Applications in the healthcare sector: TÜVIT receives accreditation for BSI TR-03161

February 16, 2023

With the receipt of the official accreditation, TÜVIT will carry out tests according to BSI TR-03161 with immediate effect. The technical guideline serves as a guideline for manufacturers of applications in the healthcare sector when creating secure solutions.

Records of pulse and heart rate, sleep data or medication plans: healthcare applications store and process a lot of personal and sensitive data. If these fall into the hands of attackers, this can sometimes have serious consequences – both for users and for manufacturers. It is therefore all the more important to protect corresponding applications from data theft or misuse as best as possible.

With the successful accreditation according to BSI TR-03161, TÜV Informationstechnik (TÜVIT) now offers manufacturers of applications in the healthcare sector tests according to the security requirements of the technical guideline. The aim of the TR is to protect the confidentiality, integrity and availability of sensitive data collected by healthcare applications. Therefore, the BSI TR-03161 contains a set of minimum requirements for the IT security of mobile applications, web applications and background systems in the healthcare sector. In addition, it can also be understood as a guideline for all applications that store or process sensitive data.

According to TR-03161, the IT security experts at TÜVIT check, among other things, the purpose, the architecture, the source code, the cryptographic implementation and the data security of corresponding applications. In doing so, they consider, for example, that the health application does not collect and process any data that does not serve its legitimate purpose, or examine whether IT security is taken into account as an integral part of the software development and life cycle. In addition to the testing aspects, TR-03161 also includes typical threat scenarios. In order to determine the resistance of applications to these, experienced pentesters from TÜVIT carry out targeted vulnerability analyses and penetration tests.

If a health application meets the requirements of BSI TR-03161, the Federal Office for Information Security (BSI) issues the desired certificate.

For manufacturers and operators of digital health applications (DiGA), the certificate according to BSI TR-03161 is also one of the necessary prerequisites for being included in the list of reimbursable digital health applications.

Related Articles

Focus on the importance of cooperation and innovation

Herrmann at the Security and Innovation Forum at Friedrich-Alexander University Erlangen-Nuremberg At the Security and Innovation Forum at Friedrich-Alexander University Erlangen-Nuremberg (FAU) on Monday, Bavaria's Interior Minister Joachim Herrmann emphasised the...

Airbus’ OneSat selected for Oman’s first satellite

Space Communication Technologies (SCT), Oman's national satellite operator, has awarded Airbus Defence and Space a contract for OmanSat-1, a state-of-the-art, fully reconfigurable, high-throughput OneSat telecommunications satellite, including the associated system....

Black Friday: Half go bargain hunting

On average, 312 euros are spent – around 11 per cent more than last year Online shops from China polarise opinion: half avoid them, the other half have already ordered from them Four out of ten young people would send AI shopping on its own When Black Friday and the...

Share This