What we do Pilot Technologies Blog About us Contact Write to us

Hospital cybersecurity: what the NIS2 Directive requires

15 minConsdinamic

What NIS2 requires of hospitals: ten measures, incident reports at 24 h, 72 h and one month, board liability, status in Romania, Moldova, Austria, Poland.

The NIS2 Di­rec­tive requires medium-sized and large hos­pi­tals in the European Union to manage cyber risk through ten minimum measures, to report sig­nif­i­cant in­ci­dents within 24 hours, 72 hours and one month, and it makes man­age­ment ac­count­able. Romania trans­posed it at the end of 2024, Poland's and Austria's laws apply from 2026, and Moldova has had its own law since 2025.

Why are hos­pi­tals a target for cy­ber­at­tacks?

Hos­pi­tals are targeted because they hold highly sen­si­tive data and cannot afford to stop, which makes them open to ex­tor­tion. In 2023, Member States reported 309 sig­nif­i­cant cy­ber­se­cu­ri­ty in­ci­dents in the health sector, more than in any other critical sector, ac­cord­ing to the European Com­mis­sion. On the EU's CIRAS incident platform, health ac­count­ed for 24% of all in­ci­dents that year, the highest volume of any sector, ac­cord­ing to the NIS360 report of ENISA, the European Union Agency for Cy­ber­se­cu­ri­ty.

CHART­BLOCK0

Ran­somware is ma­li­cious software that encrypts files and demands a ransom for the de­cryp­tion key. Ac­cord­ing to ENISA, which analysed health-sector in­ci­dents from January 2021 to March 2023, 43% of ran­somware in­ci­dents were also coupled with a data breach or data theft. The threat types from the same analysis are covered in our article on hospital digital in­fra­struc­ture and in­ter­op­er­abil­i­ty.

CHART­BLOCK1

ENISA places health in the "risk zone", together with public ad­min­is­tra­tion and other sectors with maturity gaps. The sector's specific problems are complex supply chains, legacy systems and poorly secured medical devices. Health scores 7 out of 10 for de­pen­den­cy on in­for­ma­tion tech­nol­o­gy, with very few manual fallback options for core pro­cess­es, ac­cord­ing to NIS360.

What is the NIS2 Di­rec­tive and which hos­pi­tals does it cover?

The NIS2 Di­rec­tive is the European Union's frame­work law for the cy­ber­se­cu­ri­ty of critical sectors: Di­rec­tive (EU) 2022/2555, which replaced the first NIS Di­rec­tive and had to be trans­posed by Member States by 17 October 2024. Annex I applies it to the health sector, which first of all includes health­care providers, meaning any person or entity legally pro­vid­ing health­care, plus EU ref­er­ence lab­o­ra­to­ries and parts of the phar­ma­ceu­ti­cal and medical device in­dus­tries.

The main cri­te­ri­on is size. The Di­rec­tive applies to entities that are at least medium-sized en­ter­pris­es under the EU def­i­ni­tion of SMEs (Rec­om­men­da­tion 2003/361/EC). A large hospital becomes an es­sen­tial entity, a medium-sized one an im­por­tant entity. There is an ex­cep­tion that matters in health­care: re­gard­less of size, the Di­rec­tive also covers an entity whose dis­rup­tion "could have a sig­nif­i­cant impact on public safety, public security or public health" (Art. 2(2)(c)).

The dif­fer­ence between the two cat­e­gories lies mainly in su­per­vi­sion and in the fine ceilings; the core obli­ga­tions, the measures in Article 21 and the re­port­ing in Article 23, are the same.

What does NIS2 require of a hospital?

NIS2 requires a hospital to take tech­ni­cal, op­er­a­tional and or­gan­i­sa­tion­al measures that are "ap­pro­pri­ate and pro­por­tion­ate" to the risk, to report in­ci­dents and to involve man­age­ment directly. Article 21 lists ten minimum measures, based on an "all-hazards approach":

  1. policies on risk analysis and in­for­ma­tion system security;
  2. incident handling;
  3. business con­ti­nu­ity: backup man­age­ment, disaster recovery, crisis man­age­ment;
  4. supply chain security, in­clud­ing re­la­tion­ships with direct sup­pli­ers;
  5. security in the ac­qui­si­tion, de­vel­op­ment and main­te­nance of systems, in­clud­ing vul­ner­a­bil­i­ty handling;
  6. as­sess­ing the ef­fec­tive­ness of the measures;
  7. basic cyber hygiene and training;
  8. cryp­tog­ra­phy and, where ap­pro­pri­ate, en­cryp­tion;
  9. human re­sources security, access control and asset man­age­ment;
  10. multi-factor au­then­ti­ca­tion, secured voice, video and text com­mu­ni­ca­tions and secured emer­gen­cy com­mu­ni­ca­tions, where ap­pro­pri­ate.

For sup­pli­ers, Article 21(3) requires hos­pi­tals to take into account the vul­ner­a­bil­i­ties of each direct supplier and the quality of its security prac­tices, in­clud­ing secure de­vel­op­ment pro­ce­dures.

Article 20 moves re­spon­si­bil­i­ty to the top: man­age­ment bodies approve the measures, oversee their im­ple­men­ta­tion and can be held liable for in­fringe­ments. Board members must follow training, and or­gan­i­sa­tions are en­cour­aged to offer similar training to em­ploy­ees on a regular basis.

Under NIS2, cy­ber­se­cu­ri­ty can no longer be del­e­gat­ed entirely to the IT de­part­ment: the hospital's man­age­ment approves the measures and answers for them.

Fines are set by each Member State, but the Di­rec­tive fixes minimum ceilings (Art. 34). For in­fringe­ments of Articles 21 or 23, an es­sen­tial entity can face a fine with a maximum of at least EUR 10 million or 2% of total world­wide annual turnover, and an im­por­tant entity a maximum of at least EUR 7 million or 1.4%, which­ever is higher. Member States may decide sep­a­rate­ly whether and how far public ad­min­is­tra­tion entities are fined.

How is an incident reported under NIS2?

A sig­nif­i­cant incident is reported in three fixed stages: an early warning within 24 hours, an incident no­ti­fi­ca­tion within 72 hours and a final report within one month. An incident is "sig­nif­i­cant" if it has caused or can cause severe op­er­a­tional dis­rup­tion or fi­nan­cial loss for the entity, or con­sid­er­able material or non-material damage to others (Art. 23(3)). Reports go to the CSIRT (computer security incident response team) or to the com­pe­tent au­thor­i­ty.

The CSIRT must respond, where possible within 24 hours of the early warning, with initial feedback and, on request, op­er­a­tional guidance, and the mere act of no­ti­fi­ca­tion does not increase the re­port­ing entity's li­a­bil­i­ty (Art. 23).

CHART­BLOCK2

If the incident involves patient data, the GDPR obli­ga­tion to notify a personal data breach applies along­side NIS2, with its own deadline and its own au­thor­i­ty. We explain it in our article on GDPR in health­care, con­trollers and pro­ces­sors.

What did the February 2024 attack on Romanian hos­pi­tals show?

The February 2024 attack showed that a single software supplier can become the entry point to dozens of hos­pi­tals in one night. Romania's National Cy­ber­se­cu­ri­ty Di­rec­torate (DNSC) in­ves­ti­gat­ed an attack with the Back­my­da­ta ran­somware, from the Phobos family, which en­crypt­ed the servers running the Hipocrate hospital in­for­ma­tion platform used by many hos­pi­tals, ac­cord­ing to DNSC data reported by Radio Free Europe.

On the first evening, DNSC con­firmed 21 affected hos­pi­tals, and another 79 fa­cil­i­ties were dis­con­nect­ed from the internet for checks; the number of affected hos­pi­tals later rose to more than 25. The at­tack­ers demanded a total ransom of EUR 157,000 in Bitcoin, and the au­thor­i­ties advised against paying. Most affected hos­pi­tals had recent backups, one to three days old, except one with backups that were 12 days old. The recent backups could allow easier restora­tion of the data, ac­cord­ing to DNSC.

One detail matters for NIS2: for the affected hos­pi­tals, DNSC was informed by the ap­pli­ca­tion's supplier, before any formal no­ti­fi­ca­tion from the hos­pi­tals, ac­cord­ing to DNSC. There are three lessons. Recent backups, where they existed, made it possible to restore without de­pend­ing on the at­tack­ers, ac­cord­ing to DNSC. A shared platform became a single point of failure for all of its clients. And the re­port­ing obli­ga­tion remains the hospital's, even if the supplier reports too.

Where do Romania, Austria, Poland and Moldova stand?

The four coun­tries are at dif­fer­ent stages: Romania has applied NIS2 since 31 December 2024, Poland and Austria have new laws in force since 2026, and Moldova, a can­di­date country, has its own law partly aligned with NIS2.

Country Legal act Authority or response team Status, according to official sources
Romania Emergency Ordinance 155/2024, approved by Law 124/2025 DNSC (also the national CSIRT) In force since 31 December 2024; DNSC Order 1/2026 sets the measures and the self-assessment
Austria NISG 2026, BGBl. I No. 94/2025 Federal Office for Cybersecurity In force since 1 October 2026; registration within three months
Poland National Cybersecurity System (KSC) Act, amended for NIS2 CSIRT CeZ, the sectoral team for health In force since 3 April 2026; register by 3 October 2026
Moldova Law No. 48/2023 on cybersecurity Cybersecurity Agency In force since 1 January 2025; partial alignment with NIS2; health included (consultation version)

Status checked on 7 October 2026.

How does Romania trans­pose the NIS2 Di­rec­tive?

In Romania, Emer­gen­cy Or­di­nance 155/2024, pub­lished in Official Gazette No. 1332 of 31 December 2024, trans­pos­es NIS2 and des­ig­nates DNSC as com­pe­tent au­thor­i­ty and national CSIRT. Entities in the covered sectors notify DNSC for reg­is­tra­tion within 30 days of the or­di­nance applying to them, submit an annual self-as­sess­ment of the maturity of their measures, endorsed by man­age­ment, and es­sen­tial entities submit a plan to remedy de­fi­cien­cies within 30 days. On 27 August 2026, DNSC Order 1/2026 was pub­lished, ap­prov­ing the risk-man­age­ment measures and the self-as­sess­ment method­ol­o­gy.

How does Austria apply the NIS2 Di­rec­tive?

In Austria, NISG 2026 (Network and In­for­ma­tion Systems Security Act 2026) was adopted by the National Council on 12 December 2025 and pub­lished on 23 December 2025. Its main pro­vi­sions apply from 1 October 2026, and the com­pe­tent au­thor­i­ty is the new Federal Office for Cy­ber­se­cu­ri­ty (Bun­de­samt für Cy­ber­sicher­heit), re­port­ing to the Ministry of the Interior. Entities have three months from entry into force to register.

How does Poland apply the NIS2 Di­rec­tive?

In Poland, the amend­ment to the National Cy­ber­se­cu­ri­ty System (KSC) Act entered into force on 3 April 2026. The reg­is­tra­tion deadline was 3 October 2026, the re­quire­ments must be im­ple­ment­ed by 3 April 2027, and the first audit of es­sen­tial entities and ad­min­is­tra­tive fines are possible after 3 April 2028, ac­cord­ing to the Ministry of Digital Affairs. Health has its own sectoral team, CSIRT CeZ, within the e-Health Centre (Centrum e-Zdrowia), which pub­lish­es an annual report with incident data.

CHART­BLOCK3

In 2025 there were 1,441 in­ci­dents, about 40% up on the 1,028 in 2024, in­clud­ing 5 serious in­ci­dents and 8 ran­somware attacks, ac­cord­ing to CSIRT CeZ. The rise may also reflect better de­tec­tion and re­port­ing, not only more attacks; ENISA makes the same point about European data. Computer fraud, such as phishing that imitates health in­sti­tu­tions, was the most frequent category. The team's survey, answered by 696 health­care fa­cil­i­ties, shows progress on policies but gaps at man­age­ment level:

CHART­BLOCK4

The same report notes that more than 43% of fa­cil­i­ties have no vul­ner­a­bil­i­ty man­age­ment process and more than 16% do not report in­ci­dents.

What cy­ber­se­cu­ri­ty frame­work does Moldova have?

In Moldova, NIS2 is not binding, but the country has chosen to move closer to it. Law No. 48/2023 on cy­ber­se­cu­ri­ty, adopted on 16 March 2023, has been in force since 1 January 2025 and ensures align­ment with NIS2, "albeit only par­tial­ly", ac­cord­ing to the Gov­ern­ment. The com­pe­tent au­thor­i­ty is the Cy­ber­se­cu­ri­ty Agency, set up by Gov­ern­ment Decision 1028/2023, which combines su­per­vi­sion and control with the roles of national incident response team and single point of contact.

Gov­ern­ment Decision 860/2024 on iden­ti­fy­ing service providers and Gov­ern­ment Decision 562/2025 on security obli­ga­tions followed, with 12- and 18-month dead­lines for audit reports. In the version put to public con­sul­ta­tion, the list of critical sectors included health, with health­care providers as es­sen­tial providers above the medium-en­ter­prise thresh­old and im­por­tant ones at medium-en­ter­prise level. For 2026, the re­spon­si­ble ministry and the Agency are to draft amend­ments to the Con­tra­ven­tion Code so that non-com­pli­ance can be sanc­tioned, ac­cord­ing to the Gov­ern­ment.

What is the EU doing specif­i­cal­ly for hos­pi­tals?

Along­side NIS2, the European Com­mis­sion pre­sent­ed a European action plan on the cy­ber­se­cu­ri­ty of hos­pi­tals and health­care providers on 15 January 2025. The plan has four pri­or­i­ties: pre­ven­tion, de­tec­tion, response and recovery, and de­ter­rence. Its cen­tre­piece is a European Cy­ber­se­cu­ri­ty Support Centre hosted by ENISA, pro­vid­ing guidance, tools, services and training tailored to hos­pi­tals, ac­cord­ing to the Com­mis­sion.

In concrete terms, the plan an­nounces an EU early warning service with near-real-time alerts by 2026, cy­ber­se­cu­ri­ty vouchers for smaller fa­cil­i­ties and ran­somware response play­books, rolled out pro­gres­sive­ly in 2025 and 2026. Security is also a pre­con­di­tion for the data exchange de­scribed in our article on the European Health Data Space (EHDS) and for access to data for research, ex­plained in our article on sec­ondary use of health data for AI.

What this means for a hospital in Romania or Moldova

Most of the NIS2 work is or­gan­i­sa­tion­al and can start without a large budget: status, in­ven­to­ry, man­age­ment de­ci­sions. The list below follows Article 21 and the rec­om­men­da­tions of ENISA and CSIRT CeZ. The sources con­sult­ed give no cost es­ti­mates for a hospital's NIS2 com­pli­ance; the real budget comes out of the in­ven­to­ry and risk analysis in steps 1 and 2.

  1. Check your status and reg­is­tra­tion. In Romania, confirm whether the facility is an es­sen­tial or im­por­tant entity and whether the no­ti­fi­ca­tion to DNSC has been made. In Moldova, check whether the Cy­ber­se­cu­ri­ty Agency has iden­ti­fied the facility as a service provider.
  2. In­ven­to­ry and risk analysis, approved by man­age­ment. A list of systems, data, sup­pli­ers and external con­nec­tions; the main risks and who owns each of them.
  3. Isolated and tested backups. ENISA rec­om­mends en­crypt­ed offline backups of critical data; CSIRT CeZ stresses regular restore tests, the only proof that a backup works.
  4. Multi-factor au­then­ti­ca­tion for remote access, ad­min­is­tra­tor accounts and systems holding patient data.
  5. Network seg­men­ta­tion. Medical equip­ment, clinical servers, ad­min­is­tra­tive work­sta­tions and the visitor network in separate zones, so that an attack does not spread.
  6. Vul­ner­a­bil­i­ty and patch man­age­ment, in­clud­ing a list of systems no longer sup­port­ed by their man­u­fac­tur­er.
  7. Security clauses in supplier con­tracts: prompt incident no­ti­fi­ca­tion to the hospital, con­trolled remote access, the right to audit.
  8. An incident response plan, with roles, contacts, tem­plates for the 24-hour and 72-hour reports and an annual tabletop exercise.
  9. Training: man­age­ment, as Article 20 requires, and all staff, on phishing and basic cyber hygiene.

We are a vendor too; these ques­tions apply to us as well. Ques­tions to ask any software or IT service vendor before signing, in­clud­ing for doctor-patient video con­sul­ta­tion plat­forms:

  • How quickly will you tell us about an incident that could affect our data or systems?
  • Who on your team has access to our systems, from where and with what type of au­then­ti­ca­tion?
  • How do you develop and update your product securely, and how do you handle vul­ner­a­bil­i­ties?
  • Where are the data hosted, who are your sub­con­trac­tors, and how will you export all our data at the end?
  • Can you provide the tech­ni­cal in­for­ma­tion we need for the 24-hour and 72-hour reports?

Cons­d­i­nam­ic, a company from the Republic of Moldova reg­is­tered in 2008, builds software and AI to order and goes deepest in health­care. Our projects start from the same prin­ci­ples: data pro­tec­tion from the first day, in line with GDPR, access limited to what is strictly nec­es­sary, and data that stay under the client's control.

Con­clu­sion

NIS2 turns hospital cy­ber­se­cu­ri­ty from a tech­ni­cal issue into a man­age­ment obli­ga­tion, with ten minimum measures, fixed re­port­ing dead­lines and high fine ceilings. Health reported more sig­nif­i­cant in­ci­dents than any other sector in 2023, and the 2024 attack in Romania showed how fast an incident spreads through shared sup­pli­ers. The legal frame­work differs from country to country, but the order of steps stays the same: status and reg­is­tra­tion, an approved risk analysis, tested backups, multi-factor au­then­ti­ca­tion, seg­men­ta­tion, supplier clauses and a re­hearsed incident plan.

Frequently asked questions

Does the NIS2 Directive apply to hospitals?

Yes. Annex I of Directive (EU) 2022/2555 lists healthcare providers in the health sector, which covers public and private hospitals. Hospitals of at least medium size are in scope; large ones are normally essential entities and medium-sized ones important entities. A Member State can also include a smaller provider if its disruption could have a significant impact on public health.

How quickly must a cyber incident be reported under NIS2?

Article 23 requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report no later than one month after the notification. Reports go to the national computer security incident response team (CSIRT) or the competent authority.

Who in hospital management is responsible for NIS2?

Under Article 20 of the NIS2 Directive, the hospital's management bodies approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements. Members of the management body must follow cybersecurity training. For public institutions, the liability rules for public officials remain those of national law.

What fines does NIS2 provide for?

For infringements of Articles 21 or 23, essential entities face fines with a maximum of at least EUR 10 million or 2% of total worldwide annual turnover, and important entities a maximum of at least EUR 7 million or 1.4%, whichever is higher. Member States may set separate rules for public administration entities.

Who is the NIS2 authority in Romania and in Moldova?

In Romania, the competent authority and national CSIRT is the National Cybersecurity Directorate (DNSC), under Emergency Ordinance 155/2024. Moldova is not an EU Member State, but its Law No. 48/2023 on cybersecurity has applied since 1 January 2025, and the competent authority is the Cybersecurity Agency.

What should a hospital do first to comply with NIS2?

Start by confirming the hospital's status (essential or important entity) and registering with the authority, then build an inventory of systems and a risk analysis approved by management. Quick-impact measures follow: isolated and tested backups, multi-factor authentication, network segmentation, security clauses in supplier contracts and an incident response plan that includes the reporting deadlines.

Sources
  1. Directive (EU) 2022/2555 (NIS2), EUR-Lex, 2022 — Art. 2, 3, 20, 21, 23, 34, 41 and Annex I: scope, health sector, minimum measures, management liability, reporting deadlines, fines
  2. European Commission, Commission unveils action plan to protect the health sector from cyberattacks, 15 January 2025 — 309 significant health-sector incidents reported by Member States in 2023; four priorities; ENISA support centre; early warning by 2026
  3. ENISA, Threat Landscape: Health Sector (January 2021 - March 2023), July 2023 — incidents analysed from January 2021 to March 2023: 43% of ransomware incidents coupled with a data breach; reported increases may also reflect more mature reporting; impact: data 43%, healthcare services 22%, other services 26%; offline encrypted backups
  4. ENISA, NIS360 2024, February 2025 — health in the 'risk zone'; 24% of all incidents reported in CIRAS in 2023; ICT dependency 7/10; legacy systems and poorly secured medical devices
  5. Government of Romania, Emergency Ordinance 155/2024 on the cybersecurity of networks and information systems, 2024 — NIS2 transposition; DNSC as competent authority and national CSIRT; registration notice within 30 days; annual self-assessment and remediation plan
  6. DNSC, Order No. 1 of 6 August 2026, Official Gazette No. 712 of 27 August 2026 — risk-management measures and maturity self-assessment methodology; confirms that Emergency Ordinance 155/2024 was approved by Law 124/2025
  7. Radio Free Europe Romania (Europa Liberă), Number of hospitals hit by cyberattack rises, 12-14 February 2024 — DNSC data on the Backmydata attack: 21 hospitals confirmed at first, 79 facilities disconnected, more than 25 affected, EUR 157,000 ransom, backups 1-3 days old
  8. Republic of Austria, BGBl. I No. 94/2025, NISG 2026, RIS, 23 December 2025 — Austrian transposition law; Federal Office for Cybersecurity, directly subordinate to the Minister of the Interior (§ 3a); in force 1 October 2026; registration within three months
  9. Ministry of Digital Affairs (Poland), Amendment to the National Cybersecurity System Act enters into force, 2 April 2026 — in force 3 April 2026; register by 3 October 2026; implementation by 3 April 2027; first audit and fines after 3 April 2028
  10. CSIRT CeZ (e-Health Centre, Poland), Report 2025: Cybersecurity landscape in the healthcare sector, 2026 — 435, 1,028 and 1,441 incidents in 2023-2025 (+40% in 2025); 5 serious incidents and 8 ransomware attacks in 2025; survey of 696 facilities; recommendations
  11. Government of the Republic of Moldova, Explanatory note to draft No. 889/MDED/2025, 2025 — Law 48/2023 adopted 16 March 2023, in force 1 January 2025, partial alignment with NIS2; Government Decisions 1028/2023, 860/2024, 562/2025; Cybersecurity Agency; EU candidate status
  12. Government of the Republic of Moldova, Draft decision on the identification of service providers (public consultation), 2024 — health sector: healthcare providers essential above the medium-enterprise threshold, important at medium-enterprise level
NIS2cybersecurityhospitals
Do you have a similar problem in your institution?

Tell us what you need. We come back with a prototype, not with slides.

Write to us

Other articles