Medical practice · § 203 StGB

Patient mail.Encrypted.No hurdle.

Patient communication and lab-result transfer outside mandatory KIM cases. § 203 StGB context, EU hosting, audit log per GDPR Art. 30. As of 2026.

At a glanceAs of 2026

Patient mail without an account and without forcing KIM.

  • Lab results via fax or unencrypted mailWeb reader or S/MIME, audit log included
  • Patient data sending as a manual risk stepSecureMail als Default direkt aus Outlook Classic, New oder Web
  • DICOM-Bildmaterial auf USB-Stick oder per WeTransfer an den überweisenden KollegenSecureFiles als direkte Linie für radiologische Befundpakete bis mehrere Gigabyte
Conbool ergänzt die Telematikinfrastruktur um den Alltagsbedarf, den KIM nicht abdeckt: Patient zu Praxis, Praxis zu Selbstzahler, Praxis zu PKV oder GKV außerhalb der Abrechnungsstrecke, Praxis zu Anwalt oder Gutachter, Praxis zu privater Verrechnungsstelle. Ende-zu-Ende-Verschlüsselung per S/MIME, OpenPGP oder Web-Reader für Empfänger ohne Zertifikat, EU-Hosting in Deutschland, Audit-Log pro Zugriff für die Praxisdokumentation. Die berufsrechtliche Schweigepflicht aus § 203 StGB wird technisch durch Ende-zu-Ende-Verschlüsselung und Zugriffsprotokollierung gestützt, die KBV-IT-Sicherheitsrichtlinie nach § 75b SGB V im E-Mail-Bereich abgedeckt.
Geeignet für Sie, wenn:Einzelpraxis bis MVZ mit 50 AerztenPVS-Stack: medatixx, CGM, RED, Doctolib, x.concept§ 203 StGB und DSGVO Art. 9
100 %
EU hosting
§ 203
StGB context
Audit
per access
30 min.
Setup per mailbox

Compliance anchors

§ 203 StGB medical confidentialityGDPR Art. 9 special categoriesGDPR Art. 32 securityKBV-IT-Sicherheitsrichtlinie nach § 75b SGB V

Conbool ersetzt nicht KIM, ePA, eRezept oder eAU und greift nicht in die Telematikinfrastruktur ein. Conbool deckt die Patienten- und Praxis-Kommunikation außerhalb der KIM-Pflichtfälle ab. § 203 StGB-Bezug gilt bei korrekter Konfiguration der Verschlüsselungs-Default-Regel und dokumentierter Mitarbeitendenschulung der MFA, MTRA und der angestellten Aerzte. Die berufsrechtliche Verantwortung verbleibt bei der Praxisleitung.

Four building blocks for practices and MVZ.

SecureMail for patient mail, SecureFiles for lab-result bundles, MailGuard against practice phishing, Disclaimer for required disclosures.

Typical workflows

Four scenarios from a working practice.

From patient to clinic and back.

1

Lab result to the patient

A patient without software receives the result via the web reader, no KIM account. Audit log records access and read time.

2

DICOM to the referring colleague

SecureFiles as a direct line for DICOM bundles beyond Outlook size limits.

3

Insurer query

Insurer queries containing patient data sent encrypted, with documented receipt.

4

Praxis-Phishing und gefälschte KV-Mails abfangen

MailGuard erkennt gefälschte Mails der Kassenärztlichen Vereinigung, der Landesärztekammer oder vermeintliche KIM-Störungsmeldungen mit Authentifizierungs-Anomalien, SPF-, DKIM- und DMARC-Brüchen sowie Lookalike-Domains. Die MFA an der M365-Anmeldung wird vor Credential-Phishing geschützt, bevor PVS-Zugänge und KV-Abrechnungsstrecken kompromittiert werden.

Architecture

Practice IT stays practice IT.

Conbool sits in front of Microsoft 365 or Exchange Online of the practice. Telematics infrastructure and practice management system remain unchanged.

MX switch

SMTP inbound runs through Conbool, M365 tenant remains the back-end.

KIM stays in parallel

Conbool does not replace KIM. Mandatory KIM cases continue through the telematics infrastructure.

Outlook add-in

Classic, New and Web. No setup on practice machines.

Koexistenz mit PVS-Herstellern

medatixx, CGM Albis, CGM Turbomed, RED medical, x.concept, Doctolib und vergleichbare PVS bleiben unverändert. Conbool koexistiert ausschließlich über Outlook und SMTP.

Compliance mapping

§ 203 StGB and GDPR Art. 9 in technical terms.

Patient data is a special category. Conbool delivers the protections from Art. 32 GDPR as a default.

End-to-end encryption

S/MIME, OpenPGP or web reader, depending on the recipient.

Audit log per GDPR Art. 30

Per patient contact: who, when, from where accessed.

DPA per GDPR Art. 28

Processing agreement with Conbool, sub-processor list in the DPA.

Aufbewahrungsfristen

Aufbewahrung gemäß § 630f BGB für die Patientenakte zehn Jahre, Röntgenverordnung bis zu dreißig Jahre, konfigurierbares Löschkonzept pro Mandant und pro Dokumentenklasse.

Migration

Pilot in one practice, then MVZ-wide.

One practice starts, the MVZ follows. No interaction with telematics.

Pilot in one practice

One practice tests, the rest remains unchanged.

MVZ rollout

Outlook add-in for all practices via the Microsoft admin centre.

KIM stays KIM

Mandatory cases like eAU and eRezept continue undisturbed.

Schulung des Praxispersonals

Empfehlungen für MFA-Schulung der MFA und MTRA, Briefkopf-Konsistenz, ICD-10-Diktion im Klartext-Header und QM-Dokumentation nach der Qualitätsmanagement-Richtlinie des Gemeinsamen Bundesausschusses enthalten.

Frequently asked questions

Does Conbool replace KIM?
No. KIM is the legally specified channel for mandated medical transmissions like eAU or eArztbrief. Conbool covers patient communication outside mandatory KIM cases and complements the telematics infrastructure.
How does this fit § 203 StGB?
Conbool supports medical confidentiality under § 203 StGB technically through encryption, EU hosting and audit log. Professional responsibility remains with the practice owner; correct configuration and staff training are prerequisites.
How do patients read our mail?
Patients receive a link to the web reader and read the message in a browser session, no account or software install required. For repeat recipients passwordless return kicks in for 12 months.
What does Conbool cost for practices?
Die Richtlinie der Kassenärztlichen Bundesvereinigung verlangt für Praxen je nach Praxisgröße organisatorische und technische Maßnahmen, abgestuft für Praxis, mittlere Praxis, große Praxis und Praxis mit medizinischen Großgeräten. Conbool adressiert den Bereich E-Mail-Sicherheit mit Verschlüsselung, Phishing-Schutz, Authentifizierungs-Prüfung und Empfangsnachweis. Die Anlage 1, 2 und 5 der Richtlinie zu Netzwerksicherheit, mobilen Datenträgern und Endgeräten bleibt Aufgabe der Praxis. Conbool liefert Nachweise für den E-Mail-Teil im KBV-Sicherheitscheck inklusive TOM-Dokumentation.
Wie steht es mit DICOM, Histologie und großen radiologischen Befundpaketen?
SecureFiles akzeptiert große Pakete ohne harte Größenbegrenzung pro Datei und ist auf radiologische, pathologische und endoskopische Workflows ausgelegt. Komplette DICOM-Studien, Histologie-Schnittbilder, OP-Berichte mit Bildmaterial, Endoskopie-Videos und Echokardiografie-Loops laufen direkt von Praxis zu Klinik, zum überweisenden Kollegen oder zum MDK. Der Empfänger lädt das Paket per signierten Link mit Ablauffrist und Hash-Prüfung, der Versand und Abruf bleiben im Audit-Log für das Praxis-QM und die Behandlungsdokumentation nach § 630f BGB dokumentiert.
Ist Conbool für MVZ und Praxisverbünde mit mehreren Standorten geeignet?
Ja. Conbool skaliert pro Postfach und ist für MVZ-Träger, überregionale Praxisverbünde, BAG- und Gemeinschaftspraxen sowie KV-übergreifende Strukturen vorgesehen. Es gibt zwei Architektur-Optionen: ein zentraler Tenant für den MVZ-Träger mit getrennten Domains pro Praxisstandort, oder getrennte Tenants je Praxis mit zentraler Schlüsselverwaltung beim Träger. Disclaimer-Pflichtangaben werden pro angestellten Arzt mit lebenslanger Arztnummer, KV-Bezirk, LANR und BSNR aus dem Active Directory gepflegt.
Wie läuft die Koexistenz mit Praxisverwaltungssystemen wie medatixx, CGM oder RED?
Conbool koexistiert mit den gängigen PVS-Herstellern, weil ausschließlich über Outlook und Standard-SMTP gearbeitet wird. medatixx, CGM Albis, CGM Turbomed, CGM M1 PRO, RED medical, x.concept, Doctolib, jameda und vergleichbare PVS bleiben unverändert. Es gibt keinen Eingriff in den TI-Konnektor, keine Veränderung am KIM-Clientmodul und keine Anpassung der HBA- oder SMC-B-Strecke. Der Befundimport ins PVS bleibt wie bisher manuell durch die MFA oder per KIM-Eingang. Conbool-Mails können über Outlook in die PVS-Akte des Patienten archiviert werden, sofern das PVS Outlook-Anbindung unterstützt.

Verwandte Lösungen

Verwandte Branchen

Conbool ist in benachbarten Branchen mit ähnlichem Compliance-Profil im Einsatz.

Patient mail encrypted, with no hurdle for the patient.

Demo in 30 minutes. Pilot in one practice. Modular by function.

Sources and date

Statements about § 203 StGB are based on the respective German statute in force. Statements about GDPR are based on Regulation (EU) 2016/679, in particular Art. 9 and Art. 32. Statements about KIM are based on the gematik specifications in their respective version. As of 2026.

KIM and ePA are designations of gematik GmbH. Microsoft, Microsoft 365 and Outlook are trademarks of Microsoft Corporation. Conbool is a trademark of Conbool GmbH.