TI does not end at the gateway
gematik describes services such as KIM and ePA as central digital healthcare services. In practice, they depend on local workstations, networks, name resolution, card readers and vendor components.
A reliable design therefore covers the complete path from user identity to the specialist system.
Segment practice networks purposefully
Administration, treatment rooms, medical devices, guests and building systems have different roles and protection needs. VLANs and firewall rules limit unnecessary communication.
Segmentation needs coordination with specialist vendors so required connections remain available and support responsibilities are clear.
Protect identities and workstations
Personal accounts, MFA, endpoint protection and accountable administrator rights reduce reliance on shared credentials. Roles should match reception, treatment and billing duties.
Updates and device lifecycles belong in a planned maintenance process.
Test backup and recovery
Backup becomes dependable only when recovery, access and responsibility have been tested. Practice software, records, configurations and external services may need different protection methods.
The recovery plan should define which systems return first and which specialist vendors need to participate.
Sources and scope
Official TI information is available from gematik at https://www.gematik.de/praxen and https://fachportal.gematik.de/.
JITIS designs and supports the surrounding IT platform and coordinates technical dependencies. Medical, legal and vendor-specific responsibilities remain with the appropriate parties.
