Cybersecurity & Protection

Security Flaws in ePA Clients: Implementation Problems Despite Solid Specification

Sep 14, 2026 1 min read
All articles

In spring 2026, several open-source implementations for Germany's electronic patient record (ePA) were found to have security flaws in core protection mechanisms. Three independently developed clients were affected: fbeta's epa3-service, Oviva's epa4all-client, and Med United's epa4all (service health erx).

The Problem Was in the Implementation

The vulnerabilities were located in the cryptographic layer responsible for securing health data between the ePA client and the record system. As one of those involved put it: "The specification was good, the problems were in the implementation." This is a well-known pattern: well-documented standards don't automatically prevent implementation errors. Security researchers also found vulnerabilities in the Gematik Authenticator.

Constructive Response

Those involved praised the open and constructive way the reported vulnerabilities were handled. The affected projects have since released fixes. The incident underscores the importance of independent security audits for healthcare software components, particularly when highly sensitive data is at stake.