Skip to content
All projects
01

ePA — Electronic Health Record

IBM Deutschland GmbH

Context

The electronic health record for Germany's statutorily insured, built to gematik specifications and BSI requirements — every security-relevant change is subject to audit. Authentication is the critical path here: without a stable login through each health insurer's sectoral identity provider, nobody reaches their record.

Task

Integrating and extending the sectoral IdP connection with OpenID Connect, JWT, FIDO and mutual TLS; eGK card reading via NFC through a Kotlin Multiplatform module; hardening with Keychain, certificate pinning and device-hardening measures. The real difficulty: login and reauthentication flows that must stay stable against the differing IdP implementations of many insurers — covered by snapshot and BDD tests with code coverage as a quality metric in CI.

Result

The authentication path runs approved in production and is documented for audits. In third-level support I analysed and fixed escalated auth and session issues directly with the health insurers — root-cause analysis down into the individual insurer's IdP implementation.

Technologies

SwiftSwiftUISwift ConcurrencyCombineKotlin MultiplatformOpenID ConnectJWTFIDOmTLSKeychainCertificate PinningeGK / NFCgematik / TISnapshot TestingBDDJenkinsFastlane
Client
IBM Deutschland GmbH
Sector
Healthcare
Role
Senior software engineer — authentication & security
Period
10.2023 – 06.2026
Contact

First conversation: 30 minutes, free of charge, no presentation.

You describe the situation, I tell you whether and how I can help. No slides, no sales pitch.