---
title: "Cybersecurity in Healthcare Advances in NRW"
language: "de"
type: "post"
original_url: "https://www.atlas-digitale-gesundheitswirtschaft.de/blog/2025/02/11/cybersecurity-in-healthcare-advances-in-nrw/"
human_version: "../../../../../mensch/blog/2025/02/11/cybersecurity-in-healthcare-advances-in-nrw/"
date: "2025-02-11"
section: "Hub-Article"
categories: ["Cybersecurity"]
description: "In this article, experts from North Rhine-Westphalia answer key questions about cybersecurity in healthcare."
publisher: "Lehrstuhl für Management und Innovation im Gesundheitswesen, Universität Witten/Herdecke"
---

# Cybersecurity in Healthcare Advances in NRW

*11.02.2025 · Hub-Article*

## [Cybersecurity in Healthcare Advances in NRW](../../../../en/blog/2025/02/11/cybersecurity-in-healthcare-advances-in-nrw.md)

In the digital age, cybersecurity plays a crucial role in healthcare. With the increasing digitization of patient data, the introduction of electronic health records, and the use of networked medical devices, the risk of cyberattacks also rises. Health data is among the most sensitive information, and protecting it is not only a matter of data privacy but also of patient safety. Given the ever more complex threats, healthcare organizations must develop robust security strategies to ensure data integrity and confidentiality while also meeting efficiency and patient care requirements. In this article, experts from North Rhine-Westphalia answer key questions about cybersecurity in healthcare.

**Dr. Pascal Grüttner** started his career in IT after training as a medical doctor and practicing in Bonn. He worked in software development and process optimization until 2018. Since 2018, he has been the head of the IT department at the Cellitinnen Hospital Association, a nonprofit hospital group in Cologne. Since 2019, he has also served as the Deputy Chairman of Digital Health Germany e. V. **Charalabos Chassoglou** is the Managing Director of UC Advisory GmbH. Previously, he worked for leading technology and consulting firms as a cybersecurity expert, including Vodafone, EY, and Accenture. With his extensive experience, he advises companies from various sectors and is KBV-certified for cybersecurity in healthcare. His focus is on practices, medical care centers (MVZ), and small to medium-sized clinics. **Professor Christoph Saatjohann** teaches and researches embedded security and cybersecurity in medical environments at Münster University of Applied Sciences. Previously, he researched at the Fraunhofer Institute for Secure Information Technology SIT and was part of the Applied Cryptography and Medical IT-Security research group. In the SiKIS project—Security Properties of Hospital Information Systems—he developed a security check for clinics on behalf of the Federal Office for Information Security (BSI). Professor Saatjohann also worked as a Security Engineer in the industry for six years.

### **What security incidents have occurred in your organization or with your clients?**

*Dr. Pascal Grüttner:* Fortunately, we have been spared major incidents so far. However, there have been small and locally isolated incidents, such as a virus infecting a single client. There have also been social engineering attempts that were at least partially successful. When it comes to standard attacks, like scans on our network or email-based threats, thousands are blocked daily by our security mechanisms.

*Charalabos Chassoglou:*I still see a steadily rising trend of security incidents caused by ransomware, with attackers becoming increasingly professional. Unfortunately, many IT infrastructures remain inadequately secured, making these attacks profitable for perpetrators.

*Prof. Dr. Christoph Saatjohann:* At Münster University of Applied Sciences, we had a major security incident in June 2022 that forced us to disconnect our entire IT from the internet and implement extensive incident response measures. This included assessing which systems were affected and resetting all 18,000 user accounts. My colleague, Prof. Dr. Schinzel, explains the incident details in this video: https://www.youtube.com/watch?v=l_UzKlbLY-Q.

### **What cyber risks are particularly significant for your organization?**

*Dr. Pascal Grüttner:*As a hospital group with a high level of digitization, all risks affecting digital patient records are critical. A non-functioning electronic medication system is a patient safety risk, as is a PDMS system outage or similar disruptions. Whether these are caused by external attacks, network failures, hardware malfunctions, or the hospital information system itself makes no difference in terms of impact.

*Charalabos Chassoglou:*Beyond ransomware, phishing, software vulnerabilities, and general IT system weaknesses, I see a major risk in the lack of awareness among responsible parties, who often downplay or ignore the problem. Many users are still insufficiently educated and trained on cybersecurity risks, which presents a vulnerability that attackers can easily exploit.

*Prof. Dr. Christoph Saatjohann:* Universities have diverse IT requirements, from traditional administrative systems to specialized software for automation technology, research, and medical teaching. Managing these varied systems is more complex than dealing with a static, homogeneous IT landscape, especially with the constant changes in user accounts as students enroll and graduate.

### **What cybersecurity measures do you use or develop in your organization?**

*Dr. Pascal Grüttner:* In response to the previous question, it’s vital for us to have fallback mechanisms if the electronic patient record fails. These measures must work regardless of the cause, whether it’s ransomware or network issues. In extreme cases, we revert to paper-based systems. For instance, backup copies of crucial patient data, such as medication lists, are made available as PDFs or printouts, supplemented by paper-based emergency folders to ensure patient safety.

*Charalabos Chassoglou:*Besides technical controls and monitoring, we are developing cybersecurity strategies based on the Zero Trust approach, assuming no one is trustworthy. Every data access is allowed only after multi-level verifications.

### **How do cybersecurity measures protect patient data?**

*Dr. Pascal Grüttner:* The answer could be quite extensive. There are numerous measures that secure systems and processes handling patient data, such as firewalls at the perimeter and sandboxing for email communications. Mechanisms that use AI to detect network anomalies—like SIEM systems managed by a Security Operations Center (SOC)—are becoming increasingly important. But deploying these measures requires a well-thought-out plan, including network segmentation, access rights management, and processes for identity and access management.

Organizational measures, like an Information Security Management System (ISMS), are equally crucial. Regularly updated ISMS and comprehensive security policies ensure that security efforts are coordinated effectively. Raising staff awareness is also vital. Technical and organizational measures must work together, and staff must understand their role in maintaining patient safety. Modern threats are severe, such as the ability to alter medical imaging data in real-time or control medical devices. Understanding these risks fosters acceptance of security protocols.

*Charalabos Chassoglou:*Cybersecurity measures work collectively, strengthening IT resilience and data security. The “least privilege” principle, allowing minimal necessary access for authenticated users, is crucial. This minimizes potential risks by ensuring that only essential permissions are granted.

*Prof. Dr. Christoph Saatjohann:*Today, almost all patient data is digital. It’s essential to protect it from cyberattacks, as data breaches could endanger lives. Regulations like the GDPR and medical standards mandate robust cybersecurity measures, emphasizing that patient safety is paramount.

### **What knowledge or skills do health professionals need to ensure cybersecurity in healthcare?**

*Dr. Pascal Grüttner:* This starts with understanding entry points, like emails, and integrating two-factor authentication into daily routines. Healthcare professionals also need to remain critical of technology, recognizing when systems might malfunction. Studies have shown that staff may trust device readouts over clinical symptoms, which can be dangerous.

It’s unrealistic to expect healthcare workers to master cybersecurity in depth, so training and openness to technology are essential. Software should be user-friendly and error-preventive. Key user principles and continuous education are critical, as all staff cannot be equally proficient in IT security.

*Charalabos Chassoglou:* Health professionals need a heightened awareness of cybersecurity risks and measures. Familiarity with common attack patterns is crucial to prevent predictable threats.

*Prof. Dr. Christoph Saatjohann:* Health professionals specialize in patient care, supported by IT systems that should be intuitive. Basic knowledge, like recognizing phishing emails, helps secure the organization. The design of IT systems should minimize the risk of errors compromising cybersecurity.

### **What new roles are emerging in healthcare to ensure cybersecurity?**

*Dr. Pascal Grüttner:* In our hospitals, we focus on interface roles between operations and IT, like Business Support staff who serve as IT consultants. These roles don’t always require extensive IT knowledge; understanding hospital workflows is often more valuable, and they are sometimes filled by former nurses or quality managers.

*Charalabos Chassoglou:* The roles needed already exist, like Chief Information Security Officers (CISOs), Security Analysts, Engineers, and Architects. These roles must be integrated into healthcare settings and equipped with the knowledge of handling sensitive health data.

*Prof. Dr. Christoph Saatjohann:* Administrative IT in healthcare doesn’t differ significantly from other sectors, so new roles won’t emerge here. However, medical technology will gain importance as systems become more connected. Specialized roles are needed to secure older technologies that pose growing risks.


**Kategorien:** Cybersecurity

## Bilder auf dieser Seite

- shutterstock_1299926791-scaled.jpeg: ../../../../../mensch/assets/bilder/wp-content/uploads/2024/02/shutterstock_1299926791-scaled.jpeg

---
Diese Seite ist für KI-Systeme optimiert. Version für Menschen: [Cybersecurity in Healthcare Advances in NRW](../../../../../mensch/blog/2025/02/11/cybersecurity-in-healthcare-advances-in-nrw/)
