Skip to content
Audience: DPO / Compliance

P1 and EDM — compliance status

What the practice reports to the Polish e-Health Centre, who is the controller here, what setup looks like, and which channel is frozen today.

Last reviewed:

P1 is the platform of the Polish e-Health Centre (CeZ). A practice entered in the Register of Entities Performing Medical Activity has a statutory obligation to report medical events, and some entities additionally to index electronic medical documentation.

Who is the controller here

CeZ is not a processor within the meaning of Article 28 GDPR. It is a separate public controller, acting under the Health Information System Act. The practice entrusts it with nothing — it hands data over because the law requires it, and Heltio is purely the transport channel.

The practical consequence: a patient cannot "withdraw consent" to a medical event being reported, because consent is not the legal basis. They can, however, see that data in their Patient Internet Account, independently of Heltio.

How to do it

The configuration lives in Settings → P1 integration (e-Health), as a wizard.

01

Declare the legal profile of the entity

The Legal profile of the entity step asks for three facts from the register entry and from the NFZ contract: Entity type (RPWDL register entry), NFZ contract and Primary healthcare (POZ) services.

This is not a preference — those three declarations determine how many CeZ requirements bind the practice, and the app shows the computed number. "Not declared" is a separate answer, not an answer of "no": while it stands there, no channel can be switched on. Guessing a cheaper profile would hand the practice a shorter list of requirements and call it complete.

02

Generate the certificate requests and upload the finished certificates

CeZ requires two separate certificates: a system certificate (the tunnel) and a data certificate (signing the content). The wizard generates commands to run on your own computer; the private keys and passwords stay with the practice — losing them after the application has been filed means repeating the whole procedure.

Finished certificates are uploaded in the Upload P1 certificates step. The app accepts PEM format only (.pem, .crt, .cer) and refuses a certificate that has already expired. After upload you see the fingerprint and the expiry date.

03

Fill in the practitioner identifiers

Every person providing a paid visit must have their professional practice number recorded together with the relevant professional register. The number can be checked with the Verify against CWPM button; the result is Verified, Not found in CWPM, Unverified or Check failed.

The register matters: it selects the professional-chamber identifier sent to CeZ. People with no number will not be able to complete a paid visit in a reporting practice.

04

Choose the channels

The Reporting channels step:

  • Zdarzenia Medyczne (mandatory) — for every entity in the register.
  • Indeks EDM (EDM-producing entities only) — a physiotherapy practice does not produce it, so the channel is unavailable to it.
  • e-Recepta and Issue e-skierowania — doctors only.
  • Receive e-skierowaniafrozen on 2026-08-11, because the obligation applies only to a provider holding an NFZ contract.
  • Patient consents and Medical-record access rights — these need a separate entitlement application to CeZ, independent of the integration itself.

The app refuses to enable a channel that lies outside the obligations of the declared entity type, and tells you on what basis.

Tracking submissions

The status dashboard shows every event with its status: Pending, Submitting, Submitted, Retrying, Failed (permanent), Blocked — missing PESEL/passport, Stalled — admin attention required, Not applicable. A manual retry requires a reason, which goes into the register.

The environment is chosen separately — Sandbox or Production — and each has its own certificates.

When something does not work

Error

Patient PESEL or passport is missing

What this means: A medical event requires a patient identifier; the record has none.

What to do: Fill in the PESEL or the document number in the patient record and resubmit.
Error

Certificate is expired

What this means: The certificate uploaded in the wizard has passed its expiry date.

What to do: Renew the certificate at CeZ, then use **Replace certificate**. The app will not accept a file that has already expired.
Warning

This clinic is not registered as an RPWDL entity

What this means: There is no register-book number in the configuration.

What to do: Complete the entity details. Without a register entry there is neither an obligation to report nor a technical way to submit.

Was this article helpful?