General Open Source Press Sovereignty

Sovereign Public Health Infrastructure: The Public Health Authority of Frankfurt Becomes a Global Red Hat Success Story

7. Jul 2026

A German Public Sector Story with Global Reach

We have exciting news to share: Red Hat has published a new global customer success story featuring the Public Health Authority of Frankfurt am Main (Gesundheitsamt Frankfurt am Main) – and VSHN as the platform engineering partner behind it.

After HIN (Health Info Net) became a global Red Hat success story earlier this year, this is now the second time within a few months that a VSHN customer project has been recognized on Red Hat’s global stage. And once again, the topic at the center of it is digital sovereignty in healthcare.

But this story adds a new dimension: it shows how sovereign, open source, cloud-native infrastructure works in the public sector – built for one of the largest public health authorities in Germany, funded by the EU, and shared openly for others to reuse.

Why This Project Matters

The Gesundheitsamt Frankfurt am Main is one of the largest public health authorities in Germany, with 300 employees across 8 departments. Its mission covers everything from pre-school health screenings and vaccination programs to hygiene inspections and public health emergencies.

During the COVID-19 pandemic, a structural problem became painfully visible: the 25 public health authorities in the state of Hesse were working with heterogeneous systems, workflows, and configurations. Sharing data between organizations was difficult – which made tracking infection chains harder than it needed to be.

The answer was not another isolated IT project. With support from the Public Health Authority of Frankfurt am Main, the state health ministry secured EUR 24 million in EU funding to modernize the digital infrastructure of public health in Hesse.

The result is GA-Lotse: an open source platform developed by cronn GmbH and run by VSHN as a managed service on Red Hat OpenShift.

Federated by Design: Sovereignty Down to the Municipality

What makes GA-Lotse special is its architecture. Instead of enforcing a single way of working on 25 different authorities, the team designed a federated, multitenant system.

Each district in Hesse operates its own customizable instance of the platform – with full ownership of its own applications and sensitive data. No private or unauthorized data is shared between departments. At the same time, the state can generate anonymized, aggregated reports for evidence-based decision making.

“We handle people’s most private and sensitive data – their individual health records. This requires strict compliance with data protection and privacy laws, so we have a high bar for data security,”

says Bianca Kastl, Product Owner at the Public Health Authority of Frankfurt am Main.

The platform was built with zero trust architecture and a modular design:

  • 21 modules and 8 separate PostgreSQL databases from the VSHN marketplace
  • Redis for caching and Keycloak for identity and access management
  • A service mesh with standard applications for user management, communication, and calendars
  • Passkeys instead of passwords and nontraceable IDs to prevent unauthorized data access
  • Hosting on Exoscale, a European cloud provider, for GDPR compliance and data sovereignty

Personal IDs are separated from medical records, and all data collected for reporting is anonymized and encrypted. A citizen getting a vaccination can be confident that the team cannot see their full medical history.

From Tender to Production in 3 Months

Public sector IT projects are not exactly famous for their speed. This one was different.

The tender was awarded in August 2024 – and the platform went live just 3 months later. The partnership between VSHN, Red Hat, and Exoscale allowed the team to deliver the platform in days and spend the remaining time on deployment, integration, and testing. That speed was not just nice to have: delivery within a year was a hard requirement to secure the EU funding.

“GA-Lotse and VSHN share a common foundation: openness, transparency, collaboration, open source, cloud-native technology, and the highest regulatory standards. I’m proud to support the digital transformation of such a vital part of our society together with our partners.”

says Aarno Aukia, Co-Founder of VSHN.

A key factor: the public health authorities did not need to become Kubernetes experts. VSHN manages the platform and provides Day 2 operations, so the teams can focus on their actual work.

“Thanks to VSHN and Red Hat, we don’t need to train our teams to carry out complex Kubernetes infrastructure management. They can focus on serving their departments and leave maintenance and development to the experts.”

says Bianca Kastl.

Real Impact on Public Health

GA-Lotse is not a pilot project. It is in production and used by several regions across Hesse today.

Applications like the preschool health screening module replace paper-based processes and help carry out 7,000 health checks and 45,000 dental screenings per year more efficiently. Parents can book preschool health assessments digitally. Hygiene inspections of clinical and corporate settings are scheduled and tracked on the platform.

“Instead of changing how people work, we built a platform that works for them. This real-world solution reflects the realities of the public health system and makes it more efficient.”

says Kastl.

And there is one more aspect we find remarkable: the organization published the solution as open source, including on openCode.de – a first for the German public health sector. Other public health authorities can benefit from the same platform, without starting from scratch.

“Together, we are setting new standards for innovation, digital transformation, and digital sovereignty in public health,”

says Prof Dr. Peter Tinnermann, Head of the Public Health Authority of Frankfurt am Main.

What This Means Beyond Hesse

For us, this success story confirms a pattern we see across Europe: digital sovereignty is moving from theory to practice – and the public sector is leading some of the most ambitious projects.

GA-Lotse demonstrates that sovereign infrastructure for the public sector is achievable today:

  • Open source instead of proprietary lock-in
  • European cloud hosting instead of dependency on hyperscalers
  • Federated data ownership instead of centralized data silos
  • Managed platform operations instead of building scarce Kubernetes expertise in every authority
  • Code published openly instead of duplicated public spending

Together with the HIN story from Switzerland, this shows that sovereign, cloud-native healthcare infrastructure is not a niche experiment anymore. It is running in production, in two countries, serving citizens every day.

A huge thank you to the Public Health Authority of Frankfurt am Main, cronn GmbH, Red Hat, and Exoscale for the excellent collaboration – and to all VSHNeers who made this project possible.

Download the Case Study

Public Health Authority of Frankfurt standardizes on Red Hat with VSHN

Learn More

👉 Red Hat Case Study

👉 HIN: Digital Sovereignty Made in Switzerland

👉 What is digital sovereignty?

👉 VSHN Public Health Authority of Frankfurt Success Story

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
General Open Source Sovereignty

Open Source as State Policy: What the EU Strategy and the Swiss Ständerat Vote Mean for IT Decision-Makers

12. Jun 2026

In the span of a few weeks, two policy signals landed that reinforce each other. The European Commission published a new open-source strategy positioning open source as central to EU technological sovereignty. Days later, the Swiss Ständerat accepted a motion for an impulse program on digital sovereignty by 30 to 7, against the Bundesrat’s recommendation. Both name the same mechanism: open-source technology as infrastructure for sovereign, independent digital states.

For Swiss organizations choosing technology stacks and cloud providers, the direction is now unmistakable.

What the EU strategy says

The Commission’s open-source strategy pursues four goals:

  1. Technological sovereignty through open source: scaling European open alternatives to non-EU proprietary solutions, including in digital identity wallets and public services.
  2. Ecosystem development: supporting startups, establishing stewardship frameworks, creating a maintenance instrument for critical open-source projects, and investing in skills.
  3. Public administration leadership: developing open-source procurement guidelines and strengthening the Commission’s Open Source Programme Office (OSPO).
  4. Standards and international cooperation: integrating open-source communities into EU standardization efforts.

The strategy takes a full lifecycle approach: from research through long-term maintenance. It explicitly names the goal of reducing dependence on non-EU technologies and increasing European control over “critical digital infrastructure, including software and hardware systems.”

This is not an abstract policy paper. It follows the EUR 180 million sovereign cloud procurement in April, where open-source technology was one of eight scored sovereignty dimensions. Open source is moving from “nice to have” to procurement criterion.

What the Ständerat decided

On June 10, the Ständerat accepted motion 22.3221 by Heidi Z’graggen (Die Mitte, Uri) calling for an impulse program to strengthen Swiss digital sovereignty. The motion demands seed funding for pilot projects in four areas:

  • Digital infrastructure
  • Open-source technologies
  • Cybersecurity
  • Artificial intelligence

Z’graggen argued that digital sovereignty is “ein zentraler Pfeiler sowohl staatlicher als auch wirtschaftlicher Handlungsfähigkeit” (a central pillar of state and business capability). She emphasized this is time-limited stimulus, not permanent state expansion: “Investitionen in offene, souveräne Technologien stärken unsere Innovationskraft, reduzieren Abhängigkeiten, schaffen Wertschöpfung” (investments in open, sovereign technologies strengthen innovation, reduce dependencies, create value).

The Parldigi parliamentary group backed the motion, citing the geopolitical situation and open source’s cost-saving potential.

Federal President Guy Parmelin recommended rejection, arguing existing strategies and funding instruments (including the “Digitale Schweiz 2026” program) already address digital sovereignty. The Ständerat disagreed, 30 to 7.

The motion now goes to the Nationalrat.

Switzerland already has the legal foundation

What makes the Ständerat vote notable is that Switzerland already has open-source legislation. The EMBAG (Bundesgesetz über den Einsatz elektronischer Mittel zur Erfüllung von Behördenaufgaben), in force since January 1, 2024, establishes:

  • Open Source by default: the federal administration must release self-developed software as open source.
  • Open Government Data: administrative data must be made accessible for free use.
  • Interoperability and open standards: interfaces must be documented and standards can be made binding.

The EMBAG was championed by National Council members Gerhard Andrey and Andri Silberschmidt, and Ständerat member Matthias Michel. When it passed, Switzerland became one of the first countries worldwide to mandate open-source publication of government software.

But a law that mandates release of government-built software is not the same as a program that funds new sovereign infrastructure. The EMBAG says “publish what you build.” The Z’graggen motion says “invest in building more.” The two are complementary: the legal framework exists, but the Ständerat believes implementation needs an impulse.

Two signals, one direction

Read together, the EU strategy and the Swiss vote point to the same conclusion:

EU Open Source StrategySwiss Ständerat Motion
ScopeEU-wide policy frameworkSwiss federal impulse program
MechanismProcurement criteria, OSPOs, maintenance fundingSeed funding for pilot projects
Open source roleCore sovereignty instrumentOne of four priority areas
StatusPublished strategyAccepted by Ständerat (30:7), Nationalrat pending
Legal basisBuilds on Cyber Resilience Act, Interoperable Europe ActBuilds on EMBAG (in force since 2024)

The convergence is not coincidental. Both respond to the same pressures: dependence on US hyperscalers, the CLOUD Act, supply chain risks exposed by geopolitical shifts, and the realization that digital sovereignty requires more than data residency. It requires control over the software stack.

What this means for Swiss organizations

Open source is becoming a compliance expectation, not just a technical preference. The EU scores it in cloud procurement. Switzerland mandates it in government software. Both are moving toward procurement frameworks that favor open, auditable technology over proprietary lock-in.

Public sector demand will grow. If the Nationalrat passes the Z’graggen motion, federal funding for open-source pilot projects will follow. Organizations positioned to deliver sovereign, open-source infrastructure, and to help public sector clients adopt it, have a structural advantage.

The EMBAG creates upstream supply. As the federal administration releases more open-source software, the ecosystem of Swiss-built, Swiss-maintained open-source components grows. This benefits private sector organizations that build on the same stack.

Geopolitical risk is now a board-level topic. Z’graggen’s core argument (dependence on foreign technology providers endangers long-term competitiveness) is the same argument regulated industries have been making for two years. The Ständerat vote gives it political legitimacy beyond the compliance department.

Where VSHN fits

VSHN has operated on the thesis that open source and sovereignty are inseparable since its founding. Every service in the VSHN Application Catalog runs on open-source software (PostgreSQL, MariaDB, Redis, Keycloak, GitLab, OpenBao, Forgejo), operated by a Swiss team on Swiss infrastructure.

The policy direction confirmed by both Brussels and Bern validates this approach:

  • Technology sovereignty: 100% open-source stack, active contributor to CNCF projects (K8up, Crossplane providers), Project Syn, and APPUiO.
  • EMBAG alignment: VSHN’s entire toolchain is open source and auditable. Government clients adopting VSHN services remain EMBAG-compliant without additional effort.
  • Operational sovereignty: Swiss 24/7 operations team, infrastructure-agnostic deployment (customer chooses provider), no foreign vendor dependency.

For organizations evaluating their technology stack against the direction set by EU and Swiss policy, the question is: does your infrastructure depend on a foreign vendor’s proprietary platform, or is it built on open, sovereign technology that you control?

Sources

Aarno Aukia

Aarno is Co-Founder of VSHN AG and provides technical enthusiasm as a Service as CTO.

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us