Harzklinikum Dorothea Christiane Erxleben unites Data Protection, Information Security, and Risk Management with NEXIS GRC
As a KRITIS operator (critical infrastructure), Harzklinikum maps data protection, information security, and risk management in a single system with NEXIS GRC, meeting the requirements of B3S Healthcare and the GDPR on the basis of an ISMS aligned with ISO 27001.
About Harzklinikum
Harzklinikum Dorothea Christiane Erxleben was formed in June 2012 from the merger of the municipal hospitals in Quedlinburg and Wernigerode-Blankenburg. It is the largest municipal hospital in Saxony-Anhalt, after the two state-owned university hospitals in Magdeburg and Halle/Saale.
With clinics in Blankenburg, Quedlinburg, and Wernigerode and more than 50 specialist practices in the Harz region, Harzklinikum covers a broad range of services and treatments. As a municipal institution, it maintains close cooperation with numerous partners in the region. The guiding principle “Health needs competence” describes its commitment to modern, guideline-based, and patient-oriented care.
- Location: Sachsen-Anhalt
- Sites: Clinics in Blankenburg, Quedlinburg, and Wernigerode
- Employees: ~ 2,000
- Beds: ~ 1,000 inpatient beds
- Annual revenue: ~150 million euro
- Classification: KRITIS operator in the healthcare sector
With NEXIS GRC, Harzklinikum was able to
Implement data protection, information security, and risk management together, including B3S Healthcare, ISO 27001, and the GDPR.
Assess Blankenburg, Quedlinburg, and Wernigerode consistently against B3S Healthcare.
Work through risk catalogs per asset group and assess risks in a risk treatment plan.
Establish approvals and confirmations with high acceptance through integrated workflows.
Complete the May 2021 audit successfully and reduce the effort for follow-up audits.
Maintain all processes continuously and provide the required evidence up to date whenever needed.
The Challenge
As a KRITIS operator with more than 30,000 full inpatient cases per year, Harzklinikum must keep its IT security measures at the current state of the art and demonstrate compliance every two years. For this, the BSI (Germany’s Federal Office for Information Security) points to the industry-specific security standard B3S Healthcare. In practice, building an information security management system that meets the B3S requirements and accounts for risk management is essential.
In addition, Harzklinikum wanted to implement data protection requirements, including maturity, in the same management system. It therefore looked for a provider that covers all requirements in a single solution. Harzklinikum brought the established IT service provider CANCOM into the selection process.
The goal was to:
- Evaluate a database-based software solution for the wide range of requirements
- Implement data protection, information security, and risk management fully in one solution, including all B3S specifications
- Map standardized processes in a user-friendly, resource-saving way and flexibly adapt individual processes
- Involve the IT service provider CANCOM throughout the entire process
- Integrate business departments through low-training workflows
The Result
With NEXIS GRC, Harzklinikum can present and fully evidence all activities for data protection, information security, B3S Healthcare, and risk management on a lasting basis. It thus has a solid basis for all compliance- and risk-relevant decisions.
- Passed KRITIS audit: The May 2021 audit was completed successfully, supported in part by NEXIS GRC
- One system for three disciplines: Data protection, information security, and risk management bundled, including B3S, ISO 27001, and the GDPR
- Reduced effort for follow-up audits: Processes are maintained continuously, and data is available up to date when needed
- Complete traceability: All activities are presented and evidenced on a lasting basis
- High user acceptance: Business departments are involved through low-training workflows
- Extensible: Planned integration of an e-learning system for all employees into the NEXIS GRC interface
This integrated basis also carries the regulatory requirements that have grown since then. With the NIS2 Implementation Act and the amendment to the BSIG (BSI Act), KRITIS operators automatically count as essential entities with expanded obligations in risk management, registration, reporting, and evidence. The management system built with NEXIS GRC can be extended to these requirements without rebuilding established processes.