IT Audit for Medical Practices

IT security in your practice – audited against the KBV guideline and § 390 SGB V

Fixed price from €1,500 plus VAT

Assessment to the KBV guideline, § 390 SGB V

As the owner of a practice you carry overall responsibility for IT security – even where an external IT provider looks after your systems.

Our internal audit helps you verify reliably and efficiently how the IT security guideline of the KBV (Kassenärztliche Bundesvereinigung, the German national association of statutory health insurance physicians) is implemented in your practice.

Our auditors are certified by the KBV. That ensures your audit is carried out in line with the KBV guideline and documented to withstand scrutiny – whether you rely on external providers or on your own IT staff.

An obligation to furnish proof to the KBV or to third parties is not currently set out explicitly in the German Social Code Book V (§ 390 SGB V). The KBV does recommend, however, keeping internal documentation of the measures implemented and of their review in order to meet further obligations – for instance under the GDPR (Art. 32, 28).

Our audit documents and assesses:

  • your own IT security measures in the practice
  • the services delivered by external providers
  • all evidence, risks and improvement measures

This gives you a basis that stands up to inspection and audit, and that covers your legal and organisational responsibility at the same time.

Protecting your practice at a sensible cost

Your practice is also a commercial operation – which makes the balance between security, effort and cost worth keeping. Our aim: appropriate IT security with maximum efficiency and transparency. We support you with field-tested checklists, prioritisation and recommendations for action.

Objectives of the audit

  • Verification that the KBV IT security guideline is being complied with in your practice
  • Transparency about security level, responsibilities and state of implementation
  • Assessment of the quality of service delivered by your IT providers
  • A plan of measures with priorities, deadlines and owners

Scope and delivery

1) Preparation and scope

  • Recording of systems, services and components of the telematics infrastructure (TI)
  • Review of existing contracts (data processing agreements, maintenance contracts, remote access agreements, documentation)
  • Delineation between practice and provider (roles and duties)

2) Document review

  • Review of the IT security concept, contingency plan and backup strategy
  • Inspection of logs, maintenance records and training records

3) Interviews and technical review

  • Handling of staff and permissions
  • Network plan, network security, firewall and remote access
  • Email and web applications
  • Endpoints, change management and updates
  • Backup and ability to restore
  • Requirements of the telematics infrastructure

4) Assessment and report

  • Documentation following the applicable annexes of the KBV IT security guideline, including risk rating
  • Assessment of the service quality of your providers
  • Audit report
  • Detailed plan of measures

Fixed-price packages by practice size

Our fixed-price packages follow the requirements of the KBV guideline, which rise with the size of the practice. Talk to us if your requirements differ.

PackageFixed priceIntended forScope
Small€1,500Small practices with up to 5 staffFull audit
Medium€4,000Medium-sized practices (6 – 20 staff)Full audit, on-site awareness training for staff
Large€7,500More than 20 staff, or large equipment (CT, MRI)Full audit including system review, awareness training for staff, extended follow-up support by email for up to 6 months

All prices are quoted plus VAT.

Not sure where you stand?

In a first call we clarify your situation and what makes sense as a next step. No obligation, no cost.

Book a free first call