Data protection

Patient data does not leave your practice

MediPulse works with billing data, not with patients. What reaches our servers is a practice-internal number and the line attached to it — no name, no date of birth, no address. A legal opinion confirms that, from our perspective, this data is anonymous.

Only a number

The only patient field transferred is the practice-internal ID. It can be resolved inside your practice management system and nowhere else.

Read-only

The connector on your practice server reads from the database. It never writes back and changes nothing in your data.

Germany only

Storage and processing take place exclusively in German data centers. No third-country transfers, no support access from outside.

How the data flows

  1. 1

    The connector reads

    The MediPulse connector runs on your practice server. It accesses the database of your practice management system (PVS) with read-only rights and never writes back. Your administrator installs it.

  2. 2

    The data is pseudonymized

    Everything that names a patient is stripped while still on your server. What remains is a practice-internal ID and the billing line attached to it.

  3. 3

    The transfer

    The export travels to MediPulse over an authenticated, SSL-encrypted connection. No personal patient data leaves your practice network.

  4. 4

    The analysis

    In the MediPulse cloud this becomes key figures for revenue, cost, and liquidity. Storage is AES-256 encrypted, exclusively in data centers in Germany.

What is transferred — and what is not

The complete field list, not an excerpt. Anything not listed here is not exported.

Transferred

Location
Practice-internal ID, practice name, BSNR
Provider
Practice-internal ID, title, first and last name, LANR
Patient
The practice-internal ID and nothing else
Case
Billing type, invoice number, start, end, and invoice date
Service
Date, billing code, billing type, point values, cents, factors, tariff, material cost, quantity, percentage

Physician names are transferred: without them no physician-level analysis would be possible. The legal basis is Art. 88 GDPR in conjunction with Sec. 26 (1) sentence 1 BDSG.

Stays in the practice

  • First and last name
  • Date of birth
  • Address
  • Phone number and email address
  • Health insurance number
  • Health insurer
  • The table that maps an ID to a patient

Why the data cannot be traced back

No key is transferred

The export pulls the practice-internal ID and nothing more. The table that maps this ID to a patient stays in the practice management system.

No key is created here

Because no identifying attributes arrive, there is no basis from which a mapping could be reconstructed after the fact.

The ID carries no meaning

It is specific to your practice and cannot be referenced outside your system. Without that context it stays unresolvable.

Re-identification is therefore not merely prohibited but technically impossible: the data it would require never leaves your practice network.

External reviewKWM LAW

A legal opinion, not our own assessment

The lawfulness of MediPulse under data protection law has been reviewed by KWM LAW PartG mbB, a law firm specializing in medical law. The opinion dated October 14, 2025 (file no. 10086/25) reaches two conclusions.

On patient data

The pseudonymization is demonstrably effective and re-identification is ruled out in practice. The decisive point is that MediPulse does not hold the key. The opinion relies on the judgment of the Court of Justice of the European Union of September 4, 2025 (case C-413/23 P), under which pseudonymized data is not personal data in every case but must be assessed from the perspective of the specific processor. Conclusion: from the perspective of MediPulse, the data is anonymous.

On employee data

Here the GDPR does apply, and here too the opinion finds no concerns: MediPulse processes billing data that already exists and creates no new records from it. In particular, no employee profiles are built, which would generally be unlawful under Art. 22 (1) GDPR. Processing stays limited to what the purpose requires.

The bank connection does not run through us

A supervised provider

finAPI

You connect your accounts through finAPI, an account information service licensed and supervised by BaFin, the German financial regulator, using your bank's PSD2 interface.

  • You decide which accounts are connected.
  • You set up the connection yourself.
  • You can delete it yourself at any time.

What is processed from a transaction

Booking date, amount, account IBAN, name and IBAN of the counterparty, payment reference.

This is what makes the cross-check against billing possible: what has been invoiced, what has actually arrived, where liquidity stands today.

What your data is used for — and what it is not

Benchmarks only as a group

Your figures do feed into benchmarks, but only aggregated across a group of practices. No single practice can be traced within them, and no other practice sees your values. This is also stated as a purpose in Annex 1 of the data processing agreement.

No access without your consent

Nobody at MediPulse has access to your data. If support needs to look into a fault, that happens only after you agree — not as silent standing access.

No sharing with third parties

Your data is not sold, not rented out, and not analyzed for advertising. The only parties involved are the two service providers that make operation and the bank connection possible.

Who sees what in your practice

Not every role needs every figure. Access is tiered.

Practice owner

Full access to all functions and data.

Physician

Restricted access to the physician-level view.

Administration

Access to the administrative functions.

Technical and organizational measures

Contractually agreed as Annex 2 of the data processing agreement (Auftragsverarbeitungsvertrag, in German), not as a statement of intent.

Physical access control

Rooms where data is processed are restricted to authorized persons by locking systems, access cards, and monitoring.

System access control

Individual user accounts, strict password policies, and multi-factor authentication.

Data access control

Access rights follow the need-to-know principle and are reviewed regularly.

Separation control

Data processed for different purposes is separated logically and physically, with its own authorization concepts.

Transfer control

Transmission only over secured, encrypted connections. Data transfers are logged.

Input control

Entry, modification, and deletion are logged in an audit-proof way and reviewed regularly.

Added to this is pseudonymization under Art. 32 (1) (a) and Art. 25 (1) GDPR, plus a procedure for regular review: internal audits, security assessments, and penetration tests. Our servers run in data centers certified to ISO 27001 and attested under the BSI C5 catalogue.

Who we rely on — and what binds them

Two service providers take part in the processing: the data center in Germany where our servers run, and finAPI for the bank connection. Both are sub-processors within the meaning of Art. 28 GDPR, and the data processing agreement binds them closely.

  • Every sub-processor is bound in writing to the same obligations we owe you.
  • Your audit rights apply to them directly as well.
  • We verify compliance at least once a year and document the result.
  • We are liable for a sub-processor's fault as for our own.
  • We inform you in good time before any change, and you may object.

How long we keep your data

Retention only for as long as the purpose requires (Art. 5 (1) (e) GDPR). Specifically:

Billing and service data
For the term of the contract. The time series is the purpose here — a multi-year comparison needs the earlier years.
Transaction data from the connected accounts
For the term of the contract.
After the contract ends
Return or complete, irreversible deletion within 30 days.
Backups
30 days, then overwritten. A deletion takes effect there at the latest once that period has passed.
Logs and telemetry
90 days.

A common misunderstanding: the ten-year retention period under Sec. 147 of the German Fiscal Code applies to your practice as the controller, not to MediPulse as the processor. Your tax-relevant records stay in the practice management system and in your accounting — where the period applies.

What is contractually guaranteed

Before the connection is set up, we conclude a data processing agreement (Auftragsverarbeitungsvertrag, in German) under Art. 28 GDPR. It forms Annex 1 of the terms and conditions and runs as long as the main contract. The substance is set out here so you do not have to search the document for it — the numbers in brackets point to the clause.

Bound by your instructions

  • MediPulse processes your data solely on your behalf and according to your instructions (2.1).
  • If a law compels different processing, we tell you before processing — unless that law prohibits the notice (2.1).
  • You may issue further instructions on the nature, scope, purpose, and means at any time; material instructions are documented (2.3).
  • If we consider an instruction unlawful, we tell you and may suspend it with 14 days' notice until you confirm or change it (2.4).

Confidentiality

  • Everyone at MediPulse who processes your data is bound to confidentiality (3.1).
  • They process your data only on instruction, never on their own initiative (3.2).
  • This is secured under employment law through confidentiality agreements (terms and conditions, section 9).
  • The obligation extends to cooperation partners (terms and conditions, section 9).

Rights of your patients and staff

  • We support you with technical and organizational measures in answering requests from data subjects (6.1).
  • If a data subject approaches us directly, we inform you without delay (6.2).
  • On request we hand over all processing information you need for your answer and do not hold yourself (6.2).

Notification duties

  • We report any breach of the protection of your data without delay once we become aware of it (7.1).
  • The report describes the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken (7.1).
  • If you have to inform the supervisory authority or data subjects under Art. 33 and 34 GDPR, we support you (7.2).
  • We also support you with a data protection impact assessment and any subsequent consultation of the supervisory authority under Art. 35 and 36 GDPR (7.3).

Deletion and return

  • When the contract ends, or at any time on your request, we return all documents, data, and media or delete them completely and irreversibly (8).
  • The only exception is a statutory retention period (8).
  • If a patient objects to storage, we return the data to you (8).
  • Processing ends when the main contract or this agreement is terminated; in case of doubt, terminating one counts as terminating the other (2.5).

Evidence and audits

  • We check regularly ourselves that processing matches the agreement, the agreed scope, and your instructions (9.1).
  • We document the implementation and present the evidence to you on request (9.2).
  • You may audit before processing begins and regularly thereafter — yourself or through an auditor you appoint (9.2).
  • We enable those audits and contribute to them with all reasonable measures (9.2).

Art. 82 DSGVO

Liability follows Art. 82 GDPR (10.1). A party is released from it only by proving that it bears no responsibility whatsoever for the circumstance that caused the damage — and in the case of a fine, correspondingly to the share of responsibility (10.2).

What this leaves with you

  • Use strong passwords and do not share access credentials (terms and conditions, section 8).
  • Keep credentials protected from third-party access; you are responsible for actions third parties take with your credentials (terms and conditions, section 8).
  • Report any suspected unauthorized access to us immediately — we block accounts on unusual usage patterns (terms and conditions, section 8).
  • Maintain the system requirements so a new version can be deployed at any time (terms and conditions, section 10).

The connector on your server

Your administrator installs it, either by remote access or independently with our guidance. Updates run automatically, are signed, and are checked for integrity before installation; a rollback mechanism is in place. Report faults to support@medipulse.de; response and resolution times are set out in sections 12 and 13 of the terms and conditions.

What the connector needs on your network

Outbound only

The connector opens every connection itself, TLS encrypted. Your firewall needs no inbound rule from the internet — not even when MediPulse triggers an update.

The database stays local

The connector runs on the same server as your practice management system's database and reads it through the local interface. No firewall rule is needed for the database connection.

Non-standard installations

If the database sits on a different server, or the installation deviates from the vendor's standard, our support configures the connection individually. Your IT provider receives the full network requirements in writing before setup.

The documents themselves

Do you have a data protection officer who wants to look closer? We provide the legal opinion and the full data protection documentation on request.

FAQ

Frequently asked questions

Does our firewall need to allow an inbound connection?

No. The connector opens every connection itself, TLS encrypted. No inbound rule from the internet is required. It reads the database locally on the same server, which needs no firewall rule either.

Am I even allowed to involve an external service provider as a physician?

No patient confidentiality is disclosed to MediPulse: only the practice-internal identifier is transferred, and MediPulse does not hold the key to it. In addition, everyone at MediPulse who processes your data is bound to confidentiality under employment law. We provide the legal opinion and the full data protection documentation to your data protection officer on request.

How long is my data stored?

Billing, service, and transaction data for the term of the contract, because the multi-year comparison needs the earlier years. When the contract ends, data is returned or deleted completely and irreversibly within 30 days. Backups are kept for 30 days, logs and telemetry for 90 days.

Can other practices see my figures?

No. Your figures feed into benchmarks, but only aggregated across a group of practices and without any way to trace them back to a single practice. No other practice sees your values.

Can anyone at MediPulse look into my data?

No. There is no access to your data. If support needs to look into a fault, that happens only after you agree.

Does patient data leave the practice once MediPulse is connected?

No. The only patient field transferred is a practice-internal ID, together with the billing line. Name, date of birth, address, contact details, and insurance data stay in the practice management system, as does the table that maps an ID to a patient.

Can MediPulse map the data back to individual patients?

No. MediPulse does not hold the key: the mapping table never leaves the practice network, and no identifying attributes are transferred from which a mapping could be reconstructed.

Can MediPulse change data in my practice management system?

No. The MediPulse connector accesses the database of the practice management system with read-only rights.

Where is the data stored?

Exclusively in data centers in Germany, certified to ISO 27001 and attested under the BSI C5 catalogue. No personal data is transferred to third countries outside the EU or the EEA, and there is no support access from third countries.

How is the bank connection secured?

Through finAPI, an account information service licensed and supervised by BaFin, using your bank's PSD2 interface. You connect the accounts yourself, decide which ones, and can delete the connection yourself at any time.

See for yourself in a demo which data arrives — and which does not.

Try MediPulse with no obligation and see how data and automation give you your time back.