Ginter warns health data access threatens trust in doctors
Thursday 6th August 2026 on 21:15 in
Estonia
Estonia’s Police and Border Guard Board and Internal Security Service have made thousands of monthly queries into people’s health data, an internal review found. Attorney Carri Ginter told ERR that overly broad access to sensitive information undermines trust between doctors and patients and requires tighter legal rules and judicial oversight.
“When it comes to health data, the most important thing is that I must be able to tell my doctor the truth,” Ginter said. “I must be able to entrust this information to a doctor without the police obtaining it by email.”
He said the internal review was welcome because it had finally examined how the data was being used. However, he questioned the finding that about 1,000 people were subject to queries each month, amounting to roughly 13,000 queries a year.
“I refuse to believe that Estonia has 1,000 potential criminals whose health data needs to be checked every month,” Ginter said. He added that the system clearly needed more precise regulation and significantly stricter oversight.
Ginter said that queries made without supervision would inevitably be abused. People should also be notified when their data has been accessed so they can ask why it was viewed if they were not suspected of a crime.
He rejected the authorities’ view that the existing rules were sufficient and that officials simply needed to follow them more carefully. The wording allowing access to data for purposes “connected with police tasks” was too broad, he said.
“Health data is extremely intimate and personal,” Ginter said. Access should always be linked to a specific proceeding, rather than being permitted simply because someone is a police officer.
He warned that the broad wording could enable officials to share private information about friends or acquaintances, including details about medication or mental health conditions. This could create opportunities for genetic discrimination, he said.
Ginter said the situation was seriously damaging trust in doctors. While lawyer-client telephone conversations are protected from surveillance, police officers can currently view information entrusted to a doctor, he said, without effective and regular oversight or a serious criminal proceeding that would justify access to the data.