← Back to the regulatory map
Law and regulation Norway

The Patient Records Act and the Patient Records Regulations

Valid in Norway

Last reviewed by a professional on July 17, 2026

Brief overview

The Health Personnel Act regulates the processing of health data necessary to provide, administer, and quality assure healthcare. The Medical Records Regulation supplements the law with requirements for, among other things, the content, organization, signing, and access control of the record. The regulations apply regardless of whether the documentation is written manually, dictated with speech recognition, or prepared with support from artificial intelligence.

It is useful to distinguish between traditional speech recognition, where healthcare personnel dictate text, and «speech-to-draft,» where a patient conversation is recorded, converted to text, and processed by artificial intelligence into a draft medical record note. The latter workflow may include audio recording, raw transcription, AI-generated draft, and the final medical record note. All steps must be handled with proper information security and clear management of access, storage, and deletion.

The regulations neither require nor generally prohibit the use of artificial intelligence in medical record-keeping. The AI output must be treated as a draft. The healthcare professional providing the care remains responsible for ensuring that the approved medical record note is relevant, necessary, comprehensible, and linked to the correct patient. The draft must be checked against what was actually said, observed, and assessed. Particularly important check points are negations, medications and dosages, allergies, test results, appointments, and who said what.

The business must choose a tool that is suitable for healthcare and approved for the processing of health data. Patient data should not be entered into open, general AI services that the business has not evaluated and approved. If the tool has a medical purpose, the business must also assess whether it is covered by the regulations for medical devices.

Access must be justified by an operational need, and the entity must be able to control who has had access to the information. From July 1, 2026, central requirements for documentation and logging upon making health data available are governed by Section 22 a of the Patient Records Act.

The Norwegian Directorate of Health's guidance on speech-to-draft recommends that audio recordings, raw transcriptions, and AI drafts be deleted no later than when the verified medical record note is approved. If a recording is to be used or retained as independent documentation, the entity must specifically assess this in accordance with the regulations governing medical records.

According to the same guidance, separate consent is normally not required simply because speech-to-text is used as an aid in medical record-keeping. The patient should nevertheless be informed about the recording and the use of AI, and healthcare personnel should be able to document in the usual manner if the patient does not wish the solution to be used. Other purposes, reuse, or storage of the recording may require a different assessment.

What regulates this

The Patient Records Act regulates the processing of health data in connection with healthcare and sets requirements for, among other things, purposes, duty of confidentiality, access, and information security. The Patient Records Regulations supplement the requirements for the content, organization, signing, and access control of the record. These requirements also apply when speech recognition or AI is part of the workflow.

Who is affected

Public sector

Private sector

Why it has practical significance

Speech recognition and AI can streamline medical record-keeping, but can also introduce errors, omit clinical context, or place information on the wrong patient. Healthcare personnel must therefore check and approve the result before it is included in the medical record. At the same time, the organization must manage the entire information flow, including recordings, transcriptions, drafts, vendor access, logging, and deletion.

Key Requirements and Obligations

  • Every processing of health data must be linked to a data controller entity
  • The information shall be processed for lawful and clearly defined purposes related to healthcare
  • The medical record must contain relevant and necessary information about the patient and the healthcare provided.
  • The medical record note must be understandable to other qualified healthcare professionals
  • It must be evident who entered the information, and the case note must be dated and signed or approved.
  • Healthcare personnel must review AI-generated drafts before they become part of the final medical record
  • Access to health data must be based on a service need and secure authentication.
  • Unauthorized access, search, use, or other acquisition of medical records is prohibited
  • The enterprise shall have technical and organizational measures that protect confidentiality, integrity, and availability
  • Disclosure and access must be documented and logged in accordance with Section 22a of the Patient Records Act.
  • Temporary audio recordings, transcripts, and AI drafts must have established retention and deletion procedures

What the business may consider documenting

  • Map the entire information flow from audio recording to approved medical record entry
  • Use only tools that have been evaluated and approved for the processing of health information
  • Clarify data ownership, supplier roles, storage location, subcontractors, and any use of data for model training
  • Keep AI drafts clearly separate from approved medical records
  • Require a mandatory human review before a draft can be signed or approved
  • Use a checklist for negations, medications, dosage, allergies, tests, appointments, and speaker identity
  • Verify that the note is linked to the correct patient and accurately reflects the healthcare personnel's actual assessment
  • Automate the deletion of audio, raw transcripts, and drafts once the approved note has been finalized, in cases where the material is not to be retained as documentation
  • Verify access control, logging, and follow-up checks at both the organization and the supplier
  • Provide the patient with brief and easy-to-understand information on how to use the speech-to-text feature
  • Establish an alternative method of record-keeping when the solution should not or cannot be used
  • Follow up on errors and quality differences related to, among other things, dialect, language, background noise, and multiple simultaneous speakers
  • Consider whether the solution serves a medical purpose and is therefore subject to the regulations governing medical devices
  • Update internal procedures and references to regulations following the entry into force of Section 22a of the Patient Records Act

Sources and Further Reading

The links point to external sources. Check the current text and status before using them in your own work.

The information is general information and not legal advice. The applicable requirements must be assessed based on the enterprise's sector, role, information, and specific use of technology.