Tervise- ja heaolu infosüsteemide keskus · 14. november 2023
Sisu (failidest)
EUROPEAN COMMISSION
DIRECTORATE-GENERAL
HEALTH AND FOOD SAFETY
Digital health
Follow Up Compliance Check Report
NCPeH MS-EE
FinalFollowUpCC_NCPeH-EE_ ePA ePB Compliance Check Report for NCPeH-
MS_EE/Follow Up | ePA ePB
Date: 07/11/2023
Status: Final
Version: 1.00
Author: Gartner
Approved by: DG SANTE
Reference number: FinalFollowUpCC_NCPeH-EE ePA ePB
Public: DG SANTE external
Confidentiality: Sensitive non-classified (SNC)
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 1 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
ß
Document control information
Property Value
Title Follow Up Compliance Check Report NCPeH MS-EE
Subtitle FinalFollowUpCC_NCPeH-EE_ ePA ePB Compliance Check
Report for NCPeH-MS_EE/Follow Up | ePA ePB
Author Gartner
Project owner DG SANTE
DG SANTE Project Konstantin Hypponen
Manager
Version 1.0
Confident Sensitive non-classified (SNC)
Date 07/11/2023
Contract information
Property Value
Framework Contract DIGIT/2020/OP/0005 – BEACON Lot 1
Specific Contract BEACON000046
Document history
The document author is authorised to make the following types of changes to the document without
requiring that the document be re-approved:
Editorial, formatting, and spelling;
Clarification.
To request a change to this document, contact the document author or project owner.
Changes to this document are summarised in the table in reverse chronological order (latest version
first).
Version Date Description Action Section
1.00 07/11/2023 Final version I,R All
0.10 07/11/2023 Document submitted for review (SfR) I, R All
0.02 02/11/2023 Internal review I, R All
0.01 02/11/2023 Initial draft I All
Action: I=Insert R=Replace
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 2 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
Table of contents
1 MANAGEMENT SUMMARY ..........................................................................................................5
1.1 Objectives .............................................................................................................................................5
1.2 Target audience.....................................................................................................................................5
1.3 Scope.....................................................................................................................................................5
1.4 Readiness criteria ..................................................................................................................................5
1.5 Structure................................................................................................................................................5
1.6 Abbreviations & acronyms ...................................................................................................................6
1.7 Definitions ............................................................................................................................................6
2 FINDINGS AND RECOMMENDATIONS .....................................................................................8
2.1 Structure of the findings .......................................................................................................................8
2.2 General findings and Observations.......................................................................................................9
2.3 Legal and Organisational Domain ........................................................................................................9
2.4 Service Operations ..............................................................................................................................13
2.5 Information Security ...........................................................................................................................16
3 OVERALL CONCLUSIONS ..........................................................................................................18
4 CLOSING MEETING .....................................................................................................................20
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 3 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
List of tables
Table 11: Abbreviations and Acronyms ................................................................................................................... 6
Table 2: Definitions .................................................................................................................................................. 7
Table 3: Structure of the findings ............................................................................................................................. 8
Table 4: Status Observation a ................................................................................................................................... 9
Table 5: Status Finding 1 ........................................................................................................................................ 10
Table 6: Status Finding 2 ........................................................................................................................................ 11
Table 7: Status Finding 3 ........................................................................................................................................ 11
Table 8: Status Finding 4 ........................................................................................................................................ 12
Table 9: Status Finding 5 ........................................................................................................................................ 13
Table 10: Status Finding 6 ...................................................................................................................................... 14
Table 11: Status Finding 7 ...................................................................................................................................... 14
Table 12: Status Finding 8 ...................................................................................................................................... 15
Table 13: Status Finding 9 ...................................................................................................................................... 16
Table 14: Status Finding 10 .................................................................................................................................... 16
Table 15: Status Observation b............................................................................................................................... 17
Table 16: Status Finding 11 .................................................................................................................................... 17
Table 17: Status Finding 12 .................................................................................................................................... 18
Table 18: Overview of findings/observations and their status ............................................................................... 19
List of figures
No table of figures entries found.
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 4 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
1 MANAGEMENT SUMMARY
On 29 September 2023, Gartner has received a request from the Estonian NCPeH to conduct a follow-
up compliance check for services and ePA ePB. Gartner has provided the Agenda for the follow-up
compliance check on 02 October 2023.
This follow up compliance check was carried out remotely on 17 and 20 of October 2023. The
objective of the compliance check was to assess the status of the findings from the initial compliance
check.
The compliance check team (CCT) was composed of two assessors. The subject matter experts from
the Estonian NCPeH presented the progress and activities to the assessors, aimed to the mitigation of
the findings.
1.1 OBJECTIVES
The objective of the compliance check is to assess the NCPeH compliance with the eHDSI
Requirements according to the eHDSI Readiness Criteria Checklist. This checklist is agreed by the
eHealth Digital Service Infrastructure Member State Expert Group (eHMSEG). Particular attention
was given to verify that appropriate policies and processes are in place, are communicated through the
organisation, and are implemented in order to ensure the confidentiality, integrity and availability of
information.
1.2 TARGET AUDIENCE
The target audience for this document includes:
▪ NCPeH of MS-EE;
▪ DG SANTE.
1.3 SCOPE
The scope of the compliance check covered the open findings and observations indentified during the
operational compliance check, covering the organisation of the NCPeH and its activities related to the
operation of ePrescription A and B service(s).
1.4 READINESS CRITERIA
The criteria against which the NCPeH (and its service providers) was examined are the eHDSI
Readiness Criteria Checklist1 V2.2.
1.5 STRUCTURE
This document is organised as follows:
Chapter 1 – Management Summary: provides the context of the compliance check and
summary of the outcomes;
1
https://webgate.ec.europa.eu/fpfis/wikis/x/fPzzN
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 5 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
Chapter 2 – Findings and Recommendations: details the findings and recommendations made
during the Operational Compliance Check within the set scope of the compliance check, its
criteria and objectives agreed to be achieved;
Chapter 3 – Overall Conclusions: details the overall conclusions made during the Operational
Compliance Check within the set scope of the compliance check, its criteria and objectives
agreed to be achieved;
Chapter 4 – Closing Meeting: presents a summary of the discussed topics during the closing
meeting of the Operational Compliance Check;
1.6 ABBREVIATIONS & ACRONYMS
For a better understanding of the present document, the following table provides a list of the principal
abbreviations and acronyms used.
Abbreviation/Acronym Definition
BCDR Business Continuity and Disaster Recovery
CBeHIS Cross-border eHealth Information System
CCP Compliance Check Performer
CMDB Configuration Management DataBase
DPA Data Processing Agreement
DPIA Data Protection Impact Assessment
eHDSI eHealth Digital Service Infrastructure
eHealth The use of information and communication technologies for health
eHMSEG eHealth DSI Member State Expert Group
EHR Electronic Health Record
ICC Initial Compliance Check
NC National Connector
NCPeH National Contact Point for eHealth
PIN Patient Information Notice
eP-A ePrescription (and eDispensation) A
eP-B ePrescription (and eDispensation) B
PS-A Patient Summary A
PS-B Patient Summary B
SOP Service Operation Plan
TEHIK Health and Welfare Information Systems Centreß
Table 11: Abbreviations and Acronyms
1.7 DEFINITIONS
For a better understanding of the present document, the following table provides a list of the principal
terms used.
Term Definition
Country A Member State of Affiliation / Country of prescription
Country B Member State of Treatment / Country of dispensation
Finding A statement regarding the state of a conformity or non-
conformity with the requirements, based on objective and
verifiable evidence.
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 6 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
Observation A finding that does not indicate non-conformity with the
requirements but suggests possible improvements related to the
implementation of the requirements.4
Patient Summary Patient Summary provides information on important health related
aspects such as allergies, current medication, previous illness,
surgeries, etc. It is part of a larger collection of health data called
Electronic Health Record (EHR).
ePrescription ePrescription (and eDispensation) allows EU citizens to obtain
their medication in a pharmacy located in another EU country,
thanks to the online transfer of their electronic prescription from
their country of residence where they are affiliated, to their country
of travel.
Table 2: Definitions
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 7 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
2 FINDINGS AND RECOMMENDATIONS
For the purpose of this Follow Up Compliance Check (FCC) report, the terms ‘finding’ and
‘observation’ are used as defined in the Definitions section of this report. Conclusions of the report
aim at highlighting the impact of the findings.
This report focuses on the requirements and readiness criteria leading to findings, meaning
requirements not fulfilled or readiness criteria not fully implemented. In contrast, requirements and
readiness criteria for which the NCPeH demonstrated compliance are not reflected in the report.
In addition to findings, the report also contains observations. An observation relates to an identified
opportunity for improvement that does not strictly lead to a non-compliance with the eHDSI Readiness
Criteria Checklist, but which is considered good practice by the compliance check team (CCT). To
emphasise the distinction between findings and observations, observations are indicated with Roman
numerals.
2.1 STRUCTURE OF THE FINDINGS
Finding Original Finding Text
Description
Recommendation Original Recommendation Text
Update FCC 05 Observations made during the compliance check
October 2023
Status of the Status of the finding after the compliance check
finding
Table 3: Structure of the findings
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 8 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
2.2 GENERAL FINDINGS AND OBSERVATIONS
a) Links in documentation to the former EC confluence pages
Observation The documentation provided by the Estonian NCPeH contain obsolete links to
Description the former EC confluence spaces (CEF Digital).
In the second half of 2021, the information of the CEF Digital confluence spaces
was transitioned to the new EC confluence space
(https://webgate.ec.europa.eu/fpfis/wikis/x/noOhMg). This new eHDSI
confluence space contains Operations, Semantic and Technical information. Due
to this transition, several links to the former EC confluence spaces are obsolete.
It has been observed that in the updated version of the Architecture document
(v1.3) the links have already been updated.
Recommendation
Update links in documentation which still point to locations of the former EC
confluence spaces, to the new EC confluence web pages
(https://webgate.ec.europa.eu/fpfis/wikis/x/noOhMg).
Associated finding(s): n/a
Associated requirement: n/a
Update FCC 20 The links got updated, as already noted in the report for the operational
October 2023 compliance check.
Status of the This observation can be closed
finding
Table 4: Status Observation a
2.3 LEGAL AND ORGANISATIONAL DOMAIN
1. [LO.4] Handling of the legislative changes impacting the provision of the cross-border
services
Finding TEHIK participates in meetings, organized by the Ministry (responsible for
Description legislation), about proposed changes for the upcoming year. TEHIK can provide
feedback based on the proposed changes and analyses done. Any work that needs
to be done based on the proposed legislative changes, will be incorporated in an
annual work plan. Although the process seems to be covered, this process or
procedure for handling legislative changes is not documented.
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 9 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
Recommendation
Document the process or procedure for handling legislative changes, taking into
account activities already performed in relation to this criteria (e.g. participating
in meetings on yearly proposed changes, incorporation in an annual work plan).
Update FCC 20 The NCPeH has documented the Process (see LO.4_Legislation and development
October 2023 process_EN). It covers aspects for new legislation (for a new development) or a
new development (that needs new legislation). The documentation covers the
existing process. The ministry also started to document their side of the process.
From the NCPeH, when there is a development – the required legal impact is
assessed (covering legal and developmental aspects). TEHIK has legal experts
conducting this.
Maintained by the owner of the development process -> Quality department.
Status of the This finding can be closed.
finding
Table 5: Status Finding 1
2. [LO.5] Ensuring the protection of the cross-border health data coming from the other
NCPeHs
Finding The NIS directive (general information, official EU document) covers amongst
Description others the cross-border collaboration and should be adapted in national
legislation. Each Member State should identify “operators of essential services”,
to which security requirements should be applied. It’s not clear whether the cross-
border ePrescription services are identified by Estonia as “essential services”and
therefore TEHIK being an “operator of essential services” for these services.
Recommendation
Determine if the operators of cross-border ePrescription services in Estonia are
considered as “operators of essentials services” as defined in the NIS directive.
Implement security measures accordingly.
Update FCC 20 TEHIK was identified not be an operator of essential services.
October 2023 Based on the definition of essential services, as defined by the ministry of interior,
the organization does not meet the requirements to be classified as operator of
essential services.
While Emergency Care is considered ”essential services”, the cross-border
services are not part of it (see definition of vital services on the webpage of the
ministry of interior of Estonia).
Status of the This finding can be closed.
finding
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 10 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
Table 6: Status Finding 2
3. [LO.5] Ensuring the protection of the cross-border health data coming from the other
NCPeHs
Finding The DPIA is updated whenever there is a need for it. During the compliance check
Description it was mentioned that the need for updating the DPIA is ensured in the change
management as well as in the incident management process. In the provided
documentation (extract of TEHIKs confluence pages, containing amongst others
process descriptions) this cannot be found.
Recommendation
Document the check to update the DPIA in the analysis done in the incident and
change management process, as it was mentioned to be ensured during the
compliance check.
Update FCC 20 TEHIK has amended the documentation for change and incident management
October 2023 stating that it must be assessed whether a change or incident leads to a DPIA
(mostly in case of service changes or legal changes).
Status of the This finding can be closed.
finding
Table 7: Status Finding 3
4. [LO.10] Provision of communication and training plans
Finding Whenever a new staff member joins the NCPeH, the department manager is
Description responsible for providing all kinds of (general) information. The service / project
manager of cross-border services points the new staff member orally to the
service passport, in which specific information can be found for the cross-border
services. However, both are not documented in the staff onboarding process
checklist or formalized in a welcome mail, in which is explained where to find
what kind of information.
The staff onboarding process covers very limited training, only the mandatory
security training. Training on the usage of tools for the management of incidents,
problems and changes is not included in the staff onboarding process. Only
general manuals on Jira can be found on the TEHIK’s confluence pages.
Recommendation
Include instructions where to find what kind of information (like the roles &
responsibilities on the QM confluence pages) in the onboarding process.
Formalize directing new NCPeH staff to the service passport, in which specific
information can be found for cross-border services, for example in an email they
will receive with a link to the service passport.
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 11 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
Include training about the use of tools for the management of incidents, problems
and changes in the staff onboarding process, including referral to the manuals or
quick reference cards.
Update FCC 20 The checklist has been moved to JIRA (previously was on Confluence). The
October 2023 Checklist is put together by a specialist in TEHIK. With JIRA, the completion of
these tasks can be tracked. The Tasks have to be approved by the hiring manager
(which then gets reported to the HR department).
The NCPeH demonstrated the checklist for a new employee during the
compliance check from the view of the new employee and the services manager.
TEHIK has also an onboarding day, which is mandatory for all new joiners
(general information about the organization, building walkthrough, assignment
of task).
There is also a mentoring system in place.
Depending on the position, there are additional trainings for individuals.
Status of the This finding can be closed.
finding
Table 8: Status Finding 4
5. [LO.10] Provision of communication and training plans
Finding Whenever a new staff member joins the NCPeH, the department manager is
Description responsible for providing all kinds of (general) information. The service / project
manager of cross-border services points the new staff member orally to the
service passport, in which specific information can be found for the cross-border
services. However, both are not documented in the staff onboarding process
checklist or formalized in a welcome mail, in which is explained where to find
what kind of information.
The staff onboarding process covers very limited training, only the mandatory
security training. Training on the usage of tools for the management of incidents,
problems and changes is not included in the staff onboarding process. Only
general manuals on Jira can be found on the TEHIK’s confluence pages.
Recommendation
Include instructions where to find what kind of information (like the roles &
responsibilities on the QM confluence pages) in the onboarding process.
Formalize directing new NCPeH staff to the service passport, in which specific
information can be found for cross-border services, for example in an email they
will receive with a link to the service passport.
Include training about the use of tools for the management of incidents, problems
and changes in the staff onboarding process, including referral to the manuals or
quick reference cards.
Update FCC 20 The checklist has been moved to JIRA (previously was on confluence). The
October 2023 Checklist is put together by a specialist in TEHIK. With JIRA, the completion of
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 12 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
these tasks can be tracked. The Tasks have to be approved by the hiring manager
(which then gets reported to the HR department).
The NCPeH demonstrated the checklist for a new employee during the
compliance check from the view of the new employee and the services manager.
TEHIK has also an onboarding day, which is mandatory for all new joiners
(general information about the organization, building walkthrough, assignment
of task).
There is also a mentoring system in place.
Depending on the position, there are additional trainings for individuals, where
the training on the tools is being addressed. .
Status of the This finding can be closed.
finding
Table 9: Status Finding 5
2.4 SERVICE OPERATIONS
6. [OS.05] Organization of the communication processes with the other NCPeHs
Finding For informal communications with other NCPeHs in case of issues, Slack is used.
Description Slack formally was chosen as means of communication during test events. Usage
of Slack for operational means of communication with other NCPeHs has risks
(shadow IT risks: lost control and visibility). The risk includes security and
regulatory noncompliance, and data leaks. Slack is not part of the approved tools
within TEHIK to use for communications (like Skype for Business).
Recommendation
The IT (security) department should assess the use of “Open Slack”. Often
shadow-IT software tools lack reliable backup, support, or business continuity
controls and may be vulnerable for data leaks. Keep in mind that not every
application requires instant, automated, cloud backup; 24 x 7 x 365 support; or a
fail-over alternative in the event of an emergency. Assess the extent to which the
shadow application may require additional (e.g. technical or policy) measures for
safeguarding information shared via this tool.
Update FCC 20 The information security department has provided a list of approved channels –
October 2023 and slack was not on the list. But slack is used to contact experts in other MS.
TEHIK has discussed this internally and stated to the Information Security
department that Slack is used. It is now listed as a risk. It was agreed, that no
sensitive data (patient data, security data etc.) is shared.
This was originally done by e-Mail – starting this month (October 2023) a
security exception process was implemented and the request was moved there
(DELTA).
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 13 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
Status of the This finding can be closed.
finding
Table 10: Status Finding 6
7. [OS.06] Monitoring the Service Level Agreements (SLAs) with the ICT Service
Providers/other entities managing the cross-border services
Finding No specific agreements are made in the arrangements between the Ministry and
Description TEHIK, other than minor requirements in legislation. TEHIK uses internal
service levels only. For example for business continuity there are no defined and
agreed service levels (like RPO, maximum allowable amount of data loss, and
RTO, maximum allowable recovery time) for disaster recovery measures.
Currently only an internal service level on back-up is documented.
TEHIK has not formalized a waiver from the Ministry about not having an SLA
between the Ministry & TEHIK, although there is email communication about
this subject.
Recommendation
Define and agree service levels (like RPO, maximum allowable amount of data
loss, and RTO, maximum allowable recovery time) for disaster recovery
measures.
Discuss with the Ministry the reason for and value of having agreed service levels
in a broader sense than the minor requirements in the legislation, including RTO
and RPO in case of a disaster. Otherwise formalize a waiver from the Ministry if
the Ministry about not having a formal SLA between the Ministry & TEHIK and
agreeing to TEHIK setting internal service levels.
Update FCC 20 The discussion between the Ministry and TEHIK led to a waiver that an SLA
October 2023 between the Ministry and TEHIK is not needed.
Status of the This finding can be closed.
finding
Table 11: Status Finding 7
8. [OS.07] Management of the Testing activities
Finding For testing changes as well as in disaster recovery tests, end-2-end testing is not
Description fully implemented. End users are not included to test the changed or recovered
(part of the) functionality of the cross-border service. For testing the
implementation of a new wave, some pharmacies are visited to test if the
functionality works as predicted. But it’s not documented which pharmacies
participate in end user testing. Proper end-2-end testing cannot be done by the
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 14 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
NCPeH itself, due to the lack of a copy of the pharmacy systems for different
reasons (too complex or supplier not willing to cooperate).
Recommendation
Implement end-2-end testing, including documenting which pharmacies (are
willing to) participate in end user testing and pharmacy IS suppliers showing
documented results of performed testing (like wave testing or tests done based on
submitted changes). Implement end-2-end testing also when performing disaster
recovery tests, by having end-users test the recovered (part of the) functionality
of the cross-border service, including recording the results.
Update FCC 20 The documentation was updated in the Services Passport (OS.7_Teenuse
October 2023 pass_EN), see chapter 9. Additionally, 2 pharmacies agreed on supporting the
tests if required.
There is currently no possibility to legally contract this with the pharmacy
system developer.
Testings were conducted with the pharmacies already.
The documentation in chapter 9 reflects an already existing process.
Status of the This finding can be closed.
finding
Table 12: Status Finding 8
9. [OS.09] Handling the Configuration Management activities
Finding Current CMDB information is fragmented and mostly in flat files, like MS Excel.
Description This information is not integrated in the used process management tool (Jira).
Because of this, trends analysis cannot be performed and supporting incident
prevention and change impact analyses is very limited. Although this has already
been reported (like in the recent ISKE audit or audits which are referred to in the
ISKE audit) and the recommendation has been recognized by defining a project
to implement a proper Configuration Management tool, the project has still not
started because of not having any assigned resources
Recommendation
Implement a Configuration Management System (CMS) properly, since the
current CMDB information is fragmented. Start the project to select / implement
/ transition to a new CMDB/CMS by assigning resources.
Update FCC 20 The CMS/CMDB (JIRA Insight) is live since spring 2023. The implementation
October 2023 is still ongoing – the help desk is using the CMDB and is also updating it. The
procedures are not yet fully finalized since the NCPeH plans do develop/refine
it ”on the go”. The CMDB is connected to JIRA.
The NCPeH presented an internal Confluence Page, where the owners of the
CMDB are listed (department and subject matter experts).
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 15 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
It was planned to finalize this by the end of 2023 but had to be postponed due to
a major change of the IT Security System. Technical services are covered
already (October 2023).
Status of the This finding can be closed.
finding
Table 13: Status Finding 9
10. [OS.10] Planning and monitoring the capacity and availability of the cross-border services
Finding Grafana and Zabbix are used for monitoring. Some thresholds are implemented
Description and trigger alerts to Customer support as well as system administrators. It’s not
clearly defined who is responsible for monitoring, it is a side task of multiple
resources. There is no specific resource assigned for monitoring and acting on
notifications, as a sort of ‘operator of the day’.
Recommendation
Clearly define who is responsible for monitoring and have a resource allocated
for that, to be able to immediately intervene whenever an alert is triggered or even
pro-actively whenever an indicator threatens to exceed.
Update FCC 20 The NCPeH presented the Dashboard. The NCPeH has updated the job
October 2023 descriptions of the System Administrators and the Service manager (who is
responsible for the monitoring). The monitoring description in the Service
Passport was updated (See chapter 6.2.1)
Status of the This finding can be closed.
finding
Table 14: Status Finding 10
2.5 INFORMATION SECURITY
b) [IS.06] Management of the Certificates Lifecycle
Observation In the monitoring tool a threshold is implemented to notify 30 days before
Description expiration of a certificate. An email is sent to the responsible for renewing the
certificate and to customer support. A ticket in Jira still needs to be created
manually, for recording activities (to be) performed.
Recommendation
If possible, automate the process of alerts on upcoming expiration of certificates
even more by automatically creating a ticket, based on the alert from the
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 16 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
monitoring tool. Or create a reoccurring ticket for the renewal of a certificate,
based on the certificate period.
Update FCC 20 The NCPeH has updated the procedure in the Services Passport, chapter 6.2.2.
October 2023 (OS.7_Teenuse pass_EN).
A new monitoring has been created (in Prometheus) – tickets are not yet
automatically created. This was assessed, but not followed up upon (as it was
deemed to not provide additional value -> too many tickets).
The Service Manager is responsible for this process.
Status of the This Observation can be closed.
Observation
Table 15: Status Observation b
11. [IS.05] Management of the Information Security Incidents
Finding The definition of security incidents according to ISKE is broad. Security incidents
Description are registered when they pop-up. Vulnerabilities are firstly notified of via email
and after being analysed they may be registered as security incident. In regard to
the log4j vulnerability for example, the security incident was registered, but
actions taken to solve this in the cross-border services domain are not linked to
the security incident. Furthermore, the process of handling vulnerabilities is not
documented.
Recommendation
Document the process of handling vulnerabilities and ensure the registration of a
security incident is the starting point for further actions and investigations and
link all subtasks or – incidents to the security incident.
Update FCC 20 The information security department handles vulnerabilities.
October 2023 If vulnerabilities are discovered, the report is sent to the service manager,
service administrator and information security responsible and a ticket in JIRA
is opened for it. In case a vulnerability impacts multiple services, one main
incident is logged, and sub tasks are created.
For Security incidents, the incident management procedure (IS.5_Intsidentide
haldamise kord) defines Security Incidents in 3.14.
An incident was shared during the compliance check, showing the
documentation and the sub tasks added to the incident. Reports are being send
to the Organization Director.
Status of the This finding can be closed.
finding
Table 16: Status Finding 11
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 17 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
12. [IS.07] Provision of Business Continuity and Disaster Recovery measures
Finding Results of testing the DR procedures are not documented. Therefore, no trends
Description can be analysed based on the tests performed. Furthermore, because of missing
agreed service levels (RPO, maximum allowable amount of data loss, and RTO,
maximum allowable recovery time), it cannot be checked if the recovery
measures still ensure the service levels to be achieved or if improvements are
needed. Looking at the provided disaster recovery plans, it seems last tests have
been performed in 2019.
Recommendation
Document the results (including possible findings) of testing the DR measures /
procedures. Analyse the findings and trends (in for example RTO) and identify
and implement improvements (in actual measures or documentation like the BCP
or DR plans) if applicable.
Update FCC 20 The procedure states that the DR Plan must be retested depending on the SLA.
October 2023 DR Tests are conducted twice per year.
The Disaster recovery plan was updated (mainly to clarify and add more
context/content).
The NCPeH has provided the report on the last DR test (conducted 18.08.2023).
Status of the This finding can be closed.
finding
Table 17: Status Finding 12
3 OVERALL CONCLUSIONS
The table below provides a summary of the number of findings and their classifications per domain.
Finding/ Control & Title Status
Observation
a General Observation: Links in documentation to Closed
the former EC confluence pages
1 [LO.2] Organization of the NCPeH and the Closed
National Infrastructure
2 [LO.4] Handling of the legislative changes Closed
impacting the provision of the cross-border
services
3 [LO.5] Ensuring the protection of the cross- Closed
border health data coming from the other
NCPeHs
4 [LO.5] Ensuring the protection of the cross- Closed
border health data coming from the other
NCPeHs
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 18 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
5 [LO.10] Provision of communication and Closed
training plans
6 [OS.5] Organization of the communication Closed
processes with the other NCPeHs
7 [OS.6] Monitoring the Service Level Agreements Closed
(SLAs) with the ICT Service Providers/other
entities managing the cross-border services
8 [OS.7] Management of the Testing activities Closed
9 [OS.9] Handling the Configuration Management Closed
activities
10 [OS.10] Planning and monitoring the capacity Closed
and availability of the cross-border services
b [IS.6] Management of the Certificates Lifecycle Closed
11 [IS.5] Management of the Information Security Closed
Incidents
12ß [IS.7] Provision of Business Continuity and Closed
Disaster Recovery measures
Table 18: Overview of findings/observations and their status
All findings are now closed. We would like to thank the entire Estonian team for their openness,
constructive and proactive collaboration.
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 19 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)
4 CLOSING MEETING
The closing meeting was held on Friday, 20 October 2023 after the findings were reviewed.
The NCPeH of EE acknowledged the oucome of this compliance check.
Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB
Page 20 / 20
Document version 1.0 dated 07/11/2023
Confidentiality: Sensitive non-classified (SNC)