Hospital cybersecurity: what the NIS2 Directive requires
What NIS2 requires of hospitals: ten measures, incident reports at 24 h, 72 h and one month, board liability, status in Romania, Moldova, Austria, Poland.
The NIS2 Directive requires medium-sized and large hospitals in the European Union to manage cyber risk through ten minimum measures, to report significant incidents within 24 hours, 72 hours and one month, and it makes management accountable. Romania transposed it at the end of 2024, Poland's and Austria's laws apply from 2026, and Moldova has had its own law since 2025.
Why are hospitals a target for cyberattacks?
Hospitals are targeted because they hold highly sensitive data and cannot afford to stop, which makes them open to extortion. In 2023, Member States reported 309 significant cybersecurity incidents in the health sector, more than in any other critical sector, according to the European Commission. On the EU's CIRAS incident platform, health accounted for 24% of all incidents that year, the highest volume of any sector, according to the NIS360 report of ENISA, the European Union Agency for Cybersecurity.
CHARTBLOCK0
Ransomware is malicious software that encrypts files and demands a ransom for the decryption key. According to ENISA, which analysed health-sector incidents from January 2021 to March 2023, 43% of ransomware incidents were also coupled with a data breach or data theft. The threat types from the same analysis are covered in our article on hospital digital infrastructure and interoperability.
CHARTBLOCK1
ENISA places health in the "risk zone", together with public administration and other sectors with maturity gaps. The sector's specific problems are complex supply chains, legacy systems and poorly secured medical devices. Health scores 7 out of 10 for dependency on information technology, with very few manual fallback options for core processes, according to NIS360.
What is the NIS2 Directive and which hospitals does it cover?
The NIS2 Directive is the European Union's framework law for the cybersecurity of critical sectors: Directive (EU) 2022/2555, which replaced the first NIS Directive and had to be transposed by Member States by 17 October 2024. Annex I applies it to the health sector, which first of all includes healthcare providers, meaning any person or entity legally providing healthcare, plus EU reference laboratories and parts of the pharmaceutical and medical device industries.
The main criterion is size. The Directive applies to entities that are at least medium-sized enterprises under the EU definition of SMEs (Recommendation 2003/361/EC). A large hospital becomes an essential entity, a medium-sized one an important entity. There is an exception that matters in healthcare: regardless of size, the Directive also covers an entity whose disruption "could have a significant impact on public safety, public security or public health" (Art. 2(2)(c)).
The difference between the two categories lies mainly in supervision and in the fine ceilings; the core obligations, the measures in Article 21 and the reporting in Article 23, are the same.
What does NIS2 require of a hospital?
NIS2 requires a hospital to take technical, operational and organisational measures that are "appropriate and proportionate" to the risk, to report incidents and to involve management directly. Article 21 lists ten minimum measures, based on an "all-hazards approach":
- policies on risk analysis and information system security;
- incident handling;
- business continuity: backup management, disaster recovery, crisis management;
- supply chain security, including relationships with direct suppliers;
- security in the acquisition, development and maintenance of systems, including vulnerability handling;
- assessing the effectiveness of the measures;
- basic cyber hygiene and training;
- cryptography and, where appropriate, encryption;
- human resources security, access control and asset management;
- multi-factor authentication, secured voice, video and text communications and secured emergency communications, where appropriate.
For suppliers, Article 21(3) requires hospitals to take into account the vulnerabilities of each direct supplier and the quality of its security practices, including secure development procedures.
Article 20 moves responsibility to the top: management bodies approve the measures, oversee their implementation and can be held liable for infringements. Board members must follow training, and organisations are encouraged to offer similar training to employees on a regular basis.
Under NIS2, cybersecurity can no longer be delegated entirely to the IT department: the hospital's management approves the measures and answers for them.
Fines are set by each Member State, but the Directive fixes minimum ceilings (Art. 34). For infringements of Articles 21 or 23, an essential entity can face a fine with a maximum of at least EUR 10 million or 2% of total worldwide annual turnover, and an important entity a maximum of at least EUR 7 million or 1.4%, whichever is higher. Member States may decide separately whether and how far public administration entities are fined.
How is an incident reported under NIS2?
A significant incident is reported in three fixed stages: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. An incident is "significant" if it has caused or can cause severe operational disruption or financial loss for the entity, or considerable material or non-material damage to others (Art. 23(3)). Reports go to the CSIRT (computer security incident response team) or to the competent authority.
The CSIRT must respond, where possible within 24 hours of the early warning, with initial feedback and, on request, operational guidance, and the mere act of notification does not increase the reporting entity's liability (Art. 23).
CHARTBLOCK2
If the incident involves patient data, the GDPR obligation to notify a personal data breach applies alongside NIS2, with its own deadline and its own authority. We explain it in our article on GDPR in healthcare, controllers and processors.
What did the February 2024 attack on Romanian hospitals show?
The February 2024 attack showed that a single software supplier can become the entry point to dozens of hospitals in one night. Romania's National Cybersecurity Directorate (DNSC) investigated an attack with the Backmydata ransomware, from the Phobos family, which encrypted the servers running the Hipocrate hospital information platform used by many hospitals, according to DNSC data reported by Radio Free Europe.
On the first evening, DNSC confirmed 21 affected hospitals, and another 79 facilities were disconnected from the internet for checks; the number of affected hospitals later rose to more than 25. The attackers demanded a total ransom of EUR 157,000 in Bitcoin, and the authorities advised against paying. Most affected hospitals had recent backups, one to three days old, except one with backups that were 12 days old. The recent backups could allow easier restoration of the data, according to DNSC.
One detail matters for NIS2: for the affected hospitals, DNSC was informed by the application's supplier, before any formal notification from the hospitals, according to DNSC. There are three lessons. Recent backups, where they existed, made it possible to restore without depending on the attackers, according to DNSC. A shared platform became a single point of failure for all of its clients. And the reporting obligation remains the hospital's, even if the supplier reports too.
Where do Romania, Austria, Poland and Moldova stand?
The four countries are at different stages: Romania has applied NIS2 since 31 December 2024, Poland and Austria have new laws in force since 2026, and Moldova, a candidate country, has its own law partly aligned with NIS2.
| Country | Legal act | Authority or response team | Status, according to official sources |
|---|---|---|---|
| Romania | Emergency Ordinance 155/2024, approved by Law 124/2025 | DNSC (also the national CSIRT) | In force since 31 December 2024; DNSC Order 1/2026 sets the measures and the self-assessment |
| Austria | NISG 2026, BGBl. I No. 94/2025 | Federal Office for Cybersecurity | In force since 1 October 2026; registration within three months |
| Poland | National Cybersecurity System (KSC) Act, amended for NIS2 | CSIRT CeZ, the sectoral team for health | In force since 3 April 2026; register by 3 October 2026 |
| Moldova | Law No. 48/2023 on cybersecurity | Cybersecurity Agency | In force since 1 January 2025; partial alignment with NIS2; health included (consultation version) |
Status checked on 7 October 2026.
How does Romania transpose the NIS2 Directive?
In Romania, Emergency Ordinance 155/2024, published in Official Gazette No. 1332 of 31 December 2024, transposes NIS2 and designates DNSC as competent authority and national CSIRT. Entities in the covered sectors notify DNSC for registration within 30 days of the ordinance applying to them, submit an annual self-assessment of the maturity of their measures, endorsed by management, and essential entities submit a plan to remedy deficiencies within 30 days. On 27 August 2026, DNSC Order 1/2026 was published, approving the risk-management measures and the self-assessment methodology.
How does Austria apply the NIS2 Directive?
In Austria, NISG 2026 (Network and Information Systems Security Act 2026) was adopted by the National Council on 12 December 2025 and published on 23 December 2025. Its main provisions apply from 1 October 2026, and the competent authority is the new Federal Office for Cybersecurity (Bundesamt für Cybersicherheit), reporting to the Ministry of the Interior. Entities have three months from entry into force to register.
How does Poland apply the NIS2 Directive?
In Poland, the amendment to the National Cybersecurity System (KSC) Act entered into force on 3 April 2026. The registration deadline was 3 October 2026, the requirements must be implemented by 3 April 2027, and the first audit of essential entities and administrative fines are possible after 3 April 2028, according to the Ministry of Digital Affairs. Health has its own sectoral team, CSIRT CeZ, within the e-Health Centre (Centrum e-Zdrowia), which publishes an annual report with incident data.
CHARTBLOCK3
In 2025 there were 1,441 incidents, about 40% up on the 1,028 in 2024, including 5 serious incidents and 8 ransomware attacks, according to CSIRT CeZ. The rise may also reflect better detection and reporting, not only more attacks; ENISA makes the same point about European data. Computer fraud, such as phishing that imitates health institutions, was the most frequent category. The team's survey, answered by 696 healthcare facilities, shows progress on policies but gaps at management level:
CHARTBLOCK4
The same report notes that more than 43% of facilities have no vulnerability management process and more than 16% do not report incidents.
What cybersecurity framework does Moldova have?
In Moldova, NIS2 is not binding, but the country has chosen to move closer to it. Law No. 48/2023 on cybersecurity, adopted on 16 March 2023, has been in force since 1 January 2025 and ensures alignment with NIS2, "albeit only partially", according to the Government. The competent authority is the Cybersecurity Agency, set up by Government Decision 1028/2023, which combines supervision and control with the roles of national incident response team and single point of contact.
Government Decision 860/2024 on identifying service providers and Government Decision 562/2025 on security obligations followed, with 12- and 18-month deadlines for audit reports. In the version put to public consultation, the list of critical sectors included health, with healthcare providers as essential providers above the medium-enterprise threshold and important ones at medium-enterprise level. For 2026, the responsible ministry and the Agency are to draft amendments to the Contravention Code so that non-compliance can be sanctioned, according to the Government.
What is the EU doing specifically for hospitals?
Alongside NIS2, the European Commission presented a European action plan on the cybersecurity of hospitals and healthcare providers on 15 January 2025. The plan has four priorities: prevention, detection, response and recovery, and deterrence. Its centrepiece is a European Cybersecurity Support Centre hosted by ENISA, providing guidance, tools, services and training tailored to hospitals, according to the Commission.
In concrete terms, the plan announces an EU early warning service with near-real-time alerts by 2026, cybersecurity vouchers for smaller facilities and ransomware response playbooks, rolled out progressively in 2025 and 2026. Security is also a precondition for the data exchange described in our article on the European Health Data Space (EHDS) and for access to data for research, explained in our article on secondary use of health data for AI.
What this means for a hospital in Romania or Moldova
Most of the NIS2 work is organisational and can start without a large budget: status, inventory, management decisions. The list below follows Article 21 and the recommendations of ENISA and CSIRT CeZ. The sources consulted give no cost estimates for a hospital's NIS2 compliance; the real budget comes out of the inventory and risk analysis in steps 1 and 2.
- Check your status and registration. In Romania, confirm whether the facility is an essential or important entity and whether the notification to DNSC has been made. In Moldova, check whether the Cybersecurity Agency has identified the facility as a service provider.
- Inventory and risk analysis, approved by management. A list of systems, data, suppliers and external connections; the main risks and who owns each of them.
- Isolated and tested backups. ENISA recommends encrypted offline backups of critical data; CSIRT CeZ stresses regular restore tests, the only proof that a backup works.
- Multi-factor authentication for remote access, administrator accounts and systems holding patient data.
- Network segmentation. Medical equipment, clinical servers, administrative workstations and the visitor network in separate zones, so that an attack does not spread.
- Vulnerability and patch management, including a list of systems no longer supported by their manufacturer.
- Security clauses in supplier contracts: prompt incident notification to the hospital, controlled remote access, the right to audit.
- An incident response plan, with roles, contacts, templates for the 24-hour and 72-hour reports and an annual tabletop exercise.
- Training: management, as Article 20 requires, and all staff, on phishing and basic cyber hygiene.
We are a vendor too; these questions apply to us as well. Questions to ask any software or IT service vendor before signing, including for doctor-patient video consultation platforms:
- How quickly will you tell us about an incident that could affect our data or systems?
- Who on your team has access to our systems, from where and with what type of authentication?
- How do you develop and update your product securely, and how do you handle vulnerabilities?
- Where are the data hosted, who are your subcontractors, and how will you export all our data at the end?
- Can you provide the technical information we need for the 24-hour and 72-hour reports?
Consdinamic, a company from the Republic of Moldova registered in 2008, builds software and AI to order and goes deepest in healthcare. Our projects start from the same principles: data protection from the first day, in line with GDPR, access limited to what is strictly necessary, and data that stay under the client's control.
Conclusion
NIS2 turns hospital cybersecurity from a technical issue into a management obligation, with ten minimum measures, fixed reporting deadlines and high fine ceilings. Health reported more significant incidents than any other sector in 2023, and the 2024 attack in Romania showed how fast an incident spreads through shared suppliers. The legal framework differs from country to country, but the order of steps stays the same: status and registration, an approved risk analysis, tested backups, multi-factor authentication, segmentation, supplier clauses and a rehearsed incident plan.
Frequently asked questions
Does the NIS2 Directive apply to hospitals?
Yes. Annex I of Directive (EU) 2022/2555 lists healthcare providers in the health sector, which covers public and private hospitals. Hospitals of at least medium size are in scope; large ones are normally essential entities and medium-sized ones important entities. A Member State can also include a smaller provider if its disruption could have a significant impact on public health.
How quickly must a cyber incident be reported under NIS2?
Article 23 requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report no later than one month after the notification. Reports go to the national computer security incident response team (CSIRT) or the competent authority.
Who in hospital management is responsible for NIS2?
Under Article 20 of the NIS2 Directive, the hospital's management bodies approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements. Members of the management body must follow cybersecurity training. For public institutions, the liability rules for public officials remain those of national law.
What fines does NIS2 provide for?
For infringements of Articles 21 or 23, essential entities face fines with a maximum of at least EUR 10 million or 2% of total worldwide annual turnover, and important entities a maximum of at least EUR 7 million or 1.4%, whichever is higher. Member States may set separate rules for public administration entities.
Who is the NIS2 authority in Romania and in Moldova?
In Romania, the competent authority and national CSIRT is the National Cybersecurity Directorate (DNSC), under Emergency Ordinance 155/2024. Moldova is not an EU Member State, but its Law No. 48/2023 on cybersecurity has applied since 1 January 2025, and the competent authority is the Cybersecurity Agency.
What should a hospital do first to comply with NIS2?
Start by confirming the hospital's status (essential or important entity) and registering with the authority, then build an inventory of systems and a risk analysis approved by management. Quick-impact measures follow: isolated and tested backups, multi-factor authentication, network segmentation, security clauses in supplier contracts and an incident response plan that includes the reporting deadlines.
- Directive (EU) 2022/2555 (NIS2), EUR-Lex, 2022 — Art. 2, 3, 20, 21, 23, 34, 41 and Annex I: scope, health sector, minimum measures, management liability, reporting deadlines, fines
- European Commission, Commission unveils action plan to protect the health sector from cyberattacks, 15 January 2025 — 309 significant health-sector incidents reported by Member States in 2023; four priorities; ENISA support centre; early warning by 2026
- ENISA, Threat Landscape: Health Sector (January 2021 - March 2023), July 2023 — incidents analysed from January 2021 to March 2023: 43% of ransomware incidents coupled with a data breach; reported increases may also reflect more mature reporting; impact: data 43%, healthcare services 22%, other services 26%; offline encrypted backups
- ENISA, NIS360 2024, February 2025 — health in the 'risk zone'; 24% of all incidents reported in CIRAS in 2023; ICT dependency 7/10; legacy systems and poorly secured medical devices
- Government of Romania, Emergency Ordinance 155/2024 on the cybersecurity of networks and information systems, 2024 — NIS2 transposition; DNSC as competent authority and national CSIRT; registration notice within 30 days; annual self-assessment and remediation plan
- DNSC, Order No. 1 of 6 August 2026, Official Gazette No. 712 of 27 August 2026 — risk-management measures and maturity self-assessment methodology; confirms that Emergency Ordinance 155/2024 was approved by Law 124/2025
- Radio Free Europe Romania (Europa Liberă), Number of hospitals hit by cyberattack rises, 12-14 February 2024 — DNSC data on the Backmydata attack: 21 hospitals confirmed at first, 79 facilities disconnected, more than 25 affected, EUR 157,000 ransom, backups 1-3 days old
- Republic of Austria, BGBl. I No. 94/2025, NISG 2026, RIS, 23 December 2025 — Austrian transposition law; Federal Office for Cybersecurity, directly subordinate to the Minister of the Interior (§ 3a); in force 1 October 2026; registration within three months
- Ministry of Digital Affairs (Poland), Amendment to the National Cybersecurity System Act enters into force, 2 April 2026 — in force 3 April 2026; register by 3 October 2026; implementation by 3 April 2027; first audit and fines after 3 April 2028
- CSIRT CeZ (e-Health Centre, Poland), Report 2025: Cybersecurity landscape in the healthcare sector, 2026 — 435, 1,028 and 1,441 incidents in 2023-2025 (+40% in 2025); 5 serious incidents and 8 ransomware attacks in 2025; survey of 696 facilities; recommendations
- Government of the Republic of Moldova, Explanatory note to draft No. 889/MDED/2025, 2025 — Law 48/2023 adopted 16 March 2023, in force 1 January 2025, partial alignment with NIS2; Government Decisions 1028/2023, 860/2024, 562/2025; Cybersecurity Agency; EU candidate status
- Government of the Republic of Moldova, Draft decision on the identification of service providers (public consultation), 2024 — health sector: healthcare providers essential above the medium-enterprise threshold, important at medium-enterprise level
Tell us what you need. We come back with a prototype, not with slides.