Applications in the healthcare sector: TÜVIT receives accreditation for BSI TR-03161

February 16, 2023

With the receipt of the official accreditation, TÜVIT will carry out tests according to BSI TR-03161 with immediate effect. The technical guideline serves as a guideline for manufacturers of applications in the healthcare sector when creating secure solutions.

Records of pulse and heart rate, sleep data or medication plans: healthcare applications store and process a lot of personal and sensitive data. If these fall into the hands of attackers, this can sometimes have serious consequences – both for users and for manufacturers. It is therefore all the more important to protect corresponding applications from data theft or misuse as best as possible.

With the successful accreditation according to BSI TR-03161, TÜV Informationstechnik (TÜVIT) now offers manufacturers of applications in the healthcare sector tests according to the security requirements of the technical guideline. The aim of the TR is to protect the confidentiality, integrity and availability of sensitive data collected by healthcare applications. Therefore, the BSI TR-03161 contains a set of minimum requirements for the IT security of mobile applications, web applications and background systems in the healthcare sector. In addition, it can also be understood as a guideline for all applications that store or process sensitive data.

According to TR-03161, the IT security experts at TÜVIT check, among other things, the purpose, the architecture, the source code, the cryptographic implementation and the data security of corresponding applications. In doing so, they consider, for example, that the health application does not collect and process any data that does not serve its legitimate purpose, or examine whether IT security is taken into account as an integral part of the software development and life cycle. In addition to the testing aspects, TR-03161 also includes typical threat scenarios. In order to determine the resistance of applications to these, experienced pentesters from TÜVIT carry out targeted vulnerability analyses and penetration tests.

If a health application meets the requirements of BSI TR-03161, the Federal Office for Information Security (BSI) issues the desired certificate.

For manufacturers and operators of digital health applications (DiGA), the certificate according to BSI TR-03161 is also one of the necessary prerequisites for being included in the list of reimbursable digital health applications.

Related Articles

Police Crime Statistics 2025: Further decline in crime in Brandenburg

2025 figures: Drop in theft offences / Clear-up rate remains steady The number of crimes recorded by the police continued to fall in Brandenburg last year. According to the 2025 Police Crime Statistics, it fell by 5.7 per cent to 166,508 offences (2024: 176,641...

Opinion: Water as a weapon

Why the threat to drinking water supplies in the Middle East marks a turning point in international law There are forms of infrastructure whose destruction not only has military consequences but also undermines the very foundations of human existence. The drinking...

373,000 dark web sites shut down.

One operator. 23 countries. What sounds like a headline from a cyber-thriller is actually the result of Operation Alice — one of the largest global cybercrime crackdowns in recent years. > Over nearly five years, investigators uncovered a single individual running...

Share This