medical practices are no exception, but routine: lost USB sticks with patient data, incorrectly sent doctor's letters, phishing emails to MFA accounts, theft of a practice laptop, mistaken access to other people's patient files by staff who are not authorised to access them, incorrect email distribution lists for patient communication. According to Article 33 Para. 1 GDPR, each of these incidents triggers an obligation to report within 72 hours of becoming aware of it if there is a risk to the rights and freedoms of natural persons. In the case of special categories according to Art. 9 GDPR, this threshold is practically always exceeded, which is why reporting is the rule in the doctor's practice, not the exception. If the risk is high, those affected must be notified in accordance with Art. 34 GDPR.

The reporting path must be documented, rehearsed and auditable in practice. If you have to look for a template in an emergency, you lose valuable hours. In the CIVAC workspace, the 72-hour reporting path is available as a tested audit template, including an escalation checklist, a reporting form for the responsible state authority, a template for notifying those affected in accordance with Art. 34 GDPR and a logging function for the knowledge timestamps. Audit-proof, documented, Section 33-proof. In an emergency, the practice can arrive at a decision-making situation within two hours, instead of having to reconstruct it later. This ability to escalate distinguishes a dutifully appointed function from a formal appointment without substance. In addition, the system documents the decision against reporting if, after due consideration, the risk does not require reporting, which is just as relevant to the audit as the positive report itself. This negative documentation is a frequent area of ​​supervisory review. In addition, there is the downstream lessons-learned analysis, which in practice triggers concrete measures such as authorisation adjustments, training appointments or additional encryption.

Training, TOMs and processing directory

Three operational components determine the ability to supervise a medical practice. Firstly, the training of staff in accordance with Article 39 Paragraph 1 Letter b of the GDPR, to be carried out at least once a year, with a list of participants, signatures and a catalogue of topics. The focus is on confidentiality, handling telephone and email inquiries, telematics infrastructure, patient rights, secure file management and dealing with data breaches. Secondly, the technical and organisational measures in accordance with Art. 32 GDPR, documented according to risk class, with specific measures for access control, access control, input control, order control, availability control and separation requirement. Thirdly, the processing directory according to Art. 30 GDPR, which records every processing activity from patient admission to communication of findings to file archiving, with legal basis, retention periods and recipient categories.

In practice, it is often not awareness, but rather a uniform source of truth that is missing. Training certificates are in the personnel folder, AV contracts in the email inbox, TOMs in the outdated Word document from 2022, processing directory as Excel without versioning. CIVAC bundles these artifacts into a single workspace per practice. The FAQ collection answers the 40 most frequently asked supervisory questions, the Role overview shows which other officers are also suitable in a practice, from hygiene officers to fire protection officers. The platform links training records to the processing directory so that a supervisory request for a processing activity immediately provides the associated training, TOMs and AV contracts. This shortens the response time in the audit from days to minutes and significantly reduces the burden on practice management in day-to-day business. Without this link, every supervisory inquiry remains a research project lasting several days. Audit-proof, documented, Section 30-proof. The platform also saves the version statuses of the training slides, so that the specific status of the training material on the training date can be verified in the audit and not just the date itself.

Risks of choosing the wrong DPO

The biggest risks when choosing an external data protection officer for a medical practice lie not in the appointment certificate itself, but in the subsequent practice. A DPO without industry expertise in the healthcare sector applies general GDPR logic, but overlooks special regulations such as Section 203 StGB on confidentiality, Section 630f BGB on documentation requirements, telematics infrastructure regulations, the Patient Data Protection Act and special regulations under statutory health insurance law. A DPO without a response time SLA is unreachable in an emergency; the 72-hour reporting path fails not because of the template, but because of the telephone not being picked up. Anyone who relies on the cheapest provider in the competition will buy the most expensive omission in the audit. In addition, the DPO often lacks verifiable further training, which is required under Article 37 Para. 5 GDPR and Recital 97.

A DPO without a platform delivers documents via email that cannot be found in any audit. A DPO without training leaves the practice to its own devices; a DPO without supervisory contact shys away from letters from the authorities. The consequences are fines, damage to your image and, in the worst case, questions about approval from the state medical association. CIVAC works as acompliance platform and officer-as-a-servicewith defined response times, EU data residency, ISO/IEC 27001:2022-ISMS and 93 controls in the background. The external order is transparent in the workspace and not hidden in the email tray. Anyone who commissions must check, not hope. The appointment certificate is the beginning, the evidence path is the substance. A reputable pre-selection checks industry references, documented response times, ISO certificates of the provider and the ability to hand over at the end of the contract, ideally in the form of a complete data export. Anyone who documents these four criteria before concluding a contract will exclude the most common supplier risks during the selection process and make the decision comprehensible in the audit.

Turn reading into an assignment

A medical practice does not need any additional burden on the practice management, but rather a relieving, verifiable data protection function with a clear reporting line. The decision between internal and external appointments follows the question of whether the practice team can fulfil the obligations under Art. 39 GDPR with the necessary independence, time and industry expertise. Anyone who orders internally needs a platform that structures templates, proof of training and reporting paths. Anyone who orders externally needs a partner with defined response times, EU data residency and verifiable documentation. Both are legitimate, both must be substantial, both must result in the same evidence path in the audit.

CIVAC supplies both models from a single source. Licence the Workspace for your internal representatives or have our representatives order it. The order is typically completed in two working days, instead of the classic two to six weeks lead time. 25 representative roles are live, 490 audit templates are ready for use, 93 controls according to ISO/IEC 27001:2022 secure the platform. Turn reading into an assignment. Write to info@civac.de or use the contact form on civac.de for an initial assessment of your practice. Within two working days, you will receive an appointment certificate template, a specific cost item and a suggested reporting path, tailored to the type of practice, staff size and practice software used. This turns an abstract obligation into a concrete, verifiable solution with a clear schedule and handover plan to the supervisory authority. Anyone who takes this step today will have a verifiable appointment certificate, an activated reporting path and a documented reporting line in two working days. This means that the most common supervisory complaint at medical practices is resolved in the first week. CIVAC takes care of ongoing care with documented response times, annual training and automatic reminders of follow-up obligations, so that the practice concentrates on core medical services.

FAQ

Does my individual practice have to appoint a data protection officer?

In most cases, yes. As soon as you regularly process health data and the staff works with practice software, Art. 37 Para. 1 lit. c GDPR applies to the term core activity. Section 38 BDSG also applies to 20 people who are constantly involved in automated processing at the latest. A legally secure individual case review should be carried out before the appointment and the reasons should be documented.

How much is the fine for missing or incorrect orders?

According to Art. 83 Para. 4 GDPR, fines of up to 10 million euros or 2% of the global annual turnover of the previous financial year are threatened. In practice, supervisory authorities impose amounts of between 5,000 and 50,000 euros on medical practices, depending on size, intent, severity of the breach of duty and proven willingness to cooperate. Intentional failure to do so makes the sanction significantly more expensive.

Can my practice manager also be a data protection officer?

No, that would regularly be a conflict of interest according to Art. 38 Para. 6 GDPR. The practice manager decides on processing activities herself and cannot independently control herself. On the other hand, external orders or internal MFA in a non-managerial role who report directly to the practice management, are given a sufficient time budget, are verifiably trained and do not also have IT responsibility are suitable.

What response time must an external DPO provide in an emergency?

There is no legal deadline for accessibility, but Art. 33 GDPR requires reporting within 72 hours of becoming aware of it. CIVAC contractually guarantees a two working day response time to standard inquiries and defined emergency availability for data breaches, documented in the SLA of the appointment certificate, traceable in the workspace and with clear representation rules in the event of vacation as well as a defined escalation level.

How do I change the external DPO without a compliance gap?

The old order remains effective until the new appointment certificate is issued. The processing directory, training certificates, AV contracts and open processes with a documented time stamp and version history are handed over. CIVAC imports these artifacts into the workspace and reports the change to the responsible state authority within 14 days in accordance with Art. 37 Para. 7 GDPR, so that no documentary vacuum is created and the reporting line continues seamlessly.

Do I need other representatives for my practice in addition to the DSB?

Often yes. A medical practice also regularly requires a hygiene officer in accordance with the state hygiene regulations, an occupational safety specialist in accordance with ASiG, a fire protection officer for practice sizes and a company doctor in accordance with DGUV regulation 2. The role overview on civac.de shows all 25 functions, their legal triggers, typical hourly budgets and possible bundling via the platform with a common reporting line.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles