E-Health
Perspectives
Cloud
Security and digital progress
No digital sovereignty without the cloud
(c) Getty Images

By Markus Linnemann, Vice President Critical Infrastructures at secunet

Whether it’s electronic health records, e-prescriptions, AI-assisted diagnostics or data-driven research: the digitisation of the healthcare sector does not depend on individual applications. What matters is the infrastructure behind it. It must protect highly sensitive data, meet regulatory requirements, be reliably available and, at the same time, be user-friendly enough to ensure that digital processes are actually adopted in everyday healthcare. Cloud technology promises this efficiency and can now also provide the necessary level of security. This makes it a fundamental prerequisite for both digital sovereignty and digital progress in Germany and Europe.

For a long time, IT security was primarily seen as an obstacle to digitisation processes. This view is not only outdated, but has in fact been turned on its head: today, IT security is an enabler of digitisation. This is because the more critical processes, personal data and systems vital to public services are digitised, the more important trust in the technical foundation becomes. Without security, there is no acceptance. And without acceptance, there is no scalable digitisation.

A robust infrastructure is the basis

This trend is particularly evident in the current regulatory standards being established at EU level. For example, the NIS 2 Directive requires affected organisations to implement appropriate, proportionate and effective technical and organisational measures and to document them. The KRITIS Framework Act came into force on 17 March 2026 and further strengthens the digital and physical resilience of critical infrastructure. For companies and organisations, this means that information security can no longer be viewed as a purely operational task for IT. It is becoming an integral part of corporate governance.

Anyone operating digital services today must not only secure their systems, but also clarify responsibilities, assess risks, maintain records and design their infrastructure in such a way that it continues to function even under pressure. The most important piece of advice is therefore this: rather than starting with quick, isolated measures, one should begin by carrying out a structured assessment of the current situation.

  • What is the current state of information security?
  • Which requirements are already being met?
  • Where are the gaps?
  • Which systems are particularly critical?

This results in an implementation plan that sets priorities and directs investment effectively. Particularly in regulated sectors such as healthcare, energy supply and the public sector, a robust IT infrastructure is essential for meeting not only current but also future requirements reliably and efficiently, and for implementing innovations.

Markus Linnemann. Photo (c) secunet

Data protection is not at odds with innovation

In Germany, data protection in particular is often discussed as nothing more than an obstacle. This debate falls far short of the mark. There is no such thing as ‘one single form of data protection’, let alone ‘one single level of security’. What always matters is the specific need for protection. For European companies and public institutions, this is more than just a legal footnote: anyone processing sensitive data must know which laws the provider is subject to, what access options exist, and how control is secured both technically and organisationally. In short: health data, research data, administrative data and industrial process data have different requirements. The technical architecture must be tailored to this and strike the right balance between protection, usability and opportunities for innovation.

Digital sovereignty means control, not isolation

Sooner or later, this leads to the fundamental concept of digital sovereignty, because at its core, this is also about control: What data does an organisation wish to protect, and how? Who operates the infrastructure? Who can access the data? How transparent are the technologies and processes? And how free is the organisation to switch providers without becoming dependent on them?

Digital sovereignty does not mean building everything ourselves or ruling out international cooperation. It means retaining the ability to act. This includes open standards, interoperability, verifiable security mechanisms and the ability to operate critical processes in accordance with European legal and operational requirements. Governments, public authorities, critical infrastructure companies and healthcare organisations, in particular, should therefore choose providers that stand for reliability, stability, certifications and compliance with European data protection and security standards. Digital sovereignty is not created by a label, but through verifiable architecture and informed decisions.

The secure cloud is the biggest driver of innovation

No digital sovereignty without the cloud. This may sound paradoxical at first, as cloud technology is often associated with dependency due to existing reliance on US providers. In reality, however, it depends above all on the model. As with data protection, there is no such thing as ‘the one and only cloud’. Private, public, hybrid, multi-cloud and on-premises models offer different levels of freedom, protection mechanisms and operating models. It is crucial that organisations understand their level of protection and choose the appropriate infrastructure.

(c) Getty Images

This is particularly relevant for the healthcare sector, for example. Medical data must be given special protection; at the same time, research requires extensively available, structured and often anonymised or pseudonymised datasets. Digital applications such as e-prescriptions and electronic patient records demonstrate just how heavily healthcare provision will depend on secure infrastructure in future. According to gematik, e-prescriptions are now standard for prescription-only medicines; the ‘ePA for all’ initiative brings together relevant health data and is intended to make treatments more tailored to individual needs.

All of this makes the secure migration of local databases to the cloud one of the biggest drivers of medical innovation, as both the demand and the opportunities are enormous: one year after the launch of the ‘ePA for all’ scheme, gematik reported more than 100 million documents stored and up to 93,000 doctors’ and dentists’ practices accessing their patients’ ePAs on a weekly basis. Such volumes of data cannot be managed using siloed solutions. They require scalable, secure and traceable cloud and platform architectures.

Digitisation requires trust and must be simple

The key challenge therefore lies not only in the technology, but in the interaction of the entire IT ecosystem. Digitisation in healthcare can only succeed if many different stakeholders work together: healthcare providers, health insurers, industry, research organisations, platform providers, regulators and security service providers. Despite all the technological complexity, one point must not be lost sight of: digital systems will only be used if they work in everyday practice. Security must therefore be integrated in a smart and user-friendly way. It must not be pitted against efficiency, but must make processes simpler, more reliable and more robust. This applies to doctors as well as to patients, nursing staff, administrative staff and IT teams.

Cloud computing and AI will play a central role in this over the coming years: in the structured analysis of large volumes of data, in intelligent search, in automated documentation, in decision support and in diagnostics. All these applications can help to improve patient care, accelerate research and ease the workload on healthcare professionals. However, they require that the data set is trustworthy and that the infrastructure meets the necessary security requirements.

The future of healthcare will be digital. It will only be successful if it is built on secure, sovereign and trustworthy infrastructures.

Vice President Critical Infrastructures, secunet

As a provider of IT security and digitisation in highly regulated environments, secunet supports digital transformation in the healthcare sector, including in the areas of telematics infrastructure, telemedicine, medical technology and cloud-based healthcare platforms. For organisations subject to regulatory requirements, secunet also offers secure cloud solutions ‘Made in Germany’, ranging from public, private, hybrid and multi-cloud models to on-premises scenarios.

A sovereign cloud is not an end in itself

Digital sovereignty is not an abstract political term. It manifests itself quite concretely in the question of whether an organisation can control its data, operate its systems reliably, choose its providers freely and, in doing so, effectively drive innovation. In the healthcare sector in particular, this ability determines whether digitisation creates trust or gives rise to new dependencies.

Cloud technology is not a security issue, but rather a driver of innovation. It is what makes scalability, connectivity, AI integration and data-driven care possible in the first place. Or to put it another way: the future of healthcare will be digital. It will only be successful if it is built on secure, sovereign and trustworthy infrastructures.

Contact request

Do you have any questions or comments about this article? Then contact us using the contact form on the right.

Seite 1
Submit
* Required fields
Logo

secuview is the online magazine of secunet, Germany's leading cybersecurity company. Here you will find news, trends, viewpoints and background information from the world of cybersecurity for public authorities and companies. Whether cloud, IIoT, home office, eGovernment or autonomous driving - there can be no digitisation without security.

 

In addition to the online magazine, secuview is published twice a year as a journal, which you can subscribe to free of charge in printed form or download as a PDF.

secuview is the online magazine of secunet, Germany's leading cybersecurity company. Whether cloud, IIoT, home office, eGovernment or autonomous driving - there can be no digitisation without security.

© 2026 secunet Security Networks AG