Skip to content
Beta

Health & Energy

Last updated on

For workloads run by or for healthcare providers, health and care insurers, and energy operators in Germany, and the teams building for them. The mountain is the same as for everyone; this page maps what this route demands of it, and adds nothing.

What binds here, and what each regime asks of an architecture.

Cloud use in healthcare is statute. Section 393 SGB V permits processing social and health data in cloud services only within Germany, the EU or an equivalent state, and only by a provider with a domestic establishment. It requires a current C5 attestation, Type 2 from July 2025, and, in the same sentence, that the customer-side criteria from the attestation’s report are implemented. The law itself splits the responsibility, which is SOV 8.3 with a statute behind it; STACKIT’s side is the C5 Type 2 attestation.

Hospital and practice IT security. Section 393 grounds its measures in the neighbouring provisions for hospitals and practices, section 391 among them , and in the sector security standard for insurers. The baseline is externally framed per actor class, which is SEC 1.1 with the frame already chosen.

Energy runs critical infrastructure. Section 11 EnWG obliges network operators to protect the IT that a secure network operation depends on, with catalogues of security requirements issued by the regulator, and the KRITIS regime under the BSI act adds registration, incident reporting and audited technical measures for operators above threshold. Which duties bind is an operator-class question; that they centre on availability and incident reporting is not.

Health data is the strongest case of the tier criteria. Special categories of personal data under the GDPR’s article 9 are the textbook content of Tier 1, and health data is their textbook case. The residency and establishment requirements of section 393 turn what is elsewhere a preference into law.

Tier 1, sovereignty-mandatory, for health data. Section 393 fixes where processing may happen and through whom, and health data meets the Tier 1 criteria on their own terms besides.

The energy side is decided per data set, SOV 1.3. Operational and market data commonly sit at Tier 2 with the KRITIS duties running on availability rather than residency; control-adjacent systems deserve the Tier 1 conversation. Either way the reasoning is recorded, SOV 1.2, and an estate mixing both halves classifies per data set rather than per company.

Four pillars shift; each shift traces to the map.

Sovereignty & Compliance leads. Placement and establishment are statutory (SOV 2), telemetry and backups inherit the boundary (SOV 3), and the C5 customer-side criteria make the responsibility split (SOV 8.3) the sentence an auditor starts from.

Security is elevated and classification-first. Health data makes SEC 3 the entry point: classification, the copies, and encryption with a deliberate answer to who can decrypt (SEC 7.3), which for health data is also SOV 4’s question.

Reliability is elevated, on the recovery half. Care does not pause for an outage and a network does not wait for a restore. Backup and rehearsed restore (REL 8), and recovery rehearsed against a stated time (REL 9.3), are the questions this sector’s incident history asks; the KRITIS duties add reporting on top.

Operational Excellence is elevated as the evidence machine. OPS 3’s reviewed, versioned changes are the record the attestation and the audits consume.

Performance Efficiency, Cost Optimization and Sustainability do not shift.

What an assessment of a health or energy workload accounts for regardless of where the conversation went: each of these ends evidenced or in the risk register.

Medical devices and control systems. Software as a medical device and OT control systems carry their own regimes and safety cases. This page maps the cloud workload beside them, not the device or the plant.

The thresholds. Whether a specific operator is above a KRITIS threshold, and which sector standard applies in which version, are determinations for the operator’s compliance function. The page maps what the architecture must evidence once they bind.