90976

Immagine creata con IAAI-generated image

Cybersecurity of hospitals in Europe: the first implementing measures of the European action plan

The health sector is one of the sectors of high criticality listed in Annex I to Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union, known as the NIS2 Directive. On 22 July 2026 the European Union Agency for Cybersecurity (ENISA) delivered the first implementing measures of the 2025 European action plan on the cybersecurity of hospitals and healthcare providers, through a contribution agreement with the European Commission and a new edition of the procurement guidelines.

The 2025 European action plan

In January 2025 the European Commission launched an action plan dedicated to the cybersecurity of hospitals and healthcare providers across the European Union, prompted by the growing exposure of health systems to cyberattacks and ransomware campaigns. The plan is organised around four pillars: prevent, detect, respond and recover, deter. The prevention pillar covers risk management and risk assessment capacities and cybersecurity training for healthcare professionals. Detection provides for better tools, including an EU-wide early subscription warning service for the health sector, to be developed by 2026. Response and recovery rely on the EU Cybersecurity Reserve, on incident response services and on national cybersecurity exercises. Deterrence draws, among other instruments, on the Cyber Diplomacy Toolbox.

The plan imposes no immediate obligations on healthcare entities and is designed to be rolled out progressively throughout 2025 and 2026, in collaboration with healthcare providers, Member States and the cybersecurity community. Announced measures include a European Cybersecurity Support Centre for hospitals and healthcare providers to be established within ENISA, and an invitation to Member States to consider cybersecurity vouchers for micro, small and medium-sized providers.

The contribution agreement and the support mechanism

On 22 July 2026 ENISA announced the signature of a contribution agreement with the European Commission worth EUR 6 million and running for three years, aimed at establishing the support mechanism foreseen by the action plan. The primary objective of the agreement is the implementation of a service catalogue for the health sector, which groups actions into four categories: preparedness, detection, response and governance.

The approach set out by the Agency involves repackaging and expanding the current service offer and architecture, creating harmonised approaches, reusing established methodology, tools and procurement strategy from the earlier ENISA Cybersecurity Support Action, actions to empower Member States and health entities, and building the service offer in consultation with relevant stakeholder groups.

The July 2026 procurement guidelines

On the same date ENISA published a new iteration of the procurement guidelines for the cybersecurity of hospitals and healthcare providers, prepared with the support of the NIS Cooperation Group, the EU Health ISAC (EH-ISAC), the information sharing and analysis centre for the European health sector, and the European Commission. The document covers all phases of the procurement life cycle, sets out cybersecurity requirements for suppliers, specifies the information those suppliers must provide and identifies the types of services and products for which security considerations are particularly important. It also includes a practical checklist of cybersecurity measures tailored to healthcare procurement, each linked to specific threats for the different procurement types.

The guidelines are aligned with the relevant European regulatory frameworks: the NIS2 Directive, the medical device regulations, the general data protection regulation and the European health data space regulation. The intended users range from senior technical professionals in healthcare organisations to the information technology teams that handle supplies in practice.

Where the sector stands in the NIS360 assessment

On 28 May 2026 ENISA published the third edition of the NIS360 report, an annual assessment tool covering the cybersecurity maturity and criticality of the sectors of high criticality identified in Annex I to the NIS2 Directive. A sector’s maturity is determined by four components: legislation and its effectiveness, companies and their preparedness, authorities and their institutional capacity, and sectoral ecosystem structures and their effectiveness. Criticality is assessed by considering systemic relevance, exposure and the impact of disruption.

The combination of the two dimensions defines a risk zone, which gathers sectors with lower-than-average maturity and criticality that exceeds their maturity. In the 2026 edition the risk zone includes health, railway, maritime, ICT service management, space, public administrations, drinking water and waste water. The same report records health among the four sectors that strengthened their maturity within the moderate band, together with gas, road and maritime. The Agency notes that overall improvement remains uneven both across and within sectors, owing to skill shortages, sector-specific characteristics and organisational size.

Recorded incidents and costs

The sectoral picture published by ENISA remains the first threat landscape dedicated to health, released on 5 July 2023 and based on 215 publicly reported incidents in the European Union and neighbouring countries over a period of just over two years. According to that document ransomware accounted for 54% of the threats recorded; healthcare providers concentrated 53% of incidents and hospitals alone 42%. Patient data, including electronic health records, were the most targeted asset at 30%, while 46% of incidents aimed to steal or leak the data of health organisations. Only 27% of the organisations surveyed had a dedicated ransomware defence programme.

The consequences recorded consisted mainly of breaches or theft of data (43%), disrupted healthcare services (22%) and disrupted services not related to healthcare (26%). The median cost of a major security incident in the health sector was estimated at EUR 300,000 on the basis of the 2022 ENISA study on NIS investments. In the same period the NIS Cooperation Group published a first assessment of the risk management measures then in place in the sector.

Outlook

The European action plan places the delivery of the early warning service for the health sector by 2026, while the contribution agreement signed by ENISA covers three years and provides for the progressive implementation of the support mechanism service catalogue. The next edition of the NIS360 report will draw on a survey addressed to national authorities and high criticality entities, open until 30 October 2026. The action plan, the revised procurement guidelines and the cybersecurity of medical devices are on the agenda of the 11th ENISA eHealth Security Conference, scheduled in Nicosia on 7 October 2026. Still to be defined are the final operational arrangements for the European Cybersecurity Support Centre for the health sector and the possible adoption, by individual Member States, of cybersecurity vouchers for smaller providers.

In dialogue with the 2030 Agenda

  • Goal 3 (Good health and well-being). Disruption of healthcare services caused by cyber incidents affects triage, treatment and continuity of care, with direct effects on patient safety.
  • Goal 9 (Industry, innovation and infrastructure). Hospitals, medical devices and healthcare supply chains are critical infrastructure whose resilience depends on technical requirements, procurement and detection capacity.
  • Goal 10 (Reduced inequalities). Uneven maturity across countries and across organisations of different size produces differing levels of protection for patients, an issue addressed by the cybersecurity vouchers aimed at smaller providers.
  • Goal 16 (Peace, justice and strong institutions). The action plan addresses the deterrence of attacks against health systems and the institutional capacity of the supervisory authorities provided for by the NIS2 Directive.
  • Goal 17 (Partnerships for the goals). The guidelines and the support mechanism arise from cooperation between the Agency, the Commission, the NIS Cooperation Group and the information sharing centre for the health sector.

Sources


AI AnthropoCosmic In evidenzaAI AnthropoCosmicCall for Paper aperta fino al 15 settembre 2026. Un progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicCall for Paper open until 15 September 2026. An international project for an AI at the service of humanity, the environment and the cosmos. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article