The rules on the C5 attestation from the DigiG are relevant not only for DiGA manufacturers:

According to SGB V, they affect all “service providers within the meaning of the fourth chapter and health and long-term care insurance funds as well as their respective data processors”. This includes providers of practice management software, for example. Not included are providers of general health apps that are not part of the benefits catalogue of the statutory health insurers.

The new mandatory deadlines primarily concern the choice of cloud provider processing the health data:

These cloud providers must…

  • have held a so-called C5 attestation (type 1) since July 2024, and
  • hold a C5 attestation (type 2) from July 2025.

One problem at the moment is the limited choice of cloud providers with a C5 attestation, or the fact that a cloud provider’s existing C5 attestations do not necessarily cover health data as an area of use.

The C5 catalogue covers 17 topic areas with a total of 125 criteria, some of which are also met through other standards. For processing health data, there is currently hardly any way around attestation for cloud providers. Assessing the criteria individually against certificates already held is possible, but very laborious and may not be possible without gaps. Certification to ISO 27001, for example, does not cover all aspects of a C5 attestation. The complexity of such an audit becomes clear from the cross-reference table published by the BSI at https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/CloudComputing/Anforderungskatalog/2020/C5_2022_Referenztabelle_ISO27001.html