Digital health application: The app on prescription
This is an opportunity for you to advance digital healthcare, expand your portfolio, and gain access to a reimbursement pathway that is unique on an international scale. This is because, under the Digital Healthcare Act (DVG), individuals with public health insurance are now entitled to DiGA services, which can be prescribed by doctors and psychotherapists and reimbursed by health insurance providers. Alternatively, patients can apply for reimbursement for a DiGA directly through their health insurance provider.
What does DiGA support?
DiGAs provide support in areas such as the treatment of diseases and the management of medical conditions, and, as of the latest update, may also include telemedicine services. They can take the form of a smartphone app or a web application for a browser.
However, before entering the market, the Federal Institute for Drugs and Medical Devices (BfArM) checks whether a DiGA meets all the requirements. Read our blog post to find out more about the six facts that manufacturers should be aware of.
Would you like to bring a DiGA to the market?
Inclusion in the DiGA directory by the Federal Institute for Drugs and Medical Devices is granted if your DiGA meets all requirements, including safety, suitability for use, quality, medical benefit, data protection and data security.
The pathway of a Digital Health Application until its inclusion in the DiGA Directory (BfArM) looks like this:
The positive supply effect
The positive care effect of digital health applications
Medical benefit
- Improvement in the state of health
- Reducing the duration of illness
- Prolonging survival
- Improving the quality of life
Patient-relevant improvement of structure and processes (among other things):
- Coordination of treatment procedures
- Easier access to healthcare
- Patient safety
- Developing health literacy
The requirements and development of DiGA
According to §3 Abs. 1 DiGAV, proof of compliance with the safety and functionality requirements is deemed to have been provided by the CE marking.
Manufacturers meet data protection and security requirements through a self-declaration
- The declaration is based on Annex 1 of the DiGAV
- BSI Standard 200-1, 200-2 and 200-3 provide instructions
- Introduction of a complete ISMS in accordance with ISO 27001
- BfArM does not check for compliance with data law (risk of incorrect assessment)
Exchange of data via networks in a specific format; electronic patient file (ePA) is the central data hub
- Export in human-readable and printable form
- Export in machine-readable, interoperable format
- Hardware connectivity (sensor) – use of an interoperable interface
Verification of user-friendliness for the intended groups (also for digitally untrained persons); accessibility: All DiGA listed in the directory must be either:
- include assistance for people with disabilities or
- support operating aids offered by the platform (support for every form of disability – hearing, vision, motor skills)
Penetration Testing in the Development of DiGA
With the entry into force of the DVPMG, penetration tests are no longer required only for DiGA applications with increased security needs, but are now mandatory for all DiGA applications. The goal of penetration tests is to identify security vulnerabilities at an early stage and ensure a high level of data security. We are happy to assist you in developing the test plan in accordance with the BSI’s implementation guidelines for penetration tests and taking into account the current OWASP Top 10 security risks. To ensure the tests are conducted independently, all penetration tests are performed by our BAYOOTEC experts.
Do you have an idea for a digital health application?
We understand the regulatory requirements involved in the development and approval of DiGA. From interoperability to data protection and cybersecurity—BAYOOMED’s experienced team works with you to develop and implement your DiGA.
Standard features such as onboarding, DiGA code validation, a diary, connectivity, as well as modules for patient information and interoperability are already part of the MedicalOne Connect platform —thereby shortening the development time to market.















