Protecting patient data: segmentation, attack detection, B3S
Zoning concept with firewall rule set and device inventory
More on thisIndustries / Health
Protect patient data and connect medical systems securely.
Consulting. Integration. Operations.

Built around your industry.
Your priorities
We protect patient data with encryption, network segmentation and attack detection, connect hospitals and practices to the telematics infrastructure, and integrate medical devices securely.
Zoning concept with firewall rule set and device inventory
More on thisIntegration architecture with interface catalog
More on thisCrypto inventory with risk rating
More on thisFrom strategy to implementation
Six fields of expertise. Explore the scope that fits your project.
Our approach
Health data is a special category under Article 9 GDPR, and hospitals that count as critical infrastructure must evidence an ISMS and an attack detection system under section 8a BSIG. We divide the hospital network into zones for administration, clinical workstations, medical technology and guests, control access with network access control and encrypt data at rest and in transit. Attack detection, incident response and the ISMS under B3S for hospitals are set up so that auditors and the data protection authority receive their evidence directly from operations. For collaborations with partners in the United States we additionally map the measures to the requirements of HIPAA.
A hospital group separates medical technology and administration into zones and introduces attack detection; the B3S evidence emerges from the device inventory, the risk analysis and the logs of routine operations.
Our approach
The telematics infrastructure connects hospitals, practices and pharmacies for the electronic patient record, e-prescriptions and KIM, and the Hospital Future Act funds patient portals, digital documentation and medication management. We connect hospital and practice information systems through the TI gateway or connector, manage SMC-B and health professional cards and integrate portals and documentation solutions into clinical workflows through defined interfaces. Every KHZG project receives the documentation that the funding body requires as evidence.
A hospital moves its patient portal onto an integration layer to the HIS; appointment and admission data flow without duplicate entry, and the KHZG evidence is ready before the deadline.
Our approach
The hospital information system, laboratory, radiology, image archive and billing exchange data over HL7 v2, HL7 FHIR and DICOM, and every new device brings another interface with it. We place an integration layer with an interface catalog, an integration engine and versioned FHIR profiles under ISiK between the systems, so that changes to one system no longer affect the others. We connect medical devices over DICOM and IHE profiles and document the risk management for medical IT networks under IEC 80001-1.
A hospital replaces grown point-to-point connections with an integration engine; a change of the laboratory system then affects one documented interface instead of every connected system.
Our approach
Treatment, laboratory and administrative data only yield insight once they are merged, pseudonymized and usable under clear approvals. We build data platforms on a FHIR basis with a trusted third party for pseudonymization and develop models on them for occupancy forecasts, resource planning and quality analyses. Language models for discharge letter drafts and documentation run in the institution's data center, so no patient data flows to external providers. Every system is classified under the EU AI Act and checked for a possible qualification as a medical device.
A university hospital runs a language model in its own data center; discharge letter drafts are generated from findings and progress notes, and approval stays with the treating physician.
Our approach
Patient records and image data must be retained for ten to thirty years depending on the document, and the keys for them do not belong on application servers. We keep keys for database encryption, archives and backups in hardware security modules, operate a PKI for devices, services and staff and connect signature services for discharge letters and findings. Every concept starts with an inventory of the algorithms in use and ends with a roadmap that prepares the move to post-quantum cryptography for long retention periods.
A hospital group moves the keys of its HIS databases from configuration files into a hardware security module; rotation and access are logged, and the internal PKI issues device certificates automatically.
Our approach
An outage of the HIS endangers care, and ransomware still hits hospitals frequently. We plan operating environments that survive the loss of a site, with immutable backups, tested recovery and an emergency mode that keeps admission, medication and findings workable without the HIS. Operation runs in the hospital data center, in German data centers under ISO 27001 or in a hyperscaler region in Germany, depending on the protection needs of the data.
A hospital moves its backups to immutable storage and rehearses the recovery of the HIS regularly; the emergency concept keeps admission and medication workable even in a total outage.

Typical project situations
A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.
Illustrative situations, not customer references.
01 / Health
Flat network across several sites, medical devices without updates, no attack detection, audit under section 8a BSIG announced.
Zoning concept with network access control, attack detection with SIEM, ISMS under B3S with risk analysis and catalog of measures.
Evidence under section 8a BSIG from routine operations, legacy devices in protected segments, reporting paths rehearsed.
02 / Health
Physicians dictate discharge letters, a cloud service is ruled out for data protection reasons, research waits for pseudonymized data.
Data platform on a FHIR basis with trusted third party, language model and speech recognition on own GPU servers, classification under the EU AI Act.
Discharge letter drafts in the hospital's own data center, approval by the physician, research data with a documented approval process.
03 / Health
KHZG patient portal project without connection to the HIS, connectors at end of support, evidence deadline approaching.
TI gateway with card management, integration layer with FHIR interfaces to the HIS, project documentation with mandatory criteria.
Portal in operation with appointment and admission data from the HIS, ePA and KIM connected, KHZG evidence submitted on time.
Working together
From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.
How we work
Systems, interfaces, medical devices, protection needs and gaps against GDPR, B3S and KHZG
Target architecture, zoning concept, integration layer, operating model
Segmentation, interfaces, platform and HSMs in stages during ongoing hospital operations
Monitoring, audit support, knowledge transfer
Before our first conversation
Start with a concrete challenge. These four questions help us find the right direction together.
Book a first consultationYour current challenge and the outcome you are aiming for.
An overview of sites, applications and interfaces.
Project dates, maintenance windows and known dependencies.
The right people from IT, security and operations.
Six fields of action from patient data protection to emergency operations, planned, integrated and operated by OTOKO®. Every measure can be evidenced to data protection authorities, B3S auditors and funding bodies. The entire solution runs in German data centers.
IT solutions for healthcare protect patient data, connect hospital and practice systems with medical devices and the telematics infrastructure, and keep care running through attacks and outages. OTOKO® covers six fields of action: patient data protection with segmentation and attack detection, telematics infrastructure and KHZG projects, HIS integration and medical device connectivity, a hospital data platform and AI in your own data center, encryption and PKI with hardware security modules, and resilience and emergency operations. Each field is delivered by one OTOKO® service and can be commissioned on its own.
The difference from a pure consulting project lies in operations and evidence. Every zone, interface and model comes with an inventory, a version and the documents that the GDPR, B3S for hospitals and the KHZG funding body require. The entire solution runs in German data centers. That includes the language models that draft discharge letters, so patient data does not leave the institution.
Cryptography and hardware security modules are our core competence. Keys for patient records, archives and signatures therefore sit in certified devices, with rotation and logging.
The entire solution runs in German data centers. That applies from the integration layer to the language model for documentation.
We work with operators of critical infrastructure and regulated industries. We know what B3S auditors, data protection authorities and funding bodies expect.
One team accompanies you from consulting to operations. Security architects, integration developers and data engineers stay on board, without handover to third parties.
Most institutions do not fail for lack of will but on grown networks, interfaces without owners and evidence that is produced only for the audit.
01
Imaging, monitoring and laboratory devices run on software without updates and can be reached from every office computer in the building.
02
The HIS, laboratory, radiology and billing have been linked over the years with point-to-point connections that nobody knows in full.
03
The ISMS under B3S lives in spreadsheets, risks are added before the audit and the KHZG evidence ties up IT management for weeks.
04
Treatment, laboratory and administrative data sit in separate systems, analyses are produced by export and research waits for approvals.
| On-Premises | German cloud | Hyperscaler | |
|---|---|---|---|
| Data location | Your hospital data center, HIS, image archive and HSMs on site | Data centers in Germany, operated under ISO 27001 | Azure, AWS or Google Cloud, region Germany |
| Operation | Your team or OTOKO® as managed service | OTOKO®, with processing agreement and audit rights for your institution | Shared, platform services by the provider |
| Tools | Integration engine, HSMs and GPU servers for AI on site | Hosted integration layer, data platform, HSM as a service | Managed Kubernetes, data and HSM services |
| Suited for | HIS, medical technology, language models with patient data | Portals and data platform, institutions without their own data center | Patient portals, analytics on pseudonymized data, test environments |
| Compliance | Full control, evidence from your ISMS under B3S | Processing agreement under GDPR, location Germany, evidence for B3S | Processing agreement, data protection impact assessment, standard contractual clauses per service |
Collaboration
Project
Clearly scoped undertaking such as a network segmentation, a TI connection or a KHZG project with a defined result, milestones and acceptance.
Team reinforcement
Security architects, integration developers for HL7 and FHIR or data engineers work in your teams, tools and approval processes.
Managed service
OTOKO® operates the integration layer, data platform, HSMs or backup environment with agreed service levels, reports and the evidence that B3S and the GDPR require.
What each regulation in healthcare requires and what OTOKO® delivers for it.
| Requirement | Demands | OTOKO® delivers |
|---|---|---|
| GDPR | Special protection of health data under Article 9, encryption and access control under Article 32, data protection impact assessment, processing agreements | Data protection concept, encryption with HSMs, pseudonymization with trusted third party, deletion concept, processing agreement with location Germany |
| KHZG | Eligible projects such as patient portals, digital documentation and medication management, mandatory IT security criteria, evidence of implementation | Project planning, implementation with HIS integration, fulfillment of the mandatory criteria, project documentation and evidence for the funding body |
| B3S for hospitals | ISMS, risk analysis, network segmentation, attack detection system, emergency management and evidence under section 8a BSIG every two years | ISMS setup, zoning concept, attack detection in operation, emergency concept with recovery tests, support during the audit |
| ISO 27001 | Information security management system with risk treatment, controls from Annex A, internal audits and management review | Operation of our services under ISO 27001, contribution to your ISMS, evidence for your certification and for B3S |
| NIS2 | Risk management, reporting of significant incidents, supply chain security and management accountability for entities in the health sector | Classification of your institution, catalog of measures, reporting processes, supplier assessment, documents for management and the authority |
FAQ
15 answers about your industry, the project and ongoing operations.
The portfolio covers patient data protection with network segmentation and attack detection, connection to the telematics infrastructure and KHZG projects, integration of the HIS and medical devices over HL7 FHIR and DICOM, data platforms and AI in your own data center, encryption and PKI with HSMs, and resilience and emergency operations. Each field of action can be commissioned on its own or as a package, with operation in German data centers.
Devices without vendor updates are placed in their own network segments and can be reached only through controlled transitions with defined protocols. Network access control prevents unknown devices from landing in the same segment, and attack detection monitors the traffic for deviations. The risk management under IEC 80001-1 documents which residual risks remain and who carries them.
The sector-specific security standard requires an ISMS, a risk analysis, network segmentation, an attack detection system and emergency management, evidenced every two years under section 8a BSIG. We build these components so that the evidence emerges from routine operations, and we support the audit. We work with operators of critical infrastructure and regulated industries. This approach is standard there.
Yes. Language models and speech recognition run on GPU servers in the institution's data center or in German data centers under ISO 27001, without any connection to external AI providers. The models access only approved data through the data platform, every output remains a draft until the physician approves it, and the system is documented under the EU AI Act.
The Hospital Future Act funds projects such as patient portals, digital documentation and medication management and ties the funding to mandatory IT security criteria. Funded hospitals must evidence the implementation, otherwise deductions from reimbursement apply. We plan the projects, integrate them into the HIS and deliver the documentation for the funding body.
Anyone exchanging health data with US institutions must often meet the HIPAA Security Rule in addition to the GDPR, which requires administrative, physical and technical safeguards. We map your measures to both frameworks, set up pseudonymization and transfer channels and deliver the documents for business associate agreements and standard contractual clauses.
Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.
A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.
Security architect: Zoning concept, attack detection, B3S evidence. Cryptography specialist: HSM integration, PKI, signature services. Integration developer: HL7, FHIR, DICOM, TI connection. Data engineer: Data platform, pseudonymization, model operations. Data protection and compliance consultant: GDPR, KHZG, B3S, NIS2, audit files. Project lead: Milestones, change windows, acceptance, reporting.
We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.
Systems, interfaces, medical devices, protection needs and gaps against GDPR, B3S and KHZG Prioritized list of measures, device and interface inventory, gap analysis
Project: Clearly scoped undertaking such as a network segmentation, a TI connection or a KHZG project with a defined result, milestones and acceptance. Team reinforcement: Security architects, integration developers for HL7 and FHIR or data engineers work in your teams, tools and approval processes. Managed service: OTOKO® operates the integration layer, data platform, HSMs or backup environment with agreed service levels, reports and the evidence that B3S and the GDPR require.
Monitoring, audit support, knowledge transfer Monitoring, key rotation, support for the B3S audit and KHZG evidence, stepwise handover
We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.
Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.
Health
Let us work out together how your institution protects patient data and connects its systems securely.
Book a first consultation