The Last Step Before the Pharmacy: Why Online Prescriptions in Germany Need a Qualified Electronic Signature

In this post, we’ll explain why electronically issued prescriptions in Germany generally require a Qualified Electronic Signature, and what that requirement means in practice for doctors, veterinarians, telemedicine companies, and ePrescription platforms.

21 Jul
,
2026
23 Jul
,
2026
# min read
eID Easy online prescription QES

A telemedicine company is preparing to enter Germany. The consultation flow is working, the doctors are ready, and the prescription is generated correctly. Sometimes, the developer has already tested most of the integration.

But then someone asks the question that can hold up the whole launch:

What makes the electronic prescription acceptable when it reaches the pharmacy?

In Germany, the answer is usually a Qualified Electronic Signature, or QES.

We have seen this situation first-hand.

In one recent conversation, a healthcare platform was working towards a German launch on a tight timeline. Its developer had already tested the signing flow in our sandbox before the first call. The team was not trying to work out whether an API could technically sign something. It was already further along than that.

The real questions were more practical:

How would the doctors be onboarded? Would they need to verify their identity every time? Which signing provider made sense for a relatively small number of doctors issuing a large number of prescriptions? And would the same integration still be useful when the company entered its next European market?

That last question comes up a lot.

Germany may be the immediate launch. It is not always the final destination.

The signature is therefore more than a box to tick before going live. The provider, certificate model, prescriber experience, expected volume, and future markets all influence whether the workflow will still make sense six or twelve months later.

Let’s start with the German requirement itself.

The short answer: German electronic prescriptions generally require QES

Section 2 of Germany’s Arzneimittelverschreibungsverordnung, or AMVV, sets out the information a prescription must contain.

For a paper prescription, it requires the handwritten signature of the prescribing person. For a prescription issued electronically, it requires that person’s Qualified Electronic Signature. The regulation refers to medical, dental, and veterinary prescribers, and it also uses the date of the QES as the relevant date for an electronic prescription.

There are specific exceptions and separate regimes. For example, the AMVV allows a suitable electronic identification procedure instead of QES for certain prescriptions intended for a hospital and transmitted through a system that ensures the prescription was issued by an authorised prescriber. Some categories of medicine are also governed by additional rules.

For the standard online prescription workflow that ends with dispensing through a pharmacy, however, QES is not simply the highest-security option available.

It is the signature level named by the regulation.

Why does Germany require a Qualified Electronic Signature?

On a traditional paper prescription, the prescriber’s handwritten signature connects that person to the prescribing decision.

Moving the prescription online does not remove the need for that connection. It changes how the connection is created and verified.

A QES is a defined signature level under the European eIDAS framework. It is an Advanced Electronic Signature that is based on a qualified certificate and created using a qualified electronic signature creation device. Under Article 25 of eIDAS, it has the equivalent legal effect of a handwritten signature.

In practical terms, it gives the receiving party a way to check:

  • Who signed the prescription
  • Whether the certificate supporting the signature was qualified and valid at the time
  • Whether the signed information has changed since it was signed
  • Whether the technical requirements for a QES were met

The eIDAS validation rules specifically cover the validity of the qualified certificate, the identity information connected to the signer, the qualified signature-creation process, and the integrity of the signed data.

That is also how Germany’s official E-Rezept information describes the role of the signature. The pharmacy can use the QES to determine who issued the prescription and whether its contents were changed without authorisation.

So QES is not a scanned image of a signature placed at the bottom of a PDF.

It is not simply a doctor logging into a platform and clicking Confirm.

And it is not a platform declaring, in its own database, that the doctor approved the prescription.

It is a verifiable signature created under a regulated trust framework.

Why is an Advanced Electronic Signature not enough?

An Advanced Electronic Signature, or AdES, is already a strong electronic signature.

Under eIDAS, it must be uniquely linked to the signer, capable of identifying them, created using signature data that the signer can control with a high level of confidence, and linked to the signed information so that subsequent changes are detectable.

QES builds on those requirements by adding a qualified certificate and a qualified signature-creation process.

Comparison Advanced Electronic Signature Qualified Electronic Signature
Link to the signer Uniquely linked to the signer. Uniquely linked to the signer.
Identity assurance Capable of identifying the signer. Based on a qualified certificate issued by a Qualified Trust Service Provider.
Document integrity Makes later changes to the signed data detectable. Makes later changes to the signed data detectable.
When it is used Suitable where the applicable rules permit AdES. Required where the applicable rules explicitly call for QES.
Legal effect under eIDAS Does not automatically receive handwritten-signature equivalence. Has the equivalent legal effect of a handwritten signature.

AdES can still be appropriate for many healthcare documents.

Depending on the applicable requirements, it may be suitable for patient consents, supporting treatment documents, internal approvals, contracts, or other workflows around the prescription.

But where the AMVV expressly asks for the prescriber’s QES, an AdES does not satisfy that requirement simply because it is also secure.

The correct signature level depends on the document and the workflow. It should not be chosen on the basis that “stronger sounds better” or “this one is probably close enough.”

What does a QES prove; and what does it not prove?

A QES provides strong evidence about the signer and the integrity of the signed information.

It does not do everything.

A QES does not:

  • Decide whether the medicine is clinically appropriate
  • Create the prescription data
  • Confirm that the consultation was conducted correctly
  • Replace checks on the prescriber’s current professional authorisation
  • Send the prescription into Germany’s national E-Rezept infrastructure
  • Make every prescription acceptable in every European country

This distinction is important because teams sometimes ask us for an “ePrescription solution” when they actually need one specific part of that solution.

They may already have the consultation, clinical logic, prescribing interface, and pharmacy connection. What they are missing is the trust layer that binds the doctor to the completed prescription.

Other businesses need a connection to Germany’s national E-Rezept service as well.

Those are related requirements, but they are not the same requirement.

Is an online prescription the same as Germany’s E-Rezept?

Not exactly.

We use online prescription as the broader description of a prescription created through a digital journey. That might happen after a video consultation, through a subscription-based treatment programme, or inside another remote-care workflow.

E-Rezept refers to Germany’s national electronic-prescription infrastructure.

For prescription medicines provided to people covered by Germany’s statutory health-insurance system, use of the E-Rezept has been mandatory since 1 January 2024. The doctor creates and digitally signs the prescription, it is stored in the central E-Rezept service, and the pharmacy retrieves it from that service. The Telematikinfrastruktur connects the participating healthcare organisations.

Germany’s Federal Ministry of Health explains that, within this workflow, the doctor signs using an electronic health-professional card and PIN. The paper printout sometimes given to the patient is not the prescription itself; it contains the information needed to retrieve the electronic prescription.

Comparison Online prescription Germany’s E-Rezept
What it means A broad term for a prescription created through a digital journey. Germany’s specific national electronic-prescription system.
Consultation setting Often follows an online or video consultation. Can follow an in-person or remote consultation.
Infrastructure May be part of a private or platform-specific workflow. Uses Germany’s E-Rezept service and Telematikinfrastruktur.
Compliance scope Must meet the prescription, signature, and dispensing rules that apply to the workflow. Includes defined national processes for creation, signing, storage, retrieval, and dispensing.
Role of the signing provider The platform may need a provider to create the required electronic signature. The signing provider is one part of a wider national workflow.

The simplest way to think about it is this:

The QES connects the prescriber to the prescription. The national infrastructure determines how that prescription is transmitted, stored, retrieved, and dispensed.

eID Easy can provide the electronic-signature and trust-provider layer.

It does not replace gematik, the Telematikinfrastruktur, the E-Rezept service, your clinical system, or your pharmacy connection.

How does QES fit into an online prescription workflow?

The exact implementation depends on the platform and the selected signing provider, but the overall journey is usually straightforward.

1. The platform creates the prescription

The doctor completes the consultation and prescribing decision. The platform prepares the prescription with the required patient, prescriber, medication, dosage, quantity, validity, and other applicable information.

The AMVV defines the information that must be present and includes additional requirements for veterinary prescriptions.

2. The platform initiates the QES process

The platform sends the prescription, or in some implementations only a hash of the prescription, into the configured signing flow.

The platform should already know which signing method the doctor will use. The doctor should not have to browse a long list of trust providers and work out which one is appropriate every time a prescription is issued.

3. The doctor reviews and approves it

The doctor sees the information they are about to sign and completes the authentication, consent, or approval steps required by the selected provider.

That might involve a mobile application, PIN, browser redirect, smart card, cloud certificate, or another provider-specific process.

4. The signed result returns to the platform

Once the QES has been created, the signed prescription or signature result is returned to the platform.

The platform can then continue the appropriate route into a pharmacy system, the E-Rezept infrastructure, or another permitted dispensing workflow.

At a technical level, eID Easy supports hosted and API-based signing journeys. The standard API pattern is to prepare the content, let the signer complete the selected provider’s process, and retrieve the signed result. Privacy-sensitive implementations can send a file hash rather than the document contents.

Does the doctor need to verify their identity for every prescription?

This is one of the first questions developers and product teams ask us.

The helpful answer is to separate identity verification and certificate issuance from approval of each individual signature.

Identity verification and qualified-certificate issuance

Before a qualified certificate is issued, the Qualified Trust Service Provider must verify the identity of the person receiving it. eIDAS permits several compliant routes, including physical identification, suitable electronic identification, an existing qualified certificate, or another nationally recognised method offering equivalent assurance.

Depending on the provider and certificate model, that onboarding may happen once at the beginning and then again when the certificate expires, is revoked, or needs to be replaced.

It does not generally mean repeating a complete identity-verification journey from scratch for every prescription.

Approval of each prescription signature

The doctor still has to authorise the use of their signature.

The exact experience depends on the provider. It may involve a PIN, an app confirmation, strong authentication, or another action controlled by the doctor.

So the practical answer is:

The doctor does not normally complete full identity verification for every prescription, but every signature must still be created through a valid, prescriber-controlled signing process.

That distinction matters. Full identity verification every few minutes would make for a painful prescribing workflow. A signature process with no meaningful prescriber involvement would create a different set of problems.

The right setup keeps the initial identity and certificate process secure while making recurring signing realistic for day-to-day clinical work.

The real ePrescription pattern: few signers, lots of signatures

Online prescription platforms often have a usage pattern that looks quite different from a normal document-signing product.

There may be a relatively small, known group of doctors or veterinarians. But those professionals sign repeatedly, and the total volume can become substantial.

We have discussed workflows where fewer than twenty doctors could account for six-figure annual prescription volumes.

That is why one of the first questions we ask is not simply:

How many signatures do you need?

We also ask:

How many people will be creating those signatures?

Those numbers lead to different product decisions.

A platform with ten doctors issuing prescriptions every day is not the same as a platform with ten thousand consumers signing one agreement each. Both may use QES, but the right certificate model, authentication flow, provider, support setup, and commercial structure may be completely different.

For a recurring-prescriber workflow, we normally want to understand:

  • How many doctors or veterinarians will sign?
  • Where are they based?
  • Where will the prescriptions be dispensed?
  • How many prescriptions will each person issue?
  • How does the provider onboard a new prescriber?
  • How long does the certificate remain valid?
  • What must the prescriber do for each signature?
  • How are expiry and renewal handled?
  • What happens if a signing attempt fails?
  • Which countries are likely to come next?

This is where provider selection stops being a generic compliance exercise.

It becomes part of the product design.

Do doctors need to choose a signature provider every time?

No.

That would add friction without adding much value.

eID Easy connects businesses to a network of 80+ trusted eSignature and eID providers and methods, including QES and AdES options, through one API. The point of that network is to give the platform coverage and flexibility. It is not to present every possible method to every doctor.

Your platform can configure the provider or methods appropriate for a particular workflow.

A doctor in one setup might see a single preselected method. Another platform may offer two suitable options. A business operating in several countries might enable different methods according to the prescriber’s location and the applicable requirements.

The choice sits behind the experience.

If the platform later needs another provider, certificate model, or country-specific method, it can enable that through the existing eID Easy integration rather than starting another standalone provider integration.

Can an EU QES be used across borders?

Under eIDAS, a QES based on a qualified certificate issued in one EU Member State must be recognised as a QES in the other Member States.

That is an important advantage.

It means a qualified certificate does not lose its QES status simply because it was issued by a Qualified Trust Service Provider in another EU country.

But this needs one big qualification:

Recognition of the signature as a QES is not the same as acceptance of the prescription in every national healthcare system.

A country may still have its own rules about:

  • Who may prescribe
  • Which professional identifiers must be included
  • Which medicines may be prescribed remotely
  • What information the prescription must contain
  • Which signature format or certificate attributes its system accepts
  • Where the prescription must be submitted
  • How the pharmacy retrieves and validates it

Germany’s E-Rezept workflow, for example, includes the E-Rezept service, Telematikinfrastruktur, and health-professional credentials—not only a generic QES.

This is why we describe the sensible product strategy as Germany first, Europe ready.

Solve the German requirement now, but avoid building the signing layer in a way that forces you to start over when Austria, Czechia, or another market comes next.

What about electronic prescriptions for veterinarians?

The core signature issue is similar.

Germany’s AMVV expressly refers to veterinary prescribers and requires the prescribing person’s QES when a prescription under its scope is issued electronically.

Veterinary prescriptions also require additional information. Depending on the animal and medicine, that can include:

  • The animal owner
  • The number and type of animals
  • The dose per animal and day
  • The duration of treatment
  • The indication
  • The applicable withdrawal period for food-producing animals
  • Information identifying the animals

Those requirements appear in the same AMVV provision that sets out the signature requirement.

That does not mean veterinary platforms simply copy the human E-Rezept workflow.

Veterinary prescriptions may have their own medicine, documentation, record-keeping, transmission, and dispensing rules. The national infrastructure used for human statutory-health-insurance prescriptions should not automatically be assumed to apply.

The shared product need is the trusted connection between an identified veterinary prescriber and the prescription they issue.

The surrounding workflow still needs to be designed for the veterinary context.

How eID Easy helps ePrescription platforms

Your telemedicine or ePrescription platform already owns the clinical journey.

You manage the consultation, prescribing logic, prescription data, doctor experience, and connection to the relevant pharmacy or healthcare infrastructure.

We make the signature-provider layer easier to manage.

With eID Easy, platforms can:

  • Access 80+ trusted eSignature and eID providers and methods through one API
  • Support both QES and AdES workflows
  • Connect doctors who already have suitable certificates
  • Onboard prescribers who need a new certificate
  • Configure the methods shown to each user
  • Use a hosted signing page, embedded components, or a more customised API-based journey
  • Sign document hashes in privacy-sensitive implementations
  • Add supported providers and methods without replacing the core integration
  • Reduce the number of technical connections and provider relationships managed directly

eID Easy’s platform is designed to connect businesses to Qualified Trust Service Providers and Certificate Authorities while managing the technical connections and access to different certificate and signing methods.

The right provider still depends on the use case.

Before recommending a setup, we would want to know where the prescribers are, how many there are, how often they sign, what experience the platform wants to create, and which markets are likely to follow Germany.

That is more useful than simply handing over a list of signature providers and leaving the platform to work it out.

Frequently asked questions about QES and online prescriptions in Germany

Does every online prescription in Germany require QES?

For a standard prescription issued electronically under Section 2 of the AMVV, the regulation requires the Qualified Electronic Signature of the prescribing person.

There are specific exceptions and separate regimes. One example is a prescription intended for a hospital and transmitted through a system that ensures it was issued by an authorised prescriber. Certain medicine categories may also be subject to additional rules.

The exact workflow and prescription category should therefore be reviewed, but QES is the general requirement named by the AMVV for prescriptions issued electronically.

Is a normal electronic signature sufficient?

Not where the applicable rule expressly requires QES.

A basic electronic signature or AdES may still have legal value and may be suitable for other healthcare documents. But it does not become a QES simply because it is secure, identifies the signer, or creates an audit trail.

QES has additional requirements under eIDAS, including a qualified certificate and qualified signature-creation process.

Is an online prescription the same as an E-Rezept?

No.

“Online prescription” is a broad description of a prescription created through a digital journey. Germany’s E-Rezept is a specific national system through which prescriptions are digitally created, signed, stored, retrieved, and dispensed.

For statutory-health-insurance prescriptions, the E-Rezept uses Germany’s central E-Rezept service and Telematikinfrastruktur.

Does the doctor need a new qualified certificate for every prescription?

Normally, no.

The Qualified Trust Service Provider verifies the doctor’s identity and issues or activates a qualified certificate. That certificate can then be used according to its validity conditions.

The doctor must still authorise each individual signature through the process required by the provider. When the certificate expires, is revoked, or otherwise becomes unusable, it will need to be renewed or replaced.

Does the doctor need to verify their identity every time?

Not usually through a complete identity-verification process.

Identity verification normally takes place when the qualified certificate is issued. Each prescription signature still requires appropriate prescriber authentication, consent, or approval.

The precise experience depends on the selected provider and certificate model.

Can a QES issued in another EU country be recognised in Germany?

Yes, as a QES.

Under eIDAS, a QES based on a qualified certificate issued in one EU Member State must be recognised as a QES in the others.

That does not automatically guarantee that the certificate and signature will meet every technical, professional, or infrastructure requirement of a specific German healthcare workflow. Those requirements must be checked separately.

Does eID Easy replace gematik or the E-Rezept service?

No.

eID Easy provides the electronic-signature and trust-provider layer. It does not create the clinical prescription, operate Germany’s E-Rezept service, replace the Telematikinfrastruktur, or act as the pharmacy-dispensing system.

Your platform remains responsible for the wider prescription workflow and any required connection to national infrastructure.

Does the requirement also apply to veterinarians?

Germany’s AMVV expressly covers veterinary prescribers and requires QES for prescriptions issued electronically under its scope.

Veterinary prescriptions also carry additional information requirements, and the surrounding record-keeping, medicine, and dispensing rules may differ from those for human healthcare.

Can the same integration support other European countries?

Yes, the same eID Easy integration can provide access to additional supported QES, AdES, and electronic identity methods.

The correct method is still market-specific. Other countries may not impose the same QES requirement as Germany, and each national prescription and pharmacy workflow needs to be assessed separately.

Already have the consultation and prescription flow?

Then the signature may be the last missing part.

Your developers can test an eID Easy signing journey before committing to a production rollout. They can prepare the content, complete a provider flow, and see how the signed result returns to the application.

Talk to us →

Explore the API Documentation →

This article provides general information about electronic signatures and prescription workflows. It is not legal or medical advice. Requirements can differ by prescription category, medicine, technical route, and individual circumstances.

More latest articles

See all news
See all news