Since April 1, 2025, a revised IT security policy from the National Association of Statutory Health Insurance Physicians (KBV) has been in effect, and it must be implemented in all medical and psychotherapy practices by October 1, 2025. This brings a previously often-neglected aspect into focus: the obligation to provide IT security training for practice staff. The new regulation aims to better protect patient data and minimize cyber risks in medical facilities. If you're a compliance officer, IT decision-maker, or data protection officer at a medical practice, there's action to take. In this article, we'll explain the background, show you exactly what needs to be done, and give you practical recommendations.
Why the New KBV Policy Matters
With the new IT security policy, the KBV has tightened the requirements for data protection and cyber resilience in private practices. The goal is to raise staff awareness and improve both technical and organizational security measures. A key change: all practice staff — regardless of position or role — must receive IT security training.
Who is affected?
The requirements apply to all contracted physicians and psychotherapists, and are binding at the staff level as well. Practice size determines the scope of the requirements:
- Small practices: up to 5 people with data-processing access
- Medium-sized practices: 6 to 20 people
- Large practices: more than 20 people, or practices with special equipment (e.g., CT, MRI) or special processing requirements (HÄVBW)
The policy took effect on April 1, 2025, and must be implemented by October 1, 2025.
Important: According to current information, failure to implement the policy does not trigger fee reductions or fines from the KBV. Nevertheless, the risk of data protection penalties or security incidents rises significantly.
Legal Basis: Data Protection and IT Security
To give you a solid understanding, here are the most important legal references:
General Data Protection Regulation (GDPR)
Under Art. 32 GDPR, controllers must implement appropriate technical and organizational measures (TOMs) "to ensure a level of security appropriate to the risk." This includes training and raising awareness among staff.
Art. 24 GDPR also requires accountability: you must be able to demonstrate that you have actually implemented GDPR requirements — and that includes documentation and training measures.
§ 75b SGB V (for medical practices)
For statutory health insurance care, additional federal regulations also come into play: for example, IT security requirements based on social security legislation and agreements with associations of statutory health insurance physicians. The KBV policy specifies how practices should structure their security obligations at this contractual level.
IT Security Act / BSI Baseline Protection / ISO 27001 (for guidance)
While these standards don't apply directly and universally to every medical practice, they often serve as a benchmark in audits or expert assessments. Practices asking what constitutes the "state of the art" can look to established standards for guidance.
In short: the new KBV policy reinforces legal requirements and makes staff training a mandatory part of the security strategy.
What Does IT Security Training Actually Cover?
A well-designed training program should address both technical and organizational aspects and ideally be modular. Here are the core elements:
Mandatory modules for all staff
- Basic IT security concepts (phishing, social engineering, password hygiene)
- Proper handling of sensitive data, patient records, and access controls
- Identifying and reporting security incidents
- Handling mobile devices, USB drives, and cloud services
- Secure use of email, VPN, and remote access
Role-specific advanced modules
- Administrators / IT managers: firewalls, network segmentation, patch management
- Management / leadership: governance, risk management, reporting
- Lab, diagnostics, or imaging staff: secure processing of large datasets, interfaces
Testing and control mechanisms
- Short tests or quizzes at the end of each module
- Documentation: who completed which module and when
- Refreshers: annual or semi-annual updates
Formats and tools
- E-learning platforms (on-demand)
- In-person training or workshops
- Gamification elements (simulators, interactive scenarios)
- Awareness campaigns (weekly tips, posters, phishing simulations)
How to Implement IT Security Training in Your Practice
Here's a pragmatic roadmap for meeting the requirement:
Step 1: Analyze the status quo
- Create an overview of all staff, including their roles and IT access
- Conduct a risk analysis: where are the vulnerabilities (e.g., bring-your-own-device, remote work)
- Review existing training, policies, and documentation
Step 2: Develop a training concept
- Choose a training format (e-learning, in-person, hybrid)
- Define training content and mandatory modules
- Assign responsibility for planning, delivery, and documentation
- Calculate resources: time, cost, technical infrastructure
Step 3: Start implementation
- Communicate transparently with the team: what the training is for and what obligations exist
- Start with a basic module for all staff
- Set deadlines and reminders
- Build in feedback loops
Step 4: Monitoring and evidence
- Keep records of who completed which module and when
- Review the results (quizzes, tests)
- Document training processes in your compliance and data protection concept
- Build in refreshers and updates (e.g., in response to new threats)
Step 5: Integrate into the overall security concept
- Closely link training with technical measures (e.g., access controls, encryption)
- Have staff formally commit to training policies
- Embed IT security in your organizational framework (e.g., responsibilities, escalation paths)
Common Challenges and How to Overcome Them
- Resistance within the team: Some staff see training as a tedious obligation. Involve them early, explain the benefits, and use real-world examples.
- Lack of time: Plan time slots strategically, e.g., short daily sessions instead of full-day workshops.
- Technical implementation: A robust e-learning platform, like heyData's, can help. Pay attention to usability, user-friendliness, and tracking features.
- Sustainability: Knowledge fades without refreshers. Establish regular updates or mini-refreshers.
- Documentation: Documentation is mandatory. Automated reports and audit logs make this easier.
Outlook and Recommendation
The KBV policy sets a clear standard: IT security can no longer be an optional extra in medical practices. You must introduce training for all staff in any case. This is achievable even in small practices with simple means, and in large practices with sophisticated concepts.
In the long run, a professionally deployed learning management system (LMS), combined with awareness campaigns and technical measures, pays off. This helps you build a security culture that goes beyond the minimum requirement.
Next, you should:
- Sketch out a roadmap immediately (who, when, with what)
- Evaluate suitable training providers
- Start communicating with the team
Review technical infrastructure (e.g., tracking, platforms)
Conclusion
With the new KBV policy, IT security training becomes mandatory in medical practices. It becomes a pillar of an effective data protection and security concept. For you as a compliance officer or IT decision-maker, it's clear: you need to act. With a well-thought-out concept, traceable documentation, and suitable training formats, you can meet the requirements while sustainably strengthening your practice's cyber resilience.
FAQ
How often does security training need to be repeated in medical practices?
How often does security training need to be repeated in medical practices?
As good practice, you should schedule annual refreshers. In the event of new threats or incidents, an immediate update may also be necessary.
What happens if someone doesn't complete the security training?
What happens if someone doesn't complete the security training?
You should communicate clearly that training is mandatory. For refusal, you can provide for internal measures — in extreme cases, restrictions on IT access, where legally permissible.
Can I use external training providers?
Can I use external training providers?
Yes, external providers with proven expertise are often a good choice. Important: contractual data protection arrangements (e.g., data processing agreements) must be taken into account. We're happy to support you with this step with our lawyer-approved IT security trainings on our heyData platform.







