Navigation

Get in touch
Logo
News

Industries / Health

Connect care. Protect patient data.

Protect patient data and connect medical systems securely.

Consulting. Integration. Operations.

white and black hospital bed — illustrative image

Built around your industry.

  • Hospitals and hospital groups
  • University hospitals and research institutions
  • Medical centers, practice networks and laboratories
  • Manufacturers of medical technology and health software

Your priorities

Understand the challenge. Shape the solution.

We protect patient data with encryption, network segmentation and attack detection, connect hospitals and practices to the telematics infrastructure, and integrate medical devices securely.

01

Protecting patient data: segmentation, attack detection, B3S

Zoning concept with firewall rule set and device inventory

More on this
02

HIS integration and medical device connectivity

Integration architecture with interface catalog

More on this
03

Encryption, signatures and PKI with HSMs

Crypto inventory with risk rating

More on this

From strategy to implementation

Six service modules

Six fields of expertise. Explore the scope that fits your project.

01Protecting patient data: segmentation, attack detection, B3SMicrosoft Sentinel · Network Access Control · OPSWAT MetaDefender Kiosk

Our approach

Health data is a special category under Article 9 GDPR, and hospitals that count as critical infrastructure must evidence an ISMS and an attack detection system under section 8a BSIG. We divide the hospital network into zones for administration, clinical workstations, medical technology and guests, control access with network access control and encrypt data at rest and in transit. Attack detection, incident response and the ISMS under B3S for hospitals are set up so that auditors and the data protection authority receive their evidence directly from operations. For collaborations with partners in the United States we additionally map the measures to the requirements of HIPAA.

Full scope
  • Zoning concept for administration, clinical workstations, medical technology and patient Wi-Fi with firewall rules per transition
  • Network access control and device inventory, legacy devices in protected segments with controlled transitions
  • Attack detection system with SIEM and network sensors according to the BSI guidance, incident response plan with reporting paths
  • ISMS under B3S for hospitals with risk analysis, catalog of measures and evidence for the audit under section 8a BSIG
  • Encryption of file shares and storage media, inspection of patient CDs and USB media before import

A hospital group separates medical technology and administration into zones and introduces attack detection; the B3S evidence emerges from the device inventory, the risk analysis and the logs of routine operations.

What you get

  • Zoning concept with firewall rule set and device inventory
  • ISMS documentation with risk analysis and B3S evidence
  • Attack detection in operation with incident response plan
Discuss this topic
02Telematics infrastructure and KHZG projectsTI-Gateway · KIM · ePA

Our approach

The telematics infrastructure connects hospitals, practices and pharmacies for the electronic patient record, e-prescriptions and KIM, and the Hospital Future Act funds patient portals, digital documentation and medication management. We connect hospital and practice information systems through the TI gateway or connector, manage SMC-B and health professional cards and integrate portals and documentation solutions into clinical workflows through defined interfaces. Every KHZG project receives the documentation that the funding body requires as evidence.

Full scope
  • Connection of HIS and practice management system to the telematics infrastructure through TI gateway or connector, card management for SMC-B and HBA
  • Integration of ePA, e-prescription, KIM and TI messenger into admission, discharge and the dispatch of discharge letters
  • Patient portal under the KHZG with appointment booking, admission and discharge management, connected to the HIS
  • Digital nursing and treatment documentation and medication management with interfaces to pharmacy and billing
  • Project documentation, mandatory IT security criteria and evidence for the funding body

A hospital moves its patient portal onto an integration layer to the HIS; appointment and admission data flow without duplicate entry, and the KHZG evidence is ready before the deadline.

What you get

  • TI connection with card management and operations manual
  • Integrated patient portal with interface catalog
  • KHZG project documentation with evidence for the funding body
Discuss this topic
03HIS integration and medical device connectivityHL7 FHIR R4 · HL7 v2 · DICOM

Our approach

The hospital information system, laboratory, radiology, image archive and billing exchange data over HL7 v2, HL7 FHIR and DICOM, and every new device brings another interface with it. We place an integration layer with an interface catalog, an integration engine and versioned FHIR profiles under ISiK between the systems, so that changes to one system no longer affect the others. We connect medical devices over DICOM and IHE profiles and document the risk management for medical IT networks under IEC 80001-1.

Full scope
  • Interface catalog with data flows, owners and dependencies between HIS, laboratory, radiology, image archive and billing
  • Integration engine with HL7 v2 and HL7 FHIR, messages validated, versioned and with restart after disruptions
  • FHIR profiles under ISiK and IHE profiles such as PIX, PDQ and XDS for patient master data, documents and images
  • Connection of imaging, monitoring and laboratory devices over DICOM and HL7 with device inventory
  • Risk management for medical IT networks under IEC 80001-1 with responsibilities and change procedures

A hospital replaces grown point-to-point connections with an integration engine; a change of the laboratory system then affects one documented interface instead of every connected system.

What you get

  • Integration architecture with interface catalog
  • Integration engine with versioned FHIR and HL7 interfaces
  • Risk management file under IEC 80001-1
Discuss this topic
04Hospital data platform and AI in your own data centerHL7 FHIR · Lakehouse · vLLM

Our approach

Treatment, laboratory and administrative data only yield insight once they are merged, pseudonymized and usable under clear approvals. We build data platforms on a FHIR basis with a trusted third party for pseudonymization and develop models on them for occupancy forecasts, resource planning and quality analyses. Language models for discharge letter drafts and documentation run in the institution's data center, so no patient data flows to external providers. Every system is classified under the EU AI Act and checked for a possible qualification as a medical device.

Full scope
  • Data platform on a FHIR basis with connection to HIS, laboratory, radiology and billing, data catalog and access approvals
  • Trusted third party and pseudonymization under the core data set of the Medical Informatics Initiative for research and quality assurance
  • Forecasting models for bed occupancy, surgery scheduling and staffing with versioning and monitoring
  • Language models and speech recognition for discharge letter drafts and documentation, operated on your own GPU servers
  • Classification under the EU AI Act, check of MDR relevance, data protection impact assessment and model cards

A university hospital runs a language model in its own data center; discharge letter drafts are generated from findings and progress notes, and approval stays with the treating physician.

What you get

  • Data platform with data catalog and approval process
  • Operated models with model card and monitoring
  • Documentation under the EU AI Act and GDPR with MDR classification
Discuss this topic
05Encryption, signatures and PKI with HSMsThales Luna Network HSM · Utimaco u.trust GP HSM · Entrust nShield 5c

Our approach

Patient records and image data must be retained for ten to thirty years depending on the document, and the keys for them do not belong on application servers. We keep keys for database encryption, archives and backups in hardware security modules, operate a PKI for devices, services and staff and connect signature services for discharge letters and findings. Every concept starts with an inventory of the algorithms in use and ends with a roadmap that prepares the move to post-quantum cryptography for long retention periods.

Full scope
  • Crypto inventory across HIS databases, archives, backups, TLS and signatures with rating by retention period
  • Hardware security modules as root of trust for database encryption, key management over KMIP and PKCS#11
  • Internal PKI with root CA and issuing CA for medical devices, servers, services and staff certificates, certificate lifecycle automated
  • Signature services under eIDAS for discharge letters, findings and contracts, connection of health professional card and remote signing
  • Crypto-agility and migration plan to ML-KEM and ML-DSA for archives with long retention periods

A hospital group moves the keys of its HIS databases from configuration files into a hardware security module; rotation and access are logged, and the internal PKI issues device certificates automatically.

What you get

  • Crypto inventory with risk rating
  • HSM integration with key management and operations manual
  • PKI with certificate policy and automated issuance
Discuss this topic
06Resilience and emergency operationsVeeam · Kubernetes · Terraform

Our approach

An outage of the HIS endangers care, and ransomware still hits hospitals frequently. We plan operating environments that survive the loss of a site, with immutable backups, tested recovery and an emergency mode that keeps admission, medication and findings workable without the HIS. Operation runs in the hospital data center, in German data centers under ISO 27001 or in a hyperscaler region in Germany, depending on the protection needs of the data.

Full scope
  • Availability concept with protection needs per system, recovery time objectives and redundancy across two sites
  • Immutable backups with separate access management, regular recovery tests with records
  • Emergency mode for admission, medication, laboratory and findings with emergency workstations and re-entry procedures
  • Operation of portals, integration layer and data platform on Kubernetes with infrastructure as code
  • Monitoring, patch management and capacity planning with reports for hospital management and auditors

A hospital moves its backups to immutable storage and rehearses the recovery of the HIS regularly; the emergency concept keeps admission and medication workable even in a total outage.

What you get

  • Availability and emergency concept with recovery plans
  • Backup environment with documented recovery tests
  • Operations manual with monitoring and patch procedures
Discuss this topic
doctors doing surgery inside emergency room — illustrative image
Health

Typical project situations

Where change becomes tangible.

A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.

Illustrative situations, not customer references.

01 / Health

B3S evidence at a hospital group

Flat network across several sites, medical devices without updates, no attack detection, audit under section 8a BSIG announced.

Solution

Zoning concept with network access control, attack detection with SIEM, ISMS under B3S with risk analysis and catalog of measures.

Evidence under section 8a BSIG from routine operations, legacy devices in protected segments, reporting paths rehearsed.

Discuss this topic

02 / Health

Documentation AI at a university hospital

Physicians dictate discharge letters, a cloud service is ruled out for data protection reasons, research waits for pseudonymized data.

Solution

Data platform on a FHIR basis with trusted third party, language model and speech recognition on own GPU servers, classification under the EU AI Act.

Discharge letter drafts in the hospital's own data center, approval by the physician, research data with a documented approval process.

Discuss this topic

03 / Health

TI connection and patient portal at a hospital

KHZG patient portal project without connection to the HIS, connectors at end of support, evidence deadline approaching.

Solution

TI gateway with card management, integration layer with FHIR interfaces to the HIS, project documentation with mandatory criteria.

Portal in operation with appointment and admission data from the HIS, ePA and KIM connected, KHZG evidence submitted on time.

Discuss this topic

Working together

A clear path. With your team.

From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.

How we work

  1. 01

    Assessment

    Systems, interfaces, medical devices, protection needs and gaps against GDPR, B3S and KHZG

    Prioritized list of measures, device and interface inventory, gap analysis
  2. 02

    Concept

    Target architecture, zoning concept, integration layer, operating model

    Target architecture, zoning concept, interface catalog, operating model, evidence concept
  3. 03

    Implementation

    Segmentation, interfaces, platform and HSMs in stages during ongoing hospital operations

    Integrated systems, tests, documentation, acceptance per stage in planned change windows
  4. 04

    Operations

    Monitoring, audit support, knowledge transfer

    Monitoring, key rotation, support for the B3S audit and KHZG evidence, stepwise handover

Before our first conversation

You do not need all the answers yet.

Start with a concrete challenge. These four questions help us find the right direction together.

Book a first consultation
  1. 01

    What should change?

    Your current challenge and the outcome you are aiming for.

  2. 02

    Which systems are involved?

    An overview of sites, applications and interfaces.

  3. 03

    What sets the boundaries?

    Project dates, maintenance windows and known dependencies.

  4. 04

    Who needs to be involved?

    The right people from IT, security and operations.

Background & decision criteria

What are IT solutions for healthcare?

Six fields of action from patient data protection to emergency operations, planned, integrated and operated by OTOKO®. Every measure can be evidenced to data protection authorities, B3S auditors and funding bodies. The entire solution runs in German data centers.

IT solutions for healthcare protect patient data, connect hospital and practice systems with medical devices and the telematics infrastructure, and keep care running through attacks and outages. OTOKO® covers six fields of action: patient data protection with segmentation and attack detection, telematics infrastructure and KHZG projects, HIS integration and medical device connectivity, a hospital data platform and AI in your own data center, encryption and PKI with hardware security modules, and resilience and emergency operations. Each field is delivered by one OTOKO® service and can be commissioned on its own.

The difference from a pure consulting project lies in operations and evidence. Every zone, interface and model comes with an inventory, a version and the documents that the GDPR, B3S for hospitals and the KHZG funding body require. The entire solution runs in German data centers. That includes the language models that draft discharge letters, so patient data does not leave the institution.

Why OTOKO® for healthcare

  • Cryptography and HSM

    Cryptography and hardware security modules are our core competence. Keys for patient records, archives and signatures therefore sit in certified devices, with rotation and logging.

  • German data centers

    The entire solution runs in German data centers. That applies from the integration layer to the language model for documentation.

  • Critical infrastructure and regulated industries

    We work with operators of critical infrastructure and regulated industries. We know what B3S auditors, data protection authorities and funding bodies expect.

  • One team through to operations

    One team accompanies you from consulting to operations. Security architects, integration developers and data engineers stay on board, without handover to third parties.

Delivery and details

Most institutions do not fail for lack of will but on grown networks, interfaces without owners and evidence that is produced only for the audit.

Flat network with legacy medical devices

Imaging, monitoring and laboratory devices run on software without updates and can be reached from every office computer in the building.

Interfaces without a catalog

The HIS, laboratory, radiology and billing have been linked over the years with point-to-point connections that nobody knows in full.

Evidence only for the audit

The ISMS under B3S lives in spreadsheets, risks are added before the audit and the KHZG evidence ties up IT management for weeks.

Data in silos

Treatment, laboratory and administrative data sit in separate systems, analyses are produced by export and research waits for approvals.

Three operating models
On-PremisesGerman cloudHyperscaler
Data locationYour hospital data center, HIS, image archive and HSMs on siteData centers in Germany, operated under ISO 27001Azure, AWS or Google Cloud, region Germany
OperationYour team or OTOKO® as managed serviceOTOKO®, with processing agreement and audit rights for your institutionShared, platform services by the provider
ToolsIntegration engine, HSMs and GPU servers for AI on siteHosted integration layer, data platform, HSM as a serviceManaged Kubernetes, data and HSM services
Suited forHIS, medical technology, language models with patient dataPortals and data platform, institutions without their own data centerPatient portals, analytics on pseudonymized data, test environments
ComplianceFull control, evidence from your ISMS under B3SProcessing agreement under GDPR, location Germany, evidence for B3SProcessing agreement, data protection impact assessment, standard contractual clauses per service

Collaboration

Project

Clearly scoped undertaking such as a network segmentation, a TI connection or a KHZG project with a defined result, milestones and acceptance.

  • Assessment, concept, implementation, handover
  • Fixed price or effort by milestone
  • Suited for KHZG projects, B3S preparation and system changes

Team reinforcement

Security architects, integration developers for HL7 and FHIR or data engineers work in your teams, tools and approval processes.

  • Onboarding into your workflows, systems and data protection rules
  • Scalable as the project progresses
  • Suited for institutions with their own IT and capacity gaps

Managed service

OTOKO® operates the integration layer, data platform, HSMs or backup environment with agreed service levels, reports and the evidence that B3S and the GDPR require.

  • Monitoring, updates, key rotation and support
  • Processing agreement, audit rights and reports in the contract
  • Suited for institutions without their own operations team

What each regulation in healthcare requires and what OTOKO® delivers for it.

Standards and evidence
RequirementDemandsOTOKO® delivers
GDPRSpecial protection of health data under Article 9, encryption and access control under Article 32, data protection impact assessment, processing agreementsData protection concept, encryption with HSMs, pseudonymization with trusted third party, deletion concept, processing agreement with location Germany
KHZGEligible projects such as patient portals, digital documentation and medication management, mandatory IT security criteria, evidence of implementationProject planning, implementation with HIS integration, fulfillment of the mandatory criteria, project documentation and evidence for the funding body
B3S for hospitalsISMS, risk analysis, network segmentation, attack detection system, emergency management and evidence under section 8a BSIG every two yearsISMS setup, zoning concept, attack detection in operation, emergency concept with recovery tests, support during the audit
ISO 27001Information security management system with risk treatment, controls from Annex A, internal audits and management reviewOperation of our services under ISO 27001, contribution to your ISMS, evidence for your certification and for B3S
NIS2Risk management, reporting of significant incidents, supply chain security and management accountability for entities in the health sectorClassification of your institution, catalog of measures, reporting processes, supplier assessment, documents for management and the authority

FAQ

Good questions. Clear answers.

15 answers about your industry, the project and ongoing operations.

Industry & expertise6 questions

Which IT solutions for healthcare does OTOKO® offer?

The portfolio covers patient data protection with network segmentation and attack detection, connection to the telematics infrastructure and KHZG projects, integration of the HIS and medical devices over HL7 FHIR and DICOM, data platforms and AI in your own data center, encryption and PKI with HSMs, and resilience and emergency operations. Each field of action can be commissioned on its own or as a package, with operation in German data centers.

How do we secure medical devices that no longer receive updates?

Devices without vendor updates are placed in their own network segments and can be reached only through controlled transitions with defined protocols. Network access control prevents unknown devices from landing in the same segment, and attack detection monitors the traffic for deviations. The risk management under IEC 80001-1 documents which residual risks remain and who carries them.

What does B3S for hospitals require and how does OTOKO® support the evidence?

The sector-specific security standard requires an ISMS, a risk analysis, network segmentation, an attack detection system and emergency management, evidenced every two years under section 8a BSIG. We build these components so that the evidence emerges from routine operations, and we support the audit. We work with operators of critical infrastructure and regulated industries. This approach is standard there.

Can AI for documentation run without patient data leaving the institution?

Yes. Language models and speech recognition run on GPU servers in the institution's data center or in German data centers under ISO 27001, without any connection to external AI providers. The models access only approved data through the data platform, every output remains a draft until the physician approves it, and the system is documented under the EU AI Act.

What obligations arise from the KHZG?

The Hospital Future Act funds projects such as patient portals, digital documentation and medication management and ties the funding to mandatory IT security criteria. Funded hospitals must evidence the implementation, otherwise deductions from reimbursement apply. We plan the projects, integrate them into the HIS and deliver the documentation for the funding body.

What must we consider in collaborations with partners in the United States?

Anyone exchanging health data with US institutions must often meet the HIPAA Security Rule in addition to the GDPR, which requires administrative, physical and technical safeguards. We map your measures to both frameworks, set up pseudonymization and transfer channels and deliver the documents for business associate agreements and standard contractual clauses.

Getting started & delivery5 questions

Can we start with a single area of expertise?

Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.

What should we prepare for the first conversation?

A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.

Who needs to participate in the project?

Security architect: Zoning concept, attack detection, B3S evidence. Cryptography specialist: HSM integration, PKI, signature services. Integration developer: HL7, FHIR, DICOM, TI connection. Data engineer: Data platform, pseudonymization, model operations. Data protection and compliance consultant: GDPR, KHZG, B3S, NIS2, audit files. Project lead: Milestones, change windows, acceptance, reporting.

How do you determine the schedule and effort?

We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.

What does the first stage deliver?

Systems, interfaces, medical devices, protection needs and gaps against GDPR, B3S and KHZG Prioritized list of measures, device and interface inventory, gap analysis

Operations & development4 questions

How can we work together?

Project: Clearly scoped undertaking such as a network segmentation, a TI connection or a KHZG project with a defined result, milestones and acceptance. Team reinforcement: Security architects, integration developers for HL7 and FHIR or data engineers work in your teams, tools and approval processes. Managed service: OTOKO® operates the integration layer, data platform, HSMs or backup environment with agreed service levels, reports and the evidence that B3S and the GDPR require.

What happens at handover to operations?

Monitoring, audit support, knowledge transfer Monitoring, key rotation, support for the B3S audit and KHZG evidence, stepwise handover

Can we expand to further sites or systems later?

We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.

How do we keep the solution maintainable?

Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.

Health

Let's discuss your next step.

Let us work out together how your institution protects patient data and connects its systems securely.

Book a first consultation

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.