Skip to main content
Sample_1

FRANKFURT AM MAIN PUBLIC HEALTH AUTHORITY | MAXIMUM SECURITY FOR DIGITAL HEALTH PLATFORM

Frankfurt am Main Public Health Authority sets new standards in IT security with iteratec

Secure digitalisation in the healthcare sector

The Frankfurt am Main Public Health Authority has developed ‘GA-Lotsen’, a centralised platform that brings together a wide range of citizens’ health data – including information on pre-school medical examinations, measles vaccinations, travel health advice and statistical analyses. As this involves particularly sensitive data, the highest standards of data protection and IT security in the healthcare sector had to be met.

To independently validate the platform’s security level, the Frankfurt Public Health Department commissioned iteratec to carry out a comprehensive penetration test. This was a crucial step prior to the platform going live.

Penetration testing as a go-live criterion

IT security standards were implemented throughout the platform’s development process. The aim was to create a modern yet trustworthy solution for nationwide use in public health authorities. The concluding penetration test represented the final hurdle and ultimately determined whether the platform could go live.

The independent audit carried out by iteratec was intended not only to demonstrate the effectiveness of the security mechanisms, but also to show that a forward-looking approach to security is possible within the public sector.

Developer Round Total_960x720

A bespoke application penetration test rather than a one-size-fits-all approach

For this project, iteratec developed a bespoke testing concept that went well beyond traditional compliance checks. The application penetration test consisted of three components:

Cloud Configuration Check

Web Application Penetration Testing

Keycloak Security Test

Particularly worth noting: for the Keycloak analysis, the iteratec experts used a proprietary open-source tool that was specifically designed for this use case and is publicly available on GitLab.

“For us, data security is not merely a technical obligation, but also an expression of medical respect and care towards every person who places their trust in us. Only by setting the highest standards in IT security can digital transformation truly contribute to the well-being of the population and build trust in public healthcare. That is why we make no compromises when it comes to data security and data protection, and are setting new standards for secure digital health services.”
PD Dr Peter Tinnemann, Head of the Public Health Department, Frankfurt am Main

Vulnerabilities identified, security strengthened

icon_it_security__3_

Penetration testing that makes a difference

The penetration test revealed areas for improvement. Even a robust security framework can still harbour vulnerabilities. For example, configuration flaws were discovered in the IAM system that would have allowed unauthorised access. These vulnerabilities were rectified before the launch, and the subsequent retest confirmed that the platform meets high standards of information security and data protection.

csm_icon_brain_black_ze_387x155px_829b524ff4

From optimisation to awards

The insights gained were used not only to optimise the application, but also to prepare for a planned certification. At the same time, they helped to establish modern concepts such as cloud-native architecture and zero-trust principles within the public sector – a genuine leap forward in innovation, which was recognised with the InfoSec Impact Award from NExT e.V. and the Federal Office for Information Security (BSI).

Security as the cornerstone of digital health solutions

The collaboration between the Frankfurt am Main Public Health Authority and iteratec serves as a prime example of how IT security is becoming a key factor in the success of digitalisation in the public sector. A comprehensive penetration test, bespoke testing procedures and open communication eliminate potential vulnerabilities and establish sustainable security standards.

The GA-Lotse is a pioneering project for modern administrative platforms and demonstrates the successful implementation of security concepts such as Zero Trust in public sector IT.

“Sustainable IT security can only be achieved through critical and ongoing scrutiny of implementations. iteratec has, in the best sense of the word, taken a second, close look to ensure that everything is truly secure.”
Bianca Kastl, Technical Manager and Product Owner for GA-Lotse, Frankfurt am Main Public Health Authority

Are you facing similar
challenges?

If you have any queries or questions regarding a project for your company, please send us an enquiry and we will get back to you.