The foundation for secure image management
Security & Compliance in the Healthcare Sector
Trust is good, but verification is better: we offer certified, secure cloud solutions for managing highly sensitive medical imaging data.
With Telepaxx Medical Data, you are on the safe side, both legally and technically: our infrastructure complies with the strict statutory data protection and security requirements in the healthcare sector.
We ensure the highest level of data security – to protect your patients’ data.
Certified ISMS for Telepaxx
ISO 27001 Certification
Information security in the healthcare sector is our top priority.
Our certified Information Security Management System (ISMS) ensures that we actively minimise potential risks. The most recent successful surveillance audit (May 2026) confirms the effectiveness of our measures.
Cloud security: BSI-compliant
BSI C5 Certificate
The TMD Cloud (Telepaxx Medical Data Cloud) has been awarded the stringent BSI C5 Type 1 certificate by the Federal Office for Information Security (BSI).
BSI C5 Type 2 certification is planned for the end of 2026. The BSI’s C5 catalogue sets out standards for secure cloud computing in Germany, thereby protecting your critical infrastructure.
Security at Telepaxx – far exceeding the standard
Certifications such as ISO/IEC 27001 and BSI C5 form the technical backbone of our services.
Furthermore, we also comply with all other currently applicable legal requirements regarding the security of patient data processing (e.g. in accordance with Article 9 of the GDPR).
GDPR-compliant: Location: Germany
We offer GDPR-compliant solutions with servers located in Germany and encrypted storage of medical image data in highly secure data centres.
Vote of confidence for DSB: Clear AVV
A data processing agreement (DPA) is mandatory: DPA contracts tailored to medical law and tried-and-tested data erasure procedures – audit-proof.
NIS-2 & KRITIS: Fully compatible
IT security in hospitals is under regulatory pressure. Our solutions actively support you and help you to NIS 2 Directive and KRITIS requirements to fulfil.
„Data security in the healthcare sector brooks no exceptions. Our successful audits and other security measures give our customers the assurance that we not only consider security right from the start, but actively put it into practice every day – to ensure the reliable protection of your medical data.“
Tobias Anger, Chief Executive Officer, Telepaxx Medical Data GmbH
Sovereign cloud
Self-sufficient cloud architecture
To ensure the greatest possible data sovereignty and the protection of medical data, we strictly separate the storage of encrypted data from key management:
- Transport: End-to-end encryption directly from your local PACS
- Insulation: DICOM data (data vault) and keys (key vault) are strictly separated
- Protection: Without the key, the data vault remains unreadable
You can read more about our multi-layered security approach on our blog.
Do you have any questions about our safety standards?
Do you need detailed information for your next audit, or do you have any questions about security at Telepaxx?
We would be happy to provide you, your IT manager or your Data Protection Officer (DPO) with further information in a brief online meeting.
„*“ indicates required fields