PDF for medical records: privacy and security
2 min read·25 July 2026
Medical documents as PDF contain sensitive personal data. Learn how to correctly secure, share and archive them in compliance with GDPR.
GDPR and medical PDFs
Medical data is special category personal data under GDPR. It may only be processed and shared with explicit consent of the patient or on a legal basis. When sending or receiving medical documents as PDF, extra care requirements apply: secure transmission (encrypted email or secure portal), limited access (no CC to unnecessary parties), and retention obligation (medical records: 20 years in many EU countries).
Secure medical PDFs
Use the Protect tool on PDFrust to add a password to medical PDFs when sending via email. Choose a password you share via a separate channel (e.g. by SMS). Never use the patient's name or date of birth as a password.
Flatten PDF
Try for free — no account needed
Redact sensitive information
If you want to share a medical report for a second opinion or administrative purpose where not all medical details are needed, redact the sensitive passages. Use the Redact tool on PDFrust to black out national ID numbers, medication data or diagnoses. Redaction is permanent — the text is no longer visible or copyable.
Signature for medical consent
Consent forms for medical treatments are increasingly signed digitally. Add a digital signature via the Sign tool. For medical consent forms a simple electronic signature (SES) is legally sufficient in most cases — the patient signs in the presence of a staff member.
Archiving medical records
Medical records must be retained for 20 years in many countries. Store them in a secure folder with restricted access, preferably encrypted on a secure server. Use PDF/A format for long-term archiving (this is an ISO standard for archiving that guarantees the document is still readable in 20 years). Make an annual backup on a separate medium.
Related tools