Häufig gestellte Fragen
What distinguishes an ERP for medical device manufacturers from a practice solution?
Medical device manufacturers need processes that map the EU MDR, ISO 13485, risk management according to ISO 14971 as well as end-to-end UDI assignment and batch traceability, since product-related liability and regulatory approval are the focus here. Physician practices, medical care centres (MVZ) and laboratories, by contrast, primarily need billing according to EBM (statutory health insurance patients) and GOÄ (private patients and self-payers) as well as interfaces to health insurers and the telematics infrastructure. These administrative practice tasks are usually handled by a specialised practice management system (PVS), while the ERP tends to control purchasing, merchandise management, material flow and financial accounting. In many organisations both system worlds therefore run in parallel and are coupled via defined interfaces.
Do practices and hospitals even need an ERP, or is a KIS or PVS sufficient?
The practice management system (PVS) in the practice and the hospital information system (KIS) in the hospital cover the core clinical-administrative processes such as patient management, documentation and billing, but they are not fully fledged commercial systems. An ERP complements them with purchasing, warehouse and merchandise management, supplier management, asset accounting and controlling, which are becoming increasingly important in larger institutions and groups. Larger KIS platforms already contain ERP-like modules for logistics and procurement, so the boundaries are fluid. Whether a standalone ERP makes sense therefore depends above all on the size of the institution, material volumes and the desired depth of commercial management.
Which regulatory obligations must a medical ERP support in 2026?
For manufacturers of medical devices, UDI assignment under the EU MDR is central, with the first EUDAMED modules — including UDI/device registration — mandatory to use since 28 May 2026, and the ERP should cleanly provide the data for this registration. In the outpatient sector, connection to the telematics infrastructure is mandatory for contracted physician care; since the ePA introduction in 2025 (mandatory use in practices since October 2025), systems must support the electronic patient record, and pure RSA-only connectors had to be replaced at the turn of 2025/2026 because their certificates could not be renewed. Added to this are GDPR requirements for especially sensitive health data as well as growing cybersecurity requirements, for instance from the NIS-2 regulation, now transposed into German law, for affected institutions. A suitable system should map these obligations without manual double entry and with an audit-proof audit trail.
How complex and expensive is GAMP 5 validation of a medical ERP?
GAMP 5 computer system validation follows a risk-based approach and typically comprises a user requirements specification (URS) as well as the qualification phases IQ, OQ and PQ with corresponding documentation. While simple, low-category applications can be validated in a few weeks, a complex ERP in a GxP environment can, depending on scope, take roughly in the order of several months to over a year and significantly increase project costs. Licence fees usually account for only a smaller part of total costs; the larger share goes to implementation, customising, validation, training and data migration. Specific amounts and timelines depend heavily on system complexity, interfaces and regulatory scope, which is why reliable figures can only be determined per project.
Is a cloud ERP GDPR-compliant in the medical sector?
Under Article 9 GDPR, health data is a special category of personal data and may only be processed under strict conditions and with strong technical and organisational safeguards. A cloud ERP is fundamentally permissible if a data processing agreement with clear measures is concluded and hosting takes place in the EU or in Germany. With US providers there is a tension arising from the Schrems II ruling and the US CLOUD Act, since US authorities can access data of US companies even when it is stored in the EU, which is why EU hosting is recommended for sensitive patient data. Several large providers offer dedicated EU cloud regions for this, so the specific configuration and the contract are decisive for legal compliance.
