European Commission /*Your ref.
[email protected] 07.09.2021 Our ref. 6-2/3513-1
HOIA ESI final reports to European Commission
Dear colleagues,
As per Grant Agreement Number LC-01591187, I am sending you the final financial and technical
report for Estonian national contact tracing application. The reports are electronically signed by
HWISC director, Katrin Reinhold.
Yours sincerely,
Katrin Reinhold
Director
Liisa Lvova
[email protected]
Uus-Tatari 25 / 10134 Tallinn / 694 3900 /
[email protected] / www.tehik.ee / registry code 70009770
Agreement number: ESTONIA – SI2 835429 on BL 180701
Annex IV – Model technical implementation report
Activation of Emergency Support Instrument in response to the COVID-19
Pandemic - Adaptation of national contact tracing app and backend
solutions to join the European federation gateway service
Project number: LC-01591187
Project acronym: GRANT AGREEMENT FOR AN ACTION UNDER THE
EMERGENCY SUPPORT INSTRUMENT
1) Start date of the action: 05/11/2020
2) End date of the action: 03/07/2021
3) Detailed description of the action:
Connection of a contact tracing app to the EFGS within the EU/EEA
In order to connect our existing national DP3T and GAEN based contact tracing app
„HOIA“ to EFGS we first started to analyze and collect information from other member
states and DP3T dev team about the best options for us to do so. We took part in the Joint
Controller Subgroup meetings. We decided to upgrade DP3T to a newer version and
downloaded the sample codes from EFGS. As our backend consists of microservices, it
was only logical to add the connection to EFGS as a separate backend microservice that
reads and writes the keys from and to the DP3T backend microservice.
In order to understand the biggest challenge for us one must understand that HOIA uses
one of a kind infection confirmation process, that is initiated from inside the app, but the
positive COVID-19 diagnosis is checked directly from the national Health Information
System through the front end interface of our national patient portal that allows the user to
authenticate him/herself, while keeping the user anonymous regards to the contents of the
app.
As “HOIA” was built using privacy by design principles and before joining the EFGS, all
the data in the app was considered anonymized by the Estonian legal team, we had to
rewrite the privacy policy and change the statute of the Health Information System. Also
we had to add an extra page to the infection confirmation flow to ask consent from the
users for sharing their data with EFGS in order to be compatible with the pseudonymized
approach of EFGS.
Adding the consent in a form that can be reproduced to fully anonymized app and be
accepted by our legal team was impossible, so we had to integrate the consent asking page
to our national patient portal inside the infection confirmation process that is initiated from
HOIA, but takes place inside the national patient portal in order to keep the personalized
data separated from the anonymous keys of contact tracing.
We also ran several rounds of user tests and updated our apps user interface
and https://hoia.me/ webpage. We made the content easier for the users to understand and
answer any questions regarding interoperability.
We updated our security documentation to meet the new scope of the app.
Software development activities for the adaptation or extension of a national backend
server of a contact tracing app, or of the contract tracing app itself, to fulfil the
requirements of the EFGS, for the purpose of exchanging contact tracing keys (and
other relevant information), across national borders, with other national backend
servers belonging the EU or the EEA;
We started by analyzing all the different options we had on the technical side.
We created all necessary development documentation and synchronized it between
UX, DEV, and legal team.
We created development tasks to be implemented the EFGS connection as a separate
microservice.
We ran several rounds of UX test for the new feature. (App, infection confirmation
flow and hoia.me) (NB! HOIA links to hoia.me from inside the app for links like
“more information” or “how it works”)
We divided the development into tasks for Android and IOS teams.
We tested each step of the development separately
After all required functionality was added we ran a round of 3-rd party security and
penetration testing.
We fixed all the findings and updated the security documentation
We had a weekly planning meeting and 3 standups per week to synchronize our tasks
and goals.
Preparation, testing, deployment and supporting activities for the connection of a
national backend server of a contact tracing app to the EFGS, for the purpose of
exchanging contact tracing keys, across national borders, with other national
backend servers belonging the EU or the EEA;
We had a weekly planning of PR and marketing activities, brainstorming sessions and
late night talks
Technical testing of the app and its new features were continuously tested by the dev
team and HWISC testers.
UX tests for validating the flow of the new service and its usability
New translations for the app, hoia.me webpage and privacy policy were done
Activities related to risk assessments and security plans for the national interfaces
with the EFGS.
We updated our whole documentation about HOIA (including the security documents). In
addition, we added nationally approved information about the protection of ones
smartphone and its content to hoia.me. Provided by a third party, security and penetration
tests were carried out after the development of interoperability (its findings were also
addressed and fixed).
4) Visibility of the action:
Estonian Health Board issued a press release together with HWISC, informing the users
about the interoperability option. In addition several radio interviews were carried out (in
Estonian and Russian) to talk about the applications interoperability and some overall
statistics and questions. Also an article in an Estonian newspaper Postimees.
EU logo was added inside the application, news about the apps interoperability and
information about its funding (by the European Union)
5) Date go-live connection national backend server to EFGS
30/06/2021
6) Modifications to initial planning (if applicable)
We integrated the consent asking into our patient portal inside the infection confirmer
process (as described in detailed description of the action). In addition, privacy policy had
to be totally rewritten and translated to English.
7) Any other relevant information
....
Annex VI - Financial Statement
Model of Financial Statement (to be filled in by each beneficiary )
Project Nb LC-01591187
EMERGENCY SUPPORT INSTRUMENT
Project Acronym
ESTONIA
Period from : 05.11.2020
to : 03.07.2021
Beneficiary Legal Name Health and Welfare Information System Centre
Beneficiary Short Name HWISC Beneficiary Nb
If flat-rate for indirect costs, specify % % 7
1- Declaration of eligible costs (in €)
This period Adjustments TOTAL
Personnel costs 35797,71 35797,71
Subcontracting 102967,00 102967,00
Other specific direct costs 0,00 0,00
Indirect costs 9713,53 9713,53
Total 148478,24 148478,24
Maximum Community
contribution 148478,24 148478,24
Requested Community
contribution 148478,24 148478,24
2- Declaration of receipts
Did you receive any financial transfers or contributions in kind, free of charge from third parties or did the project generate No
any income which could be considered a receipt according to Art.II.25.3 of the grant agreement ?
If yes, please mention the amount (in €) 0,00
3 - Certificate on the financial statements
Is there a certificate on the financial statements provided by an independent auditor attached to this financial statement
No
according to Art.I.4 ?
Name of the auditor Cost of the certificate (in €)
5- Beneficiary’s declaration on its honour
We declare on our honour that:
- the costs declared above are directly related to the resources used to attain the objectives of the project and fall within the definition of eligible costs
specified in Articles II.19, II.20 and II.21 of the grant agreement ;
- the receipts declared above are the only income generated by the project which could be considered as receipts according to Art. II.25.3 of the grant
agreement ;
- there is full supporting documentation to justify the information hereby declared. It will be made available at the request of the Commission and in
the event of an audit by the Commission and/or by the Court of Auditors and/or their authorised representatives.
Beneficiary’s Stamp (if applicable) Name of the Person(s) authorised to sign this Financial Statement
Katrin Reinhold
Date & Signature
signed digitally
Annex 2 - Summary Financial Report (to be filled by coordinator)
Project Acronym Project Nb Page 1/1
Reporting period from: dd/mm/yy to: dd/mm/yy
Adjustments of Requested
Beneficiary Eligible costs
Beneficiary Nb eligible costs to Total costs Community
Short Name this period Receipts
previous periods contribution
1 1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
TOTAL
Coordinator’s Stamp (if applicable) Name of the Person(s) authorised to sign this Financial Statement
Date & Signature