Language:

Zwei Frauen sitzen vor einem Computer.

SM-B Institution Certificates

A practice or institution ID that works without a card and is transmitted directly to the health care system: Medical institutions confirm their identity within the telematics infrastructure (TI) with the SM-B institution certificates – and do so fully virtually. The hardware-independent alternative to the SMC-B card therefore enables access to the electronic health card (EHC) as well. 

SM-B institutional certificates are differentiated into institutional certificates for a basic consumer (SM-B) and institutional certificates for a TI gateway (HSM-B).

Card-Free Authentication Innovation within Telematics Infrastructure 

SM-B institutional certificates (SM-B/HSM-B) are cardless, virtual ID cards for secure digital access to the TI in German healthcare. They replace the traditional physical chip card (SMC-B) with software or hardware security modules. 

The SM-B and HSM-B from D-Trust GmbH offer the first hardware-independent authentication option that health care institutions can use to identify themselves in the (TI). They are a user-friendly, fully digital version of the SMC-B card. They make proof of identity and origin more convenient and less dependent on cards and terminals. The SM-B can be used by healthcare organisations such as health insurance funds, Associations of Statutory Health Insurance Physicians and Dentists, TIM manufacturers and providers, or the chambers, as well as organisations of payers that still use a basic consumer. 

The HSM-B can be used by institutions that are already registered with an approved TI gateway provider. You can find an overview in the specialist portal of gematik. The SM-B identities are personalised in the Hardware Security Module (HSM) at the TI gateway provider and are stored and operated as HSM-B. Early users include healthcare organisations, organisations of healthcare providers, organisations of payers, digital health applications, EU mail-order pharmacies, and institutions of other healthcare professions. Further professional groups are already being planned. 

Your benefits at a glance

  • Hardware-independent – a certificate-only product that can be used online without additional hardware
  • User-friendly – simple and secure virtual access to the telematics infrastructure
  • Future-proof – the institutional certificates are ready for TI 2.0
  • Ready for immediate use – fast application process via our eHealth application portal for a seamless transition 

Verifiying identity without a card With many benefits. 

The basis for the SM-B institution certificates is secure access to the TI via a VPN connection. This enables health workers to authenticate their institution in the TI. You can also use it to electronically sign documents and data on behalf of the respective organisation. This electronic signature serves as an institutional stamp and thus as proof of origin. 

Secure encryption via KIM and access to the eHC 

Messages exchanged via the secure healthcare messaging (KIM) standard can be encrypted and decrypted with the SM-B institutional certificates. In addition, the new certificate solution also enables read access to the data on the electronic health card. 

The path to SM-B institutional certificates You must follow the steps below if you want to use the virtual SM-B institutional certificates in your organisation in future:

  • Order the SM-B/HSM-B via the D-Trust GmbH eHealth application portal. In doing so, you appoint an institutional representative. For the SM-B, you also specify either a key administrator approved by gematik GmbH or a consumer. For the HSM-B, you specify a TI gateway provider.
  • The confirming bodies for the SM-B or HSM-B, such as gematik or the electronic register of healthcare professions (eGBR), must approve the order.
  • In the D-Trust GmbH eHealth application portal, you can activate your institutional certificates once you have received them. For the HSM-B, a one-time activation of your institutional certificates at the TI gateway provider is also required; see above.

Frequently Asked Questions

Für den Erhalt der SM-B stellen Sie bitte einen Verlängerungsantrag beim eGBR. Diesen Antrag finden Sie hier: Verlängerungsantrag Institutionsidentität (SMC-B/SM-B). Nur mit dem Verlängerungsantrag kann sichergestellt werden, dass die SM-B, die Sie erhalten, die gleiche Telematik-ID wie Ihre bisherige SMC-B hat. So kann eine nahtlose Weiternutzung der Telematikinfrastruktur (KIM etc.) in Ihrer Institution sichergestellt werden. Sollte Ihr vorhandener SMC-B-Antrag beim eGBR noch keine 12 Monate alt sein und sich die angegebenen Daten nicht geändert haben, können Sie formlos, z.B. per E-Mail an egbr@bezreg-muenster.nrw.de eine neue Vorgangsnummer für den Erhalt der SM-B anfordern.

When a certificate is applied for via the D-Trust eHealth application portal, the Key Manager receives an e-mail asking to have the Certificate Signing Requests (CSRs) sent to D-Trust. D-Trust GmbH checks the CSRs, and gematik GmbH – as the issuer of the SM-B ORG institution certificates – approves the application. This is followed by the SM-B institution certificates being issued. In a final step, the certificates are sent by e-mail to the Key Manager, who adds them to the hardware security module. The SM-B institution certificates are activated on the eHealth application portal of D-Trust GmbH by the applicant or the applicant’s representative.

Certificates are applied for via the eHealth application portal of D-Trust GmbH. This is where you select a Key Manager (KM), also called a Consumer. This is a gematik-approved provider that protects the cryptographic keys of the SM-B institution certificates via a highly secure hardware security module (HSM) – against loss, damage and unauthorised access. Ultimately, the Key Manager ensures that you are able to use the relevant TI services.

D-Trust produces the SM-B institution certificates and sends them to the Key Manager, who then fills the hardware security module (HSM) with the institution certificates. The applicant or the applicant’s representative then activates the certificates. A separate PIN/PUK letter is not sent.

The SM-B institution certificates have the same validity period as the SMC-B institution certificates. Users can check how long the SM-B institution certificates remain valid in D-Trust’s eHealth application portal. To check this, it is necessary to log in using the process number and a password that may already have been assigned under https://ehealth.d-trust.net/antragsportal/.

The validity can also be verified directly in the certificates. Contact the responsible Key Manager (KM) for this.

Do you have any questions about the SM-B institution certificate?

Our support team will be happy to help you. Feel free to contact us:

Piktogramm für Support
D-Trust Support-Team

+49 (0)30 2598-4050

These products might also interest you

This is where the SM-B institution certificates come into play