Skip to content

Successful for cash benefits

Digital Care Applications (DiPA)

With TÜVIT for reimbursable DiPA

If you want your digital nursing application (DiPA) to be officially included in the DiPA directory and therefore eligible for reimbursement, you must prove that your application fulfils certain IT security, data protection and data security requirements. With the right services, we can support you successfully on the way to obtaining health insurance coverage.

Successful provision of evidence

With the help of our services, you can prove that your DiPA fulfils the requirements set by the Federal Institute for Drugs and Medical Devices (BfArM).

Maximum protection for your application

Pentests, assessments and audits protect your DiPA against cyberattacks and data theft and prevent the associated damage.

Increased trust among users

By fulfilling the DiPA requirements, you strengthen the trust that users have in the security of your application.

What is the Digital Care Applications Regulation (DiPAV)?

The Digital Care Applications Ordinance (DiPAV) is an ordinance for assessing the reimbursability of digital care applications.

It contains requirements that must be met in order for an application to be included in the BfArM's directory for digital care applications (DiPA directory) and thus be eligible for reimbursement.

The necessary requirements relate in particular to the aspects of safety, functionality, quality and data protection and security.

Your benefits at a glance

Your DiPA: Secure. Approved. Future-proof.

Digital care applications (DiPA) must meet the highest safety and quality requirements in order to be recognised by the BfArM as a health insurance benefit. We support you in providing all the necessary evidence - for greater trust, safety and long-term success.

  • Providing evidence to the BfArM
    With us, you provide the necessary evidence so that your application can become a health insurance benefit.
  • Increased trust among users 
    By fulfilling the requirements, you strengthen the trust of people in need of care and carers in your application.
  • Long-term cost savings 
    Eliminating vulnerabilities can avoid long-term costs due to potential security incidents.
  • Identification of security vulnerabilities
    You uncover potential security vulnerabilities in your DIPA at an early stage, before others do.
  • Protection of sensitive patient data
    Pentests & data protection checks ensure the security of sensitive patient data in your DIPA.
  • Defence against cyber attacks, espionage etc.
    By fulfilling the DIPA requirements, you protect your application against external threats in the best possible way.
Basic information

What you should know in advance

Is your DiPA a medical device?

Whether your DiPA is a medical device is determined by the provisions of the Medical Device Regulation. The intended purpose specified by the manufacturer is decisive.

DiPA as a medical device

For DiPA, which are classified as medical devices, proof of safety and functional suitability is generally deemed to have been provided to the BfArM by a lawful CE declaration of conformity from the manufacturer.

DiPA as a non-medical device

DiPA, which are non-medical devices, must be designed in such a way that they fulfil the requirements for safety and functional suitability in accordance with Annex 1 DiPAV.

We will support you – no matter what

Get started at last!

We advise you


TÜV NORD IT Secure Communication I Berlin
Goal achieved?

We check that


TÜV Informationstechnik I Essen

Requirements for security and data protection in digital care applications (DiPA)

Code on a screen in close-up

Penetration tests

For the product version for which inclusion in the DiPA directory is sought, a penetration test must have been carried out for all components. The test should primarily be carried out by BSI-certified test centres and include manual code reviews and a whitebox test.

We carry out the corresponding tests to provide evidence and help you to identify and close potential security gaps.

More information
Eine Frau sitzt am Schreitische uns arbeitet mit einem Aktenorder

Proof of an ISMS

DiPA manufacturers must have a certificate for the implementation of an ISMS in accordance with ISO 27001 or "ISO 27001 based on IT baseline protection".

We offer audits and GAP analyses to help you fulfil important certification requirements.

More information
Zwei Frauen arbeiten an einem Schreibtisch mit einem Laptop vor ihnen.

Proof of data protection

Since 1 August 2024, proof of compliance with data protection requirements must be provided (in accordance with the KHPflEG). This takes the form of a certificate issued in accordance with Article 42 of the GDPR.

More information
Ein Mann mit Kopfhörern sitzt am Tisch vor dem Laptop und schreibt etwas in ein Notizbuch.

Proof of data security

From 01.01.2025, DiPAs must fulfil data security requirements in accordance with Section 8 (3) DiPAV. This is the case if certification has been obtained in accordance with the BSI Technical Guideline TR-03161 (Requirements for applications in the healthcare sector). Our IT security experts will check your DiPA in accordance with the requirements of BSI TR-03161 and support you on the path to successful certification.

More information
Eine medizinische Fachkraft und eine Patientin sitzen auf einer Couch und schauen auf ein Tablet.

Procedure for digital care applications according to DiPA guidelines

DiPA directory

Manufacturers can apply for inclusion in the DiPA directory if they have conducted a comparative study with their DiPA that demonstrates a nursing benefit. If the BfArM's review of the application is positive, the DiPA will be included no later than 3 months - in justified individual cases no later than 6 months - after the complete application has been submitted.

DiPA Guide

The BfArM has summarised all the details and information on the regulations and the application procedure in a comprehensive DiPA guide.

It is primarily aimed at manufacturers seeking inclusion in the DiPA directory, but is also of interest to users who would like to familiarise themselves with the assessment basis and the properties of a DiPA.

You can find the latest version of the guideline on the BfArM website.

To the guide

Why we are a strong partner for you

Good reasons that speak in our favour