For medical practices & MVZ

One click – and your patient data is in someone else’s hands.

Health data cannot be recalled and cannot be reissued. That is why practices are a favourite target, and why your team needs a reliable instinct for that one fake email, even on a packed day. That is exactly what I train – no IT department needed, no jargon, in about 45 minutes per person.

Example scene for Medical practices
“No IT department, a full waiting room – security has to run on the side.”
“Since October 2025 the KBV (National Association of Statutory Health Insurance Physicians) has required annual training and awareness for practice staff.”
“A ransomware incident brings the whole practice to a halt – appointments, billing, TI (Germany’s telematics infrastructure for healthcare).”
Add your team See prices
€49 per person, one-off

Training, phishing test, six months of refreshers and proof of training. No subscription. A practice with six people pays €294 net.

45 min per employee

Online, can be paused at any time, even in short stages between two patients. Your own effort: enter your team, done.

PDF Proof of training with timestamp

Who was trained and when, plus the team rate. Exactly what the KBV guideline means by “verifying participation”.

0 access to TI or practice software

All I need is the name and email address of your staff. The TI connector, KIM (the secure healthcare email service) and practice management software remain untouched.

What happens after the click

What criminals do with patient data – and what it costs you.

You can hardly put a figure on the value of your data, but the attackers can. Patient data is not “stolen”, it is copied: you still have it, and now someone else does too.

Patients are blackmailed directly

With diagnoses, findings or treatment histories in hand, criminals write to the patients themselves: pay or it gets published. At the Finnish psychotherapy provider Vastaamo, this affected tens of thousands of patients.

Publication on the dark web

If no ransom is paid, lab results, doctors’ letters and addresses end up openly online, as happened in 2025 after the attack on the LUP hospitals in Mecklenburg-Western Pomerania. There is no getting them back.

Identity and billing fraud

Insurance number, date of birth and address are enough for fraud in your patients’ names: prescriptions, orders, accounts. Suspicion falls first on the practice the data came from.

The practice comes to a standstill

Encrypted systems mean no access to records, appointments and billing, often for days. Recovery, forensics and legal advice usually cost far more than any ransom.

And this is what you then have to do

72 hours

Notify the state data protection authority as soon as a risk to those affected cannot be ruled out (Art. 33 GDPR).

without undue delay

Inform every affected patient if the risk is high, which with health data is practically always the case (Art. 34 GDPR).

permanently

Responsibility for medical confidentiality (§ 203 StGB) and possible fines and damages; lost trust in your community cannot be insured.

Almost every one of these cases starts with an email that one person believed was genuine. Recognising that one email is what I train.

Typical attacks

This is how your sector is being attacked right now.

I recreate these scenarios in realistic simulations, so your team recognises them when it counts instead of only understanding them after the damage is done.

Fake KV/KBV message

An alleged fee notice or billing error pushes staff to log in on a copycat website.

Bogus TI/gematik “security update”

An email demands an “urgent update” of the connector, including login details.

Patient enquiry with attachment

An alleged patient request brings a malicious file into the practice – a gateway for ransomware.

Fake KIM/e-prescription notification

A supposed message from the secure network leads to a fake login page.

Your obligations

What you have to do – and what this lets you tick off.

For practices, what counts is the IT security guideline of the KBV (National Association of Statutory Health Insurance Physicians) under § 390 SGB V (German Social Code, Book V; until 2025: § 75b) and the GDPR. The guideline was revised in April 2025, and its training requirements have applied to practices of every size since 1 October 2025. Each point states openly whether I cover it, partly support it or whether it lies with your IT – linked to the matching attack scenario.

✓ covered
Train all employees in IT security and data protection every year and verify participation. · KBV IT security guideline, Annex 1 No. 6 and 10 (§ 390 SGB V)
↳ covers: all four attacks

The course is exactly the required “training dedicated to IT security and data protection”. The KBV explicitly names e-learning as an easy-access route. Participation and date are recorded in the proof of training.

✓ covered
Instruct staff in the safe use of IT: passwords, emails, what to do in an incident. · Annex 1 No. 9
↳ covers: Patient enquiry, KIM

Passwords and two-factor authentication, checking senders and attachments, the call-back rule and the reporting channel each have their own chapter in the course.

✓ covered
Practice management is itself aware of the risks and supports security measures. · Annex 1 No. 8
↳ covers: KV message, TI update

You take the same course as your team and see in the Cockpit where the practice stands. The proof of training documents both.

✓ covered
Handling spam and suspicious emails: do not reply, do not follow links. · Annex 1 No. 41
↳ covers: all four attacks

The phishing test after the training shows whether this sticks in everyday work, with TI, KIM and KV-related themes.

◐ partly
Onboard new employees and inform them of the rules; remind departing staff of their duty of confidentiality. · Annex 1 No. 1, 2 and 5 · § 203 StGB
↳ covers: Patient enquiry

You add new colleagues with one click and they start with the same knowledge. The formal confidentiality undertaking and the return of access credentials remain your responsibility.

◐ partly
Technical and organisational measures to protect health data. · Art. 9 and 32 GDPR
↳ covers: TI update

The KBV guideline specifies the state of the art under Art. 32. Trained staff are the organisational part; your IT service provider adds the technical side.

◐ partly
Report a data breach to the supervisory authority within 72 hours and inform patients. · Art. 33 and 34 GDPR
↳ covers: all four attacks

The course practises the internal reporting channel: who calls whom, what gets noted down, what not to do. The report itself and the breach register are handled by you or your data protection officer.

– your IT
Technical safeguards: firewall, updates, antivirus, backups, connector. · Annex 1 No. 11 to 39, Annex 5

Not part of awareness training – this lies with you or your IT service provider.

The KBV does not certify practices and does not carry out active checks; the guideline is a minimum standard and becomes the benchmark in the event of damage and when the data protection authority makes enquiries. What the KBV additionally requires of large practices, namely measuring learning success (Annex 3 No. 1), you get from me anyway: quiz and team rate.

Examples

This is what it looks like in practice.

Cockpit, team report, certificate and proof of training for a fictitious company with twelve people. All names and results are made up; the layout is exactly what you will see yourself later.

Cockpit The business Cockpit

Groups, registered people and the cost if everyone completes. From here you start training, an initial test or a repeat run.

Team report Team report in the Cockpit

The team’s click and data-entry rates, a comparison with all test runs, participation in training. Anonymised.

Team report Evidence PDF, page 1

Results at a glance and protection level with a recommendation. The PDF carries an authenticity QR code and is suitable for audits, insurers and NIS2 documentation.

Certificate Certificate of participation

Name, course, dates of training and practical test, reference to standards, signature and a verifiable certificate number with QR code.

Compliance evidence NIS2 compliance evidence

All training carried out, with time stamps and participation rates, mapped to the requirements. Also for ISO 27001, GDPR, the AI Act and cyber insurance.

Individual report Personal report

Each person sees only their own result: reaction to each test email, how the scam could have been spotted, and what their device gave away.

All example views

How I work with you

This is how my training works.

Your day-to-day practice leaves no time for training projects. So the training adapts to you: from reception to treatment room, everyone learns the same basics, each person whenever there is a quiet moment, without the practice grinding to a halt.

Two ways – you choose what suits you.

1 In person, by me

I train your team in person – on site or online, in conversation and with examples from your everyday work.

2 Everyone online on their own

Everyone learns online the way they prefer – by text or video, at their own pace, choosing the content.

My recommendation

Train first, then test – deliberately in that order.

  1. Initial training

    First I equip your team (or you do it with my materials). Everyone starts with the same basic knowledge.

  2. Phishing test as a self-check

    Only then does the simulated attack follow – not as an exam, but as a self-check: everyone sees whether what they learned holds up in everyday work.

  3. A security culture, refreshed when needed

    Training and testing grow into a constructive security culture in your business, which you simply repeat when the time comes.

📊

Your status report is based on your team’s results after the training – it shows the level you set out to reach, not the unprotected starting point.

The reverse order, testing first and training afterwards, is technically possible. Especially in a practice where everyone works under time pressure, a test “in at the deep end” can strain trust: anyone who falls for a fake KV or TI email without training quickly feels exposed rather than empowered.

No subscription, as and when you need it, and always with my personal support.

Who is behind this

A contact person from southern Baden, not a hotline.

Patrick Ihle, founder of secureIT

I am Patrick Ihle, founder of secureIT. Professionally I work in information security, and for more than 20 years I have also been a trainer and lecturer alongside my job. secureIT is my own business in Ballrechten-Dottingen near Freiburg. I visit practices in southern Baden in person on request and support everyone else online. You write to me, and I answer myself.

More about me
AI in everyday work

Patient data does not belong in any AI tool.

Rephrasing a doctor’s letter, translating a finding, answering a patient enquiry: AI is quick to hand in a practice. With patient data, this becomes a disclosure of health data to an outside provider, with consequences under the GDPR and medical confidentiality. Since February 2025 you are also required to train your team in AI literacy.

  • Health data enjoys special protection (Art. 9 GDPR), and medical confidentiality also applies to AI providers (§ 203 StGB, German Criminal Code)
  • Training obligation for everyone who uses AI (Art. 4 EU AI Act)
  • My AI course with a certificate for each person and a template AI policy for the practice
See the AI course with certificate Sample AI policy (PDF)
FAQ

Frequently asked questions

Is this enough for the KBV IT security guideline?
For the training and awareness obligations, yes. The guideline under § 390 SGB V (German Social Code, Book V; until 2025: § 75b) requires in Annex 1 that all employees are trained regularly in IT security and data protection – according to KBV (National Association of Statutory Health Insurance Physicians) guidance at least once a year – instructed in the safe handling of passwords and email, and that participation is verified (No. 6, 9, 10). That is exactly what the programme delivers, documented with a timestamp. The technical requirements of the guideline (firewall, updates, backups, connector) remain with your IT service provider. Incidentally, the KBV certifies neither practices nor courses; there is no such thing as “KBV-approved” training.
Does the phishing simulation touch my TI, KIM or practice software?
No. The simulation consists of normal emails to your employees’ addresses. I don’t access anything in your practice, install nothing and need no logins. All I get from you are your team’s names and email addresses, governed by the data processing agreement (DPA). TI (Germany’s telematics infrastructure for healthcare) and KIM (its secure messaging service) are not involved.
How much time does this really take my team?
Around 45 min per person for the course, online, and it can be paused and resumed in stages – so it also fits between two patients or into a quiet lunch break. The phishing test afterwards takes no time; it happens in the inbox. Your own effort: add the team, unlock the course, download the proof of training later. That’s done in an hour.
Do I have to tell my employees about the phishing test beforehand?
I recommend it and build the training that way: first the training, then the announced self-test. Nobody is singled out; in the Cockpit you see rates, not names. Anyone who clicks on a test email lands on a learning page rather than in a trap. Few practices have a works council; if yours does, a template works agreement is ready.
What happens to my employees’ data?
What is stored: name, email address, course completion and the result of the phishing test, on IONOS servers in Germany. Patient data is never involved. The data processing agreement (DPA) is concluded on registration and is available as a PDF for your data protection records.
Is this a subscription?
No. There is no subscription and no contract term. You book training and tests as you need them – once or on a recurring basis, whatever suits you.
What does it cost?
For businesses, €49 net per person, one-off: training, first phishing test run, team report, Cockpit and six months of monthly refreshers. Further test runs cost €22 per person. For individuals, the training with certificate costs €29 incl. VAT, but without team report, Cockpit and refreshers, hence the lower price. An initial conversation and the self-tests are free. Compare all services on the pricing page →
Does the effect of a one-off training actually last?
Not on its own, which is why I don’t stop at the certificate. Everyone who completes the course receives a short interactive lesson by email every calendar month for six months: under five minutes, no login, a different current topic each time. Keeping it short is deliberate; the effect comes from spreading it over time. In the Cockpit you see your teams’ completion rate and the average score. This refresher is included in the business price at no extra cost.
Do I need an IT department for this?
No. Setup takes about an hour: choose a course, add your team, get started. The proof of training is created automatically. If you like, I’ll set it up together with you.
How does training with you work?
However you prefer: I train your team in person (on site or online), you run the training yourself with my ready-made materials, or each person learns online at their own pace. My recommendation: train first, then run the phishing test as a self-check – that builds a security culture instead of putting people on the spot.
Will anyone on our team be singled out or monitored?
No. There is no public shaming and no personal “who clicked” list for senior management. The team is evaluated as a whole. A wrong click is a learning moment, not an entry in someone’s personnel file.
Does this cover GDPR, NIS2, ISO 27001 or insurance requirements?
It covers the awareness and training part of these obligations – including proof of training with a timestamp. I state openly what belongs to your technology/IT. You’ll find the full comparison under “Obligations & standards”.
What happens when staff change?
You add new team members later with a click: they immediately receive the online training materials and a first self-test, and join the next joint training with the same level of knowledge.
Do I get proof of training or a certificate?
Yes. Proof of participation and completion with date and timestamp is created automatically for each person – as audit-proof evidence for audits, insurers or your own documentation.
Does this also cover AI fraud and deepfakes?
Yes. Current tactics such as AI-assisted phishing, fake voices and deepfakes are part of the courses and simulations – in line with the AI literacy requirement of the EU AI Act.
Are schools and non-profit associations really free of charge?
Yes. For schools and non-profit associations the offer is free of charge – this matters to me personally.
How quickly can I start?
Right away and without a call, if you like: you register your business or institution yourself at /registrieren, add your team, choose the course and phishing templates and start the test run – all on your own in the Cockpit, set up in about an hour. To get a feel for it, there are the free self-tests. And if you’d rather have support, just send me a short message; I’ll get back to you personally.

Your question is not listed?

Ask me directly. You only need to give an email address if you want to receive my answer.

A quick confirmation that a human is typing here, not a bot.

Set up in an hour, trained by Friday.

Enter your team, activate the course, done. The proof of training for the KBV guideline is created automatically. The account is free; you only pay when you start.

Enter your team Try it myself first

Set up in an hour, trained in a week.

Create a free account, add your team, unlock the course. You only pay when you start. Would you rather see what a test email looks like first? The self-test is free.

Add your team Test it yourself first