77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Understanding KRINKO: Recommendations, commitment and obligations for institutions
Health & Hygiene

Understanding KRINKO: Recommendations, commitment and obligations for institutions

4 August 202612 min readBy Stefan Möller
CIVAC

The KRINKO at the RKI publishes the relevant recommendations on hospital hygiene. Anyone who ignores them risks liability and fines according to IfSG. This guide classifies mission, liability and operational duties.

The Commission for Hospital Hygiene and Infection Prevention (KRINKO) was established at the Robert Koch Institute in accordance with Section 23 Paragraph 1 of the Infection Protection Act. It develops recommendations for the prevention of nosocomial infections, hygiene in medical facilities and operational-organisational and structural-functional measures. For hospitals, day clinics, practices, care facilities, emergency services and similar facilities, the KRINKO recommendations are not non-binding reading material, but rather the relevant state of medical science, which has a direct effect on the traffic safety obligation and the state hygiene regulations. Anyone who does not implement it bears the burden of proof of the equivalence of their own approach in the event of damage and is at the same time under regulatory observation by the state health authorities.

This article classifies the KRINKO, clarifies the difference between recommendation and obligation, names the operational obligations in facilities and shows how hygiene officers provide evidence of implementation. It addresses four questions relating to the everyday life of a medical facility: How does KRINKO work, what legal effect do its recommendations have, what specific obligations arise in the facility and how does the knowledge get into the file in an audit-proof manner? CIVAC is a compliance platform and officer-as-a-service that organises hygiene duties with audit templates, reporting line and audit calendar in one workspace. The appointment certificate, signed, filed, verifiable. Audit-proof, documented, § 23 IfSG-proof.

Key Takeaways

  • KRINKO recommendations are assumed standards of care according to Section 23 Paragraph 3 IfSG: Anyone who deviates must prove equivalence.
  • Hygiene officers must transfer the recommendations into the facility's own hygiene plans in accordance with Section 23 Paragraph 5 IfSG and document their effectiveness.
  • Fines of up to 25,000 euros according to Section 73 IfSG and civil liability make implementation a business obligation.

Mission and working methods of KRINKO at the RKI

The KRINKO is an independent expert commission that was established at the Robert Koch Institute in accordance with Section 23 Paragraph 1 IfSG. Its members are appointed by the Federal Ministry of Health in agreement with the highest state health authorities for four years. Hospital hygiene, microbiology, infectiology, public health and nursing are represented. The commission works in working groups, calls in external experts and publishes its recommendations in the Federal Health Gazette. Important: KRINKO is not an authority, it does not issue administrative acts, but its recommendations are not legally arbitrary, but are scientifically assumed standards of care with the burden of proof.

Known KRINKO recommendations range from hand hygiene and reprocessing of medical devices to surveillance of nosocomial infections, personnel requirements in hospitals, protection against multi-resistant pathogens, hygiene measures in endoscopy and requirements for cleaning and disinfection. Updates are made as needed, for example when new evidence is available or pathogen situations change. Institutions should therefore not only be familiar with the current version, but also read transition periods and justifications. A pure collection of links on the intranet does not replace the structured link with the institution's own hygiene plan.

If you want to work properly with the commission and its output, document the KRINKO version statuses in the institution's own hygiene plan and link each recommendation with the measures on site. A central overview of current and withdrawn recommendations is part of the basic equipment. In the CIVAC workspace, this link is part of the audit templates for the hygiene officer, so that version statuses, measures and training are in one data object and not in three filing cabinets. Using the 37 central, ready-to-use audit templates, older versions of recommendations can also be reconstructed with their effective periods, which can be crucial in cases of damage with a longer time horizon.

Legal binding according to Section 23 IfSG: Presumption instead of regulation

The central standard is Section 23 Paragraph 3 IfSG: Compliance with the state of medical science in the field of infection prevention is presumed if the published recommendations of KRINKO and the Commission on Anti-Infectives, Resistance and Therapy (ART) at the RKI have been observed. This presumption of compliance is a significant legal advantage: anyone who implements and documents the KRINKO recommendations has a strong position in the dispute. Conversely, the institution that deviates bears the burden of demonstrating and proving the equivalence of the chosen measures. This distribution of the burden of proof applies both in supervisory proceedings and in civil court disputes.

The state hygiene regulations, such as MedHygV of the individual states, often expressly refer to the KRINKO recommendations and thus make them directly binding state law. There are also requirements from Section 36 IfSG for nursing facilities, schools and similar facilities as well as special legal requirements for dialysis facilities, outpatient surgery centres and birthing centres. Anyone who has to present an independent hygiene organisation, a hygiene plan and qualified hygiene officers practically cannot avoid the KRINKO.

In practice, this means: The KRINKO is not a collection of recommendations in the soft sense, but a standard of care with the burden of proof. A deviation is not prohibited, but must be justified. Anyone who chooses a different standard must document its equivalence, include the justification in the hygiene plan and prove its effectiveness through surveillance, audit and training. Others run compliance like a filing cabinet. We run it like software. The template for a justified deviation is located in the CIVAC workspace and links the justification, effectiveness measurement and reporting line to management. This means that any deviation can be explained to the supervisory authority at any time, and management has a clear report on the technical decisions made by its hygiene organisation.

Duties in facilities: hygiene plan, hygiene officer, surveillance

The KRINKO recommendations only take effect in the facility through concrete obligations. Section 23 (5) IfSG requires hospitals, day clinics and comparable facilities to have their own hygiene plan that documents the risk profile, hygienic measures and responsibilities. The plan must reflect the current KRINKO recommendations, be updated regularly and presented to the responsible authority upon request. In addition, hygiene officers and hospital hygienists are appointed in accordance with state law requirements, supplemented by hygiene-commissioned doctors in the specialist departments.

The operational tasks include surveillance of nosocomial infections in accordance with Section 23 Paragraph 4 IfSG, processing of medical devices in accordance with MPBetreibV, personnel development and training, outbreak management, procurement of hygiene products, structural and operational hygiene as well as interfaces to Company doctor, data protection officer and management. Anyone who works here without a structured audit calendar will lose track of things during the first audit at the latest. A completed task matrix prevents individual KRINKO recommendations from ending up in organisational no-man's land.

In the CIVAC workspace, the facility's own hygiene plans are stored as versioned audit templates. Each hygiene plan point refers to the associated KRINKO recommendation, the effectiveness measurement and the proof of training. The auditor calls, the evidence is ready. Anyone who integrates the hygiene officer into the same platform in which the data protection officer and the information security officer work saves considerable coordination effort and maintains a uniform reporting line to management. The appointment certificate, signed, filed, verifiable. A common reporting line also reduces the number of parallel status meetings with management and makes the supervisory documentation consistent for all mandates. Anyone who operates multiple locations particularly benefits from this bundling because location differences can be reflected in a consolidated view. This means that the management remains able to act at all times.

KRINKO and hygiene officer: Who does what?

KRINKO itself does not appoint representatives; it publishes recommendations. The appointment of hygiene officers is carried out by the institution in accordance with the state hygiene regulations and based on the KRINKO recommendation on personnel requirements in hospitals and other medical facilities. This recommendation defines qualification profiles for hospital hygienists, hygiene specialists, hygiene-commissioned doctors and hygiene-commissioned nursing staff. The order path is therefore clearly regulated: written order, documented qualifications, reporting line to management and the hospital hygienist, replacement arrangements for vacation and illness.

In practice, several roles work together. The hospital hygienist is responsible for the technical management, hygiene specialists carry out surveillance and training, hygiene-commissioned doctors and hygiene-commissioned nurses are responsible for implementation in the specialist departments. A written distribution of tasks is not an option, but a core requirement because responsibilities in the event of damage must be clarified. External service providers such as cleaning companies or processing services must also be integrated into the distribution of tasks.

CIVAC maps this role structure via the dual frame: Licence the workspace for your internal representatives, or have our representatives appointed. The appointment certificates, proof of qualifications and representation regulations are available in versions in the workspace; the KRINKO versions are linked to the task list. This makes it clear which person took on which task from which date according to which version of the recommendation. This lack of gaps is the decisive advantage in the audit compared to a file architecture in which orders and recommendations are unlinked next to each other. In the event of personnel changes, handovers with the date and task status are stored in an audit-proof manner so that professional continuity remains verifiable even at the end of the mandate. This protects the facility against the most common audit finding: incomplete order history.

Reprocessing of medical devices: KRINKO/BfArM recommendation in practice

The joint recommendation from KRINKO and BfArM on the hygiene requirements when reprocessing medical devices is one of the most practical recommendations of all. It specifies the requirements of Section 8 MPBetreibV and classifies medical devices into risk classes, each with specific reprocessing obligations. Anyone who reprocesses must use validated procedures, qualify personnel, document processes and be able to prove the reprocessing to supervisory authorities. Incorrect reprocessing is often the most expensive breach of compliance in a medical facility in the event of damage and can lead to an order to restrict operations by the state authority.

Operational implementation requires procedural instructions for each product type, a training matrix for the reprocessing teams, a release and batch system as well as recurring effectiveness measurement. Audits by state authorities often focus on reprocessing because the consequences of a gap directly affect patient safety. Anyone who hands over a preparation that requires validation as not being validated not only risks fines, but also the order to restrict operations. Outsourced processing must also be contractually and demonstrably KRINKO-compliant, otherwise the responsibility falls on the client.

In the CIVAC workspace, the KRINKO/BfArM recommendation is linked to the facility's processing matrix. Each procedure instruction refers to the associated recommendation, validation, level of training of the teams and the most recent supervisory review. When the recommendation is updated, a note appears in the test calendar so that the procedural instructions do not become silently outdated. The auditor calls, the evidence is ready. Anyone who operates multiple locations can maintain central procedural instructions with location-specific deviations and still maintain a consistent reporting line to management. This means that the processing regime in every branch remains audit-proof and documented in accordance with KRINKO.

Fines, liability and supervision: What counts in the event of damage

Violations of Section 23 IfSG and the state hygiene regulations are subject to fines according to Section 73 IfSG, in many cases with amounts of up to 25,000 euros per violation. In addition, there are civil law claims for damages from patients, which can be based on the presumption rule of Section 23 Paragraph 3 IfSG. Anyone who does not have a facility's own hygiene plan or does not have it up to date, who does not appoint qualified hygiene officers or who does not document surveillance will find themselves in an unfavorable evidentiary situation in the event of damage. The loss of insurance coverage is also a real consequence of serious or repeated defects.

Criminal risks are not excluded. In the event of intentional false documentation of the preparation or violations with significant consequences for patient safety, bodily harm due to omission, forgery of documents and similar offenses can be considered. The management is also personally liable according to Section 130 OWiG if supervisory duties have been violated. Section 130 OWiG is therefore present in hygiene organisations as well as in classic compliance functions. If you want to avert the personal liability of management, ensure verifiable supervisory measures and a documented reporting line from hygiene to management.

The operational answer is: documented ordering, documented training, documented surveillance, documented outbreak management, documented processing, documented updating of the hygiene plans. The CIVAC workspace bundles this evidence and makes it immediately available for supervisory or insurance inquiries. A missing recommendation is not cured by subsequent activity because the version status and the implementation history remain documented. Anyone who follows the KRINKO recommendations properly shortens the supervisory review considerably and at the same time relieves management of personal liability risks in accordance with Section 130 OWiG. This is the operational logic behind the statement that hygiene compliance is now a software issue.

Training obligations: How KRINKO knowledge gets into the staff

KRINKO recommendations only work if the staff knows and applies them. The training obligation arises from the state hygiene regulations and from the KRINKO recommendation on personnel requirements. It affects medical staff, nursing staff, processing staff, cleaning staff, technical staff and external service providers who work in hygiene-sensitive areas. Training courses must be documented, dated and accompanied by participant lists. A blanket statement about annual training is not sufficient in the audit; What is required is topic-related evidence with reference to the respective KRINKO recommendation and the activity group.

Practice shows: Training gaps typically arise with short-term changes in personnel, with external cleaning services and with students or interns. Training for management is also often forgotten, even though they bear the responsibility. An effective training matrix lists topics, target groups, frequencies, trainers and evidence. It is linked to the KRINKO version levels so that a recommendation update automatically triggers a training event. Onboarding training on the first day of work must also be documented, otherwise there will be a lack of evidence during the next supervisory inspection.

In the CIVAC workspace, the training matrix is ​​linked to the hygiene officer's task list, to the KRINKO recommendations and to the state hygiene regulations. Training records are stored with date, participants and topic reference. The test calendar reminds you of refreshers, the deadline runs as soon as you become aware of it. Anyone who systematically carries out the training obligation protects patients and at the same time the facility against liability risks. Audit-proof, documented, § 23 IfSG-proof. The training certificates can be exported directly from the workspace for the supervisory request and documented with the signatures of the participants. External audits by accreditation bodies also benefit from an orderly training history, for example in the certification of processing units for medical devices or in endoscopy certifications. This creates a consistent evidence path from the KRINKO version to the individual training unit.

Interfaces: KRINKO, occupational safety, data protection and KRITIS

Hospital hygiene is not an isolated discipline. It overlaps with occupational safety because employees must be protected against biological agents according to BioStoffV. It overlaps with data protection because Surveillance processes personal health data in accordance with Art. 9 GDPR. It overlaps with IT security because many hospitals have become essential facilities with their own reporting obligations via KRITIS law and NIS-2. A data breach in the hospital information system can also trigger a security report to the BSI according to NIS-2, with a 24-hour early warning and a 72-hour follow-up report. At the same time, the 72-hour deadline for the data protection supervisory authority in accordance with Article 33 of the GDPR runs.

The Whistleblower Protection Act is also relevant. Reports of hygiene deficiencies should be received via the internal reporting office in accordance with the HinSchG and processed in compliance with confidentiality. The same platform logic as for data protection and IT security is therefore also economical for hygiene and whistleblower protection. In care facilities, there are also interfaces to resident law and home supervision, which further increases the requirements for a consolidated reporting line.

CIVAC maps these interfaces via the 25 representative roles in the workspace. Hygiene officers, company doctors, data protection officers, information security officers and reporting office officers work in a uniform architecture with a common inspection calendar and a reporting line to management. A hygiene incident with data protection and security dimensions is recorded only once in the workspace and automatically translated into the respective reporting channels. This reduces the coordination effort, speeds up the reaction and permanently closes audit gaps between mandates. Anyone who manages multiple duties at the same time benefits from a uniform evidence architecture and a consolidated risk view for the board. This bundling is also the economic answer to the growing complexity of regulatory interfaces in the health sector.

From reading the KRINKO to living the hygiene system: The CIVAC path

KRINKO publishes recommendations. The institution must translate it, apply it, train it, measure it and document it in the audit. CIVAC is a compliance platform and officer-as-a-service that structures this translation path: 490 ready-to-use audit templates, recommendations version tracking, training matrix, audit calendar, outbreak log and reporting line to management. The 25 representative roles, including hygiene, company doctor, data protection, IT security and whistleblower protection, work in a uniform architecture so that interfaces do not become an audit gap. EU data residency ensures that patient data is processed within European legal areas, which is particularly relevant for hospital chains with cross-border data flow.

The dual frame: Licence the workspace for your internal hygiene officers, or have our officers appoint them. In both models, the order time is not in weeks, but in two working days. Version changes of the KRINKO recommendations appear automatically in the test calendar so that hygiene plans and procedural instructions do not quietly become outdated. Anyone who omits a version for a reason should document the reason as part of the audit trail. This multi-role architecture noticeably reduces the total operating costs of the compliance function and at the same time standardises reports to management, the supervisory board or the sponsor. Anyone who operates a clinic chain with different carrier models can still use the reporting logic consistently.

Turn reading into a mandate.: Send us your facility type, your state hygiene regulations and the desired reporting line to info@civac.de or use the contact form on civac.de. We hand over a workspace with linked KRINKO recommendations, hygiene plan templates and training matrix ready for use. Anyone looking for an initial overview of the Platform FAQ or the Hygiene Officer role path can find this without registering. The auditor calls, the evidence is ready. Turn reading into an assignment. The clock starts on awareness.

FAQ

Are KRINKO recommendations legally binding?

According to Section 23 Paragraph 3 IfSG, they are not binding in the sense of a regulation, but as a presumed standard of care. Whoever implements them has strong evidence in the dispute. Anyone who deviates must demonstrate and document the equivalence of the chosen measures. State hygiene regulations also expressly refer to KRINKO, making them directly binding state law.

Who has to create a hygiene plan according to KRINKO specifications?

Hospitals, day clinics, prevention and rehabilitation facilities and similar facilities in accordance with Section 23 Paragraph 5 IfSG are obliged to draw up their own hygiene plan. Care facilities are covered by Section 36 IfSG, outpatient surgery centres are covered by the state hygiene regulations. The hygiene plan documents the risk profile, measures and responsibilities and must be updated regularly. It must be presented to the responsible authority upon request, and in many countries also in the annual hygiene audit.

What role does the hygiene officer play towards KRINKO?

The hygiene officer translates the KRINKO recommendations into the facility's own practice. He creates and updates the hygiene plan, documents surveillance, controls training, coordinates outbreak management and reports to management. The order is made in writing and based on qualifications in accordance with state law requirements and the KRINKO recommendation on personnel requirements in medical facilities. A replacement arrangement for vacation, illness and the end of the mandate is a mandatory part of the order.

What fines are there for hygiene violations?

According to Section 73 IfSG, up to 25,000 euros per violation, and higher in individual cases. In addition, there are civil claims for damages and criminal law risks in the event of intentional false documentation or violations of patient safety. According to Section 130 OWiG, the management is personally liable if supervisory duties have been violated. Loss of insurance coverage and reputational damage are also real consequences of serious violations.

How often do KRINKO recommendations need to be reviewed in the facility?

At least with every new or changed recommendation and regularly as part of the annual hygiene audit. A quarterly version comparison in the workspace is recommended so that updates from the Federal Health Bulletin are promptly incorporated into the hygiene plan and the training matrix. In this way, proof of topicality remains verifiable at all times, and deviations can be documented with justification before the next supervisory audit.

How does CIVAC support the implementation of the KRINKO recommendations?

Via a workspace with linked KRINKO recommendations, hygiene plan templates, training matrix, surveillance logic and reporting line to management. The hygiene officer is appointed within two working days, optionally with a representative and an external hygiene specialist. Version changes are automatically marked in the test calendar, training courses are reminded, and evidence is saved in an audit-proof manner. This means the facility remains audit-proof and relieves the management of personal liability in accordance with Section 130 OWiG.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

The officer role behind this article

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles