Knowledge

ePA, FHIR and TI explained: what healthcare software projects need to know

The electronic patient record (ePA) is the central digital record of people with statutory health insurance in Germany, FHIR is the standard in which health data is exchanged in structured form, and the telematics infrastructure (TI) is the closed network of the German healthcare system over which this exchange runs. Anyone building software that processes health data will run into these three terms.

The three terms in brief

  • ePA (electronic patient record): the central digital record of people with statutory health insurance. Since the start of 2025 it is created automatically unless the insured person objects (opt-out). It holds, among other things, findings, doctors' letters and the medication list.
  • FHIR (Fast Healthcare Interoperability Resources): an international HL7 standard that organises health data into uniform building blocks — resources such as Patient, Observation or Medication — and makes them exchangeable over modern web interfaces (REST, JSON).
  • TI (telematics infrastructure): the closed, secured network of the German healthcare system, overseen by gematik. The ePA, the e-prescription and services such as KIM (secure communication between healthcare providers) all run over the TI.

Who is affected

  • Software vendors: providers of practice, hospital and pharmacy software have to integrate the TI applications into their products.
  • Health insurers: provide their members with the ePA and the associated apps.
  • Healthcare providers: practices, hospitals and pharmacies are connected to the TI and work with the ePA, e-prescription and KIM.
  • Providers handling health data: health SaaS, digital health applications and medtech products that want to exchange data with the health system in structured form sooner or later arrive at FHIR and TI.

What a connection means in practice

A TI or ePA connection is not an ordinary API onboarding. Depending on the role, products go through gematik's approval or confirmation procedures. Technically that means: implementing the relevant gematik specifications, mapping the required FHIR profiles correctly, integrating secure identities and authentication via the TI, and demonstrating the application in test and reference environments. It is doable, but it needs lead time and experience with the specifications.

Typical pitfalls

  • FHIR is a framework, not a finished product: what matters are the German profiles that define exactly what the resources must look like. Implementing only the base standard is not enough to connect.
  • Specifications change: gematik requirements evolve in stages. Version changes belong in the plan from the start.
  • Procedures need lead time: test, confirmation and approval steps take time — planning them only at the end of a project costs months.
  • Data protection from the start: health data is a special category under Art. 9 GDPR. Legal basis, encryption and permissions must be settled before you build, not after.

Our experience

Our team has worked on an ePA application and knows FHIR profiles, gematik specifications and the practical hurdles of a connection from project work. If you are planning a software project that processes health data or is to be connected to the TI, we discuss what your project specifically needs in an initial call.

FAQ

Frequently asked questions

What is the difference between ePA and TI?

The ePA is an application: the central patient record of the insured. The TI is the infrastructure beneath it — the closed network over which the ePA and further services such as the e-prescription run.

Does my software need to support FHIR?

As soon as it is to exchange data in structured form with the ePA or other TI services, effectively yes. FHIR is the defined standard; what matters are the German profiles that specify exactly what the data must look like.

Is the ePA mandatory for insured people?

It has been created automatically for people with statutory health insurance since the start of 2025, but they can object (opt-out) and control access.

Does appDev have experience with the ePA?

Our team has worked on an ePA application and knows the specifications and the steps of a connection from practice.

Planning a connection to ePA or TI?

Our team has worked on an ePA application. In an initial call we discuss what your project specifically needs.