Patient data stays in the practice, your account stays yours
MediPulse reads two sources: the billing data from your practice management system and the transactions on your practice accounts. From the practice comes a practice-internal number and the line attached to it — no name, no date of birth, no address. From the account come only records of transactions that have already happened; we cannot dispose of anything. A legal opinion confirms that, from our perspective, the practice data is anonymous.
Only a number
The only patient field transferred is the practice-internal ID. It can be resolved inside your practice management system and nowhere else.
Read-only
The connector on your practice server reads from the database. It never writes back and changes nothing in your data.
No disposal
From the account we receive only information about transactions. No credentials are held here, and no payment can be initiated through MediPulse.
Germany only
Storage and processing take place exclusively in German data centers. No third-country transfers, no support access from outside.
- GDPR compliant
- Servers exclusively in Germany
- Data centers certified to ISO 27001
- Data centers attested under BSI C5

- Bank connection via finAPI, BaFin licensed

The setup at a glance
Two sources, one destination — and in both cases only one direction of reading.
In your practice
- Practice server with the practice management system
- MediPulse connector: reads, never writes
- Pseudonymization before anything is sent
Your bank accounts
- Your bank's PSD2 interface, via finAPI
- Sign-in directly with your bank
- No credentials held by MediPulse
MediPulse
- Data centers in Germany
- Stored with AES-256
- No third-country transfers
How the data flows
- 1
The connector reads
The MediPulse connector runs on your practice server. It accesses the database of your practice management system (PVS) with read-only rights and never writes back. Your administrator installs it.
- 2
The data is pseudonymized
Everything that names a patient is stripped while still on your server. What remains is a practice-internal ID and the billing line attached to it.
- 3
The transfer
The export travels to MediPulse over an authenticated, SSL-encrypted connection. No personal patient data leaves your practice network.
- 4
The analysis
In the MediPulse cloud this becomes key figures for revenue, cost, and liquidity. Storage is AES-256 encrypted, exclusively in data centers in Germany.
What is transferred — and what is not
The complete field list, not an excerpt. Anything not listed here is not exported.
Transferred
- Location
- Practice-internal ID, practice name, BSNR
- Provider
- Practice-internal ID, title, first and last name, LANR
- Patient
- The practice-internal ID and nothing else
- Case
- Billing type, invoice number, start, end, and invoice date
- Service
- Date, billing code, billing type, point values, cents, factors, tariff, material cost, quantity, percentage
Physician names are transferred: without them no physician-level analysis would be possible. The legal basis is Art. 88 GDPR in conjunction with Sec. 26 (1) sentence 1 BDSG.
Stays in the practice
- First and last name
- Date of birth
- Address
- Phone number and email address
- Health insurance number
- Health insurer
- The table that maps an ID to a patient
Why the data cannot be traced back
No key is transferred
The export pulls the practice-internal ID and nothing more. The table that maps this ID to a patient stays in the practice management system.
No key is created here
Because no identifying attributes arrive, there is no basis from which a mapping could be reconstructed after the fact.
The ID carries no meaning
It is specific to your practice and cannot be referenced outside your system. Without that context it stays unresolvable.
Re-identification is therefore not merely prohibited but technically impossible: the data it would require never leaves your practice network.

A legal opinion, not our own assessment
The lawfulness of MediPulse under data protection law has been reviewed by KWM LAW PartG mbB, a law firm specializing in medical law. The opinion dated October 14, 2025 (file no. 10086/25) reaches two conclusions.
On patient data
The pseudonymization is demonstrably effective and re-identification is ruled out in practice. The decisive point is that MediPulse does not hold the key. The opinion relies on the judgment of the Court of Justice of the European Union of September 4, 2025 (case C-413/23 P), under which pseudonymized data is not personal data in every case but must be assessed from the perspective of the specific processor. Conclusion: from the perspective of MediPulse, the data is anonymous.
On employee data
Here the GDPR does apply, and here too the opinion finds no concerns: MediPulse processes billing data that already exists and creates no new records from it. In particular, no employee profiles are built, which would generally be unlawful under Art. 22 (1) GDPR. Processing stays limited to what the purpose requires.
Your account: we see transactions, nothing more
The bank connection runs through finAPI, not through MediPulse. finAPI is registered with BaFin, the German financial regulator, as an account information service and supervised as a payment institution under the German Payment Services Supervision Act. Your accounts are connected through your bank's PSD2 interface.


We hold no credentials
Through the PSD2 interface you authenticate directly with your bank, using your familiar method including TAN. Your online banking credentials never reach MediPulse and are not stored here. They simply do not exist on our side.
No transaction can be made through MediPulse
Only the account information service under Sec. 1 (34) of the Payment Services Supervision Act is used — a service that retrieves account information, nothing else. Initiating a payment would require a payment initiation service under Sec. 1 (33). We do not use it. Through MediPulse, no transfer can be started, no direct debit collected, and no standing order changed.
Only information arrives
What your bank transmits is information about incoming and outgoing amounts that have already happened — one direction of reading, no channel back. From it comes the cross-check against billing: what has been invoiced, what has actually arrived, where liquidity stands today.
You stay in control
You decide which accounts are connected and set up the connection yourself. You can delete it yourself at any time — in MediPulse and additionally in your bank's online banking, which lists every consent you have granted. The consent is time-limited in any case and has to be renewed regularly.
What is processed from a transaction
- Booking date
- Amount
- Account IBAN
- Name of the counterparty
- IBAN of the counterparty
- Payment reference
Misuse in the sense of a payment is therefore not a question of trust or permissions but technically impossible: the service in use has no function that moves money, and the credentials that could bypass it are not held by us.
What your data is used for — and what it is not
Benchmarks only as a group
Your figures do feed into benchmarks, but only aggregated across a group of practices. No single practice can be traced within them, and no other practice sees your values. This is also stated as a purpose in Annex 1 of the data processing agreement.
No access without your consent
Nobody at MediPulse has access to your data. If support needs to look into a fault, that happens only after you agree. The consent is documented, the access is logged, and you can inspect the log.
No AI model training
Your data is not used to train AI models — neither ours nor anyone else's.
No sharing with third parties
Your data is not sold, not rented out, and not analyzed for advertising. The only parties involved are the two service providers that make operation and the bank connection possible.
Who sees what in your practice
Not every role needs every figure. Access is tiered.
Practice owner
Full access to all functions and data.
Physician
Restricted access to the physician-level view.
Administration
Access to the administrative functions.
Technical and organizational measures
Contractually agreed as Annex 2 of the data processing agreement (Auftragsverarbeitungsvertrag, in German), not as a statement of intent.
Physical access control
Rooms where data is processed are restricted to authorized persons by locking systems, access cards, and monitoring.
System access control
Individual user accounts, strict password policies, and multi-factor authentication.
Data access control
Access rights follow the need-to-know principle and are reviewed regularly.
Separation control
Data processed for different purposes is separated logically and physically, with its own authorization concepts.
Transfer control
Transmission only over secured, encrypted connections. Data transfers are logged.
Input control
Entry, modification, and deletion are logged in an audit-proof way and reviewed regularly.
Added to this is pseudonymization under Art. 32 (1) (a) and Art. 25 (1) GDPR, plus a procedure for regular review: internal audits, security assessments, and penetration tests. Our servers run in data centers certified to ISO 27001 and attested under the BSI C5 catalogue; we present the certificates to you on request. MediPulse manages the keys for storage encryption. The key that decides the assignment to a patient, by contrast, is not held by us — it stays in your practice management system.
Who we rely on — and what binds them
Two service providers take part in the processing: the data center in Germany where our servers run, and finAPI for the bank connection. Both are sub-processors within the meaning of Art. 28 GDPR, and the data processing agreement binds them closely.
- Every sub-processor is bound in writing to the same obligations we owe you.
- Your audit rights apply to them directly as well.
- We verify compliance at least once a year and document the result.
- We are liable for a sub-processor's fault as for our own.
- We inform you in good time before any change, and you may object.
How long we keep your data
Retention only for as long as the purpose requires (Art. 5 (1) (e) GDPR). Specifically:
- Billing and service data
- For the term of the contract. The time series is the purpose here — a multi-year comparison needs the earlier years.
- Transaction data from the connected accounts
- For the term of the contract.
- After the contract ends
- Return or complete, irreversible deletion within 30 days.
- Backups
- 30 days, then overwritten. Encrypted and likewise exclusively in Germany. A deletion takes effect there at the latest once that period has passed.
- Logs and telemetry
- 90 days.
A common misunderstanding: the ten-year retention period under Sec. 147 of the German Fiscal Code applies to your practice as the controller, not to MediPulse as the processor. Your tax-relevant records stay in the practice management system and in your accounting — where the period applies.
What is contractually guaranteed
Before the connection is set up, we conclude a data processing agreement (Auftragsverarbeitungsvertrag, in German) under Art. 28 GDPR. It forms Annex 1 of the terms and conditions and runs as long as the main contract. The substance is set out here so you do not have to search the document for it — the numbers in brackets point to the clause.
Bound by your instructions
- MediPulse processes your data solely on your behalf and according to your instructions (2.1).
- If a law compels different processing, we tell you before processing — unless that law prohibits the notice (2.1).
- You may issue further instructions on the nature, scope, purpose, and means at any time; material instructions are documented (2.3).
- If we consider an instruction unlawful, we tell you and may suspend it with 14 days' notice until you confirm or change it (2.4).
Confidentiality
- Everyone at MediPulse who processes your data is bound to confidentiality (3.1).
- They process your data only on instruction, never on their own initiative (3.2).
- This is secured under employment law through confidentiality agreements (terms and conditions, section 19).
- The obligation extends to cooperation partners (terms and conditions, section 19).
Rights of your patients and staff
- We support you with technical and organizational measures in answering requests from data subjects (6.1).
- If a data subject approaches us directly, we inform you without delay (6.2).
- On request we hand over all processing information you need for your answer and do not hold yourself (6.2).
Notification duties
- We report any breach of the protection of your data without delay once we become aware of it (7.1).
- The report describes the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken (7.1).
- If you have to inform the supervisory authority or data subjects under Art. 33 and 34 GDPR, we support you (7.2).
- We also support you with a data protection impact assessment and any subsequent consultation of the supervisory authority under Art. 35 and 36 GDPR (7.3).
Deletion and return
- When the contract ends, or at any time on your request, we return all documents, data, and media or delete them completely and irreversibly (8).
- The only exception is a statutory retention period (8).
- If a patient objects to storage, we return the data to you (8).
- Processing ends when the main contract or this agreement is terminated; in case of doubt, terminating one counts as terminating the other (2.5).
Evidence and audits
- We check regularly ourselves that processing matches the agreement, the agreed scope, and your instructions (9.1).
- We document the implementation and present the evidence to you on request (9.2).
- You may audit before processing begins and regularly thereafter — yourself or through an auditor you appoint (9.2).
- We enable those audits and contribute to them with all reasonable measures (9.2).
Art. 82 DSGVO
Liability follows Art. 82 GDPR (10.1). A party is released from it only by proving that it bears no responsibility whatsoever for the circumstance that caused the damage — and in the case of a fine, correspondingly to the share of responsibility (10.2).
What this leaves with you
- Use strong passwords and do not share access credentials (terms and conditions, section 6).
- Keep credentials protected from third-party access; you are responsible for actions third parties take with your credentials (terms and conditions, section 6).
- Report any suspected unauthorized access to us immediately — we block accounts on unusual usage patterns (terms and conditions, section 6).
- Maintain the system requirements so a new version can be deployed at any time (terms and conditions, section 5).
The connector on your server
Your administrator installs it, either by remote access or independently with our guidance. Updates run automatically, are signed, and are checked for integrity before installation; a rollback mechanism is in place. Report faults to support@medipulse.de; service hours and the procedure are set out in sections 9 and 10 of the terms and conditions.
What the connector needs on your network
Outbound only
The connector opens every connection itself, TLS encrypted. Your firewall needs no inbound rule from the internet — not even when MediPulse triggers an update.
The database stays local
The connector runs on the same server as your practice management system's database and reads it through the local interface. No firewall rule is needed for the database connection.
Non-standard installations
If the database sits on a different server, or the installation deviates from the vendor's standard, our support configures the connection individually. Your IT provider receives the full network requirements in writing before setup.
The documents themselves
Do you have a data protection officer who wants to look closer? We provide the legal opinion and the full data protection documentation on request.
Who is responsible, and how to reach us
The contracting party and operator of MediPulse is Pulse Technologies GmbH, Augustenstrasse 87, 80798 Munich, Germany. We answer data protection questions at info@medipulse.de.
Frequently asked questions
Does our firewall need to allow an inbound connection?
No. The connector opens every connection itself, TLS encrypted. No inbound rule from the internet is required. It reads the database locally on the same server, which needs no firewall rule either.
Am I even allowed to involve an external service provider as a physician?
No patient confidentiality is disclosed to MediPulse: only the practice-internal identifier is transferred, and MediPulse does not hold the key to it. In addition, everyone at MediPulse who processes your data is bound to confidentiality under employment law. We provide the legal opinion and the full data protection documentation to your data protection officer on request.
How long is my data stored?
Billing, service, and transaction data for the term of the contract, because the multi-year comparison needs the earlier years. When the contract ends, data is returned or deleted completely and irreversibly within 30 days. Backups are kept for 30 days, logs and telemetry for 90 days.
Can other practices see my figures?
No. Your figures feed into benchmarks, but only aggregated across a group of practices and without any way to trace them back to a single practice. No other practice sees your values.
Can anyone at MediPulse look into my data?
No. There is no access to your data. If support needs to look into a fault, that happens only after you agree.
Does patient data leave the practice once MediPulse is connected?
No. The only patient field transferred is a practice-internal ID, together with the billing line. Name, date of birth, address, contact details, and insurance data stay in the practice management system, as does the table that maps an ID to a patient.
Can MediPulse map the data back to individual patients?
No. MediPulse does not hold the key: the mapping table never leaves the practice network, and no identifying attributes are transferred from which a mapping could be reconstructed.
Can MediPulse change data in my practice management system?
No. The MediPulse connector accesses the database of the practice management system with read-only rights.
Where is the data stored?
Exclusively in data centers in Germany, certified to ISO 27001 and attested under the BSI C5 catalogue. No personal data is transferred to third countries outside the EU or the EEA, and there is no support access from third countries.
How is the bank connection secured?
Through finAPI, an account information service licensed and supervised by BaFin, using your bank's PSD2 interface. You connect the accounts yourself, decide which ones, and can delete the connection yourself at any time.
See for yourself in a demo which data arrives — and which does not.
Try MediPulse with no obligation and see how data and automation give you your time back.