IT Security in Medical Practices and Law Firms
IT security for medical practices and law firms: KBV directive, professional secrecy, TI connector, beA, shared measures, common weaknesses and next steps.
IT security in medical practices and law firms is subject to stricter rules than in other businesses of the same size. Both handle data protected by criminal law, both depend on mandatory applications such as the telematics infrastructure or the beA mailbox, and both usually have no IT department of their own. The requirements come down to a few basic measures.
Legal basis
The starting point is section 203 of the German Criminal Code (StGB). Doctors, lawyers, tax advisers and their staff commit an offence if they disclose an entrusted secret without authorisation. This also applies to IT service providers: anyone who can access such data must be bound to confidentiality.
For practices, Article 9 GDPR applies in addition, because health data requires a higher level of protection. For lawyers, section 43a BRAO governs the duty of confidentiality and the required technical and organisational measures; for tax advisers, section 57 StBerG. Threats do not distinguish by sector: according to the BSI situation report 2025, most reported ransomware attacks affect small and medium-sized enterprises.
Medical practices: KBV directive, connector and PVS
For medical and psychotherapy practices under contract with statutory health insurers, the IT security directive of the National Association of Statutory Health Insurance Physicians (KBV) under section 390 SGB V is binding. The updated version has applied since 1 October 2025 and grades requirements by practice size: up to 5 users, 6 to 20 users, more than 20 users. New is the duty to raise staff awareness: short, regular training on phishing, attachments, screen locking and reporting channels, with proof of attendance.
The connector links the practice management system to the telematics infrastructure. It is a security device: firmware current, management interface reachable only from the practice network, its own password. In serial mode it performs firewall functions; in parallel mode a firewall must protect the practice network.
The practice management system (PVS) holds all patient data. It needs a server with a current operating system, backups with restore tests, and remote maintenance only after approval and with a second factor. Medical devices often run on operating systems the manufacturer no longer updates. They belong in a separate network segment that permits only the connection to the PVS.
Law firms: professional law as the benchmark
For lawyers and tax advisers there is no directive comparable to the KBV’s. The benchmark is professional law, and it is no less strict. Five points matter:
- beA: Card and PIN are personal. Staff receive their own access with restricted rights.
- Client data: Storage outside the firm’s systems without contractual safeguards, for example in private cloud storage, breaches the duty of confidentiality.
- Mobile work: Notebooks and smartphones holding case files need full-disk encryption, remote wipe and VPN access with a second factor. A lost, unencrypted notebook is a reportable data protection incident.
- Email encryption: Transport encryption is the minimum; for sensitive content, end-to-end encryption or a client portal.
- File destruction: After retention periods expire, digital files are deleted, including from archives and backups. Decommissioned storage media are wiped or destroyed with documented proof.
Shared measures
The technical basics are the same for both.
| Measure | Implementation |
|---|---|
| MFA | Second factor for VPN, remote maintenance, Microsoft 365, specialist software and administrator accounts |
| Backup | 3-2-1 rule, one copy offline or immutable, regular restore tests |
| Patch management | Operating systems, specialist software, connector, firewall and router with fixed deadlines; Windows 10 unsupported since 14 October 2025 |
| Segmentation | Medical devices, patient or client Wi-Fi, printers and servers on separate networks |
| Roles | Rights by task, no shared accounts, no administrator account for daily work |
| Incident plan | Procedure for software failure, ransomware and data exfiltration; notification of the supervisory authority within 72 hours |
| Service provider contract | Data processing agreement under Article 28 GDPR plus confidentiality undertaking under section 203 StGB |
The software vendor looks after its product; network, firewall, backup, MFA and end devices remain the responsibility of the practice or firm.
Typical weaknesses:
- Patient Wi-Fi on the same network as medical devices and the PVS server
- Vendor remote maintenance permanently active, without MFA, with the installation password
- Backup on a USB drive permanently connected to the server
Key points
- Practices and law firms are subject to section 203 StGB; practices additionally to the KBV directive, law firms to professional law.
- The basic measures are identical: MFA, separated backup, patch management, segmentation, roles, incident plan and service provider contract.
- Every measure starts with an assessment of network, remote access, permissions, end devices and backups.
How DEVACON carries out this assessment as part of its IT security check is described on the page Cybersecurity.
This article comes from the DEVACON blog and was editorially revised for the new website.