AI in the Gutachter procedure: what is allowed?

As of October 2026 · about 7 minutes to read

More and more programs promise help with the report to the Gutachter, the independent expert reviewer who assesses applications for long-term therapy on behalf of the health insurer. Many colleagues rightly ask: am I even allowed to use them? This article puts the most important rules into context – without replacing legal advice.

Not legal advice. We are not aware of any binding statement by the Kassenärztliche Bundesvereinigung (KBV, the National Association of Statutory Health Insurance Physicians) or the psychotherapist chambers on software-assisted report drafts. We set out the legal bases and say how we interpret them. The decision for your practice is yours, if necessary after consulting your chamber.

The central rule: write it in person

The Psychotherapie-Vereinbarung (the psychotherapy agreement), which governs the application and Gutachter procedure as an annex to the Bundesmantelvertrag-Ärzte (the national framework contract for physicians), contains an unambiguous sentence:

“The report to the Gutachter is to be written entirely in person by the psychotherapist.” (German original: „Der Bericht an die Gutachterin oder den Gutachter ist von der Psychotherapeutin oder vom Psychotherapeuten vollständig persönlich zu verfassen.“)

This makes clear what is not possible: having another person or a program write a report and submitting it unchecked. The Gutachter is meant to read the professional assessment of the treating clinician, not someone else’s text.

It is less clear where the line lies for permissible aids. Word processing, spell checking, a dictation device or your own text templates have been common for years. What probably matters is whether the report is based on your own findings in substance, and whether you word, review and take responsibility for it as your own text.

What follows for software

In our interpretation, the rule gives rise to a few minimum requirements for any tool that helps with the report:

  1. The basis is your records. A draft may contain only what you have documented yourself – session notes, findings, questionnaire values. Content that a language model invents has no place in the report.
  2. Every statement can be traced. You must be able to see what a sentence rests on. Only then can you actually check it instead of merely reading it through.
  3. Professional judgements stay with you. Diagnosis, prognosis and treatment plan are your decisions. Software should not propose them; at most it should carry over what you have decided yourself.
  4. You edit and take responsibility for the text. The draft is working material. Whatever is submitted, you have read, revised and approved as your own report.

Tools that produce a report from a few keywords “at the push of a button” are hard to reconcile with this standard. The less traceable it is where a wording comes from, the harder it becomes to answer for the text as personally written.

Medical device or not?

Software can be a medical device within the meaning of Regulation (EU) 2017/745 if it is intended for medical purposes, for example diagnosis, prognosis or treatment. A program that suggests diagnoses, assesses suicide risk or interprets questionnaire values as “moderate depression” operates in this area. Conformity assessment and CE marking apply to such products.

Pure documentation and administration software that organises the therapist’s information and puts it into report form is, in our assessment, not a medical device. Ask a vendor how it classifies its software and which functions it deliberately excludes.

Data protection and professional secrecy

Reports contain health data, even when pseudonymised with a code. Pseudonymised data remain personal data. When using software, the following in particular must therefore be observed:

  • Data processing agreement under Art. 28 GDPR (German: DSGVO) with the vendor, including a list of sub-processors;
  • Place of processing: Where is the data stored, where does the language model run, are inputs stored or used for training?
  • Professional secrecy: Under § 203 of the German Criminal Code (StGB), holders of professional secrets may disclose secrets to service providers only as far as necessary for their work, and must bind them to confidentiality;
  • Data protection impact assessment: With new technologies and health data it may be required under Art. 35 GDPR;
  • Data minimisation: Real names do not belong in a report tool; the code is enough.

For software used in the care of people with statutory health insurance, special requirements for cloud services also apply (§ 393 SGB V, Book V of the Social Code), including requirements on location and on attestations under the C5 criteria catalogue of the Federal Office for Information Security (BSI). Ask vendors who holds the attestation: the data-centre operator or the application itself.

And the EU AI Act?

The European AI Act, Regulation (EU) 2024/1689, applies in stages. For practices that use an AI system, what matters most is that operators must ensure sufficient AI literacy among the people who use the system (Art. 4). A tool that structures documentation does not, in our assessment, count among the high-risk systems of the regulation. Providers must be transparent about the use of AI; AI output should be recognisable as a draft.

Questions you should ask a vendor

  • Does every sentence in the draft come from my own records, and can I see the source?
  • What happens to sentences for which there is no source?
  • Does the software suggest diagnoses, prognoses or risk assessments?
  • Where is the data stored, where does the language model run, and is it used for training?
  • Is there a data processing agreement and an obligation under § 203 StGB?
  • Who holds which security attestation – the vendor itself or its data centre?

A review scheme for your own report

Whichever tool you use, it helps to run through three questions before you send it:

  1. Do I recognise every sentence as mine? Adjust wording you would not use yourself. The report should carry your professional language.
  2. Can I name the place in my documentation for every statement? Where that fails, add the evidence or delete the statement.
  3. Do diagnosis, goals, plan and prognosis come exclusively from me? These sections carry your clinical responsibility; they must not be adopted from software suggestions.

If you can answer yes to these questions, you have, as we understand it, written the report in person – whether the first version came from a pen, a dictation device, a text template or a tool that structures the material.

How we align the Application Copilot with this

We have aligned the Application Copilot (German: Antrags-Copilot) with these requirements. It arranges your session notes and questionnaire values into the structure of the PTV 3 (the official report form) and shows the source with date on every sentence. Sentences without a source are flagged “Not sourced” (German: “Nicht belegt”). It takes over diagnosis, prognosis and treatment plan only from your own verbatim entries; it makes no diagnoses and assesses no risks. You review, change and write the report in person. The sample report on a fictional case shows an example.

Sources