Request patient records

Praxis Bennewitz – for former patients

To prevent misuse, we first confirm your email address. Afterwards you can submit the actual request.

Usage notes

How it works

  1. You confirm your email address via a link we send you. This prevents anyone from submitting a request in your name.
  2. You enter your details and upload a photo or scan of your ID, so we can be sure it is really you making the request.
  3. Before anything leaves your computer, all your details – and your ID document too – are placed directly in your browser into a digital, sealed "envelope".
  4. Only the IT service provider managing the former practice's patient records holds the matching "key" for this envelope. No one else can open it – not even the server this form runs on.
  5. As soon as the sealed envelope reaches us, we send you a confirmation: your request has arrived.
  6. The IT service provider opens the envelope only on their own computer, processes your request, and then sends you the documents by post.
  7. You can check the processing status at any time via the link in our emails.

What exactly does "encrypted" mean?

Imagine your details are placed in an envelope and sealed with a padlock for which only a single key exists. Only the IT service provider holds that key. The padlock itself sits openly on our website so any browser can seal the envelope – but only whoever holds the matching key can open it again.

What does our server see?

Our server never sees your name, date of birth, address, or ID document in plain text. It only forwards the already-sealed envelope – the way a postal service only carries the envelope without being able to read the letter inside.

Transparency

After submitting, we can show you on the confirmation page exactly what was transmitted to us in encrypted form, along with a detailed log of every step. This log is generated exclusively in your browser and stored nowhere – we have no access to it ourselves.

Why this portal?

You might wonder: why not just send an email? The answer has to do with the security of your health data.

An email is like a postcard

A normal email isn't transported like a sealed letter – it's more like a postcard. On its way from your computer to our inbox, it passes through several relay points on the internet – different servers that each forward the message onward. At every one of these stops, the content can in principle be read.

Why "encrypted" email is often still not secure enough

Many email providers at least secure the transmission between servers – similar to a courier transporting the postcard in a locked vehicle. But this isn't guaranteed: this protection is technically optional and can fail or be bypassed without you or us noticing. And even when the transmission was secured, the email sits unencrypted again once it reaches its destination – the recipient's mail server. Anyone with access to that mailbox, for example through a hacked account, can then read it.

Why we therefore don't send documents by email

Patient records contain especially sensitive health data. According to Germany's Federal Commissioner for Data Protection, only encryption that runs continuously from sender to recipient ("end-to-end") is acceptable for the electronic transmission of such data – meaning only you and the IT service provider can read the content, no one in between. A normal email does not provide that. That is why we never send patient records by email, and why we do not accept requests submitted by email either.

That's why this form exists

Your details are already end-to-end encrypted in your browser before anything is transmitted at all – so the continuous encryption required for data protection is in place from the very start. You can find out exactly how this works under "Usage notes".