Skip to content
Home visits in the Nordstemmen area
Technology for seniors & learning

Electronic Patient Record 2026: Setting Up the ePA App

Electronic patient record 2026: set up your health insurer's ePA app, verify your identity, switch NFC on and set the access rights - help at your home.

13 min read Elektronische PatientenakteSmartphoneGesundheitDatenschutzSenioren

Almost every person with statutory health insurance in Germany already has one: the electronic patient record, or ePA for short. Health insurers have now created around 73 million (gematik) records, because since January 2025 the record is created automatically unless you object (Bundesministerium für Gesundheit). More than 100 million (gematik) documents are already stored in them. The catch: many people have a record without ever having seen it - because the path into the app ended at one of the first hurdles. In 2026 a second attempt is particularly worthwhile, because the gematik shareholders have agreed on a substantial expansion of functions: since 1 July 2026 you can configure push notifications, and from mid-July the electronic medication plan starts in pilot regions (gematik). This guide walks you patiently through every step - finding the app, identification, NFC, access rights, hiding documents, representation for relatives. And if you have no smartphone or would simply rather have someone sitting next to you: we come to your kitchen table as part of our tech help for seniors.

Electronic patient record 2026 - setting up the appFind your insurer's app, verify your identity, switch NFC on, set access rights - step by stepFive steps to the ePA app1Load your insurer's appfrom the app store of your health insurer2Verify your identitywith an ID card or a passport3Switch NFC onfor the ID card and the health card4Set access rightspractice 90 days, pharmacy 3 days5Name a representativerelatives may help manage itIs your phone recent enough?20%one in five usersneeds a newer phoneAndroid 14 or iOS 18 (gematik)No smartphone?your insurer's ombuds office helps (BMG)New from July 2026Push notificationsadjustable in the app since 1 JulyMedication plan (eMP)pilot from mid-July 2026Full-text searchfurther stage later in 2026nationwide from early 2027 (gematik)73mrecords created(gematik)100mdocuments stored(gematik)90 daysaccess for the practice(BMG)3 daysaccess for pharmacies(BMG)Your insurer's app - ID verification - NFC on - 90 days of access - a representative for relativesWe set up the ePA app at your home - in the Hildesheim and Leine valley region

Key takeaways

  • The ePA is created automatically for people with statutory insurance - you can object at any time, including afterwards via your insurer or the app (Bundesministerium für Gesundheit).
  • Identification was the biggest hurdle for a long time. Since December 2025 a procedure has been listed in which your electronic ID card or passport at the smartphone is enough - no PIN letter, no trip to a post office (gematik).
  • Nothing works without NFC switched on: the ID card and the health card are held against the phone by radio, and the setting sits in your phone's options.
  • The access rights are yours: practices get 90 days by default, pharmacies three days - both can be shortened, extended or withdrawn entirely in the app (Bundesministerium für Gesundheit).
  • Since 1 July 2026 the apps require at least Android 14 or iOS 18. According to gematik estimates, this affects roughly one in five users (Verbraucherzentrale Bundesverband).
  • We set up the ePA app during a home visit - identification, NFC, access rights, representation for relatives - or explore the topic calmly in a smartphone and privacy course at your home.

What the ePA really is in 2026

The electronic patient record is a personal, digital drawer for your health documents: findings, doctors' letters, discharge letters from hospital, the dental bonus record and the list of redeemed e-prescriptions. The idea behind it is simple: anyone who changes practice today, goes into hospital or seeks a second opinion carries paper back and forth - or documents are simply missing. In the ePA they sit in one place, and you decide who may see them. Since January 2025 health insurers have created the record automatically unless you object; the nationwide rollout began at the end of April 2025 (Bundesministerium für Gesundheit).

The gematik figures for the first year show that the system has arrived in everyday care: around 73 million (gematik) records created, more than 100 million (gematik) documents stored and up to 93,000 (gematik) practices accessing their patients' records every week - in early October 2025 it was about 84,000 (gematik). The medication list is retrieved more than 21 million (gematik) times per week. Since 1 October 2025, use has been mandatory for practices and pharmacies (Bundesministerium für Gesundheit). What matters for you: that obligation applies to the practices - for you as an insured person the ePA remains voluntary.

What is inside

Findings and doctors' letters make up a good half of all documents, joined by discharge letters, dental bonus records and the list of redeemed e-prescriptions (gematik).

Who decides

You do. Whether the record exists at all, who may look inside and for how long - you steer all of it via the app or via your health insurer.

What stays voluntary

Using it is your decision. You can object before the record is created and at any point afterwards, and you can withdraw the objection again (Bundesministerium für Gesundheit).

This is exactly why setting it up pays off, even if you are sceptical about digitalisation in healthcare: the record exists anyway, and practices are filling it. Anyone who does not set up the app still has an ePA - but cannot see what is in it and cannot steer access in any detail. So the app is less an additional digital project than the key to a drawer that already belongs to you.

Finding the right app

The first stumbling block is a small thing that nevertheless stops many people: there is no central ePA app. Every health insurer provides its own. So in your phone's app store you search for the name of your insurer, not for the words "patient record". Make sure the provider really is your health insurer - the stores are also full of health apps that have nothing to do with your record. Some insurers separate the service app from the ePA app, others have built the record into their main app. When in doubt, a call to your insurer helps; the service number is printed on your health card.

Since July 2026 you need a current phone

On 1 July 2026 the telematics infrastructure switched to a more modern encryption method. Since then the ePA and the e-prescription require at least Android 14 or iOS 18 (Verbraucherzentrale Bundesverband). According to gematik estimates, roughly one in five (Verbraucherzentrale Bundesverband) users could be affected. Check your version in the settings under "About phone" or "General" - and update if your device still offers it. If your phone is too old for an update, the way forward is a newer device or the options without a smartphone described further below.
  1. Search the app store for the name of your health insurer and check that the insurer itself is named as the provider.
  2. Look at the system requirement before installing: without Android 14 or iOS 18 the record no longer starts since July 2026 (Verbraucherzentrale Bundesverband).
  3. Install the app and have your health card plus a valid ID card or passport ready.
  4. Pick a calm slot: allow half an hour for the first registration so that nothing happens under time pressure.
  5. For questions, use your insurer's service number from the back of your health card - not a number from an email.

If you are unsure whether your device will play along at all, or whether an update is worth it, we look at it together in the smartphone course at home. And if a new phone really is due, the move need not be a drama: our article on moving to a new device describes how to do it in an orderly way.

Identification: the hurdle that got smaller

This is where most people dropped out in recent years - and for good reason. Because the record holds highly sensitive health data, your insurer has to be certain that it really is you operating the app. For a long time this ran via a PIN letter for the health card, which took weeks and often ended up unused in a drawer, or via a trip to a post office. For the first registration, the Federal Health Ministry names the electronic ID card with PIN or the health card with PIN (Bundesministerium für Gesundheit).

Since December 2025 the situation has been more relaxed: gematik has for the first time listed an identification procedure with confirmed technical security suitability in which you identify yourself with an electronic ID card or passport directly through the smartphone app (gematik). The procedure reads the NFC chip of your identity document and compares it with a capture from the phone camera. The practical effect: no PIN letter, no appointment at a branch, no waiting time. Whether your insurer already offers this procedure is shown in the app or can be checked by phone.

Route to identificationWhat you needGood to know
ID card or passport via the appAn NFC-capable identity document and a current smartphoneListed since December 2025; no PIN letter and no post office (gematik)
Electronic ID card with PINThe ID card and the six-digit online ID PINNamed by the Federal Health Ministry for the first registration (BMG)
Health card with PINAn NFC-capable card and the PIN from your insurerThe PIN arrives by letter; that takes time and has to be requested
Procedure at a branchYour ID document and an appointment in personDependable, but involves a journey and waiting time
Via your health insurerA call or a letter to your insurerSensible if there is no smartphone available

One note from practice: the online ID PIN of your identity card is not the same as the PIN of your health card - nor the one for your bank card. Anyone who has not yet used the ID card online often only has the five-digit transport PIN from the letter of the ID authority and has to change it once into a six-digit PIN of their own. That sounds fiddly, but it is exactly the point at which many people give up. We go through it with you during the home visit so that in the end you hold your own credentials - sorted much as we recommend when setting up a password manager.

Switching NFC on

NFC stands for near-field communication and is the radio technology with which your phone talks to a chip over a few centimetres - the same technology that makes contactless payment possible. For the ePA it is indispensable: both the electronic ID card and the health card are held against the back of the phone during registration. If NFC is switched off, the process breaks off without a comprehensible explanation, and people look for the fault in the wrong place.

  • On Android devices: search the settings for "NFC" or "Connected devices" and activate the switch; often there is also a tile in the quick settings bar.
  • On an iPhone: on current models NFC is permanently active and does not need to be switched on - the app simply prompts you to hold the document against the phone.
  • Take the case off: thick protective cases, card pockets or metal parts noticeably disturb the reading.
  • Find the right spot: depending on the model, the NFC area sits in the upper third of the back - search slowly instead of swiping quickly.
  • Hold still: the ID document should rest there for a few seconds until the app has read the data completely.

The most common mistake when holding the card

Many people place the ID card or health card on the screen - the correct place is the back of the phone. And the second most common reason for a break-off: too much movement. Put the phone on the table, the ID document on top of it and leave both lying there until the app gives feedback. If you like, we practise this as part of our tech help for seniors until it works reliably.

Access rights for practice and pharmacy

Once the app is running, the part that turns the ePA into your record begins. By default, a practice in which you insert your health card receives access for 90 days (Bundesministerium für Gesundheit) - a span that covers a typical course of treatment. Pharmacies get three days (Bundesministerium für Gesundheit) after the card has been read. Both are only default settings: through the app you can shorten or extend the duration or exclude individual providers entirely. The Verbraucherzentrale describes the range as running from a single day to permanent access (Verbraucherzentrale).

90 days for the practice

The default after your card is inserted. If you only see a stand-in doctor once, you can shorten the duration to a few days in the app (Bundesministerium für Gesundheit).

Three days for the pharmacy

After reading your card, the pharmacy may access the record for three days - enough for dispensing, short enough for your peace of mind (Bundesministerium für Gesundheit).

Exclude entirely

Individual providers can be blocked completely. Access then stays denied, even if the card is inserted there.

A second, often overlooked point is the access log. In the app you see which provider viewed or uploaded something and when. That is the real gain in control: you do not have to trust anyone, you can simply look. Since 1 July 2026 this can be combined with push notifications - more on that shortly. Anyone who enjoys keeping digital access tidy will find the right setting for it in our privacy course at home.

Hiding documents individually

Not every diagnosis is every practice's business. That is precisely what hiding is for: you can mark individual documents or whole folders so that only you can see them (Bundesministerium für Gesundheit). For all treating providers the document is then invisible - and without any note appearing that something has been hidden. The Verbraucherzentrale describes it as an all-or-nothing principle: a document is either visible to all authorised providers or to none (Verbraucherzentrale).

Two things hardly anyone knows

First: the billing data from your health insurer lands automatically in a hidden folder that only you can view (Verbraucherzentrale). Second: with particularly sensitive data - on mental illness, an HIV infection or a termination of pregnancy, for example - the practice is meant to point this out to you before storing it, and you can object (Verbraucherzentrale). For genetic examinations, written consent is required.

Hiding deserves an honest weighing-up, and nobody can make it but you: a hidden finding protects your privacy, but it is also missing for the doctor who might have needed it in an emergency. There is no universally valid recommendation here - only your decision, which you can change at any time. We show you where the switch sits and what it does; which documents you hide is up to you.

Representative access for relatives

For many families this is the most important function of all. You can name a representative - relatives, trusted people or legal representatives - who may help manage your record through their own app (Bundesministerium für Gesundheit). Your daughter then sees the discharge letter after a hospital stay, your son can set access rights, and you still keep control, because the representation can be withdrawn at any time.

  • The representation is set up in your ePA app and has to be confirmed in the other person's own app - so both sides need a record that is already set up.
  • The scope can be graded: from pure viewing to full management of your access rights.
  • Withdrawal is possible at any time and takes effect immediately - so the decision is not a one-way street.
  • A representation makes particular sense when a hospital stay is coming up or when your own phone is too old for the app.
  • Talk openly beforehand about what the representative may see - documents that nobody else should see can be hidden.

In practice we often set this up as a pair: an older person and an adult child, both with their phone on the table. It takes a quarter of an hour and takes a lot of pressure out of the topic, because in an emergency someone can look along. If the relatives live further away, it also works with a delay - we prepare everything and the confirmation follows later. What that costs is stated transparently in our price overview.

What to do without a smartphone

Having no smartphone means neither that you have no ePA nor that you have no rights. The record exists anyway, and your rights apply unchanged. The Federal Health Ministry names three routes: the ombuds office of your health insurer, which on request regulates access, accepts objections and issues logs; a desktop client on the computer, for which you need your health card plus a card reader or a GesundheitsID; and representation by a person you trust (Bundesministerium für Gesundheit).

The written route via your insurer is the underrated classic here: an informal letter is enough to restrict access, object to storage or request a log. And in the treatment room, according to the Federal Government, a verbal note is sufficient if a document is not to go into the record (Bundesregierung). So you need to master neither an app nor any technology in order to say no - which is perhaps the most important sentence in this article.

Health data is highly sensitive. Access to one's own record must not depend on technical equipment or financial means.

Lucas Auer, health policy officer at the Verbraucherzentrale Bundesverband

This is exactly why the Verbraucherzentrale Bundesverband is calling for device-independent access - such as assisted services in pharmacies, health terminals and a desktop application (Verbraucherzentrale Bundesverband). Until that is available everywhere, the pragmatic route remains: representation by relatives, the ombuds office for everything in writing - and if there is a tablet in the house anyway, the app can often be set up there too. What that looks like with larger text and calm operation is something we show in the tablet course at home.

Recognising scams around the ePA

Where millions of people are uncertain, fraudsters are quick to arrive. The Verbraucherzentrale warns about forged emails in the name of well-known health insurers that supposedly inform you about the ePA or offer a way to object, while luring you onto rebuilt websites (Verbraucherzentrale). A current example from the phishing radar works with a hard deadline: if the health card is not exchanged by 15 July 2026 (Verbraucherzentrale), it will supposedly be unusable from 1 August 2026 (Verbraucherzentrale). One of the sender addresses used had been registered abroad only days earlier (Verbraucherzentrale) - and had nothing to do with the insurer it named.

  • Time pressure and threats: deadlines such as "by 15 July" or the supposed loss of your health card are meant to push you into a quick click (Verbraucherzentrale).
  • An impersonal salutation: "Dear insured person" instead of your name is a clear warning sign (Verbraucherzentrale).
  • A reference to a supposed change in the law that does not exist - your insurer informs you about real changes by post and in the app.
  • A link instead of the known route: genuine matters are handled in your insurer's app or via the service number on the back of your card.
  • A request for a PIN, ID data or a photo of your health card - an insurer does not ask for that in an email.

No insurer asks for your PIN by email

Move such messages to the spam folder and do not follow any of the requests they contain (Verbraucherzentrale). If you are unsure whether a message is genuine, call your insurer on the number printed on your health card - not on a number from the email. Our guide to spotting phishing and fake calls shows how to unmask these scams in general.

New functions in 2026 and the view to 2027

In September 2025 the gematik shareholders agreed on a substantial expansion of functions that is arriving step by step in 2026 (gematik). Since 1 July 2026 (gematik) the insurers' ePA apps have been receiving updates: in them you can set whether and about what you would like to receive push notifications - for instance when the discharge letter is uploaded after a hospital stay or when a new specialist practice accesses your record (gematik). That turns the silent log into active information, without you having to open the app.

Push notifications

Adjustable in the app since 1 July 2026: you decide yourself what you are informed about - from the discharge letter to a new practice accessing your record (gematik).

Electronic medication plan

In pilot operation from mid-July 2026: the eMP adds dosage details and intake instructions to the medication list and is to replace the paper plan (gematik).

Full-text search

Planned as a further expansion stage: documents will be findable via keywords instead of leafing through long lists (gematik).

The electronic medication plan is the innovation with the greatest everyday benefit, especially for people taking several medicines. It starts from mid-July 2026 in the model regions of Franconia, Hamburg and parts of North Rhine-Westphalia and is part of the digitally supported medication process (Deutsches Ärzteblatt). Unlike the existing medication list, which enumerates redeemed e-prescriptions, it shows the current overall medication with dosage and intake instructions and is intended in due course to replace the federal paper medication plan (Pharmazeutische Zeitung). Over-the-counter products and controlled substances can also be added (Pharmazeutische Zeitung).

Full-text search and the voluntary transfer of data to the health research data centre are planned for later (gematik). Structured documents such as the vaccination record, maternity record and child examination booklet are also under discussion, although the timing for their inclusion has not yet been settled (Ärzte Zeitung). According to the gematik plan, all agreed functions are to be rolled out nationwide by early 2027 (gematik). Anyone who sets up the app now gets these extensions automatically - another reason not to postpone the second attempt.

How we set up the ePA app at your home

All of this can be managed alone. Many people still fail - not for lack of intelligence, but because of a chain of small hurdles: the insurer's app is called something other than expected, the PIN belongs to something else, NFC is off, the ID card lies on the screen instead of on the back. Each single hurdle is tiny, but together they are enough to make someone put the phone aside in frustration. That is why we come to your kitchen table and do it together: find and install the app, handle identification with your ID document, switch NFC on and practise the holding, set the access rights the way you want them, hide documents if you wish and set up representation for relatives.

As a rule this is done in a single appointment. We work on your own device, with your own credentials - you hand nothing over and keep all PINs yourself in the end. If you would like to go deeper, the privacy course at home fits, in which we calmly go through access rights, data economy and spotting false messages. Anyone who would like to feel more confident with their phone in general is right in the smartphone course - depending on the device as an Android course or an iPhone course at home.

We drive out into the Hildesheim and Leine valley region, for example for tech help in Hildesheim - one personal contact, no call centre, and we explain without jargon. There is no ePA that is the perfect solution for every case; what there is, is a record that you understand and steer yourself. If you are working on your technology anyway, two related topics from this week are worth a look: the switch from copper to fibre at home and the question of how to choose a smart door lock safely. And if you are unsure where to begin, send us a short message - we will sort it out together.

Your record, your pace

The ePA is not a test you have to pass. It is a drawer that belongs to you - and you decide how far to open it. Once you have set up the app, you can see what is inside, who has looked in and you can object at any time. That is more control than before, not less.

Sources and studies

This article is based on data from: gematik (ePA for all - figures and data as well as the review after one year: around 73 million records created, more than 100 million documents stored, up to 93,000 practices accessing weekly, more than 21 million weekly retrievals of the medication list; the shareholders' decision on the expansion of functions, push notifications since 1 July 2026, the electronic medication plan from mid-July 2026, full-text search and the research data centre as further expansion stages, nationwide rollout in early 2027; the listing of an identification procedure using an electronic ID card or passport since December 2025), Bundesministerium für Gesundheit (The ePA for all: automatic creation since January 2025 with a right to object, nationwide rollout from April 2025, mandatory use for practices and pharmacies since October 2025, 90 days of access for practices and three days for pharmacies, hiding documents, representative access, the ombuds office and desktop client without a smartphone, identification at first registration), Deutsches Ärzteblatt (New ePA functions are being rolled out step by step: model regions Franconia, Hamburg and parts of North Rhine-Westphalia, schedule up to early 2027), Pharmazeutische Zeitung (Extensive new ePA functions from 2026: the electronic medication plan within the digitally supported medication process, dosage details, over-the-counter products and controlled substances, replacement of the federal medication plan), Ärzte Zeitung (Which new ePA functions are to come in 2026: medication plan, full-text search, possible structured documents such as the vaccination and maternity records with no fixed date), Verbraucherzentrale Bundesverband (Access to the ePA must not fail because of the device: Android 14 or iOS 18 since 1 July 2026, the gematik estimate of roughly one fifth of users affected, the demand for device-independent access), Verbraucherzentrale (Electronic patient record - what it can do and how to use it: access duration from one day to permanent, the all-or-nothing principle when hiding, the hidden folder for billing data, the duty to point out sensitive data, the ombuds office; phishing radar on forged health insurer emails around the health card and the ePA) and Bundesregierung (Questions and answers on the ePA for all: verbal objection in the practice).

Related Articles