The gematik commissioned the Fraunhofer Institute SIT to independently examine the security concept of the electronic patient record (ePA).
This review was carried out voluntarily, even though it is not required by law.
Overall, the system architecture of the ePA was judged to be appropriate, with additional recommendations for improvement proposed.
These include measures against intentional or unintentional manipulation by an organisation’s own staff, as well as optimisations of the interfaces to health insurers and medical service providers. The gematik has already begun to address the weaknesses identified in order to increase security further.
The full report has been published by gematik: https://www.gematik.de/media/gematik/Medien/ePA_fuer_alle/Abschlussbericht_Sicherheitsanalyse_ePA_fuer_alle_Frauenhofer_SIT.pdf