ISO 27001 certification successfully confirmed during the surveillance audit – View the current certificate

ISMS certificate successfully renewed

ISO 27001 Certification: Reliable Standards for the Healthcare Sector

Telepaxx Medical Data GmbH meets the strict requirements of the international standard ISO/IEC 27001:2022 to ensure the reliable protection of our customers’ data.

Our consistent implementation of this established security standard is reviewed and verified annually through external audits. The effectiveness of our ISMS was successfully confirmed once again in May 2026.

What a successful surveillance audit means for you

Certificates alone do not provide protection – but putting security into practice does. That is why ISO 27001 certification is an ongoing process for us and an integral part of our day-to-day work.

In May 2026, external auditors successfully audited our Information Security Management System (ISMS) as part of a surveillance audit and confirmed our certification without any restrictions.

For our customers, this means they have a partner at their side who not only documents data security in accordance with international standards, but actively practises it and continuously improves it.

Telepaxx Medical Data is certified according to ISO 27001

CURRENT ISO 27001 CERTIFICATE

Download the current ISO/IEC 27001:2022 certificate for Telepaxx Medical Data GmbH here in German or English. Its continued validity is ensured through annual surveillance audits.

  • Valid until: 29 June 2028
  • Certification body: DQS
  • Last surveillance audit: May 2026

Protection of sensitive data

We process image data in accordance with strictly regulated security procedures. Our ISMS is a key component in ensuring the confidentiality, integrity and availability of data at all times.

Proactive risk management

Rather than reacting to threats, we take proactive measures. Cyber risks are systematically identified and assessed as part of the ISMS, and minimised through preventive safeguards.

Contributing to your compliance

As a cloud service provider for healthcare organisations, we ensure objective accountability – towards IT departments, data protection officers and regulatory bodies.

Michael Schöll, CISO, Telepaxx Medical Data GmbH

“For us, ISO 27001 certification is not just a promise, but a way of life. I am proud of how our team puts information security into practice. The successful annual audit is proof that we apply the highest security standards to protect our customers” medical data.”

Michael Schöll, CISO, Telepaxx Medical Data GmbH

Security at Telepaxx: more than just ISO 27001

ISO 27001 certification is the foundation – but when it comes to cloud deployment in healthcare settings, we go one step further.

  • BSI C5 certificate: With the TMD Cloud, we meet the strict requirements set by the Federal Office for Information Security (BSI) regarding the use of cloud solutions in healthcare facilities. Compliance with these requirements will become mandatory by spring 2027 at the latest. More about the BSI C5 certificate
  • NIS-2 & KRITIS: With our certified SaaS solutions, we help hospitals meet the increased requirements of the NIS 2 Directive regarding information security, data protection and resilience. Read more in the blog post

Frequently asked questions about ISO 27001 certification

ISO 27001 is the international standard for information security management systems (ISMS). It sets out how organisations must systematically identify, assess and control information security risks. Certification demonstrates that these requirements have been independently verified.

An ISMS is a systematic framework comprising policies, processes and measures that an organisation uses to manage its information security. It ensures that data remains confidential, secure and available – both technically and organisationally.

ISO/IEC 27001:2022 is the current version of the international security standard. The year indicates the year of revision. Compared with the previous version from 2013, new security measures have been added and the structure of the standard has been updated.

An ISO 27001 certificate is valid for three years. During this period, annual surveillance audits by an accredited certification body are mandatory. After three years, a full recertification audit takes place.

A surveillance audit is an annual external audit of the ISMS carried out between initial certification and recertification. The auditor checks whether the system is being actively implemented, whether measures have been put into practice, and whether appropriate action has been taken in response to changes in risk.

An ISO 27001 audit assesses whether the ISMS meets the requirements of the standard: risk management, security measures, internal audits and management review. During the surveillance audit, an additional check is carried out to ensure that corrective actions from the previous year have been implemented.

The healthcare sector handles highly sensitive patient data. ISO 27001 ensures that service providers protect this data in accordance with strict standards. At the same time, certification helps healthcare organisations to comply with the GDPR and NIS 2 compliance to prove.

There is currently no legal requirement for all hospitals to obtain ISO 27001 certification. Within the framework of the NIS 2 Directive KRITIS operators and small and medium-sized healthcare facilities are required to provide ISO 27001 certification or equivalent evidence of information security.

The current ISO/IEC 27001:2022 certificate for Telepaxx Medical Data GmbH is available to download on this page – in German and English. Its validity is confirmed by annual surveillance audits.

ISO 27001 certifies an organisation’s information security management system. The BSI’s C5 certificate specifically assesses cloud services for security and transparency. For cloud software used in healthcare facilities, this C5 certification mandatory from 2027.

Do you have any questions about our safety standards?

We would be happy to provide you, your IT manager or your Data Protection Officer (DPO) with further information about security at Telepaxx and, in more detail, about ISO 27001 certification during a brief online meeting.

*“ indicates required fields

Lastname*
This field is hidden when viewing the form