Industries & sectors – IT security for clinics & practices · NIS2 & § 393 SGB V

IT security in healthcare: demonstrably resilient

NIS2, PDSG and § 393 SGB V demand robust technology rather than declarations of intent – highly available, documented and operated in Germany. You can adopt the compliance evidence of the centron infrastructure directly into your own risk management.

centron Security · clinic environment
eu-de · Hallstadt Data Centre
Systems
HIS / PACS
Backups
Air-gap
Compliance
C5 / ISO
HIS Hospital information system · HA pool
● Active
PACS Image archive · NVMe volumes
● Running
BK S3 Object Lock · immutable
● Secured
DR cProtect · separate fire compartment
● Ready
Recovery testedcBacks · documented
  • Fail-safe – HIS and PACS on redundant high-availability servers.
  • Air-gap backups – physically isolated backups as ransomware protection.
  • Digital sovereignty – operated in Hallstadt, Nuremberg and Frankfurt am Main.
  • Evidence for your audit – ISO 27001 (IT-Grundschutz), C5 attestation, TOMs and DPA.
Why centron

What medical IT has to withstand

Digitalisation in healthcare raises the bar for infrastructure – in regulatory and technical terms at the same time.

Uninterrupted clinical operations

HIS and PACS run on highly available systems with redundant supply – outages during treatment are not a residual risk you accept.

Air-gapped backups against ransomware

Backups are physically separated from the production system and immutable via the object lock function of S3 Object Storage – even a compromised production system cannot reach them.

Evidence for NIS2 and Section 393 SGB V

The evidence for the infrastructure share of your compliance is in place: ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773) and an unqualified BSI C5:2020 Type 1 attestation, each with its scope, plus TOMs and the data processing agreement in the Trust Center. This does not replace your own ISMS, but you do not have to audit the platform yourself.

Relief for stretched IT teams

Managed services with named contacts take over operations, updates and monitoring – your in-house IT stays free for clinical systems and users.

In clinic routine

What does this mean in practice for your clinic?

Patient safety starts with data availability: four effects a specialised infrastructure partnership delivers in clinic operations.

Sovereignty instead of being driven

While centron ensures high availability and compliance in the background, your IT department leads the clinic’s digital innovation projects – instead of chasing incidents.

Professional authority with the board

With centron’s certificates behind you, you communicate with management at a new level of security – provable rather than asserted.

Efficiency through specialisation

Your team is relieved of nightly maintenance and routine checks. centron takes over operation, patching and monitoring of the platform.

Responsiveness as the standard

Optimised disaster recovery processes significantly reduce downtime – recovery is tested and documented regularly.

From risk analysis to operations

Compliance that holds up in daily operations

Anyone processing patient data needs both: technology that holds in an incident, and documents that survive an audit. centron provides highly available systems with contractual SLAs, physically separated backups and the compliance basis – certificates with scope, documentation of technical and organisational measures, and the data processing agreement. Certifying your own application remains your task; you get reliable infrastructure evidence for it.

Made in GermanyCompany · Data centres · Support
View evidence in the Trust Center
  • Highly available – redundant systems for HIS & PACS
  • Air gap – backups beyond an attacker's reach
  • § 393 SGB V – evidence for your certification
  • Germany – processing without third-country transfer
Regulatory landscape

Implementing NIS2, PDSG, B3S and § 393 SGB V reliably

The regulatory framework interlocks: NIS2 and the BSI Act set the cybersecurity duties, PDSG and § 393 SGB V protect the health data, and the B3S translates both into hospital technology. For the emergency planning behind it, the BSI 200-4 standard describes the approach; the fundamentals of the healthcare cloud apply throughout.

Regulations and their requirements
RegulationWhat it requires
NIS2 / BSI ActThe NIS2 implementation act entered into force on 6 December 2025; the registration deadline with the BSI expired on 6 March 2026. Affected institutions implement risk management measures under Section 30 BSIG and report significant security incidents within 24 hours.
PDSGGoverns the protection of health data in the telematics infrastructure and forms the basis for the electronic patient record (ePA). For medical practices, Section 75b SGB V specifies the IT security requirements.
§ 393 SGB VFor cloud processing of health data it requires processing in permissible regions, a domestic establishment, appropriate technical and organisational measures and a current C5 attestation.
B3S hospital standardThe sector-specific security standard specifies technical requirements for hospitals. For hospitals with 30,000 or more inpatient cases per year it is the usual way to demonstrate compliance with the BSI Act to the supervisory authority.
DiGAVGoverns the requirements for “apps on prescription”. The evidence towards the BfArM is provided by the manufacturer of the application, not the infrastructure provider.
Hospital future & transformation fundsApplications for the hospital future fund ended in 2021; since 2026 the hospital transformation fund has taken over this role. Both require security-compliant infrastructure.
Strategic leverage

Your partnership with centron: leverage for your IT department

Why specialised partnerships strengthen your IT: the difference is not the hardware but competence in the legal framework, depth of support and audit assistance. The evidence is available in the Trust Center.

Expert partnership and standard hosting compared
Focus areacentron expert partnershipStandard hosting
Legal frameworkSpecialisation in PDSG & NIS2Generic SLAs
Support levelDirect access to level 3 engineersAnonymous ticket system
Audit supportComplete documentation in the Trust CenterOwn research required
Strategic roleFocus on shaping (innovation)Focus on upkeep (maintenance)
Recommended modules

The right centron products

Clinics and medical institutions typically implement IT security with these modules – combinable and extensible at any time.

Managed Server
From
53,12 € / month
Operations included
  • Set up by centron
  • Updates & monitoring
  • Backups included
S3 Object Storage
From
5,00 € / month
Object lock
  • Immutable backups
  • 0,02 € per GB
  • Outbound traffic free
cProtect
From
0,03 € / month
Ransomware protection
  • 15-minute replication
  • Failover in seconds
  • Separate fire compartment
In brief

What infrastructure does IT security in healthcare require?

IT security in healthcare requires highly available systems for HIS and PACS, physically separated backups and documented evidence for NIS2, PDSG and § 393 SGB V. The core building block is the Managed Server from 53,12 € per month, complemented by S3 Object Storage with object lock for air-gapped backups and cProtect for fast recovery. The infrastructure runs in our own German data centres, certified to ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773) and with an unqualified BSI C5:2020 Type 1 attestation. New accounts receive €200 in starting credit.

Modules and prices
ModulePrice
Managed Serverfrom 53,12 € / month
S3 Object Storagefrom 5,00 € / month
cProtectfrom 0,03 € / month
Industries & sectors FAQ

Frequently asked questions

Does centron meet the requirements of NIS2 and PDSG?

For the part that concerns the infrastructure, yes: ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773), an unqualified BSI C5:2020 Type 1 attestation, TOM documentation and a data processing agreement, all with their scope in the Trust Center. However, the addressee of Section 393 SGB V (introduced by the PDSG) and of NIS2 remains your institution: risk analysis, ISMS, reporting channels and the security of your applications are for you to demonstrate. centron provides the documentation for the supply-chain share.

What exactly does Section 393 SGB V require?

If you process health data via cloud services as a care provider, you must check whether your provider meets the requirements of Section 393 SGB V: processing in permissible regions, a domestic establishment, appropriate technical and organisational measures and a current C5 attestation. centron meets the location and establishment requirements and holds a BSI C5:2020 Type 1 attestation for the ccloud³ as well as ISO 27001 certification based on IT-Grundschutz. You can obtain the documents from the sales team.

What is an air-gapped backup and why does it matter here?

An air-gapped backup sits beyond the reach of the production system. Ransomware typically encrypts everything reachable from the infected system – including attached backups. With S3 Object Storage and object lock, backups are stored immutably: within the retention period they cannot be overwritten or deleted, not even with stolen credentials. See backup for patient data for how this looks for practices and clinics.

What is centron responsible for, and what remains with us?

centron is responsible for platform and operations: data centres, virtualisation, network, monitoring, logging, platform backup, and incident, change, emergency and provider management. Your operating systems, your applications, your business processes and your content – including the patient data itself – remain your responsibility. This boundary is expressly recorded in the scope of our ISO 27001 certification and can therefore be evidenced in an audit.

How is the migration of our medical applications supported?

The centron solution team works hand in hand with your IT. The migration follows a detailed project plan to avoid downtime and preserve the integrity of your databases.

Are personal contacts available?

Yes. At centron you have direct access to competent contacts (level 3) who know your infrastructure environment in detail and advise you as equals.

Does centron also offer dedicated DiGA hosting?

Yes. Manufacturers of digital health applications run their solution on the certified platform. The evidence towards the BfArM is provided by the manufacturer itself; centron supplies the certificates with their scope, the TOM documentation and the data processing agreement. Which evidence your application needs in detail depends on its protection requirements.

How is patient confidentiality under Section 203 StGB preserved?

An IT service provider supporting professional secrecy holders with data processing is an “other participating person” under Section 203 (3) StGB. The personnel involved must be bound to confidentiality – at centron this is implemented through corresponding staff obligations and the documented technical and organisational measures.

Is patient data processed outside Germany?

No. Customer data is processed exclusively in German data centres, with no transfer to third countries. The deployment location for cloud workloads is our own data centre in Hallstadt near Bamberg. centron is a German company with no foreign parent company.

Get started for free

Sign up and receive €200 credit at centron within your first 60 days.

This promotional offer applies to new accounts only. Available exclusively to businesses.