DiGA stands for Digitale Gesundheitsanwendung, commonly translated as digital health application. In Germany it describes certain CE-marked medical devices in lower risk classes whose main function is digital and which have passed the federal fast-track procedure for listing in the DiGA directory.
Manufacturers must address data protection, information security, interoperability and evidence of positive healthcare effects. A normal wellness app is not automatically a DiGA, and listing does not mean that an application can never contain a security vulnerability.
Why is cybersecurity particularly important?
Health data is sensitive, mobile and cloud components create several trust boundaries, and availability or integrity can influence care. Secure development, authentication, supplier control and repeated technical testing therefore belong throughout the lifecycle.
Which areas does the Fast-Track process assess?
| Area | Core question |
|---|---|
| Medical device | Is there appropriate CE marking, a primarily digital function and an eligible risk class? |
| Data protection | Are purposes, legal bases, individual rights, retention and data flows traceable? |
| Information security | Is there an effective continuous security process for product, infrastructure and suppliers? |
| Interoperability | Can relevant data be exchanged safely through the intended formats and interfaces? |
| Positive healthcare effect | Is medical benefit or a patient-relevant improvement of structure and process demonstrated? |
Security is a process, not an application item
The BfArM guide addresses an information security management system and security as an ongoing process. Changes to app, backend, libraries, cloud services or data flows can invalidate an older assessment. Manufacturers therefore need asset and vulnerability management, secure updates, incident response, supplier control and a responsible reporting path for external researchers.
What should technical testing cover?
Testing covers not only the mobile app but also the API, user and administrative roles, tenant separation, cloud configuration, local storage, cryptography and update mechanisms. Trust boundaries between patient, provider, manufacturer and third party are particularly important. Scope and repetition follow change and risk; one report shortly before an application does not provide assurance for the full operating lifecycle.
Thank you for your feedback! We will review it and optimize this content.