Industries & sectors – Protecting sensitive health data · ISO 27001 & BSI C5

Patient data: GDPR-compliant backups, fully verifiable

A system failure on Monday morning with a full waiting room is no reason to panic with the right backup – just a restore. Protect patient and practice data reliably against outages, cyberattacks and data loss.

cBacks Console · practice backup
eu-de · Hallstadt Data Centre
Last run
successful
Storage
Object Lock
Location
Germany
BK Daily backup · automated
● Scheduled
LOCK S3 Object Lock · immutable
● Active
RST Test restore · documented
● Passed
DR cProtect · separate fire compartment
● Ready
Recovery testedpractice data · complete
  • GDPR-compliant – backups of sensitive patient data with retention to your rules.
  • Fast recovery – practice data restored quickly in an emergency.
  • Automated – backups without extra effort in daily practice.
  • Multi-layer protection – against ransomware, hardware defects and operator errors.
Why centron

What a backup for health data must deliver

Patient data is among the most sensitive information there is – backing it up is an obligation, not a precaution.

Stored immutably

Backups are stored immutably via the object lock function of S3 Object Storage: within the retention period they cannot be overwritten or deleted – not even with stolen credentials.

Automated, not manual

Backups run to schedule without anyone having to remember. Failed runs report themselves instead of failing silently.

Documented for audits

Certificates with scope, documentation of technical and organisational measures and the data processing agreement are available in the Trust Center – the basis for your processing register. What the regulatory framework means for practice IT as a whole is covered in IT security in healthcare.

Restores are testable

A backup is only as good as the last successful restore. Test restores can be scheduled instead of becoming an experiment in an emergency.

How onboarding works

Your transparent path to GDPR-compliant backups

From the first analysis to monitored operations – four steps that take medical practices, dental practices, specialist centres and medical care centres to audited backups.

Initial consultation

In a free initial consultation we clarify your practice’s starting point and protection needs – which systems run, which data accrues, what is backed up today.

Advice & risk analysis

Together we assess risks and recovery objectives: what may fail, for how long, and which retention periods apply to your treatment records.

Planning & quote

You receive a concrete backup plan with a transparent quote – building blocks, intervals, retention and costs broken down clearly.

Set-up & ongoing protection

centron sets up the backup and monitors it in operation. Failed runs raise alerts, and test restores are documented.

From risk analysis to operations

Retain, delete, restore

The GDPR requires both: keeping data available as long as retention obligations demand, and deleting it afterwards. Both belong in the backup strategy, not in a handwritten note. Retention rules in the object storage let periods expire automatically – and anything inside the period is protected against modification. Which periods apply to your institution is your decision; you get the technical implementation.

Made in GermanyCompany · Data centres · Support
View evidence in the Trust Center
  • Object lock – immutable for the retention period
  • Periods – retention and deletion as you define them
  • Separated – independent of the production system
  • Germany – processing without third-country transfer
Regulatory landscape

What GDPR, § 393 SGB V and § 630f BGB require of backups

Three duties stand behind every backup: retain for as long as the periods require; delete once they have expired – in the backup copies too; and test and document recoverability regularly. What the framework means for practice IT as a whole is covered in depth by IT security in healthcare.

Regulations and their requirements
RegulationWhat it requires
Art. 32(1) GDPRThe availability and resilience of systems must be ensured; personal data must be restorable quickly after an incident. For health data under Art. 9 GDPR the bar is correspondingly high.
§ 393 SGB VSince 1 July 2024 it permits the processing of social and health data via cloud services only under certain conditions – including permissible regions, a domestic establishment, appropriate TOMs and a current C5 attestation.
§ 630f(3) BGBTreatment records must generally be retained for ten years after the end of treatment, unless longer periods apply. For individual areas, for example under radiation protection law, different and sometimes considerably longer periods apply.
§ 203 StGBAn IT service provider supporting professional secrecy holders with data processing is an “other participating person” under § 203(3) StGB – the personnel involved must be bound to confidentiality.
Recommended modules

The right centron products

Clinics and medical institutions typically implement IT security with these modules – combinable and extensible at any time.

S3 Object Storage
From
€5.00 / month
Object lock
  • Immutable backups
  • €0.02 per GB per month
  • Outbound traffic free
cBacks Backup
Price
on request
Automated backup
  • Scheduled, not manual
  • Retention as defined
  • Restores are testable
cProtect
From
€0.03 / month
Recovery in seconds
  • 15-minute replication
  • Failover in seconds
  • Separate fire compartment
In brief

How do you back up patient data in a GDPR-compliant way?

GDPR-compliant backup of patient data requires automated runs, immutable storage and documented retention and deletion periods. The core building block is S3 Object Storage from €5.00 per month with object lock, complemented by cBacks for automation and cProtect for fast recovery. The infrastructure runs in our own German data centres, certified to ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773) and with an unqualified BSI C5:2020 Type 1 attestation. New accounts receive €200 in starting credit.

Modules and prices
ModulePrice
S3 Object Storagefrom €5.00 / month
cBacks Backupon request
cProtectfrom €0.03 / month
Industries & sectors FAQ

Frequently asked questions

Is data backup mandatory in a medical practice?

Yes. Art. 32(1) GDPR requires that the availability and resilience of systems are ensured and that personal data can be restored quickly after an incident. For health data under Art. 9 GDPR the bar is correspondingly high. Added to this are the retention obligations for treatment records.

How long must patient data be retained?

The periods follow from the treatment context and professional regulations – under § 630f(3) BGB generally ten years after the end of treatment, in certain cases, for example under radiation protection law, considerably longer. Which period applies to your institution is for you or your legal advisors to decide. Technically we implement it through retention rules in the object storage: inside the period the backup is protected, afterwards it expires automatically.

Is a C5 attestation mandatory for storing patient data?

Yes, for cloud use. Since 1 July 2024, § 393 SGB V has permitted care providers to process social and health data via cloud services only under certain conditions, which include a current C5 attestation of the processing entity. Since 1 July 2025 a C5 Type 2 attestation has been envisaged for this; the C5 equivalence regulation also allows certain alternative certifications combined with an action plan. centron holds a BSI C5:2020 Type 1 attestation for the ccloud³ and ISO 27001 certification based on IT-Grundschutz; you can obtain the current status of the attestation and the documents from the sales team.

Where should patient data be stored?

§ 393 SGB V permits processing in Germany, the EU and the EEA as well as in third countries with an adequacy decision, provided the processing entity has a domestic establishment. Also check which locations and services are actually covered by your provider’s certificate – at centron these are the Hallstadt, Nuremberg and Frankfurt am Main locations.

Where are the backups stored?

Exclusively in German data centres, with no transfer to third countries. The deployment location for cloud workloads is our own data centre in Hallstadt near Bamberg. The corresponding evidence – certificates with scope, technical measures and the data processing agreement – is available in the Trust Center.

Does centron meet the requirements of § 393 SGB V?

§ 393 SGB V requires processing in permissible regions, a domestic establishment, appropriate technical and organisational measures and a current C5 attestation. centron meets the location and establishment requirements and holds a BSI C5:2020 Type 1 attestation for the ccloud³ as well as ISO 27001 certification based on IT-Grundschutz. You can obtain the current status and the documents from the sales team.

How often should backups run?

Ideally automated and daily. Critical data can additionally be backed up at shorter intervals.

How long does recovery take after an outage?

That depends on the volume and the infrastructure. Professional backup solutions allow practice operations to resume quickly – and with cProtect a failover system is ready in seconds if needed.

Which institutions is a GDPR-compliant backup solution suitable for?

For medical practices, dental practices, specialist centres, medical care centres and other medical institutions with sensitive patient data.

Does a backup protect against ransomware?

Only if it sits beyond the attacker’s reach. Ransomware typically encrypts everything reachable from the infected system – including attached backups. That is why centron keeps backups in a separated environment and immutable via object lock: within the retention period they cannot be overwritten, not even with stolen credentials.

What is centron responsible for, and what remains with us?

centron is responsible for platform and operations: data centres, virtualisation, network, monitoring, logging, platform backup, and incident, change, emergency and provider management. Your operating systems, your applications, your business processes and your content – including the patient data itself – remain your responsibility. This boundary is expressly recorded in the scope of our ISO 27001 certification and can therefore be evidenced in an audit.

How is patient confidentiality under § 203 StGB preserved?

An IT service provider supporting professional secrecy holders with data processing is an “other participating person” under § 203(3) StGB. The personnel involved must be bound to confidentiality – at centron this is implemented through corresponding staff obligations and the documented technical and organisational measures.

Which documents do I receive for data protection reviews and audits?

The data processing agreement under Art. 28 GDPR, the documentation of technical and organisational measures under Art. 32 GDPR, and the certificates and the C5 attestation including their scope. All documents are available in the Trust Center.

Get expert advice

Tell us about your project. Our sales team will get back to you within one business day.

The consultation is free of charge and without obligation.