The steps described below are the backbone of the P1 configuration. None of them can be filled in from memory — you need the RPWDL register book, the access package from Centrum e-Zdrowia and the professional licence numbers of the whole team. The app says so outright: "These numbers cannot be derived or guessed — copy them exactly from the documents named below".
How to do it
Entity identification
Copy from the register book:
- RPWDL księga rejestrowa — "12-digit number or W-NNNNNN format from your RPWDL entry".
- NIP (tax ID) and REGON.
- Resortowe kody identyfikacyjne (cz. 1–8) — "Each part identifies a tier of the entity classification".
- Organisational cell number — część VII of the resortowy kod, digits only. A blank field means
001.
From the CeZ access package copy the Provider OID node — the entry with that name, ending in …2.7. and a number. Entities that maintain an EDM index also enter the EDM repository OID, ending in …7.24. and a number. These are two different numbers — a common mistake is entering one into both fields.
Every step described below looks the same: (1) the bar of the nine configuration steps, (2) the step you are currently on, (3) the fields to copy from your documents.
Legal profile of the entity
This step decides which obligations bind you. You choose the Entity type (RPWDL register entry) — Physiotherapy practice or Healthcare entity (podmiot leczniczy), for instance — and the NFZ contract: No contract — private practice only, Contract for the provision of healthcare services or Contract + "Recepta na Ruch" pilot.
Below that, the Resulting profile appears together with the number of binding requirements.
Certificate signing request (CSR)
CeZ requires two separate requests: one for the system certificate (TLS) and one for the data certificate (WSS). The screen gives you ready commands under the heading Commands — run them on your own computer.
Two key pairs are produced. You send the .csr files to CeZ; the key files and their passwords stay with you. The warning is literal: "losing them after the application is filed means starting the application over".
If you would rather not do this yourself, Email Heltio support stands next to it.
Upload P1 certificates
Two fields: WSS certificate (signing) and TLS certificate (mTLS). Both accept .pem, .crt and .cer files — dragged onto the field as well.
RPWDL2 issues the certificates inside a .p12 file. Heltio accepts the certificate part in PEM only, and the extraction command stands in the error message and in the step description.
Once uploaded, each certificate shows Expires and Fingerprint, with Replace certificate next to it. The certificates are valid for two years — renew them before they run out.
Practitioner identifiers
"Every practitioner who delivers a billable visit at an RPWDL clinic must have an NPWZ (professional licence number) registered with KIF, NIL, NIPiP or KIDL." For each team member set:
- NPWZ (professional licence number) — 3–11 characters.
- Professional registry — KIF (physiotherapists), NIL (doctors), NIPiP (nurses and midwives), KIDL (laboratory diagnosticians).
- Active for P1 reporting.
The Verify against CWPM button checks the number in the chamber's register. The result lands in the CWPM status field: Verified, Not found in CWPM, Unverified or Check failed.
Sandbox connectivity test
The last step runs a real search for your register entry on the CeZ server. The app reassures you: "It sends no patient data".
Run test ends in either Connection OK or Connection failed, and shows the round-trip time, the operation checked and the number of matching registry entries next to it.
When something does not work
Could not parse the file. Heltio accepts an X.509 certificate in PEM form only (.pem, .crt, .cer).
What this means: A .p12 file straight from RPWDL2 was uploaded, or a private-key file instead of the certificate.
This certificate is already expired. Renew it with CeZ before uploading.
What this means: The file is valid, but its expiry date has passed.
Nothing to connect with: the certificates are missing. Go back to the “Upload P1 certificates” step and upload both the WSS and the TLS certificate.
What this means: The connectivity test was run before the certificates were uploaded.
The CWPM registry does not know this number in the selected chamber. Check the number and the chamber.
What this means: The professional licence number does not appear in the register of the chamber you selected.
The number exists in CWPM, but the first and last name differ character for character.
What this means: The number is right, the personal details are not — usually a missing Polish character or a hyphen.
The CWPM registry did not answer the query. Your data may well be correct — try again later.
What this means: The chamber's register was unavailable.
Who has access
Clinic AdminEvery step needs the clinic owner's or administrator's rights. Uploading a certificate is recorded in the audit log, and the certificates and keys themselves are stored encrypted in Heltio.
Related
- P1 integration — overview — the whole path and the health dashboard.
- Medical events — what happens after a successful test.
- Encryption — how we hold keys and certificates.
Related features
P1 integration — overview
Who is obliged to report to the Polish e-Health system, how the configuration in Heltio runs, and where you check whether visits are actually reaching Centrum e-Zdrowia.
Medical events in P1
A completed visit reaches Centrum e-Zdrowia by itself. This article says exactly what goes out, within what deadline, how to recognise a held event and what to do with it.
Indeks EDM in P1
The second channel of the Centrum e-Zdrowia integration: the document stays in Heltio and an index entry goes to P1. It concerns only entities that produce electronic medical records — a physiotherapy practice is not one.