The legal framework of the EESZT

 

 

The National eHealth Infrastructure is operated within a strictly regulated legislative framework. The regulation of the EESZT is ensured on several legislative levels. The data protection regulations related to its records have been laid down in Act XLVII of 1997 on the Processing and Protection of Medical and Other Related Personal Data, which grants the EESZT the necessary rights to lawfully handle (store, process, display etc.) medical and other related personal data. For more than 20 years now, the Hungarian legal system has provided for the empowerment to connect and transfer medical and personal identification data in the healthcare provider network for the purpose of effective medical treatment, public health and epidemiological measures, the organisation of patient pathways and other purposes specified by law.

The availability of treatment and medication history is essential for effective medical treatment.

 

Before, the availability of these data was limited which could jeopardise effective medical treatment. The EESZT provides the necessary tools for this purpose.

Since the data contain personal and medical information, it is protected by a system of the highest, level 5 of security as established by the act on the electronic information security of central and local government agencies.

 

 

 

Providing a legal basis for the functioning of the EESZT, clarifying the circumstances of data management

 

 

Regulation of the organisational issues of the EESZT (appointing the operator, the administrative body managing the register of selfdetermination and the operator of the cross reference storage)

 

  • Conditions, process of joining
  • Rules and scheduling of joining
  • Scheduling the introduction of mandatoryuse of certain services
  • Detailed regulation of certain services

 

 

 

 

 

 

Summary of EESZT regulation

References to legislation in force

Cited pieces of legislation and their abbreviation:

General rules relating to the operation of the EESZT:

Designation of the National Healthcare Service Center:

  • Government Decree No 516/2020 (XI. 25.) by authorisation under Section 38(3) c) of the Health Data Act
    • Section 7(4): Operator of the EESZT
    • Section 7(5): Body managing patient consent records pursuant to Section 35/H of the Health Data Act
    • Section 7(6): Body managing connection code for performance of tasks under Section 35/L of the Health Data Act

Designation of Nemzeti Infokommunikációs Szolgáltató Zrt. as operator:

Operation of the EESZT at the Government Data Center:

Prescription of EESZT joining and data provision as a minimum condition for authorisation, sanctioning

Prescription of EESZT data provision as condition for financing

Option of data management based on voluntary consent:

Mandatory use of the EESZT for data streams between providers:

Identification, user management:

Operational records:

System authorisation procedure:

Suitability of IT system used for EESZT connection:

Downtime, disruption:

Data processing log:

 

Obligation to join:

Group of persons required to join the EESZT:

Conditions and rules of joining:

Joining deadlines:

 

Data provision obligation

Means of providing data:

Initial date for performing the data provision obligation:

Reporting and data provision obligation:

Central event catalogue:

Health documentation records:

Health profile (eProfile):

Electronic prescription (ePrescription):

Electronic prescription of medical devices (eGYSE):

Electronic referral (eReferral) and scheduling appointments:

  • on rules of electronic referral, Section 4/A
  • on rules of scheduling appointments, Section 4/B

Electronic service ordering and scheduling appointments:

Master data management and records:

 

Data access rights:

Identification and authorisation management records, management of access rights:

Availability of directly accessible platform:

Central event catalogue:

Health document records:

Health profile (eProfile):

Electronic referral (eReferral) and scheduling appointments:

  • on rules of electronic referral, Section 4/A
  • on rules of scheduling appointments, Section 4/B

Electronic service ordering and scheduling appointments:

Electronic prescription (ePrescription):

Electronic prescription of medical devices (eGYSE):

Electronic disease registers:

Master Data Publication:

System links:

Documentation forwarding outside of the health care network:

Data verification by the NHIFM relating to wait lists:

Data processing based on voluntary consent:

Retroactive data upload:

Patient consent records, digital patient consent declarations:

Registration of representation right in the EESZT:

 

Data processing:

Online consultation:

Digital Image Forwarding:

Report forwarding:

Documentation forwarding outside of the health care network:

Electronic disease register:

 

Legal regulations relating to data processing:

 

Legal regulations relating to compliance with information security:

  • Information Security Act. Act L of 2013 on the electronic information security of State and local authority bodies
  • Implementing Decree: Decree No 41/2015 (VII. 15.) of the Minister of the Interior on requirements relating to technological security and secure information devices and products defined in Act L of 2013 on the electronic information security of State and local authority bodies, and to classification in security classes and security levels

 

Other relevant legislation: