Industries & sectors – IT security for clinics & practices

IT security in healthcare: demonstrably resilient

NIS2, PDSG and § 393 SGB V demand robust technology rather than declarations of intent – highly available, documented and operated in Germany.

Why centron

What medical IT has to withstand

Digitalisation in healthcare raises the bar for infrastructure – in regulatory and technical terms at the same time.

Uninterrupted clinical operations

HIS and PACS run on highly available systems with redundant supply – outages during treatment are not a residual risk you accept.

Air-gapped backups against ransomware

Backups are physically separated from the production system and immutable via the object lock function of S3 Object Storage – even a compromised production system cannot reach them.

Evidence for NIS2 and Section 393 SGB V

The evidence for the infrastructure share of your compliance is in place: ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773) and an unqualified BSI C5:2020 Type 1 attestation, each with its scope, plus TOMs and the data processing agreement in the Trust Center. This does not replace your own ISMS, but you do not have to audit the platform yourself.

Relief for stretched IT teams

Managed services with named contacts take over operations, updates and monitoring – your in-house IT stays free for clinical systems and users.

Error: Invalid Frontmatter Path: /var/www/www.centron.de/htdocs/user/pages/08.use-cases/27.it-sicherheit-gesundheitswesen/03._split/produkt-split.en.md Failed to read produkt-split.en.md: Unexpected characters (s reach'}) at line 9 (near "- {t: 'Air gap', d: '– backups beyond an attacker's reach'}"). --- title: Split section eyebrow: 'From risk analysis to operations' heading: 'Compliance that holds up in daily operations' plain: true badge: {b: 'Made in Germany', sub: 'Company · Data centres · Support'} link: {href: '/en/ressourcen/trust-center', label: 'View evidence in the Trust Center'} checklist: - {t: 'Highly available', d: '– redundant systems for HIS & PACS'} - {t: 'Air gap', d: '– backups beyond an attacker's reach'} - {t: '§ 393 SGB V', d: '– evidence for your certification'} - {t: 'Germany', d: '– processing without third-country transfer'} --- Anyone processing patient data needs both: technology that holds in an incident, and documents that survive an audit. centron provides highly available systems with contractual SLAs, physically separated backups and the compliance basis – certificates with scope, documentation of technical and organisational measures, and the data processing agreement. Certifying your own application remains your task; you get reliable infrastructure evidence for it.

    Recommended modules

    The right centron products

    Clinics and medical institutions typically implement IT security with these modules – combinable and extensible at any time.

    Managed Server
    From
    53,12\u00a0\u20ac / month
    Operations included
    • Set up by centron
    • Updates & monitoring
    • Backups included
    S3 Object Storage
    From
    5,00\u00a0\u20ac / month
    Object lock
    • Immutable backups
    • 0,02 \u20ac per GB
    • Outbound traffic free
    cProtect
    From
    0,03 € / month
    Ransomware protection
    • 15-minute replication
    • Failover in seconds
    • Separate fire compartment
    In brief

    What infrastructure does IT security in healthcare require?

    IT security in healthcare requires highly available systems for HIS and PACS, physically separated backups and documented evidence for NIS2, PDSG and § 393 SGB V. The core building block is the Managed Server from 53,12\u00a0\u20ac per month, complemented by S3 Object Storage with object lock for air-gapped backups and cProtect for fast recovery. The infrastructure runs in our own German data centres, certified to ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773) and with an unqualified BSI C5:2020 Type 1 attestation. New accounts receive €200 in starting credit.

    Modules and prices
    ModulePrice
    Managed Serverfrom 53,12\u00a0\u20ac / month
    S3 Object Storagefrom 5,00\u00a0\u20ac / month
    cProtectfrom 0,03 € / month
    Industries & sectors FAQ

    Frequently asked questions

    Does centron meet the requirements of NIS2 and PDSG?

    For the part that concerns the infrastructure, yes: ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773), an unqualified BSI C5:2020 Type 1 attestation, TOM documentation and a data processing agreement, all with their scope in the Trust Center. However, the addressee of Section 393 SGB V (introduced by the PDSG) and of NIS2 remains your institution: risk analysis, ISMS, reporting channels and the security of your applications are for you to demonstrate. centron provides the documentation for the supply-chain share.

    What is an air-gapped backup and why does it matter here?

    An air-gapped backup sits beyond the reach of the production system. Ransomware typically encrypts everything reachable from the infected system – including attached backups. With S3 Object Storage and object lock, backups are stored immutably: within the retention period they cannot be overwritten or deleted, not even with stolen credentials.

    Is patient data processed outside Germany?

    No. Customer data is processed exclusively in German data centres, with no transfer to third countries. The deployment location for cloud workloads is our own data centre in Hallstadt near Bamberg. centron is a German company with no foreign parent company.
    Further reading

    More for healthcare

    Get started for free

    Sign up and receive €200 credit at centron within your first 60 days.

    This promotional offer applies to new accounts only. Available exclusively to businesses.

    Jetzt loslegen Sales kontaktieren