Knowledge Base → Sectors → 🩺 Digital Health & DiGA
🩺 Digital Health & DiGA
Digital-health data protection: DiGA fast-track (BfArM), DiGAV, security (BSI TR-03161) and data-protection certification (e.g. TÜViT), and the European Health Data Space.
Key resources (36)
- Datenschutz nach Artikel 42 DSGVO
- BfArM - Startseite - DiPA-Leitfaden (Stand 15.07.2026, Version 1.3) — Sicherheit: Zertifikat max 5 Jahre - aber relates to Product version DIPA Leitfaden 1.3 - 15 July 2026
- DiGAV — Verordnung über das Verfahren und die Anforderungen zur Prüfung digitaler Gesundheitsanwendungen — Verordnung über das Verfahren und die Anforderungen zur Prüfung der Erstattungsfähigkeit digitaler Gesundheitsanwendungen in der gesetzlichen Krankenversicherung (Digitale Gesundheitsanwendungen-Verordnung - DiGAV)
- Prüfpflichten und -rechte der Krankenkassen bei der Abgabe von Digitalen Gesundheitsanwendungen (DiGA) nach § 33a SGB V - www.bund
- Spezifikation für Health Device Data Transfer veröffentlicht — Am 15-Apr-2026 hat die gematik die finale Fassung der Spezifikation veröffentlicht (Spezifikation für Health Device Data Transfer veröffentlicht | gematik).
- Healthcare cyberattacks hit pacemakers and millions of patient records — Boston Scientific and McKesson
- FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices — USA: FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices
- ENISA: Procurement guidelines for the cybersecurity of hospitals — ENISA: Procurement guidelines for the cybersecurity of hospitals and healthcare providers - July 2026
- FDA Announces First Participant Selected for TEMPO for Digital Health Devices Pilot — “The FDA selected Dexcom, Inc., as the first participant in the TEMPO pilot. The Dexcom Glucose Health Program, which the FDA will continue to evaluate for its intended use during the pilot, is intended to address two clinical use areas in the ACCESS Model.”
- Mitarbeiterexzesse im Gesundheitsbereich: BlnBDI verhängt Bußgelder und überrascht dabei — Mitarbeiterexzesse im Gesundheitsbereich: BlnBDI verhängt Bußgelder und überrascht dabei
- Medical diagnosis AIs can be tricked into telling whose data trained them — Membership-inference risk in medical AI: a model can be probed to reveal whether a specific person’s records were in its training data — a patient-data confidentiality concern.
- The Medical Device Cybersecurity Gap Hiding in Plain Sight - MedTech Intelligence
- New obstacles for health care: Federal and state national security regulations increasingly target health data — Health and life sciences companies are navigating largely unaligned compliance obligations meant to keep U.S. health and genomic data out of foreign adversaries’ reach. Published 24 April 2026
- Private health records of half a million Britons offered for sale on Chinese website — Medical data of 500k Biobank volunteers listed for sale on Alibaba, UK minister reveals
- GDNG in der Praxis: Zuständigkeiten und Anzeigeverfahren — GDNG in der Praxis: Zuständigkeiten und Anzeigeverfahren bei länderübergreifender Gesundheitsforschung
- Update MDCG 2019-11 rev.1 - Qualification and classification of software - Regulation (EU) 2017/745 and Regulation (EU) 2017/746 ( — Medical device vs Accessory
- Healthcare Exchange Standards: Consent about AI — Healthcare Exchange Standards: Consent about AI
- Navigating the Global Regulatory Landscape: A Foundation for Medical Device Commercial Viability - MedTech Intelligence
- Healthcare Exchange Standards: FHIR Consent backed by XACML enforcement — Healthcare Exchange Standards: FHIR Consent backed by XACML enforcement
- Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions — FDA Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions - Guidance for Industry and Food and Drug Administration Staff - June 2025
- Healthcare Exchange Standards: Controlling AI in Healthcare — “PurposeOfUse” field in FHIR
- Data Act & EHDS: What clinics, MedTech and software manufacturers need to know — Data Act & EHDS: What clinics, MedTech and software manufacturers need to know | heise online
- Health Technology Ecosystem — Making Health Tech Great Again
- New Digital Health Ecosystem and HIPAA Flexibilities Facilitate Sharing of Patient Health Information
- MDCG 2025-6: Interplay between the MDR/IVDR and the AI Act — AIB 2025-1 - MDCG 2025-6 - Interplay between the Medical Devices Regulation (MDR) & In vitro Diagnostic Medical Devices Regulation (IVDR) and the Artificial Intelligence Act (AIA)
- DiGA-Report 2024 — Die Einhaltung der aktuellen Datenschutz- und Datensicherheitsanforderungen verursacht für DiGA-Hersteller zusätzliche Kosten in Höhe von 160.000 - 270.000 Euro je DiGA.80 Diese Aufwände entstehen beispielsweise für die Erfüllung der Prüfungen durch das BSI oder BfArM, die Durchführung regelmäßiger Pentests oder weitere Zertifikate, zum Beispiel bei Software-Updates. Hinzu kommt, dass für einige der erforderlichen Prüfungen oder Zertifizierungen nicht ausreichend benannte Stellen existieren, so dass Prüfungen teilweise erst nach Monaten durchgeführt werden können.
- Data Protection Working Group
- CNIL — Health & health data (all resources) — Watch the webinar again: healthcare establishments, health standards and the “governance” of data protection
- Agence du Numérique en Santé — All CNIL content on health and health data PGSSI-S, Electronic identification reference system for “actors in the health, medico-social and social sectors [natural persons]” - esante.gouv.fr And more generally, all the documents of the General Policy for the Security of Health Information Systems – esante.gouv.fr
- Données de santé : la CNIL rappelle les mesures de sécurité et de confidentialité pour l’accès au dossier patient informatisé (DPI — To go further
- Cybersecurity False Claims Act settlement (diagnostics firm)
- Digitale Gesundheitsanwendungen
- HHS Trustworthy AI Playbook — G7 Hiroshima Summit: “Hiroshima Process International Code of Conduct for Organizations ( Developing Advanced AI Systems” ( 2023.
- European Health Data Space (EHDS) Regulation — European Health Data Space Regulation In effect The European Health Data Space (EHDS) Regulation came into force in March 2025, initiating a transition period. It seeks to create a unified framework for the use and exchange of electronic health data throughout the EU. The EHDS mandates that holders of electronic health data make their data accessible to health data access bodies (HDABs). These bodies will then make the data available on a secure platform to data users who have obtained an access permit. While users will generally only have access to anonymized data, they may, in exceptional circumstances, be granted access to pseudonymized data. Key components of the EHDS Regulation are scheduled for application in March 2029, with further provisions taking effect in March 2031.
- Revoir le webinaire : établissements de santé, les référentiels en santé et la « gouvernance » de la protection des données — Health data: the CNIL recalls the security and confidentiality measures for access to the electronic patient record (EPR)
- DiGA - Digitale Gesundheitsanwendungen: Apps auf Rezept — Am 15-Apr-2026 hat die gematik die finale Fassung der Spezifikation veröffentlicht (Spezifikation für Health Device Data Transfer veröffentlicht | gematik).
🇨🇭 Swiss electronic patient record (EPD/EPR)
- Swiss EPD (electronic patient record) — federal e-health record; revFADP applies and health data is sensitive. Watch the FDPIC and BAG / eHealth Suisse for developments. (expand as items surface)
🆕 Recent additions (auto)
- 2026-09-03 SEC And FDA ‘Bolster Cooperation,’ Potentially Signaling New Enforcement Priorities — The SEC and FDA are deepening their coordination and likely sharpening their attention on healthcare disclosures. The agencies’ new information-sharing framework could increase scrutiny of public-company statements concerning FDA-regulated products, regulatory approvals, clinical trials, and safety matters….By: Ashurst Perkins Coie (Health RSS Feed)
- 2026-09-02 Ad Law News and Views - July 2026 — Staying ahead of regulatory change requires keeping an eye on developments across industries and agencies alike. In this month’s featured articles, our Ad Law team explores key issues shaping today’s business environment—from advertising AI-powered products and protecting sensitive health data to preparing for the FCC’s heightened robocall enforcement efforts….By: Kelley Drye & Warren LLP (Privacy RSS Feed)
- 2026-08-20 AI-Assisted Triage: Accelerating Post-Market Surveillance While Eliminating Reporting Blind Spots - MedTech Intelligence (MedTech Intelligence)
Curated from the personal reference library. Add items directly on this page.