NIS2 · Sector deep-dive
NIS2 for Healthcare
Health is one of the eleven Annex I sectors of high criticality, which means large in-scope healthcare entities are normally supervised as essential entities — the strictest supervisory regime NIS2 provides. The sector covers healthcare providers as defined in the cross-border healthcare directive, EU reference laboratories, entities carrying out research and development of medicinal products, entities manufacturing basic pharmaceutical products and preparations, and entities manufacturing medical devices considered critical during a public health emergency.
Why healthcare is treated as high criticality
Healthcare is the one sector where a cybersecurity incident converts directly into clinical risk. When an electronic patient record system, a laboratory information system or a radiology archive goes down, clinicians lose medication histories, allergy flags and prior imaging at the moment they need them. Hospitals that have been hit by ransomware have diverted ambulances, cancelled elective surgery for weeks and reverted to paper charting — and studies of those events consistently find measurable effects on treatment times, not just on administration.
The technology estate makes this harder than in most sectors. A mid-sized hospital runs thousands of connected devices from dozens of vendors, many certified as medical devices and therefore not freely patchable by the hospital's own IT department. Long procurement cycles keep imaging systems and analysers in service for a decade or more, often on operating systems that stopped receiving security updates years ago. Clinical shift work pushes staff towards shared accounts and fast, low-friction logins, exactly where multi-factor authentication feels most disruptive.
On top of that, the data is unusually attractive. Health records combine identity data, financial data and information patients would pay to keep private, which is why the sector sees both extortion of the organisation and extortion of individual patients after a breach.
Where healthcare providers typically have the biggest gaps
- Unmanaged medical devices. Connected pumps, monitors, analysers and imaging modalities are procured clinically, not through IT, and frequently never reach the asset inventory. What is not inventoried cannot be segmented, monitored or risk-assessed.
- Flat clinical networks. Devices, workstations and administrative systems often share the same broadcast domain, so a single compromised workstation can reach a ward's entire device population.
- Shared and generic accounts. Ward logins shared across a shift defeat access control and destroy the audit trail an incident investigation depends on.
- Continuity plans that assume IT comes back quickly. Downtime procedures are often written for hours, not for the two to four weeks a serious ransomware recovery actually takes.
- Vendor remote access. Device manufacturers and system integrators hold standing remote access for maintenance, often through their own tooling and outside the hospital's identity management.
What this means for the Article 21 measures
- Business continuity and crisis management — Article 21(2)(c). Downtime procedures must be clinically usable: printed medication lists, paper observation charts, an agreed restoration order between departments, and a rehearsed decision on when to divert patients. Test the restore, not only the backup.
- Asset management and access control — Article 21(2)(i) and (j). Bring medical devices into the same inventory as IT assets, with owner, criticality, patch status and network location. Replace shared ward accounts with individual identities and apply multi-factor authentication to remote and administrative access.
- Supply chain security — Article 21(2)(d). Assess device manufacturers and clinical software vendors on how they handle vulnerabilities, how long they support a product and how their remote access is controlled — and write those answers into the contract.
These sit inside the same ten-measure framework every in-scope entity must satisfy — see the full Article 21 requirements page. Because a large hospital is normally an essential entity, supervision is proactive: the authority can inspect and demand evidence without waiting for an incident, and the reporting clock in Article 23 starts at 24 hours for the early warning.
Documentation
The NIS2 Starter Kit's risk assessment, asset inventory and continuity templates adapt to clinical environments — extend the asset register with device criticality and patch constraints.
