KRITIS Requirements vs. B3S Standards for Healthcare Providers in Germany

“Like other vital public services in Germany, including water and electricity, the German government classified hospitals as critical infrastructure or KRITIS.”

The German government deemed all hospitals treating over 30,000 cases annually as critical infrastructure supporting German citizens. All KRITIS-designated hospitals were required to update their IT security by the end of 2021.

By 2021, all hospitals in Germany must meet and exceed cybersecurity standards set forth by the BSI in response to increases in attacks during the global pandemic. BSI created a new industry standard – B3S. This new method incorporated 168 standards. All hospitals, regardless of size in Germany, are required to meet B3S standards.

A significant portion of B3S standards includes monitoring, incident response, and reporting. To meet these requirements, hospitals either staff their security operations or outsource to a managed detection and response like a Nova MDR solution from ForeNova.

What are the KRITIS Requirements for Hospitals?

Hospitals that fall under the KRITIS designation should leverage the ISO 27000 framework to help meet several critical mandates, including the enablement of proper security controls defined by the BSI.

These BSI-mandated controls include:

  • Enablement of detection and response capabilities
  • Cybersecurity breach reporting to the BSI within 72 hours of the event
  • Deployment of an Information Security Management System (ISMS)
  • 24×7 security operations capability to handle all incident responses

Here are other critical components hospitals need to execute for KRITIS:

Registration with BSI

KRITIS operators must register with the BSI and provide a primary contact for compliance, cybersecurity, and breach notifications.

Implementation of Security Measures and Intrusion Detection Systems

KRITIS hospitals must enable and sustain all adaptive controls, processes, and procedures necessary to safeguard IT systems against cyberattacks, adhering to BSI’s minimum standards.

Reporting Mandates and Information Sharing With the BSI

KRITIS operators must report major IT incidents to the BSI within 72 hours and provide necessary details for incident management. All KRITIS hospitals must also share relevant information with other hospitals and BSI authorities.

The KRITIS-designated hospital needs to develop and deploy a comprehensive disaster recovery plan to include:

  • Business impact analysis (BIA)
  • Business continuity management
  • Business continuity plan
  • Recovery time objectives

Aligning KRITIS, ISMS, B3S, and ISO 270001

The BSI mandates that KRITIS hospitals deploy and sustain an ISMS that aligns with ISO 27001 standards.

The ISMS follows four principles defined within ISO 27001: plan, implement, control, and optimize. It establishes an independent structure for improving IT security, including central roles like an IT security officer and risk analysis to identify vulnerabilities.

KRITIS hospitals need to provide evidence specifically around their risk management program, proof of monitoring, demonstrate compliance, audit management, and other elements from the B3S.

These hospitals must hire external auditors and report their findings to the BSI every two years.

Understanding B3S Standards

The B3S features 168 standards for resilient IT and patient care. These standards become categorized as must, should, and optional requirements.

The standards become broken out into five categories:

  • Interoperability: Securing data access across multiple platforms
  • Data security: Enabling encryption across all data sources
  • Privacy: Meeting all privacy mandates
  • Consent Management: Enabling patent consent systems
  • Data quality: Sustain all data’s integrity, confidentiality, and availability.

Hospitals in Germany that have already implemented ISO 27001 and an ISMS are the most prepared to meet BSI and IT-SIG 2.0 security act requirements.

Key Differences Between KRITIS and B3S

KRITIS is simply a designator for a hospital based on the number of cases to enable “state-of-the-art” cybersecurity capabilities that align with BSI directives. The KRITIS directive also states that the hospital needs to deploy an ISMS system aligned with the ISO 270001 framework. B3S provides additional standards hospitals need to enable to become compliant with BSI directives.

B3S Impact on Smaller Hospitals

Smaller hospitals not classified under KRITIS have a crucial deadline of January 1, 2022, to ensure their IT security meets state-of-the-art standards. The Social Code (SGB V) § 75c introduces new IT security regulations for hospitals aligned with BSI law, effective January 1, 2022. From this date, all hospitals must adhere to strict KRITIS IT security requirements, regardless of size.

  • “Starting in January 2022, small hospitals must introduce electronic patient records (ePA), digital referrals, and e-prescriptions.”
  • These changes will raise challenges in storing and managing patient data, a common target of cyberattacks. They must implement suitable data processing systems while adhering to strict data protection guidelines.
  • KRITIS hospitals must provide evidence to the BSI, but small hospitals have no such requirement under Section 75c SGB V or the PDSG.
  • “In October 2020, Germany enacted the Patient Data Protection Act (PDSG), which affects all hospitals and refers to IT security.”

Preparing For an Attack Requires a Preventive Mindset

Aligning with B3S standards for IT security measures is crucial for compliance because most incidents lead to data protection breaches. These breaches can occur because of cyberattacks or mishandling of personal data.

  • A common breach involves inadequate role and authorization systems for patient data; for example, a hospital in The Hague was fined 460,000 euros for allowing all employees access to patient records without proper authorization.
  • Similarly, a Portuguese hospital was fined 400,000 euros in 2018 for the same issue.
  • The German States Rhineland-Palatinate also fined a hospital 105,000 euros for multiple data protection violations related to patient admissions.

Funding Availability for Hospitals

“From 2019 to 2024, 500 million euros per year—totaling four billion euros—will be allocated to meet KRITIS requirements for large hospitals. Additionally, 4.3 billion euros are available via the Hospital Future Fund for smaller hospitals, with funding applications open until December 2021.”

Operators must invest at least 15 percent of their funds in IT security improvements.

What is the Importance of IT-SIG 2.0 with German Healthcare Facilities?

IT-SIG 2.0, the German IT Security Act 2.0, is essential for healthcare facilities as it mandates stricter cybersecurity for critical infrastructure, including hospitals. This regulation ensures the protection of sensitive patient data and the availability of medical systems against cyberattacks, which could disrupt patient care and endanger lives. It compels healthcare facilities to prioritize strong cybersecurity practices for operational resilience.

IT-SIG 2.0 also plays a critical role in mandating hospitals implement required adaptive controls, including intrusion detection, or face considerable fines. This mandate also provides additional security requirements for hospitals by creating additional reporting and data protection in alignment with GDPR.

Stricter Compliance Requirements

IT-SIG 2.0 mandates hospitals to implement necessary adaptive controls like intrusion detection or risk significant fines.

Protection of Patient Data

IT-SIG 2.0 enforces strong cybersecurity to protect sensitive patient records from unauthorized access or breaches.

Operational Continuity

The act seeks to ensure IT systems’ resilience against cyberattacks, minimize downtime, and maintain access to patient data in critical healthcare services.

Increased Accountability

Healthcare facilities must show compliance with IT-SIG 2.0 regulations, facing penalties for non-compliance.

Note: Companies should leverage Security Information Event Management (SIEM) for attack detection, case management, and playbook distribution to meet IT-SIG 2.0 security operations requirements, which include continuous monitoring, incident response, and compliance notification reporting.

The Role of MDR In Assisting Hospitals With KRITIS and B3S Compliance Mandates?

KRITIS and non-KRITIS healthcare providers struggling with staffing shortages will benefit from a partnership with an MDR provider like ForeNova. MDR helps health providers regardless of size. All healthcare providers must monitor their various security controls, protecting their digital assets, patient information, and employee data.

Here are some essential points regarding the value of MDR and B3S:

  • B3S standards for healthcare require security monitoring of all healthcare-related applications, networks, devices, databases, and portals.
  • Healthcare providers required under IT-SIG 2.0 must ensure proper intrusion detection and security operations, continuous monitoring, and reporting are operational 24/7.
  • As defined within B3S, it mandates that all hospitals have incident response plans and processes for responding to all cybersecurity events, including data breaches.

Conclusion

Ultimately, hacks in healthcare endanger lives and civic society. Minimum IT security standards, such as the KRITIS requirements, can help improve hospital security. Facility operators must follow these guidelines to ensure long-term protection against threats. The primary purpose is to keep cyber attacks from affecting hospital operations.

ForeNova, an EU-based MDR supplier, knows the complexities of healthcare compliance. All health providers, including hospitals, face overlapping mandates, redundant security controls, and cost overruns. These hospitals struggle to save security operations costs while maintaining BSI, IT-SIG 2.0, and KRITIS compliance. Staying current with B3S’s continual developments will benefit greatly from having a relationship with ForeNova.

NIS2 Compliance Requirements for the Healthcare Industry in Germany

Like the General Data Protection Regulation (GDPR), NIS2 carries considerable fines for organizations that cannot meet their mandates. It also holds individuals accountable for failure to comply, and it mandates far more transparency and collaboration to help stop security breaches within their digital infrastructure.

Healthcare organizations in Germany must follow several compliance mandates to protect their critical infrastructure. HIPAA for Germany, GDPR, and the German Federal Data Protection Act.

Compliance mandates overwhelm healthcare organizations looking for ways to lower their security operations costs. To help meet these requirements, organizations turn to ForeNova’s managed detection and response (MDR) services.

Why is NIS2 Necessary for all Healthcare Providers in Germany?

Healthcare providers are still in the middle of the digital transformation journey, modernizing their various medical applications, upgrading devices, and extending access to electronic medical records. They need to account for the requirements for NIS2 by deploying required security measures and incident response plans during or after the transformation projects.

NIS2 mandates that all healthcare providers meet and exceed the compliance requirements.

Here is a list of the most critical NIS2 mandates all Germany-based healthcare providers need to enable or execute:

  1. Perform a risk analysis on all healthcare-related applications, current cybersecurity practices, and devices before and after the modernization project is finished to determine better what remediation steps will be required to meet NIS2.
  2. Embedding automated incident response and remediation capabilities within normal business operations helps reduce cybersecurity risks. Attempting to respond to every cyberattack with manual resources is no longer a valid option. Hackers leveraging adversarial artificial intelligence (AI) and machine learning (ML) capabilities increase their attack velocity, requiring healthcare providers to counter this threat with automated response functions. Managed detection and response (MDR) providers like ForeNova assist healthcare clients in meeting this challenge.
  3. All healthcare providers must maintain backup and recovery capability to ensure that all relevant healthcare data is accessible and retrievable during a ransomware attack.
  4. Healthcare providers have become increasingly dependent on global supply chains for medicines, medical devices, operating room equipment, and hospital supplies. Each provider must implement all necessary cyber controls to prevent attacks that steal medical data, breach other ecosystem parties within the supply chain, and disrupt hospital operations.
  5. Develop and implement a vulnerability management program to include continuous assessment, reporting, and recommendations for remediation.
  6. A significant part of the NIS2 mandate for healthcare focuses on physical security. Hospitals, clinics, and remote locations must implement and sustain proper physical security controls, including biometric access to sensitive hospital areas, badge readers, surveillance cameras, and trained security officers.
  7. Access to applications, systems, network devices, and workstations must be protected using multi-factor authentication (MFA), which is essential in meeting NIS2. Medical record breaches will occur once the hacker steals healthcare workers’ initial username and password credentials. Without MFA, which offers a second level of authentication, hackers will have easy access to medical data.
  8. Under NIS2, healthcare providers must enable encryption in all areas where personally identifiable information resides, including hosted applications, email systems, and databases. All data, whether in transit or at rest, must be encrypted.
  9. All healthcare providers in Germany and the rest of the EU member states must ensure that all employees complete cybersecurity awareness training to comply with NIS2.
  10. Another area addressed within the NIS2 mandate is the need for all healthcare providers to encrypt all phone, email, and text messaging.

Meeting and exceeding these ten requirements under NIS2 are critical for all healthcare providers in Germany. Failure to achieve and sustain these ten directives will cause several fines and penalties improved by the German national authority.

Corporate Accountability

Prior to changes within NIS2, if management teams cut funding for cybersecurity controls, managed services contract renewals, or reduced security operations resources, they would not become personally liable for negligence and intentional misconduct under NIS2.

NIS2 in Germany states, “Management within a healthcare provider is liable for any damages caused by the organization during a data breach or other cyberattack. Fines could exceed €10,000,000 or up to 2% annual turnover and suspension of services.”

Authorities could levy additional fines against the German health organization for failing to notify them within 24 hours of the security breach. The health organization must also file a formal report detailing the event within 72 hours of the initial notification, including a root cause analysis and other important artifacts.

Along with financial implications, German health organizations also face an impact on their reputation as trusted healthcare providers. The organization will face countless lawsuits for non-compliance.

How Should German Healthcare Providers Collaborate With National Authorities Surrounding NIS2?

NIS2 is an EU-wide cybersecurity law. Member states, including Germany, have the right to extend other requirements within the NIS2 framework specific to healthcare organizations operating within their borders.

The German government plans to update its NIS2 directive to reflect the changing global threat landscape and its impact on citizens’ personal information. In current drafts, the government added cybersecurity certifications for critical facilities to provide updated artifacts to the Federal Office of Information Security regarding their cybersecurity technical and operations every three years.

German healthcare organizations in the third category will need to ensure they comply with this additional NIS2 mandate. NIS2 may not apply to some entities because their size or other factors prevent them from being classified as essential or necessary. Germany recognized this and drafted a third category.

This third category is called critical facilities. While this supplement is still in draft stages, it shows the power each member state, including Germany, has in adding additional requirements for health providers beyond the initial scope of NIS2 compliance.

What is the Role of MDR Services For Meeting NIS2 Compliance?

With the adoption of NIS2, healthcare providers in Germany need to adopt a more proactive approach to security operations and focus more on a risk-based approach to protecting their regulated data.

This change in focus towards security operations and risk management alters how the organization needs to handle incident response, threat hunting, access to threat intelligence, and updating encryption policies and implementation. These changes in how the organization becomes more proactive and risk-based oriented directly reflect how management will become far more liable for breaches than in previous years.

    • Managed Detection and Response (MDR) offerings continue to become a lifesaver for many healthcare organizations regarding meeting Germain NIS2 directives. The value delivered by MDR offerings remains exceptional to healthcare organizations in Germany requiring automated incident response and other advanced capabilities.
    • 24x7x365 continuous monitoring of all healthcare systems, applications, and databases (NIS2)
    • MDR services help lower operations costs than staffing in-house security operations resources, infrastructure, and maintenance costs for security tools to handle everyday cybersecurity incidents. Cost savings are becoming a primary justification for investing in an MDR service.
    • ForeNova future proofing helps keep their clients updated with the latest protection capabilities to help prevent attacks using artificial intelligence (AI) without impacting the users.
    • MDR’s ability to automate NIS2 compliance reporting and event notification is also a critical service. Healthcare organizations in Germany have a very strict notification of a security event along with a 72-hour deadline for root cause analysis. MDR’s experience in compliance automated reporting helps healthcare providers meet NIS2 requirements.
    • Access to global talent helps MDR providers like ForeNova meet their service level agreement (SLA). Healthcare providers in Germany need help retaining security operations talent. ForeNova’s ability to staff to meet their clients’ NIS2 and other compliance requirements is one of their key differentiators in the managed services space.
    • MDR providers also help organizations stay current on compliance requirements by constantly evaluating new security adaptive control solutions, including artificial intelligence (AI) and machine learning (ML) capabilities, to enhance automated incident response and reporting.

Why ForeNova?

NIS2 in Germany, like other EU compliance mandates, will constantly change. The AI Act, DORA, and NIS2 will continuously become updated as the global threat landscape changes. Partnering with ForeNova, health providers in Germany will be a firm focused on helping them meet and exceed NIS2 and other compliance mandates while reducing risk and operations costs.

Are you interested in knowing more? Click here to schedule an MDR demo today with the ForeNova team!

5 Ways MDR Services Address TISAX® Compliance Talent Gap

Cybersecurity talent shortages affect every industry, government, and higher education institution. Organizations with deep pockets have the luxury to spend their capital on recruiting, hiring, and keeping top cybersecurity engineering talent. Small-to-medium enterprise (SME) organizations continue to be challenged with accessing talent, specifically those with expertise compliance mandates, including TISAX® for the German automotive industry.

Continue reading “5 Ways MDR Services Address TISAX® Compliance Talent Gap”

How to Create an Effective Incident Response Plan Template for TISAX® Compliance?

Automotive manufacturing, design, and assembly firms invest nearly three years to achieve various maturity and assessment levels defined by the Trusted Information Security Assessment Exchange (TISAX®) compliance framework.

Continue reading “How to Create an Effective Incident Response Plan Template for TISAX® Compliance?”

Top 5 Benefits of Managed Detection and Response for TISAX® Compliance

The Trusted Information Security Assessment Exchange (TISAX®) details an assessment process for the automotive industry in Germany and the rest of the European Union (EU). Automotive giants, including BMW, prefer to work with suppliers who have achieved specific maturity levels after completing the various cybersecurity assessments.

Continue reading “Top 5 Benefits of Managed Detection and Response for TISAX® Compliance”

MDR for TISAX® compliance – How do MDR Services Work to Help You Comply?

The Trusted Information Security Assessment Exchange (TISAX®) applies to all automotive firms and supply chain partners who access sensitive information. This sensitive data could be customer automotive information, employee data, and information regarding competitive products.

Continue reading “MDR for TISAX® compliance – How do MDR Services Work to Help You Comply?”

Immer up to date!

Abonnieren Sie unseren Newsletter und erhalten Sie wertvolle Branchen-Insights, Produkt-Updates und aktuelle Analysen von ForeNova direkt in Ihr Postfach.

Wir verwenden Brevo als unsere Marketing-Plattform. Indem Sie das Formular absenden, erklären Sie sich einverstanden, dass die von Ihnen angegebenen persönlichen Informationen an Brevo zur Bearbeitung übertragen werden, gemäß den Datenschutzrichtlinien von Brevo.