Healthcare · Section 75c SGB V & B3S

Before the next incident
brings your hospital to a halt

Since January 1, 2022, Section 75c of the German Social Code Book V (SGB V) has required every hospital in Germany to maintain appropriate technical and organizational security measures reflecting the state of the art, and to renew that proof every two years. At the same time, real ransomware incidents in recent years show just how directly hospitals are being targeted. Three areas get most of our attention, because that's where things actually go wrong: hospital information systems, networked medical devices, and reception as the entry point for social engineering.

Documentation suitable for Section 75c & B3S Experience with hospital IT & medical technology Free initial consultation
Two worlds

Where attackers actually get in at hospitals

Hospitals combine classic IT with medical technology and constant foot traffic, a combination few other industries share in quite this form.

Ward & reception

People, devices, open doors

Open entrances and a steady stream of visitors and outside contractors create an environment where physical access control is structurally hard to enforce. Add staff under constant strain: shift work, staff turnover, and high workloads reliably lower vigilance against phishing and pretexting.

At the bedside sit networked medical devices: infusion pumps, monitors, imaging systems. They are often maintained by the manufacturer and rarely covered by classic IT security concepts.

A white coat, a clipboard, and the line "I'm here from technical services for the maintenance" open more doors in a hospital than in almost any other industry. Reception desks sit unattended at times, real outside contractors (cleaning, medical equipment servicing, catering) already move through the building unannounced, and night-shift staff rarely have time to scrutinize an ID badge. Our physical and social engineering assessments simulate exactly these scenarios, in a controlled way and with agreement in advance on who gets notified if things go wrong.

Server room & HIS

Interfaces, remote maintenance, segmentation

The hospital information system is the central system for patient records, billing, and ward workflows: often grown over many years, with many interfaces to third-party systems. Each of those interfaces is a way in, and usually nobody has the complete picture of them anymore.

The medical devices from the ward show up again here, as network connectivity, remote maintenance access, and a segmentation question. That's where we usually test them, rather than actively attacking the devices themselves, because medical devices must not be put at risk during live operation.

Whether a single compromised machine stays a local problem is decided by the segmentation between the HIS, IoMT, and administration, together with access rights and Active Directory hardening. That's why both belong in every hospital pentest.

What can happen

Wertachkliniken: a day without IT

Bobingen & Schwabmünchen · September 2024

According to media reports, the Wertachklinik hospital group in Bobingen and Schwabmünchen was hit by a ransomware attack in early September 2024. IT systems were disconnected from the external network as a precaution to prevent further spread, and the Bamberg General Public Prosecutor's Office (Central Cybercrime Unit) opened an investigation. The incident is not an isolated case: the BSI-funded "SiKIS" research project (Fraunhofer SIT) systematically documented vulnerabilities in German hospital information systems in 2024.

Based on public reporting. accessgranted was not involved in this incident.

We work with, among others, Kreiskliniken Reutlingen on IT and medical-technology security. See our own experience in healthcare
B3S mapping

Our test modules, mapped to the B3S "Medical Care" standard

The B3S is organized into topic areas. Here's exactly which pentest module covers which area, so your evidence has no gaps.

Network & systems security
Infrastructure Pentest
Access & permissions management
Active Directory Pentest
Physical security of server rooms & wards
Physical Pentest
Staff awareness & behavior
Social Engineering & Phishing Simulation
Medical devices & networked equipment (IoMT)
Custom assessment
Night shift · 10:30 pm

What an access attempt at a hospital actually looks like

The main entrance closed hours ago; the emergency department didn't. Someone in work clothes, toolbox in hand, badge on a lanyard, follows a nurse through the door onto the ward and mumbles something about a fault in the utility room. Nobody asks, because three call bells are going at once and because outside technicians at this hour are nothing unusual. A little later, that person is alone in the ward office in front of a logged-in workstation, or at the door to the server room.

That's exactly how we test, but never without agreement. Before we start, it's settled who in the building knows, which areas are off-limits (for example the ICU, operating theaters, and anything with direct patient impact), how our people identify themselves immediately when challenged, and who is reachable as the emergency contact. If the attempt gets spotted and stopped, that's a good result, not an embarrassing one. And the moment patient care could be affected anywhere, we stop before it comes to that.

Our approach

How does a pentest work at a hospital?

Patient safety always comes first. That's why our approach at hospitals is coordinated more closely than in other industries.

01

Scope with patient safety in mind

Together, we define which systems get actively tested and which are only analyzed passively, especially anything with direct patient impact.

02

Testing with an emergency contact

Information gathering, network scans, and manual testing within the agreed scope, with a defined emergency contact and an immediate stop if anything unexpected affects production systems.

03

Report with B3S mapping

Every finding is rated by severity, exploitability, and impact on hospital operations, and documented with recommendations, a management summary, and mapping to the B3S "Medical Care" standard.

Relevant modules

These tests bring your hospital IT up to the state of the art

Section 75c and the B3S ask for evidence on several levels at once. These three modules are how we cover them together.

  • Physical Pentest

    Simulated access attempts at reception, wards, and server rooms. Covers the physical attack surface that hospitals face especially often.

  • Social Engineering

    Phishing and pretexting simulations tailored to shift work and the high workload of daily hospital operations.

  • Infrastructure & Active Directory

    Network segmentation between the HIS, IoMT, and administration, access rights, and AD hardening.

Additionally relevant for larger facilities

Above the KRITIS threshold: NIS2 and KRITIS

From 30,000 fully inpatient cases per year, your facility is also considered a KRITIS operator, with its own evidence obligations under the BSI Act and NIS2. Our compliance pages break down exactly what that means.

Pentesting in healthcare: your questions

Section 75c SGB V doesn't prescribe a specific test method, but it does require appropriate state-of-the-art measures, re-verified every two years. A penetration test is the standard technical instrument for providing that proof. Without regular testing, you have no evidence in the event of an incident that you met your obligation.
The B3S (industry-specific security standard) from the German Hospital Federation is a BSI-recognized way to translate the "state of the art" requirement under Section 75c, or the KRITIS requirements under Section 8a BSIG, into concrete measures. For KRITIS operators in healthcare, implementing a recognized B3S is the de facto standard; for smaller facilities, it's a useful, voluntary point of reference.
Yes, within a tightly agreed scope. Medical devices are subject to their own regulatory requirements and must not be put at risk during live operation. In most cases, we test the devices' network connectivity, segmentation, and remote maintenance access rather than actively attacking the devices themselves.
Before any test, we jointly define which systems get actively tested and which are only analyzed passively. For anything with direct patient impact, the rule is simple: test more cautiously, or skip it, when in doubt. A defined emergency contact and an immediate stop for unexpected effects are a standard part of every hospital assessment.
Yes, that's part of our Physical Pentest module. We simulate realistic access attempts, for example posing as a technician or a delivery driver, and check whether reception, access controls, and server rooms hold up. The approach is agreed in advance with a defined group of people on your side.
That depends heavily on scope: number of locations, systems involved, whether IoMT networks are included, and whether physical and social engineering testing are part of it. After a free initial consultation, we'll know your scope and you'll get a transparent, fixed-price quote.