In patient centered care, patients are treated by multiple healthcare personnel (HCP) in different organizations, and this requires patient sensitive data to be available in different systems. Access to data while simultaneously safeguarding patient privacy is a complex area. This article aims to describe the obstacles of access to health data between different stakeholders. Findings: We have reviewed Norwegian laws and regulations regarding documentation, confidentiality and access to data for HCP. These acts call for a system for identification of the HCP and need for that HCP to access those data across organizations, and this is considered difficult to provide from a technical perspective. Conclusion: Todays legislation supports access to data across different organizations with the aim to provide healthcare, but the requirements imposed by the law, is difficult to solve from a technical perspective.
Keywords: Data access; Data protection; GDPR; Healthcare governance; electronic health records.