
Section 393 SGB V: since 1 July 2025 only a C5 Type 2 attestation counts, with one 18-month exception
A German healthcare provider or health insurer processing social and health data in the cloud needs, under section 393(3) SGB V, a current C5 attestation of the data-processing entity. Subsection 4 fixes when Type 1 was enough, since when Type 2 is required and which 18 months apply to systems newly placed on the market.
Key takeaways
- Section 393(1) SGB V permits service providers within the meaning of Chapter Four, health and long-term care insurers and their respective processors to process social and health data by way of a cloud computing service only if the requirements of subsections 2 to 4 are met.
- Section 393(2) SGB V restricts the place of processing to Germany, EU Member States, states treated as equivalent under section 35(7) SGB I, or third countries with an adequacy decision under Article 45 GDPR, and in every case requires that the data-processing entity has an establishment in Germany.
- Section 393(3) no. 2 SGB V requires a current C5 attestation of the data-processing entity with regard to the C5 basic criteria; no. 3 requires that the corresponding criteria for customers contained in the attestation report have been implemented. The attestation alone is not enough; the customer side must evidence its part.
- Section 393(4) sentence 3 SGB V: where an IT system is first placed on the market after 30 June 2025, a C5 Type 1 attestation counts as current for the first 18 months after placing on the market, and a C5 Type 2 attestation from the 19th month.
- Section 393(4) sentence 4 SGB V accepts, instead of a C5 attestation, an attestation or certificate under a standard whose observance ensures a level of security comparable to or higher than the C5 standard; the Federal Ministry of Health may determine by ordinance which standards qualify.
- Section 393(5) and (6) SGB V tie the "appropriate" technical and organisational measures under subsection 3 no. 1 to section 390 (contracted physicians), section 391 (approved hospitals) and the B3S-GKV/PV (health insurers); in all other cases, equivalence to section 391 applies.
A permissive rule with three conditions and one date
Section 393 SGB V is neither a prohibition nor an appointment duty. It is a permission with conditions: service providers and insurers may process social and health data by way of a cloud computing service provided the requirements of subsections 2 to 4 are met (section 393(1) SGB V). The conditions concern the place (subsection 2), the security (subsection 3) and the evidence of security (subsection 4). The date that changed the evidence is 1 July 2025, and it is now more than a year old. This article reads the provision in the version shown by gesetze-im-internet.de on 15 September 2026; the quotations below are our translations of the German statutory text, which alone is authoritative.
The addressees under subsection 1 are service providers within the meaning of Chapter Four of SGB V, health and long-term care insurers and their respective processors. Chapter Four of SGB V covers the relations between health insurers and service providers, that is contracted physicians and dentists, approved hospitals, pharmacies and providers of therapeutic remedies, among others. The software vendor whose practice management system runs in the cloud is addressed as a processor.
Subsection 2: the place of processing
Section 393(2) SGB V provides that the processing of social and health data by way of a cloud computing service may take place only (1) in Germany, (2) in a Member State of the European Union or (3) in a state treated as equivalent under section 35(7) SGB I or, where an adequacy decision under Article 45 of Regulation (EU) 2016/679 exists, in a third country, and only if the data-processing entity has an establishment in Germany. The domestic establishment is a condition in addition to the place: a provider that processes exclusively in an EU data centre but has no establishment in Germany does not satisfy subsection 2.
Subsection 3: measures, attestation and the customer side
Section 393(3) SGB V provides that processing under subsection 1 is permissible only if, in addition to the requirements of subsection 2, (1) appropriate technical and organisational measures in line with the state of the art have been taken to ensure information security, (2) a current C5 attestation of the data-processing entity with regard to the C5 basic criteria exists for the cloud systems and technology used within the cloud computing service, and (3) the corresponding criteria for customers contained in the attestation report have been implemented.
No. 3 is overlooked in practice. The C5 criteria catalogue of the Federal Office for Information Security (BSI) contains, alongside the requirements for the cloud provider, corresponding criteria that the customer must implement, for instance in managing access rights or configuring encryption. The provider's attestation covers its side. Whether the customer side is implemented must be evidenced by the service provider itself, and that is precisely why subsection 7 requires a checklist of the corresponding customer criteria for the publication of attested systems.
Subsection 4: Type 1, Type 2 and the 18 months
Section 393(4) sentences 1 and 2 SGB V provide that until 30 June 2025 a C5 Type 1 attestation counts as a current C5 attestation within the meaning of subsection 3 no. 2, and that from 1 July 2025 a current C5 Type 2 attestation counts as such. The difference between the types lies in the subject of the examination: a Type 1 attestation confirms the suitability of the controls at a reference date, a Type 2 attestation additionally confirms their operating effectiveness over an examination period. Since 1 July 2025 the statute demands the second statement. A Type 1 attestation issued in spring 2025 has therefore not supported the processing since that date, however recent it is.
Sentence 3 contains the exception: where an IT system is first placed on the market after 30 June 2025, a C5 Type 1 attestation counts as current for the first 18 months after placing on the market, and a C5 Type 2 attestation from the 19th month. The exception attaches to the system, not to the provider: a provider that first places a new cloud system on the market in October 2025 may operate it with a Type 1 attestation until the end of the 18th month, that is into April 2027, and needs Type 2 from the 19th month. For a system that was on the market before 1 July 2025 there is no such period. Anyone relying on the exception must therefore be able to evidence the date of first placing on the market.
Sentence 4 opens the provision to other standards: processing under subsection 3 no. 2 is also permissible where, for the cloud systems and cloud technology used, an attestation or certificate under a standard exists in place of a current C5 attestation, provided that observance of that standard ensures a level of security comparable to or higher than the C5 standard. Sentence 5 authorises the Federal Ministry of Health, in agreement with the BSI, to determine by ordinance which standards meet that test. Until such an ordinance exists, the burden of demonstrating comparability lies with the processor.
Subsections 5 and 6: what "appropriate" under no. 1 means
Section 393(5) SGB V deems technical and organisational measures appropriate within the meaning of subsection 3 no. 1 where (1) in contracted medical and dental care the requirements of section 390, (2) in approved hospitals the requirements of section 391 and (3) for health insurers the requirements of the sector-specific security standard for statutory health and long-term care insurers (B3S-GKV/PV) are met. Section 393(6) sentence 1 adds that in all other cases measures are deemed appropriate if they are equivalent to the requirements of section 391. For pharmacies, providers of therapeutic remedies or care facilities that fall under neither section 390 nor section 391, the hospital benchmark of section 391 is therefore the reference.
What a service provider must have on file today
Four pieces of evidence follow from the wording and must be available in the event of a supervisory review. First, the place of processing and the provider's domestic establishment under subsection 2. Second, the provider's C5 attestation under subsection 3 no. 2, as Type 2 since 1 July 2025, or the date of first placing on the market of the system where the 18-month period of subsection 4 sentence 3 is relied on. Third, the implementation of the corresponding customer criteria under subsection 3 no. 3. Fourth, the provider's own measures under subsection 3 no. 1, measured against section 390, section 391 or the B3S-GKV/PV.
Attestations expire, and a Type 2 attestation covers an examination period, not the future. In CIVAC the expiry date and examination period of each provider attestation can be kept as a recurring task, the checklist of customer criteria filed as a document, and the 19th month set as a deadline for every system placed on the market after 30 June 2025. This changes nothing about the duty itself; section 393 SGB V does not require the appointment of a person, but evidence that is complete at the time of review.
Where this article stops
CIVAC is not a law firm and does not provide legal services within the meaning of the German Legal Services Act (Rechtsdienstleistungsgesetz). This article reproduces section 393 SGB V. Whether a specific service is a cloud computing service within the meaning of the provision, whether a specific certificate ensures a comparable or higher level of security under subsection 4 sentence 4, when a system was first placed on the market, and whether a specific service provider's measures are equivalent to section 391 is not decided by this text but by the processor towards its supervisory authority.
Frequently asked questions
Is a C5 Type 1 attestation still sufficient for cloud processing of health data?
As a rule, not since 1 July 2025. Section 393(4) sentence 2 SGB V provides that from that date a current C5 Type 2 attestation counts as the current C5 attestation. The only exception is in sentence 3: for an IT system first placed on the market after 30 June 2025, a Type 1 attestation suffices for the first 18 months after placing on the market.
Who does section 393 SGB V apply to?
Under section 393(1) SGB V, to service providers within the meaning of Chapter Four of SGB V, to health and long-term care insurers and to their respective processors, insofar as they process social and health data by way of a cloud computing service. The cloud provider as processor is thus addressed just as much as the practice or hospital using its service.
May the cloud be located in the United States?
Section 393(2) no. 3 SGB V permits processing in a third country where an adequacy decision under Article 45 of Regulation (EU) 2016/679 exists, and in every case only if the data-processing entity has an establishment in Germany. Whether an adequacy decision exists for a specific third country and what it covers must be checked at the time of processing.
What are the corresponding criteria for customers?
The BSI's C5 criteria catalogue contains, alongside the requirements for the provider, criteria that the cloud customer must implement itself. Section 393(3) no. 3 SGB V makes their implementation a condition of the processing, and section 393(7) SGB V requires a checklist of these criteria for the publication of an attested system on the platform of the competence centre for interoperability in healthcare.
Are there alternatives to the C5 attestation?
Section 393(4) sentence 4 SGB V accepts an attestation or certificate under a standard whose observance ensures a level of security comparable to or higher than the C5 standard. Which standards qualify may be determined by the Federal Ministry of Health under sentence 5, in agreement with the BSI, by ordinance.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Sections 6, 17, 45 ElektroG: registration before placing on the market, take-back from 400 square metres, fines up to EUR 100,000
