2 Days. 10+ Experts. Countless IAM & GRC Insights. Register for NEXIS INVOLVE | September 9-10 | Regensburg

Healthcare

Harzklinikum Dorothea Christiane Erxleben unites Data Protection, Information Security, and Risk Management with NEXIS GRC

As a KRITIS operator (critical infrastructure), Harzklinikum maps data protection, information security, and risk management in a single system with NEXIS GRC, meeting the requirements of B3S Healthcare and the GDPR on the basis of an ISMS aligned with ISO 27001.

Healthcare

About Harzklinikum

Harzklinikum Dorothea Christiane Erxleben was formed in June 2012 from the merger of the municipal hospitals in Quedlinburg and Wernigerode-Blankenburg. It is the largest municipal hospital in Saxony-Anhalt, after the two state-owned university hospitals in Magdeburg and Halle/Saale.

With clinics in Blankenburg, Quedlinburg, and Wernigerode and more than 50 specialist practices in the Harz region, Harzklinikum covers a broad range of services and treatments. As a municipal institution, it maintains close cooperation with numerous partners in the region. The guiding principle “Health needs competence” describes its commitment to modern, guideline-based, and patient-oriented care.

  • Location: Sachsen-Anhalt
  • Sites: Clinics in Blankenburg, Quedlinburg, and Wernigerode
  • Employees: ~ 2,000
  • Beds: ~ 1,000 inpatient beds
  • Annual revenue: ~150 million euro
  • Classification: KRITIS operator in the healthcare sector

With NEXIS GRC, Harzklinikum was able to

Map Three Disciplines in One System

Implement data protection, information security, and risk management together, including B3S Healthcare, ISO 27001, and the GDPR.

Audit All Three Clinic Sites

Assess Blankenburg, Quedlinburg, and Wernigerode consistently against B3S Healthcare.

Assess and Treat Risks in a Structured Way

Work through risk catalogs per asset group and assess risks in a risk treatment plan.

Involve Business Departments without Training

Establish approvals and confirmations with high acceptance through integrated workflows.

Pass the KRITIS Audit

Complete the May 2021 audit successfully and reduce the effort for follow-up audits.

Evidence Data Up to the Day

Maintain all processes continuously and provide the required evidence up to date whenever needed.

The Challenge

As a KRITIS operator with more than 30,000 full inpatient cases per year, Harzklinikum must keep its IT security measures at the current state of the art and demonstrate compliance every two years. For this, the BSI (Germany’s Federal Office for Information Security) points to the industry-specific security standard B3S Healthcare. In practice, building an information security management system that meets the B3S requirements and accounts for risk management is essential.

In addition, Harzklinikum wanted to implement data protection requirements, including maturity, in the same management system. It therefore looked for a provider that covers all requirements in a single solution. Harzklinikum brought the established IT service provider CANCOM into the selection process.

The goal was to:

  • Evaluate a database-based software solution for the wide range of requirements
  • Implement data protection, information security, and risk management fully in one solution, including all B3S specifications
  • Map standardized processes in a user-friendly, resource-saving way and flexibly adapt individual processes
  • Involve the IT service provider CANCOM throughout the entire process
  • Integrate business departments through low-training workflows

The Approach

The project started in August 2020 and followed a clearly structured phase model.

Evaluation and Selection of NEXIS GRC

Harzklinikum conducted the discussions with the providers together with its IT service provider CANCOM. NEXIS GRC best matched the requirement criteria. The convincing factors were the comprehensive content with different user modes for experts and business users, the close integration of data protection and information security functions, and the flexibility of Nexis as a mid-sized partner.

Phase 1: Structure, Documents, and SoA

The teams configured NEXIS GRC to Harzklinikum's specifications, with a focus on B3S and data protection. They captured the company structure, the areas under review, and the entire legal entity structure, and determined that all three sites would be audited against B3S Healthcare. The teams created, adopted, and transferred guidelines and policies into the system and linked them to the B3S controls. The Statement of Applicability (SoA) then followed.

Phase 2: Risk Management and Workflows

In risk management, the responsible staff worked through the risk catalogs for the assigned asset groups and assessed the risks in a risk treatment plan. In parallel, Harzklinikum introduced workflows for document approvals and action confirmations. The integrated workflow functions let the business departments come on board smoothly and without much training effort.

Phase 3: Planned Expansion

As a next step, Harzklinikum plans to add an e-learning system, integrated directly into the NEXIS GRC interface for all employees.

The Result

With NEXIS GRC, Harzklinikum can present and fully evidence all activities for data protection, information security, B3S Healthcare, and risk management on a lasting basis. It thus has a solid basis for all compliance- and risk-relevant decisions.

  • Passed KRITIS audit: The May 2021 audit was completed successfully, supported in part by NEXIS GRC
  • One system for three disciplines:  Data protection, information security, and risk management bundled, including B3S, ISO 27001, and the GDPR
  • Reduced effort for follow-up audits:  Processes are maintained continuously, and data is available up to date when needed
  • Complete traceability: All activities are presented and evidenced on a lasting basis
  • High user acceptance: Business departments are involved through low-training workflows
  • Extensible: Planned integration of an e-learning system for all employees into the NEXIS GRC interface

This integrated basis also carries the regulatory requirements that have grown since then. With the NIS2 Implementation Act and the amendment to the BSIG (BSI Act), KRITIS operators automatically count as essential entities with expanded obligations in risk management, registration, reporting, and evidence. The management system built with NEXIS GRC can be extended to these requirements without rebuilding established processes.

See how software-supported security and data protection management works in practice

Learn how NEXIS GRC helps KRITIS operators and healthcare organizations map B3S, ISO 27001, the GDPR, and the requirements of NIS2 in a single system, pass audits, and reduce effort on a lasting basis.