BlackTree Security · Infrastructure · Automation · AI

Healthcare Cybersecurity in Europe: From Guidance to Operational Readiness

A cyberattack on a hospital is not only an information-security incident. When records, diagnostics, communications or connected devices become unavailable, cybersecurity becomes part of patient safety.

That is the central idea behind the European action plan on the cybersecurity of hospitals and healthcare providers. Presented by the European Commission in January 2025, the plan is being rolled out through 2025 and 2026 with support from Member States, healthcare organisations, the cybersecurity community and ENISA.

The plan is not a replacement for existing law. Healthcare providers already operate in a dense regulatory environment that includes GDPR, NIS2 and national healthcare-security requirements. Products and suppliers are also affected by rules such as the Cyber Resilience Act.

The action plan is better understood as an attempt to make those obligations more usable. It adds sector-specific guidance, support, early warning, training and response capabilities around organisations that cannot tolerate extended downtime.

The practical question for hospitals is not whether another European initiative exists. It is whether the initiative changes how they prepare for the next incident.

Why healthcare requires a different resilience model

Many organisations can temporarily move to manual processes when technology fails. Healthcare can do the same for some functions, but the safe window may be short.

Electronic health records, imaging, laboratory systems, pharmacy platforms, identity services, medical devices, appointment systems and communications are increasingly connected. A single incident can affect clinical and administrative work at the same time.

The consequences are also difficult to prioritise. Restoring the system with the most users may not be the safest choice. A less visible application can be essential to urgent care, medication or diagnostics.

This is why healthcare resilience must begin with clinical impact rather than technical asset value.

The four priorities of the EU plan

The action plan is organised around four priorities: prevent, detect, respond and recover, and deter.

These priorities are useful because they describe a lifecycle rather than a collection of products.

Prevent

Prevention includes cybersecurity maturity assessments, guidance on critical practices, staff training, risk assessment and support for implementing improvements.

For a hospital, prevention should include ordinary technical hygiene, but it must also account for clinical constraints. A vulnerable system may support equipment that cannot be patched without vendor approval. A network segment may contain devices with long lifecycles and limited logging. A third party may need remote access to maintain a critical platform.

The correct response is not to accept those risks silently. It is to make them visible, reduce exposure through compensating controls and establish a plan for replacement or stronger support.

Detect

The plan includes work on an EU-wide early-warning service for the health sector and a European known-exploited-vulnerabilities catalogue relevant to medical devices, electronic health records and ICT providers.

Shared intelligence can give healthcare organisations earlier notice of attacks that move across the sector. Its value depends on local preparation. An alert is useful only when a hospital can determine whether the affected product, supplier or vulnerability exists in its environment.

That requires an asset and dependency inventory that includes medical technology, software versions, hosting, supplier ownership and clinical use.

Respond and recover

The action plan supports a healthcare-specific role for the EU Cybersecurity Reserve, sector playbooks, exercises, rapid-response services and ransomware recovery capabilities.

External support can be essential during a crisis, but it should strengthen an internal response structure rather than replace it. Hospitals still need decision owners, tested escalation routes, isolated recovery capability, access to logs and a reliable method for communicating when normal systems are unavailable.

Recovery also needs clinical validation. Restoring a database is not enough if users cannot trust that records are complete, current and correctly associated with patients.

Deter

Deterrence includes cooperation against ransomware actors, disruption of criminal infrastructure and measures intended to reduce the economics of attacks.

An individual hospital cannot dismantle a ransomware group, but it can reduce the attacker’s leverage. Strong backups, controlled privileged access, network separation, fast detection and rehearsed decision-making make it more difficult to turn encryption or data theft into a prolonged crisis.

A European support centre will not remove local responsibility

ENISA is establishing a European Cybersecurity Support Centre for hospitals and healthcare providers. The centre is intended to provide tailored guidance, tools, services and training.

This can improve consistency and reduce the burden on organisations that lack specialist resources. It may also help distribute threat information more quickly across Member States.

Healthcare organisations should still decide how the centre fits into their operating model:

  • Who receives its alerts?
  • Who checks whether the organisation is affected?
  • How are actions prioritised against clinical risk?
  • Who can request rapid-response support?
  • What evidence and system access can be shared during an incident?
  • How does the route interact with national authorities, the NCSC and sector organisations such as Z-CERT?

Support is most effective when the relationship is understood before an emergency.

The Netherlands already has useful building blocks

Dutch healthcare organisations are not starting from zero. NEN 7510 provides a sector-specific information-security framework, while Z-CERT supports threat sharing and incident response across healthcare. The NCSC provides national coordination and guidance.

The Cyberbeveiligingswet implementing NIS2 enters into force on 15 August 2026. Healthcare is one of the covered sectors, and organisations within scope face duties relating to registration, risk management and incident reporting.

This creates an opportunity to avoid parallel programmes. NEN 7510, NIS2 readiness, GDPR controls and the EU healthcare action plan should use the same service maps, risk assessments, incident process and evidence where possible.

The organisation needs one accurate description of how care depends on technology, not four different compliance versions.

GDPR and patient data remain part of every incident

Healthcare data is highly sensitive, but confidentiality is only one part of the risk. Integrity and availability also matter.

An attack may expose patient information, change it, make it unavailable or create uncertainty about whether it can still be trusted. The incident response process must therefore include privacy and clinical decision-making from the start.

GDPR notifications have their own thresholds and timelines. NIS2 reporting focuses on significant cyber incidents and operational disruption. A healthcare incident may trigger both frameworks, even though the information required by each authority is not identical.

A combined classification process should assess:

  • whether personal data is affected;
  • whether data may have been altered;
  • which clinical services are disrupted;
  • the number and vulnerability of affected people;
  • the expected duration and geographic reach;
  • whether a supplier or medical device is involved;
  • whether the incident is still spreading;
  • which notifications are required.

The process should work with incomplete information. Waiting for certainty can cause an organisation to miss the earliest reporting deadline.

Medical devices make asset management harder

Hospitals contain a mixture of conventional IT, operational technology and regulated medical devices. Some systems run for many years, depend on specialised support or cannot accept standard endpoint tools.

An inventory needs more than an IP address and device name. It should record:

  • clinical purpose and patient-safety impact;
  • manufacturer and support provider;
  • software and firmware versions;
  • network location and communication paths;
  • remote-access method;
  • responsible internal owner;
  • maintenance windows and constraints;
  • available logs and recovery procedures;
  • replacement or end-of-life plan.

This information allows threat intelligence to become action. Without it, a critical warning can turn into a manual search across departments while the exposure remains open.

Suppliers are part of the care pathway

The availability of healthcare services often depends on software vendors, cloud providers, laboratories, device manufacturers, telecommunications providers and managed service partners.

Supplier assurance should focus on the conditions that matter during disruption:

  • How quickly must the supplier notify the hospital?
  • Is support available at night and during weekends?
  • Can the supplier isolate one customer without affecting others?
  • Does remote access use named identities and strong authentication?
  • Where are backups and logs held?
  • Are subcontractors involved in a critical function?
  • How is a severe vulnerability communicated and remediated?
  • What happens if the supplier itself cannot operate?

The contract should support these questions, but exercises should test the relationship.

Make recovery a clinical exercise

Technical recovery tests often stop when systems are online. Healthcare needs to go further.

A useful exercise follows the service from incident to patient care. Can staff access the right records? Are laboratory and imaging results current? Can medication processes operate safely? Are temporary paper processes reconciled when systems return? Can clinicians see which data was created during the outage?

The exercise should include technology, clinical leadership, privacy, communications, facilities, suppliers and executives. It should also test a scenario in which the primary communications channel is unavailable.

The outcome is not a pass or fail. It is a list of assumptions that proved correct, assumptions that failed and improvements that have an owner.

Use the action plan as an accelerator

The EU healthcare cybersecurity action plan can provide valuable sector-specific support during 2026: shared guidance, training, early warning, maturity assessment and response resources.

Its greatest value will come when hospitals connect those resources to existing obligations and local operations.

Patient safety, GDPR, NIS2, device security, supplier risk and incident recovery are not separate problems during a ransomware attack. They become one problem at the same time.

Healthcare resilience should be designed the same way: as one programme that protects care, not a collection of compliance projects competing for the same people.

Sources and further reading

This article provides general technical and operational context, not legal or medical advice.

Leave a Reply

Your email address will not be published. Required fields are marked *