NIS2 for Health
Hospitals hold the worst combination in the directive: legacy medical devices that cannot be patched, 24/7 availability requirements, and special-category personal data that makes every incident a dual NIS2 and GDPR event.
Which entities are covered
Healthcare providers, EU reference laboratories, entities carrying out R&D of medicinal products, entities manufacturing basic pharmaceutical products and preparations, entities manufacturing medical devices considered critical during a public health emergency.
Sub-sectors named in the annex
- Healthcare providers
- EU reference laboratories
- R&D of medicinal products
- Manufacture of basic pharmaceutical products
- Medical devices critical during a public health emergency
Scope traps specific to this sector
Trap 1
A single ransomware incident triggers article 23 (24h to the CSIRT) and GDPR article 33 (72h to the DPA) with different content and different recipients.
Trap 2
Connected medical devices sit under the MDR for safety and under NIS2 article 21(2)(e) for security — two regimes, one device.
Trap 3
Many hospitals are public bodies and may also be caught by the public administration entry.
What else applies to you
GDPR article 33 for personal data breaches; MDR (Regulation (EU) 2017/745); the CER directive.
NIS2 rarely arrives alone. Where another EU act covers the same ground and is at least equivalent in effect, article 4 disapplies the corresponding NIS2 provisions — but only those, and only where that test is met.