Hacker News new | ask | show | jobs
by chekibreki 1337 days ago
tl;dr

To transfer patient data between doctors and (state) insurance companies, doctor‘s offices need to have a hardware VPN device. The system was implemented by the company „gematic“. A small number of companies produce these devices.

The certificates on these devices expire after five years. Now, instead of simply updating the certificates, the companies want the state and the doctors to buy new devices which costs around 400 million.

The CCC firstly explained that this is bullshit and a total waste of money and secondly showed that it is easy to update the devices. They could do it themselves but only need the private key from gematic.