Skip to main content

Sovereign cloud: Building a future-proof health care platform for Sana

Introduction

For Sana IT Services GmbH, one of Germany's leading health care providers, building a secure cloud platform as part of a hybrid and multi-cloud strategy is a key component of digital transformation. To develop a “Made in Germany” platform, Sana partnered with STACKIT and teamed with Deloitte Germany for the design and implementation. The focus is on both technical implementation and targeted capability building. Through knowledge transfer and a structured handover, Sana will be able to independently operate and further develop the cloud platform—with targeted support available if required.

Digital sovereignty is essential for health care as part of critical infrastructure.

The situation

With more than 41,000 employees, 46 hospitals, and 57 medical care centers nationwide, Sana is one of the largest private hospital operators in Germany. The company is pursuing an ambitious digital transformation, including a central cloud platform to standardize IT applications and make them centrally available to Sana team. With the introduction of the electronic patient record system (ePA 3.0), Sana decided to integrate this new technology into a modern, cloud-based ecosystem from the outset. Compared with a decentralized application landscape, this approach offers considerable advantages in terms of flexibility, security, efficiency, and innovation across the group.

To help ensure data sovereignty and compliance with such regulations as the GDPR, BSI-C5, and the Hospital Future Act (KHZG), patient data had to remain in Germany. To increase flexibility in application selection and mitigate vendor lock-in, controlled interoperability through standardized interfaces was also necessary. Additional requirements from Sana included transparent control and governance (control of data flows and centralized rights management), business-critical resilience (availability and cybersecurity), and the capability to innovate (AI, analytics, telemedicine, and research).

In addition to these points, there were two other important aspects. First, ePA-related components had to be implemented in selected clinics during the initial expansion phase, under demanding regulatory conditions and a tight timeline—significantly increasing the delivery pressure. Second, a systematic transfer of knowledge was necessary to enable Sana to operate and further develop the platform independently, or with targeted support, in the future.

“The partnership between Sana and STACKIT strengthens our digital sovereignty. It paves the way for a ‘Made in Germany’ cloud platform on which we can securely continue to develop scalable digital applications.”

-Stefanie Kemp, Chief Transformation Officer and Member of the Executive Board of Sana Kliniken AG

The solution

The extensive requirements made it clear that setting up and operating a future-proof cloud platform required more than just technological know-how. For this reason, Sana collaborated with Deloitte to support the project, given its extensive experience in the health care industry, Cloud experience, and demonstrated operational capabilities. STACKIT, a German provider of sovereign cloud solutions, was also engaged to work with Sana and Deloitte. STACKIT—part of Schwarz Digits, the IT and digital division of the German Schwarz Gruppe—offers infrastructure-as-a-service (IaaS) and platform-as-a-service (PaaS) solutions that are entirely hosted in German data centers. 

Implementation took place in four steps according to Deloitte's Cloud Transformation Playbook. This involved Deloitte specialists from Cloud Strategy & Transformation, Cloud Engineering & Platform Development, and the Deloitte Operate team, who worked closely with the Sana Clinics IT team throughout. First, the cloud architecture was defined based on requirements and Deloitte leading practices. Second, rapid assessments were used to determine suitable approaches for integrating the various applications into the target architecture model. Third, they set up the cloud landing zone on STACKIT as a secure framework for the platform and implemented scalable Kubernetes clusters. These form the foundation for the ePA-relevant OmniConnect software and other forward-looking services. Lastly, the initial cloud applications were rolled out in selected clinics.

The newly established cloud operating model also involved creating corresponding roles (e.g., service owners). This was implemented in stages: initially, the roles were staffed jointly by Deloitte and Sana, before handing them over completely to the Sana teams. To prepare the Sana teams for their new tasks and build the necessary skills, Deloitte conducted targeted cloud training courses in parallel, covering topics ranging from governance and Kubernetes to automation. The training content was the same as that used by Deloitte for its own training courses. STACKIT’s specialists were also closely involved in the project, for example, to troubleshoot problems and clarify complex technical concerns, including daily tri-teaming formats. A joint Project Management Office (PMO) and a shared decision and risk log helped manage complex stakeholder interests efficiently.

“By working with STACKIT as our platform partner and Deloitte on project implementation, we have laid the foundation for a secure cloud platform. It was important to us to take an approach that combines implementation and empowerment, so that Sana IT Services can continue to operate and expand the platform independently.”

-Tobias Eimermacher, Managing Director of Sana IT Services GmbH

The impact

Digital transformation poses challenges for the health care industry, including data protection, IT security, and flexible service provision. With its new sovereign cloud platform, Sana has established a secure and scalable foundation for the next steps in its transformation roadmap. The platform benefits employees and patients alike by enabling innovative, secure services such as electronic patient records and streamlined processes, supporting an effective, flexible, modern working environment. 

This project is just one of several initiatives Sana is implementing with Deloitte. Depending on priorities and constraints, additional applications are being rolled out step by step, such as workplace and messenger solutions and a hospital information system (HIS). Advanced AI use cases and analytics applications are also in the pipeline.

“Digital sovereignty is essential for health care as part of critical infrastructure. Sensitive data must be subject to German and European law without exception. With STACKIT, we can guarantee this. We are proud to have created a forward-looking, sovereign platform with Sana and Deloitte, and we look forward to continuing to develop it together.”

-Bernd (Bernie) Wagner, CEO of STACKIT and Member of the Executive Board of Schwarz Digits

About the collaboration

Sana, Deloitte, and STACKIT have implemented a sophisticated and innovative project with sovereign cloud that resonates with the spirit of the times. It is also relevant for many other companies and organizations in the critical infrastructure sector and regulated industries. This collaboration demonstrates the potential of a sovereign cloud ecosystem that’s “Made in Germany” - integrating infrastructure, security, and delivery.

“We are delighted with the successful outcome of this strategic project, in which we designed and built a secure, scalable cloud for Sana in a very short time. The close collaboration between Deloitte, Sana and STACKIT, as well as Deloitte's technology and industry knowledge and experience, are the cornerstones of this flagship project for the health care sector and other industries where digital sovereignty is crucial.”

-Dr. Benedikt Ernst,Director, Cloud Strategy & Transformation, Deloitte Germany

Explore our capabilities

Did you find this useful?

Thanks for your feedback