Hygiene plan according to § 36 IfSG: structure, obligations and examination security
According to Section 36 IfSG, a hygiene plan is mandatory for many facilities. This guide shows the structure, binding content, responsibilities of the hygiene officer and how to maintain the plan in an audit-proof manner.
According to Section 36 Paragraph 1 of the Infection Protection Act (IfSG), hospitals, care facilities, shared accommodation, schools, daycare centres and other mentioned facilities must maintain a written hygiene plan. The responsible health authorities check this without cause and after reports and complaints. The plan is not a form, but rather a binding work instruction for the entire company, from the entrance door to the dirty laundry. Who runs it, who updates it, who documents training: all of this must be comprehensibly recorded in the hygiene officer's appointment certificate and in the plan itself. The deadline begins as soon as a reportable illness occurs, so preparation is not an option, but a requirement. The inspection by the health department often takes place without prior notice; the inspector expects a current plan, a named person and complete proof of training within a few minutes.
This article explains what content a hygiene plan must cover, how the general hygiene plan, house plan and work instructions differ and what role the hygiene officer plays in the company. You will find out how auditors typically recognise deficiencies, what fines are threatened according to Section 73 IfSG and how maintenance of the plan can be operationally simplified. The aim is a document that not only complies with Section 36 IfSG, but is also used in audits, complaints and outbreak management, i.e. a working basis instead of a file. At the end there is a clear recommendation as to which tasks should remain internal and which should be ordered externally.
Key Takeaways
- According to Section 36 IfSG, the hygiene plan must be kept in writing, facility-specific and always up-to-date; the federal state framework hygiene plan does not replace it.
- The facility management is responsible for the creation and updating; the plan is operationally carried out by the appointed hygiene officer.
- Audit robustness does not come from scope, but rather from versioning, proof of training and verifiable effectiveness controls.
Legal basis: Section 36 IfSG, state regulations and framework hygiene plans
The central standard is Section 36 IfSG. Paragraph 1 obliges the facilities listed in the regulation to create internal procedures for infection hygiene in hygiene plans. Paragraph 2 also requires participation in inspections by the health department. In addition, state hygiene regulations apply, such as the medical hygiene regulations of the federal states (MedHygVO) as well as specific requirements for care facilities, rehabilitation clinics and outpatient surgery centres. In addition, for certain sectors there are the Drinking Water Ordinance, the Food Hygiene Ordinance and the Biological Substances Ordinance with TRBA 250 for activities in the healthcare sector. The KRINKO-BfArM recommendation for the reprocessing of medical devices also applies to dental practices.
The federal state framework hygiene plans, issued by the state health authorities, are intended as guidance, not as a replacement. Anyone who adopts the state framework hygiene plan unchanged does not comply with Section 36 IfSG because the plan must be facility-specific. Rooms, patient groups, procedures, cleaning products and sources of supply differ. The KRINKO recommendations from the Robert Koch Institute (RKI) should also be used as the state of the art. They have no legal status, but are considered the standard of care owed in the event of a dispute and are regularly used by courts for interpretation. The same applies to AWMF guidelines and to DIN standards such as DIN EN 14885 for the evaluation of disinfectants.
For operational implementation, it is recommended to dovetail with other obligations, such as the Biological Substances Ordinance (BioStoffV), TRBA 250 and the Medical Device Operator Ordinance. The appointed hygiene officer keeps these sources in version form and documents deviations with reasons. The appointment certificate, signed, filed, verifiable: Without this component, the hygiene plan remains a piece of paper without a support. On the other hand, if you maintain all legal sources in a single file structure, you can inspect it in minutes to show which standard establishes which section of the plan, without having to search for file folders or compare dates.
Mandatory content: What a hygiene plan must cover
A complete hygiene plan typically contains twelve to fifteen chapters. The following are mandatory: description of the facility and risk areas, cleaning and disinfection plans (surfaces, instruments, hands), processing of medical devices, laundry and waste disposal, drinking and industrial water hygiene, food hygiene (if relevant), handling of reportable pathogens, outbreak management, personnel hygiene including protective clothing, training and instruction concept as well as responsibilities with the name of the person responsible for hygiene. These chapters are supplemented by appendices with safety data sheets, VAH list extracts, training protocols and inspection reports.
Every cleaning and disinfection plan must contain four pieces of information: What is cleaned or disinfected, with what (product with VAH or RKI listing if necessary), how (concentration, exposure time, procedure) and who is responsible. If this information is missing, the inspector has a complaint on his hands. For pathogens that require reporting according to § 6 and § 7 IfSG, the reporting method must be described, i.e. telephone number of the health authority, representation regulations and reporting deadline (24 hours after knowledge). The report is made immediately, in writing, with information about the person, pathogen and route of transmission, if known. Electronic reporting via DEMIS is already standard for many pathogens and should be shown in the plan.
Two areas are underestimated in practice: drinking water hygiene according to the Drinking Water Ordinance with documented Legionella tests and the processing of medical devices according to KRINKO-BfArM recommendations. Anyone who only treats these topics cursorily will have a problem in the audit. Audit-proof, documented, § 36-proof only arises through clear procedural instructions with responsibility and proof of control. Dealing with multi-resistant pathogens (MRE), the laundry cycle between the dirty and clean sides and the disposal of infectious waste in accordance with AS 18 01 03 also belong in every plan that wants to reflect the standard of care required. For food areas, the HACCP concept supplements the hygiene plan in a separate chapter.
Role and appointment of the hygiene officer
The state hygiene regulations for medical facilities regulate whether a hygiene officer, a hygiene specialist or a hospital hygienist must be appointed. For hospitals, rehabilitation clinics and facilities for outpatient surgery, the MedHygVO North Rhine-Westphalia provides for a graduated ordering requirement, depending on the number of beds and risk profile. For care facilities, schools, daycare centres and shared accommodation, Section 36 IfSG does not necessarily specify a hygiene officer as a person, but in practice naming them is the only way to demonstrate responsibility. Insurers also regularly request the name in applications for business liability and D&O policies.
The order is made in writing by the facility management. A correct appointment certificate contains: scope of tasks, proof of qualifications (certified training according to RKI recommendations or comparable), authorities (access, authority to issue instructions, escalation path), time budget and reporting line to management. Without these components, the order is formally vulnerable. The hygiene officer does not have ultimate responsibility; according to Section 13 OWiG, this remains with the management, but is responsible for care, training and initial testing. An annual written confirmation of tasks and activities is part of the audit-proof files. If the person changes, the appointment certificate must be formally revoked and replaced with a new one, which is stored as a version in the workspace.
If you do not have capacity internally, you can appoint the hygiene officer as an external representative. CIVAC is a compliance platform and officer-as-a-service and offers both models: Licence the workspace for your internal representatives, or have our representatives order it. Both paths lead to the same audit-proof files with an appointment certificate, a catalogue of tasks and an activity report. The CIVAC SLA for the first order is two working days; in the classic market, two to six weeks are common. In acute cases of need, this difference makes the difference between an order and a silent audit. The reporting line to the management is managed in a structured manner in the CIVAC workspace, including quarterly and annual reports.
Creation step by step: From the frame to the house plan
The first step is an inventory: type of facility, patient or client groups, rooms with risk classification (clean room, operating room, lounge, sanitary area), medical devices used and cleaning chemicals. The second step is the risk assessment: which pathogens are relevant, which transmission routes are plausible, and which protective measures are proportionate. This assessment forms the technical basis of the plan and should be documented as a separate chapter, with clearly stated assumptions and sources. A risk assessment without citing the source is considered inadequate in the audit.
The third step is the derivation of the procedural instructions. One sheet per procedure: scope, responsible, means, procedure, frequency, control, documentation. The fourth step is to link up with other representatives, such as the occupational safety specialist for employee protection and the company doctor for vaccination and prevention programs according to ArbMedVV. Interfaces are named in the plan, duplicate regulations are avoided, cross-references instead of multiple maintenance. The data protection officer must also be involved as soon as health data is processed, for example when documenting vaccinations or recording illnesses. In facilities with hazardous substances, the hazardous substances officer must also be included in the cross-reference structure.
The fifth step is training. Section 36 IfSG requires employees to be instructed. In practice, initial training upon recruitment and annual repetition with proof of attendance have proven to be effective. Contents include hand hygiene according to the WHO scheme, handling personal protective equipment, reporting channels, behaviour in the event of injuries with a risk of infection, and cleaning and disinfection procedures. The sixth step is approval by management with a date and signature. Only then is the hygiene plan effective and binding for all employees. Beforehand: no plan, no control, no proof. The entire creation process should be recorded in project documentation so that questions about the methodology can be answered later.
Update: versioning, training, effectiveness monitoring
A hygiene plan is not a one-time document. Section 36 IfSG requires ongoing care. In practice, three reasons are relevant for an update: new or changed legal regulations (e.g. adaptation of the KRINKO recommendations or new TRBA regulations), structural changes to the facility (new building, new process, new provider for cleaning or laundry) and findings from inspections, audits or outbreaks. A complete revision is recommended at least once a year, documented with version status, date and person responsible. Written approval from management completes each revision.
Versioning does not mean writing a date on the cover page. It is called: List of changes with chapter, type of change, justification and release. Anyone who replaces a plan archives the previous version for at least five years, and often longer in medical institutions. The auditor calls, the evidence is ready.: It is precisely this reflex that distinguishes an audit-proof plan from a collection folder. Training records include date, content, participants, duration and signed confirmation, archived at least for the duration of the employment relationship. In the digital workspace, training courses can be recorded with an electronic signature and a complete audit trail, which makes it much easier to provide evidence in the event of a dispute.
Effectiveness control is the underestimated component. This includes spot checks for surface disinfection, audits in risk areas, evaluation of cleaning protocols and, if necessary, microbiological controls. The results are included in the hygiene officer's activity report to management, at least annually, in writing, with a list of measures. A useful structure is quarterly reports with operational findings and an annual report with strategic recommendations. If you don't measure effectiveness, you can't control it and can't prove it in an audit. Complaints from employees or relatives must also be evaluated in a documented manner because they are often early indicators of structural deficiencies.
Inspections by the health department and typical complaints
The responsible health authority carries out infection hygiene monitoring in accordance with Section 36 Paragraph 2 IfSG. Inspections take place on an ad-hoc basis, after complaints or on a regular basis. The examiner has the right to enter rooms, view documents and conduct interviews. Refusal or incomplete submission of the hygiene plan will result in orders and, if repeated, fines of up to 25,000 euros in accordance with Section 73 IfSG. In serious cases, the authority can partially or completely prohibit operations until the deficiencies are eliminated. Inspection results are usually communicated in writing, with deadlines for correcting defects.
The most common complaints are operationally sober: cleaning and disinfection plan without concentration information, missing or outdated VAH listing of the disinfectant, no documented staff training, missing appointment certificate from the hygiene officer, unclear reporting path for reportable pathogens, missing Legionella testing in the drinking water system and incomplete processing documentation for medical devices. In daycare centres and schools, topics such as changing areas, sandboxes and drinking water at exercise areas are also included, and in care facilities there is the documentation of MRE management. In dental practices, the authorities check the preparation lists and validation documents of sterilizers particularly closely. In day hospitals, the focus is on recovery rooms and the operating room cleaning frequency.
If you want to be prepared for inspections, you do an internal inspection once a year with the same checklist that the health department uses. These checklists are published in the federal states' framework hygiene plans and can be adapted. The results are recorded in the activity report and maintained as an action plan with deadlines. In this way, the plan becomes the basis for work, not a file. Experience has shown that one internal inspection per year significantly reduces the complaint rate of the official inspection. Anyone who prepares the handover to external inspectors has the appointment certificate, current plan and proof of training ready.
Interfaces to data protection, occupational safety and quality management
A hygiene plan does not stand alone. It intervenes in health data, for example when recording illnesses, vaccination status or outbreak reports. The external data protection officer checks whether collection, storage and transmission to authorities comply with the requirements of Article 9 GDPR and Section 22 BDSG. In medical facilities, medical confidentiality obligations in accordance with Section 203 of the Criminal Code apply. According to Art. 33 GDPR, data breaches must be reported within 72 hours; the hygiene plan should specify the interface process to the DSB function. The order processing contract with the software provider is also relevant for the processing of health data in practice software.
In occupational safety, the BioStoffV applies with TRBA 250. The occupational safety specialist and the company doctor carry out the risk assessment for biological agents, and the hygiene plan documents the protective measures derived from this. Duplicate regulations must be avoided; clear cross-references are mandatory. If you maintain both topics in one system, the maintenance effort is significantly reduced. The fire protection officer is also involved if disinfectants are stored as hazardous substances (alcohol-based), because additional storage and quantity limits then apply.
In quality management according to DIN EN ISO 9001 or specific industry standards (e.g. DIN EN ISO 15224 for medical facilities), the hygiene plan is a controlled document. This means: release, version status, distribution and training are reflected in the QM system. Audits by certifiers check precisely this document control and random samples of its use in the company. Others run compliance like a filing cabinet. We run it like software.: Anyone who maintains the hygiene plan, data protection, occupational safety and QM in a versioned workspace has a single source of truth in the audit, instead of four folders with three versions. This bundling also reduces training costs because content is maintained centrally and distributed to all employees.
Digital maintenance: From PDF folders to versioned workspaces
Most hygiene plans today live in Word, PDF and paper. The problem is not the format, but the lack of discoverability. Anyone who asks during the audit about the valid version of the cleaning plan in the operating room often gets three answers from three people. Stepping into the digital workspace solves exactly this problem: clear source, clear version, clear responsible person, clear proof of training. A collection folder becomes a controllable compliance asset that works even when there are personnel changes without any handover pain. The central file replaces the network of emails, Word versions and file folders that has grown over the years.
The CIVAC workspace bundles the hygiene plan, appointment certificate, training certificates, activity report and inspection logs in an audit-proof file. 490 ready-to-use audit templates cover cleaning and disinfection samples, appointment certificates and activity reports. Version statuses are maintained automatically, escalation deadlines remind you of the annual revision. EU data residency is standard, which is particularly relevant for institutions with health data and personnel files, as are the order processing contracts according to Art. 28 GDPR. The platform does not replace the technical work, but it makes it visible and verifiable, both for management and external auditors.
Operationally, this means: initial instruction for new employees is recorded with date, content and confirmation, cleaning documentation can be carried out on a mobile basis, defects end up in the action plan with a deadline and person responsible. The reporting line to management is structured and the activity report is generated from the existing data at the push of a button. This creates a hygiene plan that not only complies with Section 36 IfSG, but also actually controls the operation. Experience has shown that the care time per quarter decreases significantly, while the quality of the evidence increases at the same time. Anyone who operates a QM system in parallel interlinks both areas in the same workspace instead of maintaining parallel worlds.
Turn reading into an assignment
If you are responsible for a hygiene plan, you are typically faced with one of three situations: you do not yet have a plan and need to create one, you have derived a plan from the general hygiene plan and know that it needs to be updated for a specific facility, or you have an established plan that recently raised objections in the audit. CIVAC has a clearly defined path for all three initial situations, from the initial consultation to the order and ongoing care. The decision internally or externally is not an ideological one, but an operational one.
CIVAC is a compliance platform and officer-as-a-service. This means: Licence the workspace for your internal representatives, or have our representatives order it. In the Workspace model, you get 490 ready-to-use audit templates, including hygiene plan structures, cleaning and disinfection patterns, appointment certificates and activity reports. In the officer model, an appointed external hygiene officer with certified qualifications takes care of the care, training and initial testing. The SLA for the first order is two working days, instead of two to six weeks in the classic market. Substitution arrangements for vacation and illness are also contractually covered in the officer model.
Both models can be combined: workspace for ongoing care, external hygiene officer for technical management. If you want to know which model suits your facility, write to info@civac.de or use the contact form on civac.de. You will receive an initial assessment in two working days, with a model recommendation, cost framework and order path. Turn reading into a mandate.: The quickest way from duty of care to proof is the reliable order, documented in the workspace, carried by a named person, ready for the next inspection.
FAQ
Who is obliged to keep a hygiene plan according to Section 36 IfSG?
The facilities listed in Section 36 Paragraph 1 IfSG are obligated, in particular hospitals, preventive and rehabilitation facilities, day clinics, dialysis facilities, care facilities, facilities for outpatient surgery, shared accommodation, correctional facilities as well as schools and daycare centres. The respective facility management is responsible, who can delegate the operational task to an appointed hygiene officer, but retains ultimate responsibility in accordance with Section 13 OWiG. For medical facilities, the respective state hygiene regulations also apply.
Is the state’s general hygiene plan sufficient?
No. The general hygiene plan is a technical orientation and not a replacement for the facility-specific plan. The plan must depict rooms, procedures, cleaning products and those responsible for the specific facility. An unchanged takeover does not comply with Section 36 IfSG and is regularly criticized in the audit because there is no connection to the actual facility. It makes sense to use the framework plan as a structural template and adapt it chapter by chapter to your own facility.
How often does the hygiene plan need to be updated?
A complete audit is recommended at least once a year, and additionally when new legislation, structural changes or after outbreaks and inspections occur. Every change must be documented in the list of changes with the date, chapter and reason and approved by the facility management so that the versioning remains traceable in the audit. Interim editorial adjustments, such as new telephone numbers, are also noted with the date.
Does a hygiene representative have to be appointed?
For medical facilities, the state hygiene regulations regulate the obligation to order according to facility type and number of beds. For schools, daycare centres and care facilities without an explicit obligation, the order is still recommended in order to demonstrate responsibility. The appointment is made in writing, dated and signed by the management, and contains tasks, authorities, reporting line and proof of qualifications. It is stored in the personnel file and in the compliance workspace.
What fines are there for violations?
Violations of Section 36 IfSG can be punished with fines of up to 25,000 euros according to Section 73 IfSG. In addition, there are possible orders from the health authority, such as banning operations, as well as liability consequences if infection events are due to missing or inadequate plans. In serious cases, criminal consequences under Section 75 IfSG or Section 222 StGB are also conceivable. Insurers may also limit coverage for personal injury.
How long do old versions of the hygiene plan have to be kept?
A retention period of at least five years is recommended, in medical facilities often ten years or longer, depending on national legal requirements and the retention requirement for patient documentation. Previous versions must be archived marked with the version status and validity period so that in the event of damage, the plan in effect at the time of the incident can still be found. In the digital workspace, archiving occurs automatically with an unchangeable audit trail.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.