Case study: ePA – Electronic patient record

Edgeless Systems software protects the data of millions of insured individuals in electronic patient record system

ePA logo

The electronic patient record (ePA) is a nationwide standardized system based on Germany’s telematics infrastructure. Acting on behalf of the legislator, gematik GmbH defines the standards, operates core services such as identity and access management, and certifies applications. Statutory health insurers provide their members with apps and portals built by IT providers according to gematik’s specifications. Patients retain full control over which doctors or pharmacies can upload or view documents, ensuring secure and cross-institution access to health information.

Challenge

The electronic patient record (ePA) is a cornerstone of Germany’s digital healthcare system. Its operation is subject to strict data protection and technical requirements. One of the most demanding aspects is the “technical operator exclusion” mandated by Gematik, which must be implemented via a trusted execution environment (TEE): the infrastructure and backend operator must verifiably have no access to the health data. At the same time, the infrastructure must serve millions of insured individuals reliably and with high performance. 

Solution

Edgeless Systems provides confidential computing software that fulfills exactly these requirements. In collaboration with IBM, the software is used in the ePA to run sensitive applications inside isolated, hardware-protected environments based on Intel confidential computing CPUs. This ensures that even the infrastructure operator cannot access patient data. The software from Edgeless Systems comes with transparent source code, enables holistic attestation of the application, and it faciliates easy scaling on Kubernetes. 

Result

The complete solution, including Edgeless Systems’ confidential computing software, is certified by Gematik and enables a secure, scalable ePA backend system for up to 50 million insured individuals, including members of AOK, Barmer, and Techniker Krankenkasse. The project demonstrates how regulatory data protection requirements and technical operator exclusion can be reliably and efficiently realized with confidential computing. 

OC3 Talk

Thorsten Gau, CTO of IBM Consulting, presented the project at Edgeless Systems’ Open Confidential Computing Conference (OC3).