IT security in healthcare: demonstrably resilient
NIS2, PDSG and § 393 SGB V demand robust technology rather than declarations of intent – highly available, documented and operated in Germany. You can adopt the compliance evidence of the centron infrastructure directly into your own risk management.
- Fail-safe – HIS and PACS on redundant high-availability servers.
- Air-gap backups – physically isolated backups as ransomware protection.
- Digital sovereignty – operated in Hallstadt, Nuremberg and Frankfurt am Main.
- Evidence for your audit – ISO 27001 (IT-Grundschutz), C5 attestation, TOMs and DPA.
What medical IT has to withstand
Digitalisation in healthcare raises the bar for infrastructure – in regulatory and technical terms at the same time.
Uninterrupted clinical operations
HIS and PACS run on highly available systems with redundant supply – outages during treatment are not a residual risk you accept.
Air-gapped backups against ransomware
Backups are physically separated from the production system and immutable via the object lock function of S3 Object Storage – even a compromised production system cannot reach them.
Evidence for NIS2 and Section 393 SGB V
The evidence for the infrastructure share of your compliance is in place: ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773) and an unqualified BSI C5:2020 Type 1 attestation, each with its scope, plus TOMs and the data processing agreement in the Trust Center. This does not replace your own ISMS, but you do not have to audit the platform yourself.
Relief for stretched IT teams
Managed services with named contacts take over operations, updates and monitoring – your in-house IT stays free for clinical systems and users.
What does this mean in practice for your clinic?
Patient safety starts with data availability: four effects a specialised infrastructure partnership delivers in clinic operations.
Sovereignty instead of being driven
While centron ensures high availability and compliance in the background, your IT department leads the clinic’s digital innovation projects – instead of chasing incidents.
Professional authority with the board
With centron’s certificates behind you, you communicate with management at a new level of security – provable rather than asserted.
Efficiency through specialisation
Your team is relieved of nightly maintenance and routine checks. centron takes over operation, patching and monitoring of the platform.
Responsiveness as the standard
Optimised disaster recovery processes significantly reduce downtime – recovery is tested and documented regularly.
Compliance that holds up in daily operations
Anyone processing patient data needs both: technology that holds in an incident, and documents that survive an audit. centron provides highly available systems with contractual SLAs, physically separated backups and the compliance basis – certificates with scope, documentation of technical and organisational measures, and the data processing agreement. Certifying your own application remains your task; you get reliable infrastructure evidence for it.
- Highly available – redundant systems for HIS & PACS
- Air gap – backups beyond an attacker's reach
- § 393 SGB V – evidence for your certification
- Germany – processing without third-country transfer
Implementing NIS2, PDSG, B3S and § 393 SGB V reliably
The regulatory framework interlocks: NIS2 and the BSI Act set the cybersecurity duties, PDSG and § 393 SGB V protect the health data, and the B3S translates both into hospital technology. For the emergency planning behind it, the BSI 200-4 standard describes the approach; the fundamentals of the healthcare cloud apply throughout.
| Regulation | What it requires |
|---|---|
| NIS2 / BSI Act | The NIS2 implementation act entered into force on 6 December 2025; the registration deadline with the BSI expired on 6 March 2026. Affected institutions implement risk management measures under Section 30 BSIG and report significant security incidents within 24 hours. |
| PDSG | Governs the protection of health data in the telematics infrastructure and forms the basis for the electronic patient record (ePA). For medical practices, Section 75b SGB V specifies the IT security requirements. |
| § 393 SGB V | For cloud processing of health data it requires processing in permissible regions, a domestic establishment, appropriate technical and organisational measures and a current C5 attestation. |
| B3S hospital standard | The sector-specific security standard specifies technical requirements for hospitals. For hospitals with 30,000 or more inpatient cases per year it is the usual way to demonstrate compliance with the BSI Act to the supervisory authority. |
| DiGAV | Governs the requirements for “apps on prescription”. The evidence towards the BfArM is provided by the manufacturer of the application, not the infrastructure provider. |
| Hospital future & transformation funds | Applications for the hospital future fund ended in 2021; since 2026 the hospital transformation fund has taken over this role. Both require security-compliant infrastructure. |
Your partnership with centron: leverage for your IT department
Why specialised partnerships strengthen your IT: the difference is not the hardware but competence in the legal framework, depth of support and audit assistance. The evidence is available in the Trust Center.
| Focus area | centron expert partnership | Standard hosting |
|---|---|---|
| Legal framework | Specialisation in PDSG & NIS2 | Generic SLAs |
| Support level | Direct access to level 3 engineers | Anonymous ticket system |
| Audit support | Complete documentation in the Trust Center | Own research required |
| Strategic role | Focus on shaping (innovation) | Focus on upkeep (maintenance) |
The right centron products
Clinics and medical institutions typically implement IT security with these modules – combinable and extensible at any time.
- Set up by centron
- Updates & monitoring
- Backups included
- Immutable backups
- 0,02 € per GB
- Outbound traffic free
- 15-minute replication
- Failover in seconds
- Separate fire compartment
What infrastructure does IT security in healthcare require?
IT security in healthcare requires highly available systems for HIS and PACS, physically separated backups and documented evidence for NIS2, PDSG and § 393 SGB V. The core building block is the Managed Server from 53,12 € per month, complemented by S3 Object Storage with object lock for air-gapped backups and cProtect for fast recovery. The infrastructure runs in our own German data centres, certified to ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773) and with an unqualified BSI C5:2020 Type 1 attestation. New accounts receive €200 in starting credit.
| Module | Price |
|---|---|
| Managed Server | from 53,12 € / month |
| S3 Object Storage | from 5,00 € / month |
| cProtect | from 0,03 € / month |
Frequently asked questions
Does centron meet the requirements of NIS2 and PDSG?
What exactly does Section 393 SGB V require?
What is an air-gapped backup and why does it matter here?
What is centron responsible for, and what remains with us?
How is the migration of our medical applications supported?
Are personal contacts available?
Does centron also offer dedicated DiGA hosting?
How is patient confidentiality under Section 203 StGB preserved?
Is patient data processed outside Germany?
More for healthcare
Get started for free
Sign up and receive €200 credit at centron within your first 60 days.
This promotional offer applies to new accounts only. Available exclusively to businesses.