Skip to content
Cybersecurity

IT Security in Medical Practices and Law Firms

IT security for medical practices and law firms: KBV directive, professional secrecy, TI connector, beA, shared measures, common weaknesses and next steps.

Published on 4 min read

Reception desk in light stone with a monitor in a bright office with a glass front.

IT security in medical practices and law firms is subject to stricter rules than in other businesses of the same size. Both handle data protected by criminal law, both depend on mandatory applications such as the telematics infrastructure or the beA mailbox, and both usually have no IT department of their own. The requirements come down to a few basic measures.

The starting point is section 203 of the German Criminal Code (StGB). Doctors, lawyers, tax advisers and their staff commit an offence if they disclose an entrusted secret without authorisation. This also applies to IT service providers: anyone who can access such data must be bound to confidentiality.

For practices, Article 9 GDPR applies in addition, because health data requires a higher level of protection. For lawyers, section 43a BRAO governs the duty of confidentiality and the required technical and organisational measures; for tax advisers, section 57 StBerG. Threats do not distinguish by sector: according to the BSI situation report 2025, most reported ransomware attacks affect small and medium-sized enterprises.

Medical practices: KBV directive, connector and PVS

For medical and psychotherapy practices under contract with statutory health insurers, the IT security directive of the National Association of Statutory Health Insurance Physicians (KBV) under section 390 SGB V is binding. The updated version has applied since 1 October 2025 and grades requirements by practice size: up to 5 users, 6 to 20 users, more than 20 users. New is the duty to raise staff awareness: short, regular training on phishing, attachments, screen locking and reporting channels, with proof of attendance.

The connector links the practice management system to the telematics infrastructure. It is a security device: firmware current, management interface reachable only from the practice network, its own password. In serial mode it performs firewall functions; in parallel mode a firewall must protect the practice network.

The practice management system (PVS) holds all patient data. It needs a server with a current operating system, backups with restore tests, and remote maintenance only after approval and with a second factor. Medical devices often run on operating systems the manufacturer no longer updates. They belong in a separate network segment that permits only the connection to the PVS.

Law firms: professional law as the benchmark

For lawyers and tax advisers there is no directive comparable to the KBV’s. The benchmark is professional law, and it is no less strict. Five points matter:

  • beA: Card and PIN are personal. Staff receive their own access with restricted rights.
  • Client data: Storage outside the firm’s systems without contractual safeguards, for example in private cloud storage, breaches the duty of confidentiality.
  • Mobile work: Notebooks and smartphones holding case files need full-disk encryption, remote wipe and VPN access with a second factor. A lost, unencrypted notebook is a reportable data protection incident.
  • Email encryption: Transport encryption is the minimum; for sensitive content, end-to-end encryption or a client portal.
  • File destruction: After retention periods expire, digital files are deleted, including from archives and backups. Decommissioned storage media are wiped or destroyed with documented proof.

Shared measures

The technical basics are the same for both.

MeasureImplementation
MFASecond factor for VPN, remote maintenance, Microsoft 365, specialist software and administrator accounts
Backup3-2-1 rule, one copy offline or immutable, regular restore tests
Patch managementOperating systems, specialist software, connector, firewall and router with fixed deadlines; Windows 10 unsupported since 14 October 2025
SegmentationMedical devices, patient or client Wi-Fi, printers and servers on separate networks
RolesRights by task, no shared accounts, no administrator account for daily work
Incident planProcedure for software failure, ransomware and data exfiltration; notification of the supervisory authority within 72 hours
Service provider contractData processing agreement under Article 28 GDPR plus confidentiality undertaking under section 203 StGB

The software vendor looks after its product; network, firewall, backup, MFA and end devices remain the responsibility of the practice or firm.

Typical weaknesses:

  • Patient Wi-Fi on the same network as medical devices and the PVS server
  • Vendor remote maintenance permanently active, without MFA, with the installation password
  • Backup on a USB drive permanently connected to the server

Key points

  • Practices and law firms are subject to section 203 StGB; practices additionally to the KBV directive, law firms to professional law.
  • The basic measures are identical: MFA, separated backup, patch management, segmentation, roles, incident plan and service provider contract.
  • Every measure starts with an assessment of network, remote access, permissions, end devices and backups.

How DEVACON carries out this assessment as part of its IT security check is described on the page Cybersecurity.

Topics Medical practice Law firm KBV directive Professional secrecy IT security check

This article comes from the DEVACON blog and was editorially revised for the new website.