ePA — Electronic Health Record
Context
The electronic health record for Germany's statutorily insured, built to gematik specifications and BSI requirements — every security-relevant change is subject to audit. Authentication is the critical path here: without a stable login through each health insurer's sectoral identity provider, nobody reaches their record.
Task
Integrating and extending the sectoral IdP connection with OpenID Connect, JWT, FIDO and mutual TLS; eGK card reading via NFC through a Kotlin Multiplatform module; hardening with Keychain, certificate pinning and device-hardening measures. The real difficulty: login and reauthentication flows that must stay stable against the differing IdP implementations of many insurers — covered by snapshot and BDD tests with code coverage as a quality metric in CI.
Result
The authentication path runs approved in production and is documented for audits. In third-level support I analysed and fixed escalated auth and session issues directly with the health insurers — root-cause analysis down into the individual insurer's IdP implementation.
Technologies
- Client
- IBM Deutschland GmbH
- Sector
- Healthcare
- Role
- Senior software engineer — authentication & security
- Period
- 10.2023 – 06.2026
First conversation: 30 minutes, free of charge, no presentation.
You describe the situation, I tell you whether and how I can help. No slides, no sales pitch.