Skip to content
Alonso Sala
CRIMINAL LAWYERS
Legal Analysis

Unlawful Access to Medical Records: Art. 197.2 CP in Spain

August 12, 2026Updated: 

Art. 197.2 of the Spanish Criminal Code (CP) punishes with 1 to 4 years in prison and a fine of 12 to 24 months anyone who, without authorisation, accesses by any means reserved personal or family data of another held in files or on computer, electronic or telematic media, or in any other public or private archive or register, or who seizes, alters or uses such data. The medical record is the paradigm case, and the offence is complete on consultation, with no need for the data to be disclosed. Because health is one of the categories listed in Art. 197.5 CP, the penalties are imposed in their upper half: 2 years and 6 months to 4 years in prison and a fine of 18 to 24 months. Where the offender is the person in charge of or responsible for the file, Art. 197.4 CP raises the range to 3 to 5 years in prison, which becomes 4 to 5 years with the health aggravation; disseminating, disclosing or transferring the discovered data to third parties is punished under Art. 197.3 CP with 2 to 5 years in prison, and profit-seeking conduct affecting health data brings the range of Art. 197.6 CP to 4 to 7 years in prison. Where a public authority or officer accesses the data by taking advantage of their position, Art. 198 CP imposes the corresponding penalties in their upper half and, in addition, absolute disqualification for 6 to 12 years. Proceedings require a complaint by the aggrieved person or their legal representative (Art. 201.1 CP), subject to the exceptions in Art. 201.2 CP.

Need help with your case? Talk to a criminal defense lawyer at Alonso Sala.

Looking up the medical record of an acquaintance, a former partner or a public figure, with no care relationship to justify it, is one of the situations that most often ends in criminal proceedings for disclosure of secrets. As lawyers in unlawful access to medical records, we set out the applicable regime from both positions: that of the professional under investigation and that of the patient whose record was consulted.

The Conduct Under Art. 197.2 CP Applied to Medical Records

Art. 197.2 CP punishes, with the same penalties as the basic offence — one to four years in prison and a fine of twelve to twenty-four months — anyone who, without authorisation, seizes, uses or modifies, to the detriment of a third party, reserved personal or family data of another held in files or on computer, electronic or telematic media, or in any other type of public or private archive or register; and it adds that the same penalties apply to anyone who, without authorisation, accesses such data by any means and to anyone who alters or uses it to the detriment of the data subject or a third party.

A medical record fits that subject matter without difficulty: it is an archive, computerised or not, holding reserved personal data of a third party. The relevant conduct in these cases is the access limb, which is complete on consultation. No seizure of any document is required, nor extraction, nor disclosure: opening the file of a patient outside one's own duties completes the offence. This provision must also be distinguished from unlawful access to information systems under Art. 197 bis CP, which requires breaching the security measures put in place to prevent access — something that does not happen when a professional enters the system with their own valid credentials. For the full map of the provision, see our guide to Art. 197 CP.

One detail of the wording has defensive value. The requirement that the conduct be carried out to the detriment of a third party, or of the data subject or a third party, attaches grammatically to the limbs of seizing, using, modifying and altering; the access limb appears without that clause. Whether detriment must also be present in mere access is a contested question, and raising it is essential where the consultation was isolated, left no trace of any subsequent use and had no effect at all on the patient.

The Aggravation for Health Data (Art. 197.5 CP)

Art. 197.5 CP provides that where the acts described in the preceding paragraphs affect personal data revealing ideology, religion, beliefs, health, racial origin or sexual life, or where the victim is a minor or a person with a disability in need of special protection, the penalties are to be imposed in their upper half. Health is expressly listed, so in access to a medical record the aggravation is the rule rather than the exception.

The effect is arithmetical and should be borne in mind from the moment of classification. Applied to the range in Art. 197.2 CP, the upper half is two years and six months to four years in prison and a fine of eighteen to twenty-four months. The aggravation depends on the nature of the data, not on the motive for the access or the later use made of it: it is enough that what was consulted reveals the person's state of health — diagnoses, admissions, treatments, test results or the very fact of being treated in a particular service. That is why the argument is rarely about whether Art. 197.5 CP applies, and almost always about whether there was authorisation to access the record.

The Person in Charge of or Responsible for the File (Art. 197.4 CP)

Art. 197.4 CP punishes the acts covered by paragraphs 1 and 2 with three to five years in prison where they are committed by the persons in charge of or responsible for the files, computer, electronic or telematic media, archives or registers, or where they are carried out through the unauthorised use of the victim's personal data. It adds that, if the reserved data has been disseminated, transferred or disclosed to third parties, the penalties are to be imposed in their upper half. Combined with the health aggravation, the resulting range is four to five years in prison.

This is where one of the most frequent technical battles is fought. Prosecutors tend to equate anyone holding credentials to the clinical information system with the person in charge of or responsible for the file, and that reading goes beyond the provision: the subtype describes a position of control over the archive — whoever decides on it, administers it or keeps it — not that of someone who simply uses it to do their job. Applying Art. 197.4(a) CP to every professional with a user profile turns the aggravated subtype into the general rule and empties Art. 197.2 CP of content, and that objection must be raised in the defence pleadings before the sentencing range moves three years upward.

The Officer Who Abuses Their Position (Art. 198 CP)

Where access occurs in a public facility, Art. 198 CP comes into play: an authority or public officer who, outside the cases permitted by law, without legal cause arising from an offence, and taking advantage of their position, carries out any of the conduct described in the preceding article is punished with the penalties respectively laid down there, in their upper half and, in addition, with absolute disqualification for a period of six to twelve years.

The provision does not apply merely because someone works in a public hospital. It requires the status of public officer within the meaning of Art. 24.2 CP — participating in the exercise of public functions by direct operation of the law, by election or by appointment by a competent authority — and, above all, an actual abuse of the position: the official capacity must have been the instrument of the access. There is a further point the defence must watch at the classification stage: both Art. 198 CP and Art. 197.5 CP require the penalty to be imposed in its upper half, and that elevation cannot be counted twice over the same range. Where both apply, the specific weight of Art. 198 CP lies mainly in the absolute disqualification, which is the consequence that really decides a professional career.

Access, Disclosure and the Boundary with Arts. 199 and 417 CP

Accessing and disclosing are different acts governed by different provisions. If the discovered data is disseminated, disclosed or transferred to third parties, Art. 197.3 CP imposes two to five years in prison — three years and six months to five years in its upper half under Art. 197.5 CP — and its second paragraph punishes with one to three years in prison and a fine of twelve to twenty-four months anyone who, knowing of its unlawful origin and without having taken part in its discovery, carries out that dissemination: this is the charge that reaches whoever receives the data and passes it on.

Where there was no improper access but rather disclosure of what was legitimately known, the classification changes entirely. Art. 199.1 CP punishes with one to three years in prison and a fine of six to twelve months anyone who discloses another's secrets learned by reason of their trade or employment relationship, and Art. 199.2 CP aggravates the response for a professional who, in breach of their duty of professional secrecy, divulges another person's secrets: one to four years in prison, a fine of twelve to twenty-four months and special disqualification from that profession for two to six years. Where the discloser is an authority or public officer and the secrets are those of a private individual, Art. 417.2 CP provides for two to four years in prison, a fine of twelve to eighteen months and suspension from public employment or office for one to three years.

The Supreme Court clarified the dividing line in the judgment resolving cassation appeal 3274/2023, of 26 March 2026: the key lies in how the information was accessed, because Art. 197 CP presupposes unauthorised access whereas Art. 417 CP punishes a person who discloses data they obtained legitimately by reason of their office. Transposed to healthcare, a professional who consults the record of a patient they are not treating falls under Art. 197 CP; one who learns the information through their care duties and later repeats it outside them falls under Arts. 199 or 417 CP. The distinction is developed in our analysis of disclosing secrets versus breaching official secrets.

When Data Protection Proceedings Become a Criminal Case

Almost every improper access to a medical record begins in the administrative sphere: an internal audit, a complaint by the patient to the provider, or a complaint to the Spanish Data Protection Agency. That route and the criminal one follow different logics. Sanctioning proceedings are normally directed against the data controller — the hospital, the insurer or the public administration — and examine whether access profiles were proportionate, whether audit trails existed, whether least-privilege policies were in place and whether compliance was effectively monitored. Criminal liability, by contrast, is individual and attaches to the specific person who consulted the data.

The move from one route to the other occurs when the facts meet the elements of the offence: unauthorised, intentional access to reserved data of an identified person. A system configuration failure, an access profile poorly scoped by the organisation or the absence of an audit log are shortcomings of the data controller, not offences committed by those who suffer them. Where evidence of a criminal offence appears, the precedence of the criminal courts means the sanctioning procedure gives way until the case is resolved, and the bar on double punishment operates where there is identity of subject, facts and legal basis. In practice the most significant consequence is procedural: what the professional states or admits in the administrative file or in the provider's internal audit may end up in the criminal case, so both fronts must be coordinated from the very first request for information.

The Aggrieved Person's Complaint and Its Exceptions (Art. 201 CP)

Art. 201.1 CP provides that, in order to proceed for the offences in this Chapter, a complaint by the aggrieved person or their legal representative is required. This is a procedural requirement and not a mere formality: without the patient's complaint, proceedings cannot be opened on this basis. Art. 201.2 CP disapplies that requirement for the acts covered by Art. 198 CP — the officer who abuses their position — and also where the offence affects the general interest or a plurality of persons, or where the victim is a minor or a person with a disability in need of special protection. The plurality-of-persons exception is decisive in the mass-access cases detected by audit, where action of the court's own motion does not depend on each patient complaining. Art. 201.3 CP adds that the pardon of the victim or their legal representative extinguishes the criminal action, without prejudice to Art. 130.1.5, second paragraph.

For a patient who suspects their record has been consulted, the order of steps matters. It is advisable first to approach the provider, as data controller, to obtain the information on accesses logged against their medical record, identifying users, dates and modules consulted, because that trail is the core evidence in the proceedings and is retained only for limited periods. With it, a complaint can be filed and appearing as a private prosecutor assessed, which allows the patient to propose investigative steps — notably computer forensic evidence on the logs — and to pursue the civil claim: Arts. 109 and 116 CP require compensation for the damage and loss caused by the offence, which covers the non-pecuniary harm flowing from the spread of a person's health status through their working or personal environment.

Professional Consequences and Limitation

For a clinician or an administrative employee, the prison sentence is often not the most feared consequence. Art. 56.1.3 CP allows the court, for prison sentences of under ten years and having regard to the seriousness of the offence, to impose special disqualification from public employment or office, a profession or a trade as an accessory penalty where those rights had a direct connection with the offence committed, a connection that must be expressly established in the judgment. To this are added the special disqualification of two to six years under Art. 199.2 CP in disclosure cases and the absolute disqualification of six to twelve years under Art. 198 CP. Alongside the criminal case, the provider's or the administration's own disciplinary proceedings also run, with their own time limits and their own classification of the misconduct, which is not automatically governed by the outcome of the criminal case.

Limitation is governed by Art. 131.1 CP, which looks to the maximum penalty attached to the offence. For Art. 197.2 CP, with a maximum of four years in prison, and for Art. 197.4 CP, with a maximum of five, the period is five years, because the ten-year rule requires the maximum penalty to exceed five years. The period rises to ten years where the maximum exceeds five without exceeding ten, as happens under Art. 197.6 CP — acts carried out for profit that also affect health data — punishable by four to seven years in prison. The difference matters in older accesses that an audit brings to light years later.

Lines of Defence and the Audit Trail as Evidence

The defence is built on the basis for access, which is the normative element of the offence. It must be documented whether there was a care relationship — including continuity of care, referrals, on-call cover, review of an emergency episode or validation of a prescription — whether the data subject consented to the consultation, or whether there was authorisation grounded in healthcare regulations or the provider's internal protocols. Once the basis is established, the requirement of acting without authorisation falls away and the conduct sits outside Art. 197.2 CP.

The second line is the subjective element. The offence is intentional and has no negligent form, so accidentally opening a file, access resulting from a search on matching names, or access produced by the configuration of the system itself do not constitute it. If the professional acted in the belief that they were authorised, Art. 14 CP is the route: an unavoidable mistake as to a fact constituting the offence excludes criminal liability and, where avoidable, the offence would be punished as negligent where applicable — which here means no liability at all, since no negligent form exists.

The third line is evidential. The prosecution almost always relies on the audit trail of the clinical information system, and that record establishes a session, not necessarily a person: credentials shared across shifts, terminals left open in common areas, unclosed sessions and the informal passing on of passwords are organisational realities that open a genuine space of doubt as to authorship. It is also worth examining exactly what the log proves — whether it records the mere opening of a screen or the actual viewing of content — its integrity and chain of custody, the reliability of the timestamping system, and the possibility of proposing rebuttal computer forensic evidence. To this are added, in the limbs that require it, the argument on detriment and, in every case, confining the Art. 197.4 CP subtype to whoever genuinely held the status of person in charge of or responsible for the file.

⚖️ Do you need a criminal defence lawyer?

A firm dedicated exclusively to criminal law. We assess your case and design the defence strategy.

→ Unlawful access to medical records and health data

📞 +34 91 078 65 74

Frequently asked questions

Is it an offence to look at an acquaintance's medical record without disclosing anything?

Yes. Art. 197.2 CP punishes anyone who, without authorisation, accesses by any means reserved personal data held in files or registers. The offence does not require subsequent disclosure: consultation not covered by one's care duties already amounts to the conduct. Disclosure is a separate and more serious offence under Art. 197.3 CP, carrying 2 to 5 years in prison.

What is the sentence for accessing health data?

The range under Art. 197.2 CP is 1 to 4 years in prison and a fine of 12 to 24 months. Art. 197.5 CP requires those penalties to be imposed in their upper half where the acts affect data revealing, among other things, health, so the applicable range becomes 2 years and 6 months to 4 years in prison and a fine of 18 to 24 months.

Is every clinician with login credentials the person responsible for the file?

No. Art. 197.4(a) CP raises the sentence to 3 to 5 years in prison where the acts are committed by the persons in charge of or responsible for the files, media, archives or registers. Holding credentials in order to perform a job does not turn the user into the person in charge of or responsible for the file: the aggravated subtype requires a position of control over the archive, and applying it indiscriminately to any system user is open to challenge.

What if the person accessing the record is a public hospital official?

Art. 198 CP applies to an authority or public officer who, outside the cases permitted by law, without legal cause arising from an offence and taking advantage of their position, carries out any of the conduct described in Art. 197 CP: it imposes the corresponding penalties in their upper half and, in addition, absolute disqualification for 6 to 12 years. It requires the status of public officer within the meaning of Art. 24.2 CP and actual abuse of the position, not mere membership of the staff.

Can the data protection authority fine and a criminal court convict for the same access?

They are separate routes and criminal proceedings take precedence. Sanctioning proceedings in data protection matters are normally directed against the data controller — the healthcare provider — for control failures, whereas criminal liability attaches to the individual who accessed the record. Where evidence of an offence emerges, the administrative procedure gives way to the criminal one, and the bar on double punishment operates where there is identity of subject, facts and legal basis.

Is a complaint by the patient needed to open the case?

As a rule, yes. Art. 201.1 CP requires a complaint by the aggrieved person or their legal representative. Art. 201.2 CP makes an exception for the acts covered by Art. 198 CP and for cases where the offence affects the general interest or a plurality of persons, or where the victim is a minor or a person with a disability in need of special protection. Art. 201.3 CP provides that the victim's pardon extinguishes the criminal action, without prejudice to Art. 130.1.5, second paragraph.

Can a conviction prevent someone from continuing to practise as a healthcare professional?

It can. Art. 56.1.3 CP allows the court, for prison sentences of under ten years, to impose as an accessory penalty special disqualification from a profession or trade where that right had a direct connection with the offence, a connection that must be expressly established in the judgment. Art. 199.2 CP additionally provides for special disqualification from the profession for two to six years, and Art. 198 CP for absolute disqualification of six to twelve years.

What is the limitation period for this offence?

Art. 131.1 CP sets the period by the maximum penalty attached to the offence: five years for Art. 197.2 CP, whose maximum is four years' imprisonment, and also five for Art. 197.4 CP, whose maximum is five years. The period rises to ten years where the maximum penalty exceeds five years without exceeding ten, as in the profit-seeking scenario involving health data under Art. 197.6 CP, punishable by four to seven years in prison.

Do you need criminal defense in this area?

We are criminal defense lawyers specializing in unlawful access to medical records and health data. We act urgently to protect your rights.

View expertise

Related Articles

View all

Before you act, speak to a criminal defence lawyer.

What you read here is just the beginning. Transform information into active defence by contacting our team of experts.