Compliant cloud hosting for German Digital Health Applications (DiGAs)
In November 2019, new legislation passed by the German government provided a massive impetus for developers of German digital healthcare apps (DiGA) to get their products to market. According to the Digital Healthcare Act (DVG), if their app is formally approved by the German government, it can be prescribed by doctors and funded by health insurers. However, the following summer, when the European Court of Justice invalidated the integrity of the privacy shield between the EU and US, many German HealthTech developers were left reeling. They were unexpectedly prohibited from storing health data related to German citizens on US-based cloud providers. Despite some updates on the ruling in regards to the possibility of using US cloud subsidiaries based in the EU, the issue of compliance with non-EU cloud providers remains ambiguous.
The Digitalization of German Healthcare
The German Digital Healthcare Act was a significant piece of legislation designed to facilitate the digitalization of the German healthcare system. The Act was an effort to acknowledge and incorporate the valuable contribution of digital health applications in healthcare outcomes. Any DiGA that provides qualitative support to a patient managing a diagnosed medical condition can now be listed on a government directory of approved apps. Once listed, this DiGA can be prescribed by a doctor for their patient’s care, the cost of which will be covered by statutory health insurance. Roughly 72 million German citizens currently insured under the statutory health insurance scheme are entitled to such prescriptions.
The Push to Become an Approved DiGA
The Act was a huge boost to the German HealthTech industry and sparked a flurry of digital health innovation. To get their app approved and listed on the directory, digital health companies need to submit their app for a formal evaluation by the Federal Institute for Drugs and Medical Devices (BfArM), where it will be assessed for quality, functionality, effectiveness, and data security and data protection.
The EU Bans US Cloud providers
In July 2020 the European Union Court of Justice ruled that the EU-US privacy shield was incompatible with the requirements of GDPR and therefore invalid. This ruling left the developers of DiGAs in a vulnerable position because it meant that DiGAs and their associated patient data could no longer be stored and processed on US cloud services. This was something of a tremendous blow given the global dominance and widespread popularity of US cloud providers such as American Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP).
Where can DiGAs be Hosted?
The ruling left some confusion however about the use of US cloud subsidiaries based in the EU. Amazon Web Services, for example, was quick to point out that it offers cloud hosting on its server located in Frankfurt, Germany. Earlier this year BfArM provided some further guidance on the issue, outlining several conditions that need to be in place that make it permissible to use a US owned cloud provider located in the EU. Primarily you need to guarantee that an appropriate level of protection is in place to ensure the privacy of personal data. Essentially data requires record-level encryption before being transferred and stored on the cloud, and encryption keys need to be stored separately. Furthermore, you are required to obtain a Data Processing Agreement (DPA) with the EU subsidiary of the parent company.
It is worth noting that the BfArM pointed out that their guidance could be overruled by one of Germany’s independent data protection authorities. (There is a separate authority in each of Germany’s separate 16 states).
EU-Based Cloud Providers
To avoid the headache of achieving regulatory compliance while using a US owned cloud provider, many DiGA developers are choosing instead to partner with EU-based cloud platforms. The need to meet GDPR compliance requirements that will allow them to achieve BfArM approval is a strong incentive to avoid any legal uncertainty.
Integrating Communication Functionality into your DiGV
If developers are hoping to integrate communication functionality into their digital health apps via ready-to-use SDKs, APIs, and code samples they need to find communication backend providers who can host their software in any location and with any cloud provider they choose. This could be problematic as many CPaaS (Communication- platform-as-a-service) providers store and manage customer data on their own cloud, so DiGV developers will need to check what cloud provider they rely on.
How QuickBlox Can Help
If you are building a DiGA that requires communication functionality, QuickBlox can assist. We have total flexibility over wherever you wish to run your instance. Here’s 4 reasons why you should partner with us:
- We provide a complete communication backend with instant messaging and group chat, peer to peer and multiparty video calling, file sharing and other functions accessible through ready-to-use SDKs and APIs. Check out our communication features here and SDK and API documentation here.
- We can deploy our software anywhere you need. Choose a EU owned cloud hosting provider and we will assist you with the secure installation and configuration of your instance ensuring GDPR compliance and data protection. We also support on-premise installation in your own private server.
- We have a long history of supporting communication solutions for the healthcare industry, both in Europe and the US. Our HIPAA compliant texting, voice, and video calling has been integrated to power remote health monitoring, patient management, and of course telemedicine and tele-consultation.
- We also offer a teleconsultation and virtual waiting room app that is powered by our backend Q-consultation is GDPR and HIPAA compliant and can be hosted on your preferred cloud provider.
To find out more please contact us now.