KBV-compliant IT security and managed services for a dental practice with telematics infrastructure.Königszahn operates a modern dental practice with digital infrastructure — including connectivity to Germany's Telematikinfrastruktur (TI), the mandatory digital health network. To securely handle patient data and meet regulatory requirements, the practice needed a professional security strategy.
The Problem
Dental practices connected to the TI are subject to strict IT security requirements from the Kassenärztliche Bundesvereinigung (KBV), Germany's association of statutory health insurance physicians:
KBV IT Security Directive requires documented technical and organizational measures
TI components (connector, eHBA health professional card, SMC-B institution card) require specific configuration management and regular updates
Patient data is subject to enhanced protection under GDPR and German social law (SGB V)
Practice staff needs awareness training for social engineering, phishing, and secure password practices
The practice had functional IT but no structured security documentation and no defined process for patches and updates.
Approach
Implementation followed a practice-oriented methodology:
Current State Assessment: Inventory of all IT systems, network components, and TI infrastructure — connector, card terminals, eHBA, SMC-B, practice management system
Gap Analysis: Comparison of current state against KBV IT Security Directive requirements (Appendices 1–5)
TI Component Catalog: Complete documentation of all TI components with firmware versions, certificate expiration dates, and update cycles
Security Documentation: Creation of comprehensive KBV-compliant documentation — network diagram, access control concept, emergency plan, backup concept
Awareness Training: Hands-on training for practice staff on phishing detection, password security, and patient data handling
Solution
The result rests on three pillars:
Security Documentation
Complete KBV-compliant documentation per Appendices 1–5 of the IT Security Directive
Network and infrastructure diagram covering all systems, interfaces, and data flows
Access control concept with role-based access to patient data and practice systems
Emergency and recovery plan for IT outages and data loss
Patch Governance
Monthly patch cycle for operating systems, practice software, and TI components
TI firmware monitoring tracking connector and card terminal updates
Certificate management for eHBA and SMC-B with timely renewal
Awareness Program
Initial training for the entire practice team
Practical examples of healthcare-specific phishing and social engineering
Quick reference guides for daily IT security practices in the office
Result
Full KBV compliance — all IT Security Directive requirements documented and implemented
Ongoing patch management — regular updates for all systems including TI components
Trained team — practice staff sensitized to IT security risks
Audit-ready — documentation available for inspection by KBV or data protection authorities at any time
Tech Stack
Infrastructure: Windows clients, practice management system, TI connector (Secunet/Rise)
TI Components: eHBA, SMC-B, card terminals
Network: Segmented practice network with firewall
Documentation: KBV IT Security Directive (Appendices 1–5)
Compliance: GDPR, SGB V (German social law), KBV IT Security Directive