Patient data: GDPR-compliant backups, fully verifiable
A system failure on Monday morning with a full waiting room is no reason to panic with the right backup – just a restore. Protect patient and practice data reliably against outages, cyberattacks and data loss.
- GDPR-compliant – backups of sensitive patient data with retention to your rules.
- Fast recovery – practice data restored quickly in an emergency.
- Automated – backups without extra effort in daily practice.
- Multi-layer protection – against ransomware, hardware defects and operator errors.
What a backup for health data must deliver
Patient data is among the most sensitive information there is – backing it up is an obligation, not a precaution.
Stored immutably
Backups are stored immutably via the object lock function of S3 Object Storage: within the retention period they cannot be overwritten or deleted – not even with stolen credentials.
Automated, not manual
Backups run to schedule without anyone having to remember. Failed runs report themselves instead of failing silently.
Documented for audits
Certificates with scope, documentation of technical and organisational measures and the data processing agreement are available in the Trust Center – the basis for your processing register. What the regulatory framework means for practice IT as a whole is covered in IT security in healthcare.
Restores are testable
A backup is only as good as the last successful restore. Test restores can be scheduled instead of becoming an experiment in an emergency.
Your transparent path to GDPR-compliant backups
From the first analysis to monitored operations – four steps that take medical practices, dental practices, specialist centres and medical care centres to audited backups.
Initial consultation
In a free initial consultation we clarify your practice’s starting point and protection needs – which systems run, which data accrues, what is backed up today.
Advice & risk analysis
Together we assess risks and recovery objectives: what may fail, for how long, and which retention periods apply to your treatment records.
Planning & quote
You receive a concrete backup plan with a transparent quote – building blocks, intervals, retention and costs broken down clearly.
Set-up & ongoing protection
centron sets up the backup and monitors it in operation. Failed runs raise alerts, and test restores are documented.
Retain, delete, restore
The GDPR requires both: keeping data available as long as retention obligations demand, and deleting it afterwards. Both belong in the backup strategy, not in a handwritten note. Retention rules in the object storage let periods expire automatically – and anything inside the period is protected against modification. Which periods apply to your institution is your decision; you get the technical implementation.
- Object lock – immutable for the retention period
- Periods – retention and deletion as you define them
- Separated – independent of the production system
- Germany – processing without third-country transfer
What GDPR, § 393 SGB V and § 630f BGB require of backups
Three duties stand behind every backup: retain for as long as the periods require; delete once they have expired – in the backup copies too; and test and document recoverability regularly. What the framework means for practice IT as a whole is covered in depth by IT security in healthcare.
| Regulation | What it requires |
|---|---|
| Art. 32(1) GDPR | The availability and resilience of systems must be ensured; personal data must be restorable quickly after an incident. For health data under Art. 9 GDPR the bar is correspondingly high. |
| § 393 SGB V | Since 1 July 2024 it permits the processing of social and health data via cloud services only under certain conditions – including permissible regions, a domestic establishment, appropriate TOMs and a current C5 attestation. |
| § 630f(3) BGB | Treatment records must generally be retained for ten years after the end of treatment, unless longer periods apply. For individual areas, for example under radiation protection law, different and sometimes considerably longer periods apply. |
| § 203 StGB | An IT service provider supporting professional secrecy holders with data processing is an “other participating person” under § 203(3) StGB – the personnel involved must be bound to confidentiality. |
The right centron products
Clinics and medical institutions typically implement IT security with these modules – combinable and extensible at any time.
- Immutable backups
- €0.02 per GB per month
- Outbound traffic free
- Scheduled, not manual
- Retention as defined
- Restores are testable
- 15-minute replication
- Failover in seconds
- Separate fire compartment
How do you back up patient data in a GDPR-compliant way?
GDPR-compliant backup of patient data requires automated runs, immutable storage and documented retention and deletion periods. The core building block is S3 Object Storage from €5.00 per month with object lock, complemented by cBacks for automation and cProtect for fast recovery. The infrastructure runs in our own German data centres, certified to ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773) and with an unqualified BSI C5:2020 Type 1 attestation. New accounts receive €200 in starting credit.
| Module | Price |
|---|---|
| S3 Object Storage | from €5.00 / month |
| cBacks Backup | on request |
| cProtect | from €0.03 / month |
Frequently asked questions
Is data backup mandatory in a medical practice?
How long must patient data be retained?
Is a C5 attestation mandatory for storing patient data?
Where should patient data be stored?
Where are the backups stored?
Does centron meet the requirements of § 393 SGB V?
How often should backups run?
How long does recovery take after an outage?
Which institutions is a GDPR-compliant backup solution suitable for?
Does a backup protect against ransomware?
What is centron responsible for, and what remains with us?
How is patient confidentiality under § 203 StGB preserved?
Which documents do I receive for data protection reviews and audits?
More for healthcare
Get expert advice
Tell us about your project. Our sales team will get back to you within one business day.
The consultation is free of charge and without obligation.