Applications in the healthcare sector: TÜVIT receives accreditation for BSI TR-03161

February 16, 2023

With the receipt of the official accreditation, TÜVIT will carry out tests according to BSI TR-03161 with immediate effect. The technical guideline serves as a guideline for manufacturers of applications in the healthcare sector when creating secure solutions.

Records of pulse and heart rate, sleep data or medication plans: healthcare applications store and process a lot of personal and sensitive data. If these fall into the hands of attackers, this can sometimes have serious consequences – both for users and for manufacturers. It is therefore all the more important to protect corresponding applications from data theft or misuse as best as possible.

With the successful accreditation according to BSI TR-03161, TÜV Informationstechnik (TÜVIT) now offers manufacturers of applications in the healthcare sector tests according to the security requirements of the technical guideline. The aim of the TR is to protect the confidentiality, integrity and availability of sensitive data collected by healthcare applications. Therefore, the BSI TR-03161 contains a set of minimum requirements for the IT security of mobile applications, web applications and background systems in the healthcare sector. In addition, it can also be understood as a guideline for all applications that store or process sensitive data.

According to TR-03161, the IT security experts at TÜVIT check, among other things, the purpose, the architecture, the source code, the cryptographic implementation and the data security of corresponding applications. In doing so, they consider, for example, that the health application does not collect and process any data that does not serve its legitimate purpose, or examine whether IT security is taken into account as an integral part of the software development and life cycle. In addition to the testing aspects, TR-03161 also includes typical threat scenarios. In order to determine the resistance of applications to these, experienced pentesters from TÜVIT carry out targeted vulnerability analyses and penetration tests.

If a health application meets the requirements of BSI TR-03161, the Federal Office for Information Security (BSI) issues the desired certificate.

For manufacturers and operators of digital health applications (DiGA), the certificate according to BSI TR-03161 is also one of the necessary prerequisites for being included in the list of reimbursable digital health applications.

Related Articles

AI boom: Data centres are becoming a security issue

AI boom: Data centres are becoming a security issue

The rapid expansion of AI infrastructure is driving investment in data centres to record levels. At the same time, power density, technical complexity and reliance on energy, cooling and communications systems are all increasing. This is also fundamentally altering...

When every second counts

Why communication is becoming a key resource for resilient infrastructure The new European CER guidelines are changing the way we view critical infrastructure. Resilience no longer simply means protecting buildings, networks and technical facilities against failures....

Rail transport infrastructure: Platform barriers?

Rail transport infrastructure: Platform barriers?

From ticket gates to security architecture: what Germany can learn from other countries Will access to the platform soon be restricted to holders of a valid ticket only? The idea of platform barriers is back in Germany. Yet even a brief international comparison shows...

Share This