gematik Produktgutachten
gematik Produktgutachten
A gematik product assessment is a security check to ensure digital health products, such as medical apps, software, or electronic patient records (ePA), are safe to use. For more information on how these assessments support the healthcare sector, check out our healthcare industry overview. This assessment helps these products connect securely to Germany's telematics infrastructure (TI), a special network for healthcare. It verifies whether the products are secure and comply with strict data protection rules. Only certified testing companies, approved by gematik GmbH, can conduct these assessments. Products must pass all the checks to be approved for use in the TI. Learn more about penetration testing.
Key Points
- Definition: The gematik product assessment evaluates the security of digital health products for use in Germany's telematics infrastructure.
- Why It's Needed: Required to approve products for use within the telematics infrastructure.
- What It Includes: Checking the source code, testing security through simulated attacks, and identifying vulnerabilities.
- Certified Testing Companies: Only specialized, certified companies can conduct these assessments.
- Security Benefits: Ensures healthcare data remains safe and private.
Related Terms
What is a Gematik Product Assessment?
A gematik product assessment is a safety review that ensures digital health products meet all the necessary rules and requirements. These products, including electronic patient records (ePA) and health apps, are used in Germany's telematics infrastructure. The assessment looks at factors like security, data protection, and technical standards to make sure the products are safe and work effectively.
Products like the ePA or health apps must meet the high standards set by gematik before they can be used within the telematics infrastructure (TI). This process helps protect sensitive health information and ensures all systems work seamlessly together.
Requirements and Testing Steps Explained
The assessment is conducted by testing companies that are certified by gematik. These companies follow several important steps to identify and fix any security issues, ensuring that digital health products are safe and reliable. These steps include:
- Source Code Analysis: Examining the program code to find any vulnerabilities. This can be done manually or with special tools.
- Penetration Testing: Simulating cyberattacks to identify weak points in the software. Learn more about penetration tests here.
- Vulnerability Assessment: Identifying any security risks that attackers could potentially exploit.
Who Needs a Gematik Product Assessment?
A gematik product assessment is required for:
- Medical Apps: Apps that are intended for use within the telematics infrastructure.
- Software Solutions: Software that processes or shares health data.
- Medical Devices: Devices that connect to the TI and handle sensitive information.
Examples include apps that manage electronic patient records, systems that handle insurance data (VSDM - Versichertenstammdatenmanagement, which means managing basic information about insured people), and connectors that link securely to the TI.
Benefits of the Gematik Product Assessment
A gematik product assessment offers several benefits, such as:
- Improved Security: Ensures the software is secure and complies with the General Data Protection Regulation (GDPR).
- Builds Trust: Only products that pass all checks are approved for the TI, which helps build trust among users and stakeholders in the healthcare system.
- Market Access: Without a gematik product assessment, a product cannot be used within the TI. Therefore, certification is crucial for entering the German healthcare market.
Certified Testing Companies for the Product Assessment
The gematik GmbH decides which testing companies are authorized to conduct these assessments. These certified testing companies are independent IT security firms that ensure all requirements are met.
One example of such a company is PwC, which is one of the leading testing bodies for digital health products in Germany.
FAQ
A GEMATIK product report evaluates and tests digital health products to see whether they meet safety and quality requirements and can be safely used in the telematics infrastructure.
The GEMATIK product review is carried out by certified testing centers and IT security companies that are approved by gematik.
All digital health solutions and products that are to be used in the telematics infrastructure require a gematik product report. This includes apps, software solutions, and medical devices.