About me
Blog
Europe/Berlin
--:--:--
Projects

Königszahn – Security Governance & Managed Services

June 1, 2025
KBV-compliant IT security and managed services for a dental practice with telematics infrastructure. Königszahn operates a modern dental practice with digital infrastructure — including connectivity to Germany's Telematikinfrastruktur (TI), the mandatory digital health network. To securely handle patient data and meet regulatory requirements, the practice needed a professional security strategy.
Dental practices connected to the TI are subject to strict IT security requirements from the Kassenärztliche Bundesvereinigung (KBV), Germany's association of statutory health insurance physicians:
  • KBV IT Security Directive requires documented technical and organizational measures
  • TI components (connector, eHBA health professional card, SMC-B institution card) require specific configuration management and regular updates
  • Patient data is subject to enhanced protection under GDPR and German social law (SGB V)
  • Practice staff needs awareness training for social engineering, phishing, and secure password practices
The practice had functional IT but no structured security documentation and no defined process for patches and updates.
Implementation followed a practice-oriented methodology:
  1. Current State Assessment: Inventory of all IT systems, network components, and TI infrastructure — connector, card terminals, eHBA, SMC-B, practice management system
  2. Gap Analysis: Comparison of current state against KBV IT Security Directive requirements (Appendices 1–5)
  3. TI Component Catalog: Complete documentation of all TI components with firmware versions, certificate expiration dates, and update cycles
  4. Security Documentation: Creation of comprehensive KBV-compliant documentation — network diagram, access control concept, emergency plan, backup concept
  5. Awareness Training: Hands-on training for practice staff on phishing detection, password security, and patient data handling

The result rests on three pillars:
  • Complete KBV-compliant documentation per Appendices 1–5 of the IT Security Directive
  • Network and infrastructure diagram covering all systems, interfaces, and data flows
  • Access control concept with role-based access to patient data and practice systems
  • Emergency and recovery plan for IT outages and data loss
  • Monthly patch cycle for operating systems, practice software, and TI components
  • TI firmware monitoring tracking connector and card terminal updates
  • Certificate management for eHBA and SMC-B with timely renewal
  • Initial training for the entire practice team
  • Practical examples of healthcare-specific phishing and social engineering
  • Quick reference guides for daily IT security practices in the office

  • Full KBV compliance — all IT Security Directive requirements documented and implemented
  • Ongoing patch management — regular updates for all systems including TI components
  • Trained team — practice staff sensitized to IT security risks
  • Audit-ready — documentation available for inspection by KBV or data protection authorities at any time

  • Infrastructure: Windows clients, practice management system, TI connector (Secunet/Rise)
  • TI Components: eHBA, SMC-B, card terminals
  • Network: Segmented practice network with firewall
  • Documentation: KBV IT Security Directive (Appendices 1–5)
  • Compliance: GDPR, SGB V (German social law), KBV IT Security Directive