Directive NIS2 European Union
Cart 0
Annex I · sector 5 of 18

NIS2 for Health


Hospitals hold the worst combination in the directive: legacy medical devices that cannot be patched, 24/7 availability requirements, and special-category personal data that makes every incident a dual NIS2 and GDPR event.

Annex
I
Default class
Essential
Supervision
ex ante
Maximum fine
10 M€ / 2 %

Which entities are covered


Healthcare providers, EU reference laboratories, entities carrying out R&D of medicinal products, entities manufacturing basic pharmaceutical products and preparations, entities manufacturing medical devices considered critical during a public health emergency.

Sub-sectors named in the annex

  • Healthcare providers
  • EU reference laboratories
  • R&D of medicinal products
  • Manufacture of basic pharmaceutical products
  • Medical devices critical during a public health emergency

Scope traps specific to this sector


Trap 1

A single ransomware incident triggers article 23 (24h to the CSIRT) and GDPR article 33 (72h to the DPA) with different content and different recipients.

Trap 2

Connected medical devices sit under the MDR for safety and under NIS2 article 21(2)(e) for security — two regimes, one device.

Trap 3

Many hospitals are public bodies and may also be caught by the public administration entry.

What else applies to you


GDPR article 33 for personal data breaches; MDR (Regulation (EU) 2017/745); the CER directive.

NIS2 rarely arrives alone. Where another EU act covers the same ground and is at least equivalent in effect, article 4 disapplies the corresponding NIS2 provisions — but only those, and only where that test is met.

Cart 0