📘 PKV Guide

Your Health Data and Your Insurer: What PKV May Ask, See and Share

Between medical confidentiality and legitimate verification runs a well-marked legal line. What your insurer may ask, whom it may contact — and the consent you control.

Sensitive Data, Marked Boundaries

A health insurer necessarily processes the most sensitive data category there is. German and EU law respond with correspondingly thick walls: GDPR\'s special-category protections, insurance contract law, medical confidentiality — and a consent architecture that keeps you at the controls more than most policyholders realise.

The central instrument: the confidentiality release (Schweigepflichtentbindung). Your doctors owe you secrecy; the insurer may only ask them anything with your consent — and since a landmark constitutional ruling, insurers must offer case-by-case releases instead of demanding one blanket permission for everything.

What the Insurer May Do — and When

PhasePermitted data practice
ApplicationAsk the written health questions; with your consent, query doctors about the declared history
Ongoing contractProcess claims data you submit; no fishing expeditions in your medical life
Claims verificationRequest treatment records relevant to a specific claim — with your (ideally case-specific) release
Large/contested claimsCommission medical reviews; you may insist on per-request consent and see what was asked

What Stays Outside the Insurer\'s Reach

Your Active Rights

GDPR gives you access (a full copy of what the insurer holds — Article 15), correction of errors, and deletion where retention rules allow. You may revoke a blanket confidentiality release and switch to case-by-case handling at any time; claims processing may take marginally longer, which is the honest price of maximal control. The industry\'s shared hint system for risk assessment (HIS) is queryable too — a self-request shows whether you are listed. And every insurer has a data protection officer whose contact sits in the privacy notice; unresolved disputes go to the data protection authority or the insurance ombudsman, both free.

Sensible Practice for Policyholders

Answer application questions precisely — data minimalism never justifies incomplete disclosure, which endangers the contract itself. Prefer case-by-case releases if granular control matters to you. Submit claims through the app rather than email (encrypted, logged, purpose-bound). And once a year, glance at what automatic transmissions you have consented to — tax module, employer confirmations, bonus programmes — and prune what you no longer use.

The Bottom Line

The system\'s architecture is sound: purpose-bound consents, constitutionally shaped release practice, genetic red lines and GDPR\'s toolbox. Your job is smaller but real — disclose honestly where the law demands, consent deliberately where it gives you the choice, and use the access rights that make the walls inspectable.

Frequently Asked Questions

Can my private insurer contact my doctors without asking me?
No — doctors owe you confidentiality, and the insurer needs your release (Schweigepflichtentbindung) to ask them anything. You are entitled to case-by-case releases instead of a blanket permission, and releases are bound to the specific purpose.
Can insurers demand genetic test results?
No. The Gendiagnostikgesetz prohibits insurers from requiring genetic tests or demanding existing results for health insurance. Only very high-sum life or disability policies have narrow statutory exceptions — health cover is not among them.
How can I see what data my insurer holds about me?
File a GDPR Article 15 access request — the insurer must provide a copy of your stored data free of charge. You can also self-query the industry's HIS hint system and involve the data protection officer or ombudsman if something looks wrong.

Compare PKV Tariffs for Your Situation

Our independent advisors help expats and professionals find the right private health insurance — personalised to your age, health, and budget.

Get My Free Quote