Skip to content
Alonso Sala
CRIMINAL LAWYERS

Unlawful Access to Medical Records and Health Data: Defence Lawyers

Criminal defence in the unauthorised access, use or transfer of health data and medical records (Art. 197.2 and 197.5 CP), with aggravated penalties because the information is specially protected data.

Article 197.2 of the Spanish Criminal Code (CP) punishes with imprisonment of 1 to 4 years and a fine of 12 to 24 months accessing without authorisation reserved personal data held in files, such as a patient's medical record, without requiring any subsequent disclosure: mere access or consultation out of curiosity already consummates the offence. Because health data is especially protected, the penalty is imposed in its upper half under Art. 197.5 CP, and if the offender is the person responsible for the healthcare file or discloses the data, the aggravated subtype of Art. 197.3-4 CP applies; when a public authority or officer accesses the data by abusing their position, Art. 198 CP adds absolute disqualification of 6 to 12 years. The criminal route is compatible with sanctioning proceedings brought by the Spanish Data Protection Agency, which requires coordinating both fronts of defence. At Alonso Sala we examine the basis for access — the care relationship, consent, or legal authorisation — to rule out criminal liability, and we take on both the defence of healthcare staff under investigation and the private prosecution on behalf of the affected patient.

What Art. 197.2 CP protects

Article 197.2 of the Spanish Criminal Code protects privacy against the unlawful processing of reserved personal data held in files or on computer, electronic or telematic media. It punishes anyone who, without authorisation, seizes, uses or modifies reserved personal or family data of another recorded in any type of archive, as well as anyone who, without authorisation, accesses such data by any means or alters or uses it to the detriment of the data subject or a third party. The penalty is imprisonment of one to four years and a fine of twelve to twenty-four months, the same as the basic offence of disclosure of secrets in Art. 197.1 CP.

The medical record is the paradigmatic example of a file protected by this provision. Accessing a patient's health record without a care relationship, consulting the hospital information system out of curiosity or for personal reasons, or extracting data from an occupational health file without authorisation, are conducts that fall under Art. 197.2 CP. Disclosure of the data is not required: mere unauthorised access or use completes the offence.

The health-data aggravation (Art. 197.5 CP)

The distinctive feature of these cases is that the medical record contains specially protected data. Article 197.5 CP provides that, where the acts described in the preceding paragraphs affect personal data revealing ideology, religion, beliefs, health, racial origin or sexual life, or where the victim is a minor or a person with a disability in need of special protection, the penalties are imposed in their upper half. In the case of health data, this aggravation applies almost automatically, raising the penalty range of Art. 197.2 CP.

If profit-seeking intent also concurs and the acts affect data covered by Art. 197.5 CP, Art. 197.6 CP raises the penalty to imprisonment of four to seven years. The boundary between access out of curiosity and access aimed at obtaining a benefit or harming a third party is therefore decisive for the legal classification.

Penalties and aggravated subtypes

The system of Art. 197 CP is completed by several subtypes relevant to the healthcare and employment context. Art. 197.3 CP punishes with imprisonment of two to five years the dissemination, disclosure or transfer to third parties of the discovered data. Art. 197.4 CP aggravates the penalty when the acts are committed by the person or entity in charge of or responsible for the file —typically, healthcare or administrative staff with legitimate access to the system who use it for purposes alien to their function— or when the data is disseminated.

Where the access is carried out by an authority or public official taking advantage of their office and outside the cases permitted by law, Art. 198 CP applies, imposing the respective penalties in their upper half and, in addition, absolute disqualification for a period of six to twelve years. This provision is particularly relevant for staff of public hospitals, mutual insurers, inspection services or administrations with access to health data.

Alongside criminal liability, improper access to a medical record usually gives rise to sanctioning proceedings before the Spanish Data Protection Agency (AEPD) under the GDPR and the LOPDGDD. Both proceedings may coexist, so the defence strategy must address the whole. In this area it is advisable to coordinate the defence with that of disclosure of secrets offences and, where applicable, with the unlawful access to computer systems of Art. 197 bis CP, whose framing is different.

Elements of the offence and defence lines

The defence always starts from analysing the basis for access: if there was a care relationship, the data subject's consent, legal authorisation or a purpose covered by healthcare regulations, the conduct may fall outside the offence. The subjective element is essential: Art. 197.2 CP requires conscious and unauthorised access, so that accidental access, access covered by internal protocols, or access necessary for patient care does not constitute the offence. The firm of Alonso Sala, based at Velázquez 27, Madrid, undertakes both the defence of healthcare and administrative professionals under investigation and the private prosecution of patients whose records have been breached. For a case assessment you may contact us on 91 078 65 74.

Penalties & Consequences

Type / ScenarioCriminal Penalty
Basic offence (Art. 197.2 CP)Unauthorised access, use, modification or transfer of reserved personal data held in files: imprisonment of one to four years and a fine of twelve to twenty-four months.
Health-data aggravation (Art. 197.5 CP)Where it affects health data or other specially protected data, the penalties are imposed in their upper half; with profit-seeking intent over such data, Art. 197.6 CP raises the penalty to imprisonment of four to seven years.
Public official (Art. 198 CP)An authority or official who accesses outside the legal cases taking advantage of their office is liable to the penalties in their upper half and absolute disqualification of six to twelve years.

* Penalties shown are indicative. The actual penalty depends on case circumstances, applicable mitigating and aggravating factors.

Our Defense Strategy

01

Analysis of the basis for access

We examine whether there was a care relationship, the data subject's consent or legal authorisation justifying the consultation of the record, which may exclude the conduct from Art. 197.2 CP from the outset.

02

Defence of the subjective element

The offence requires conscious and unauthorised access. Proving that the access was accidental, necessary for patient care or covered by internal protocols may render the conduct non-punishable.

03

Coordination with the administrative route

We coordinate the criminal defence with the sanctioning proceedings before the AEPD, avoiding statements or admissions in one procedure that would harm the position in the other.

Privacy Crimes in Spain: Discovery & Disclosure of Secrets — Defence Guide

Privacy crimes — discovery and disclosure of secrets (Art. 197 CP), illegal access to computer systems (Art. 197 bis), and non-consensual image sharing (Art. 197.7) — are among the fastest-growing offences in Spain. The digital environment has made private communications, intimate images and personal data especially vulnerable. These offences carry prison sentences of up to 5 years and require specialised technical defence combining legal expertise with digital forensics.

Penalty Table: Privacy Crimes

OffenceArticleDescriptionPenalty
Discovery of secrets (basic)Art. 197.1Seizing letters, emails, or intercepting telecommunications1 – 4 years prison
Disclosure to third partiesArt. 197.3Revealing or transferring discovered secrets2 – 5 years prison
Sensitive data (health, sexuality, ideology)Art. 197.5Discovery/disclosure involving specially protected data3 – 5 years prison
Illegal access to computer systemsArt. 197 bisUnauthorised access breaching security measures6 months – 2 years
Non-consensual image sharing (sexting)Art. 197.7Sharing intimate images obtained with consent3 months – 1 year
Professional perpetratorArt. 197.4Crime committed by person in charge of data filesUpper half + disqualification

Key Defence Strategies

Consent Defence

If the victim gave express consent to access their communications or devices, the crime is excluded. The defence must prove that consent was freely given, specific and not obtained through deception.

Fruit of the Poisonous Tree

If the prosecution's evidence was obtained through illegal means (hacked WhatsApp, unauthorised wiretap), it is inadmissible under Art. 11.1 LOPJ. Challenging the chain of custody is critical.

Lack of Criminal Intent (Dolo)

If the access was accidental or by mistake (opening someone else's email by confusion, finding an unlocked phone), there is no criminal intent. The prosecution must prove the accused acted knowingly.

Whistleblowing Protection

EU Whistleblowing Directive (2019/1937) protects employees who report illegal activity through proper channels. Revealing secrets to expose crime may be justified, though procedure matters.

IP Attribution Challenge

An IP address alone may not identify the perpetrator. Shared connections (Wi-Fi, VPN, corporate networks) create reasonable doubt about who actually accessed the data.

Statute of Limitations

Basic privacy crimes prescribe in 5 years. Digital evidence is volatile — logs, IPs and server records may be deleted. Early action by both prosecution and defence is essential.

Key Case Law

Supreme Court doctrineWhatsApp access without password is still a crime

The Supreme Court confirmed that accessing a partner's unlocked phone constitutes the crime of Art. 197.1 CP. The absence of a password does not imply consent. Privacy is presumed regardless of security measures.

Supreme Court doctrineEmployee monitoring: workplace communications doctrine

Following the European Court of Human Rights case law on employer monitoring of employee communications, the Court ruled that such monitoring requires prior, clear policy notification. Without it, evidence is inadmissible and the employer may face criminal liability.

Supreme Court doctrineNon-consensual image sharing: Art. 197.7 elements

Clarified that Art. 197.7 requires images obtained WITH victim's consent (within a relationship) and shared WITHOUT consent. Images obtained covertly constitute a different offence (Art. 197.1).

Why Choose Us?

Need a criminal defense lawyer for this type of offense? Here's how we work:

Absence of unauthorised accessIf the professional had access authorisation by reason of their care or administrative function, or the data subject gave consent, the requirement of Art. 197.2 CP is not met.
Lack of intentAccidental access or access arising from the configuration of the system, with no intention of learning data alien to one's function, lacks the intentional element the offence requires.
Challenging the traceability evidenceAccess logs and audit trails must reliably establish the identity of the perpetrator and the actual viewing of the data; their technical weakness opens defence avenues.
+15 Years of ExperienceTeam dedicated exclusively to criminal law before Spanish courts and tribunals.
Direct AttentionYour case is handled directly by a senior lawyer of the firm.

Need urgent criminal defence?

Contact our specialist criminal defence lawyers. We evaluate your case confidentially.

This page is for information purposes only and does not constitute legal advice: every case requires individual assessment. How this content is produced and verified: editorial policy.

Do you need specialised legal assistance?

The judicial system is complex. We have the criminal-law specialisation and technical resources required to take on the defence.

Call