Digital health application: The app on prescription

This is an opportunity for you to advance digital healthcare, expand your portfolio, and gain access to a reimbursement pathway that is unique on an international scale. This is because, under the Digital Healthcare Act (DVG), individuals with public health insurance are now entitled to DiGA services, which can be prescribed by doctors and psychotherapists and reimbursed by health insurance providers. Alternatively, patients can apply for reimbursement for a DiGA directly through their health insurance provider.

What does DiGA support?

DiGAs provide support in areas such as the treatment of diseases and the management of medical conditions, and, as of the latest update, may also include telemedicine services. They can take the form of a smartphone app or a web application for a browser.

However, before entering the market, the Federal Institute for Drugs and Medical Devices (BfArM) checks whether a DiGA meets all the requirements. Read our blog post to find out more about the six facts that manufacturers should be aware of.

Would you like to bring a DiGA to the market?

Inclusion in the DiGA directory by the Federal Institute for Drugs and Medical Devices is granted if your DiGA meets all requirements, including safety, suitability for use, quality, medical benefit, data protection and data security.

The pathway of a Digital Health Application until its inclusion in the DiGA Directory (BfArM) looks like this:

Characteristics of a DiGA:
DiGA meets requirements for:
ensures positive supply effects:
DiGA meets requirements for:
No exclusion of DiGA according to:

Medical device

main function based on digital technology

purpose of use is health-related

low risk potential (class I, IIa or IIb)

security

Suitability for use and quality of the medical device

details according to DiGAV

medical benefit

or

patient-relevant improvement of structure and processes

(studies may be required)

details according to DiGAV

Data protection

and

Data security

details according to DiGAV

chapter 3 SGB V

or

negative decision by the G-BA

A medical (or psychotherapeutic) prescription or approval from the health insurance provider

The positive supply effect

The positive care effect of digital health applications

Medical benefit

  • Improvement in the state of health
  • Reducing the duration of illness
  • Prolonging survival
  • Improving the quality of life

Patient-relevant improvement of structure and processes (among other things):

  • Coordination of treatment procedures
  • Easier access to healthcare
  • Patient safety
  • Developing health literacy

The requirements and development of DiGA

Functionality and safety

According to §3 Abs. 1 DiGAV, proof of compliance with the safety and functionality requirements is deemed to have been provided by the CE marking.

Data protection and data security

Manufacturers meet data protection and security requirements through a self-declaration

  • The declaration is based on Annex 1 of the DiGAV
  • BSI Standard 200-1, 200-2 and 200-3 provide instructions
  • Introduction of a complete ISMS in accordance with ISO 27001
  • BfArM does not check for compliance with data law (risk of incorrect assessment)
Interoperability

Exchange of data via networks in a specific format; electronic patient file (ePA) is the central data hub

  • Export in human-readable and printable form
  • Export in machine-readable, interoperable format
  • Hardware connectivity (sensor) – use of an interoperable interface
User-friendliness and accessibility

Verification of user-friendliness for the intended groups (also for digitally untrained persons); accessibility: All DiGA listed in the directory must be either:

  • include assistance for people with disabilities or
  • support operating aids offered by the platform (support for every form of disability – hearing, vision, motor skills)

Penetration Testing in the Development of DiGA

With the entry into force of the DVPMG, penetration tests are no longer required only for DiGA applications with increased security needs, but are now mandatory for all DiGA applications. The goal of penetration tests is to identify security vulnerabilities at an early stage and ensure a high level of data security. We are happy to assist you in developing the test plan in accordance with the BSI’s implementation guidelines for penetration tests and taking into account the current OWASP Top 10 security risks. To ensure the tests are conducted independently, all penetration tests are performed by our BAYOOTEC experts.

Do you have an idea for a digital health application?

We understand the regulatory requirements involved in the development and approval of DiGA. From interoperability to data protection and cybersecurity—BAYOOMED’s experienced team works with you to develop and implement your DiGA.

Standard features such as onboarding, DiGA code validation, a diary, connectivity, as well as modules for patient information and interoperability are already part of the MedicalOne Connect platform —thereby shortening the development time to market.

Miriam Schulze, CEO BAYOOMED

Miriam Schulze
CEO 

Successfully Launch Your DiGA

Drawing on our experience from numerous DiGA projects, we’ll guide you not only through the regulatory requirements for safety, data protection, and medical benefit, but also through a smooth technical implementation—from the initial idea to inclusion in the DiGA directory.

What do you envision for your DiGA? Tell us about your project—together, we’ll find the fastest path to a reimbursable application.

Contact Form

Preferred contact method
Data protection notice *