Skip to content
Compliance

Hospitals & Critical Infrastructure: B3S, NIS-2 Extension, and Smart Use of KHZG Funds

|
|
7 min read

In 2026, German hospital CIOs have a desk full of duties. At the same time, ransomware attacks on the sector have not slowed down since 2023. The list of obligations is long:

  • the sector-specific security standard B3S,
  • the NIS-2 extension to all hospitals,
  • the mandatory link to the ePA (electronic patient record),
  • proof of how KHZG funds were used.

The Rules That Come Together in 2026

  • B3S Hospital (BSI-certified): a must for hospitals with 30,000+ inpatient cases per year. For smaller ones it is optional. Even so, insurers and auditors often expect it.
  • NIS-2 Implementation Act: extends critical infrastructure duties to all hospitals, no matter how many beds they have. The management (board, GmbH leaders) is personally liable.
  • Patient Data Protection Act (PDSG) + ePA: you must connect to the ePA and log in via the TI connector. You must also be able to prove patient access rights in digital form.
  • KHZG funds: a federal funding program for cyber security. You must prove how you used the money. 15 % of the funds must go into IT security.

Where Hospital CIOs Feel the Pain

1. Mixed Devices, Old Standards

MRI machines run on Windows 7. OR robots run on Linux that can't be updated. Patient monitors use serial links. The asset list is often incomplete. The level of protection each device needs is rarely written down.

Structured asset management helps here. Medical devices get their own class. Vendor contracts are linked. The patch status is shown as it really is, which often means "compensating control: network segmentation".

2. Ransomware Puts Patients at Risk

A surgery can't take place because the patient record is encrypted. That is not just an "IT incident". It is harm to a patient, with legal liability. NIS-2 Art. 23 requires an early warning within 24 h. During a running OR program, you must document that warning before anyone discusses it.

A 72h crisis communication plan prepares you for this:

  • ready-made templates to inform patients,
  • a workflow to move OR cases elsewhere,
  • an early warning to the regulator that the crisis team has practiced.

3. The ePA Link as a Compliance Task

The TI connector links hospital IT to the gematik telematics network. Users log in with the electronic health professional card (eHBA). Every access to patient data needs an audit trail. An integrated Keycloak IAM solution can use the eHBA as a second factor. That way you don't have to run three separate systems.

4. Supplier Risks in Daily Clinic Work

Think of lab providers, imaging clouds, nursing records as SaaS and device vendors with remote access. Each one is a possible way in. NIS-2 Art. 21(2)(d) makes third-party risk management (TPRM) a must. A supplier portal with a self-service questionnaire cuts the upkeep sharply.

5. Proof of KHZG Spending

You must use the funds for the stated purpose. You must also prove this up to 6 months after the payout. A single line called "cyber security platform" is not enough. Each investment needs a clear reason: which risk does it reduce? The risk register links risks to their treatment and gives you that proof.

Where to Spend KHZG Funds First

  1. Asset inventory with protection-need rating: everything else builds on it. Without it, there is no clean B3S audit.
  2. Mail security with CAPE sandbox: phishing is still the main way into hospitals in 2026. CAPE opens attachments in a sandbox on its own.
  3. Identity platform with eHBA support: compliance, SSO and the account lifecycle in one step.
  4. SIEM with forensic depth: ransomware forensics needs 12 months of logs, not 30 days.
  5. Risk management platform: B3S audit, KHZG proof and board reports from one source.

How One Platform Serves the Sector

SecTepe.Core provides the base for the ISMS and risk management. SecTepe.Comm adds the tools for daily security work. You host both yourself, in your own data center or with a German municipal hoster. Patient data never leaves the house. Several hospitals of one operator can share central tools. No data flows between them.

What to Expect for Setup

  • 200-bed hospital, medium IT maturity: 6 months for the B3S base and 12 months until you are ready for the B3S audit. The first platform investment is about €120 k (eligible for KHZG funds).
  • Hospital group with 5 sites: 9 months for the base at all sites in parallel and 15 months for a group-wide audit program. The first investment is about €250 k, but much cheaper per site.

Compliance Mapping

  • B3S Hospital (BSI-certified): 5 protection goals, 30+ requirements, audit every 2 years.
  • NIS-2 Art. 20–23: duties of the management, minimum measures and an early warning within 24h.
  • SGB V §75c, PDSG: TI link, ePA duties and login with the eHBA.
  • KHZG funding category 10: IT security, with proof of use.
  • ISO 27001: often required by insurers and in audits by the hospital operator.

Conclusion

In 2026, hospitals face a wave of rules that Excel and good intentions can no longer handle. An integrated ISMS and security platform helps. If you use KHZG funds in the right order, it covers B3S, NIS-2 and ePA from one source. At the same time, it lowers the ransomware risk and with it the risk to patients.