Patient mail.Encrypted.No hurdle.
Patient communication and lab-result transfer outside mandatory KIM cases. § 203 StGB context, EU hosting, audit log per GDPR Art. 30. As of 2026.
Patient mail without an account and without forcing KIM.
- Lab results via fax or unencrypted mailWeb reader or S/MIME, audit log included
- Patient data sending as a manual risk stepSecureMail als Default direkt aus Outlook Classic, New oder Web
- DICOM-Bildmaterial auf USB-Stick oder per WeTransfer an den überweisenden KollegenSecureFiles als direkte Linie für radiologische Befundpakete bis mehrere Gigabyte
Compliance anchors
Conbool ersetzt nicht KIM, ePA, eRezept oder eAU und greift nicht in die Telematikinfrastruktur ein. Conbool deckt die Patienten- und Praxis-Kommunikation außerhalb der KIM-Pflichtfälle ab. § 203 StGB-Bezug gilt bei korrekter Konfiguration der Verschlüsselungs-Default-Regel und dokumentierter Mitarbeitendenschulung der MFA, MTRA und der angestellten Aerzte. Die berufsrechtliche Verantwortung verbleibt bei der Praxisleitung.
Four building blocks for practices and MVZ.
SecureMail for patient mail, SecureFiles for lab-result bundles, MailGuard against practice phishing, Disclaimer for required disclosures.
SecureMail
S/MIME, OpenPGP or web reader for patients without software. Outlook add-in for the practice.
SecureMail in detailSecureFilesSecureFiles
DICOM and lab-result bundles as a direct line between practice and GP or hospital.
SecureFiles im DetailMailGuardMailGuard
Erkennt gefälschte KV-, KBV-, Aerztekammer- und Krankenkassen-Mails, Business-Email-Compromise gegen die Praxisverwaltung sowie Credential-Phishing gegen die Microsoft-365-Anmeldung. Mehrstufige Prüfung auf SPF, DKIM, DMARC, Header-Anomalien, Lookalike-Domains und Anhangsfilter mit CDR vor dem Eingang in den M365-Tenant.
MailGuard im DetailDisclaimerDisclaimer
Server-seitige Pflichtangaben für Praxisinhaber, MVZ-Geschäftsführung und angestellte Aerzte. Heilberufsrechtliche Angaben nach Berufsordnung der Landesärztekammer, lebenslange Arztnummer (LANR), Betriebsstättennummer (BSNR), KV-Bezirk und Aerztekammer werden zentral aus dem Active Directory gepflegt und in jede ausgehende E-Mail eingesetzt.
Disclaimer im DetailFour scenarios from a working practice.
From patient to clinic and back.
Lab result to the patient
A patient without software receives the result via the web reader, no KIM account. Audit log records access and read time.
DICOM to the referring colleague
SecureFiles as a direct line for DICOM bundles beyond Outlook size limits.
Insurer query
Insurer queries containing patient data sent encrypted, with documented receipt.
Praxis-Phishing und gefälschte KV-Mails abfangen
MailGuard erkennt gefälschte Mails der Kassenärztlichen Vereinigung, der Landesärztekammer oder vermeintliche KIM-Störungsmeldungen mit Authentifizierungs-Anomalien, SPF-, DKIM- und DMARC-Brüchen sowie Lookalike-Domains. Die MFA an der M365-Anmeldung wird vor Credential-Phishing geschützt, bevor PVS-Zugänge und KV-Abrechnungsstrecken kompromittiert werden.
Practice IT stays practice IT.
Conbool sits in front of Microsoft 365 or Exchange Online of the practice. Telematics infrastructure and practice management system remain unchanged.
MX switch
SMTP inbound runs through Conbool, M365 tenant remains the back-end.
KIM stays in parallel
Conbool does not replace KIM. Mandatory KIM cases continue through the telematics infrastructure.
Outlook add-in
Classic, New and Web. No setup on practice machines.
Koexistenz mit PVS-Herstellern
medatixx, CGM Albis, CGM Turbomed, RED medical, x.concept, Doctolib und vergleichbare PVS bleiben unverändert. Conbool koexistiert ausschließlich über Outlook und SMTP.
§ 203 StGB and GDPR Art. 9 in technical terms.
Patient data is a special category. Conbool delivers the protections from Art. 32 GDPR as a default.
End-to-end encryption
S/MIME, OpenPGP or web reader, depending on the recipient.
Audit log per GDPR Art. 30
Per patient contact: who, when, from where accessed.
DPA per GDPR Art. 28
Processing agreement with Conbool, sub-processor list in the DPA.
Aufbewahrungsfristen
Aufbewahrung gemäß § 630f BGB für die Patientenakte zehn Jahre, Röntgenverordnung bis zu dreißig Jahre, konfigurierbares Löschkonzept pro Mandant und pro Dokumentenklasse.
Pilot in one practice, then MVZ-wide.
One practice starts, the MVZ follows. No interaction with telematics.
Pilot in one practice
One practice tests, the rest remains unchanged.
MVZ rollout
Outlook add-in for all practices via the Microsoft admin centre.
KIM stays KIM
Mandatory cases like eAU and eRezept continue undisturbed.
Schulung des Praxispersonals
Empfehlungen für MFA-Schulung der MFA und MTRA, Briefkopf-Konsistenz, ICD-10-Diktion im Klartext-Header und QM-Dokumentation nach der Qualitätsmanagement-Richtlinie des Gemeinsamen Bundesausschusses enthalten.
Frequently asked questions
Does Conbool replace KIM?
How does this fit § 203 StGB?
How do patients read our mail?
What does Conbool cost for practices?
Wie steht es mit DICOM, Histologie und großen radiologischen Befundpaketen?
Ist Conbool für MVZ und Praxisverbünde mit mehreren Standorten geeignet?
Wie läuft die Koexistenz mit Praxisverwaltungssystemen wie medatixx, CGM oder RED?
Verwandte Lösungen
NIS2 im Überblick
Richtlinie, Umsetzungsgesetz und BSIG: wer betroffen ist und was gilt.
SEPPmail-Alternative
SaaS-SecureMail aus der EU, ohne Appliance-Pflege.
NIS-2 E-Mail-Verschlüsselung
S/MIME, PGP und Domain-Verschlüsselung nach NIS-2 angemessen.
NIS-2 E-Mail-Sicherheit
NIS-2-konforme E-Mail-Sicherheit mit Audit-Trail.
PDF-Verschlüsselung
Sensible PDFs verschlüsselt versenden, ohne Empfänger-Konto.
Secure Message Portal
Empfänger-Web-Reader für Schlüssel-lose Empfänger.
Verschlüsselung für Thunderbird
Ohne Add-on und ohne Zertifikate auf den Endgeräten.
Verwandte Branchen
Conbool ist in benachbarten Branchen mit ähnlichem Compliance-Profil im Einsatz.
Patient mail encrypted, with no hurdle for the patient.
Demo in 30 minutes. Pilot in one practice. Modular by function.
Sources and date
Statements about § 203 StGB are based on the respective German statute in force. Statements about GDPR are based on Regulation (EU) 2016/679, in particular Art. 9 and Art. 32. Statements about KIM are based on the gematik specifications in their respective version. As of 2026.
KIM and ePA are designations of gematik GmbH. Microsoft, Microsoft 365 and Outlook are trademarks of Microsoft Corporation. Conbool is a trademark of Conbool GmbH.