Since January 2026, medical practices and hospitals have faced sanctions if they do not populate the ePA. At the same time, key questions concerning technology, access rights and liability remain unresolved.
The electronic patient record (ePA) has been mandatory for medical practices and hospitals to use since October 2025. Since January 2026, non-compliance has carried specific sanctions: cuts to remuneration of up to 2.5 per cent, loss of the TI supplement and, in extreme cases, exclusion from billing. Hospitals without a TI connection lose the telematics supplement. Usage figures are rising noticeably: in December 2025, the ePA recorded 1.2 million log-ins by insured persons and 6.5 million uploaded documents. This still does not answer the question of whether the ePA actually works at scale.
Between mandatory use and technical reality
A survey by the National Association of Statutory Health Insurance Physicians among around 4,500 medical practices presents a mixed picture: 80 per cent of doctors have already uploaded documents, yet dissatisfaction with the technical implementation remains high. Criticism includes the lack of full-text search, an unclear document repository and recurring disruptions to the telematics infrastructure, which cause considerable time demands in day-to-day practice. Representatives of professional associations describe it as an “unsorted collection of PDFs” rather than a genuine management tool.
Open questions with direct relevance for providers
- How disruptions to the telematics infrastructure must be documented in a legally sound manner so that they are recognised as grounds for excuse in sanction proceedings.
- How precisely patients will be able to control in future which treating professionals may view which documents – at present, blocking largely works on an all-or-nothing basis.
- How the planned access of occupational physicians to the ePA will be designed and whether the explicit consent of insured persons will no longer be required for this in future.
- Which nationwide interoperability standards for accompanying digital applications, such as the medication process, will still be made binding.
For hospitals and medical practices, this means that formal obligation and practical functionality are currently noticeably misaligned. Those who focus solely on meeting the minimum requirements risk neither reliably avoiding sanctions nor realising the actual benefit of the ePA for treatment processes.
From a compliance issue to a process issue
Organisations that successfully integrate the ePA into their day-to-day work do not treat it as an isolated IT obligation; they embed it in admissions, ward rounds, diagnostics and discharge as a fixed component of core processes. This also includes providing targeted training for staff and clearly assigning responsibilities for documentation, objection management and evidence of disruptions – before the next quarterly billing cycle is due.
Conclusion: Compliance is not enough; process integration is
The ePA does not become effective simply by being populated, but by being embedded in stable clinical and administrative workflows. As long as technical and legal questions of detail remain unresolved, a robust internal process architecture is the most reliable safeguard – both against sanctions and against friction losses in day-to-day work.