← All industries

Healthcare

There's no gap between patient data and patient safety.

Hospitals, medical care centres, laboratories, and care facilities carry a double load: NIS2 demands risk management, and the GDPR protects health data as a special category. The good news — both are answered by the same work.

Does this apply to you?

Annex 1 · Sector 4

Sector: Healthcare

Providers of healthcare services, EU reference laboratories, pharmaceutical research, manufacturers of pharmaceutical products, and manufacturers of critical medical devices.

Entity of essential importance

at least 250 employees — or annual turnover above €50 million and an annual balance sheet total above €43 million

Applies to entity types under Annex 1 · Section 28(1), (2) BSIG

Important entity

at least 50 employees — or annual turnover and balance sheet total above €10 million

Applies to entity types under Annexes 1 and 2 · Section 28(1), (2) BSIG

Important for you: Manufacturers of other medical devices and in-vitro diagnostics, by contrast, sit in Annex 2 (Sector 5.1) — the classification decides which threshold applies to you.

Covered regardless of size: operators of critical facilities, qualified trust service providers, top-level domain registries, and DNS service providers (Section 28(1) Nos. 1, 2 BSIG); trust service providers always count as an important entity (Section 28(2) No. 1 BSIG). Employee count and financial figures are alternative thresholds (either one triggers coverage); for the financial figures, both values must be exceeded. Whether your specific company is covered is a case-by-case question — that's what lawyers are for.

What's typically in the register in this sector

Hospital / practice information systemNetworked medical devicesLaboratory information systemImage archive (PACS)Duty rosteringPatient portal

These obligations decide it for you.

Section 30(2) No. 2 BSIG

Handle incidents before care delivery stops

An encrypted patient information system isn't an IT problem — it's a care-delivery problem. Detecting, handling, and following up needs to be rehearsed, not improvised.

Section 30(2) No. 9 BSIG

Keep access under tight control

Personnel security, access control, and managing your ICT systems: whoever fills in on the emergency ward needs rights assigned — and whoever leaves can't keep them.

Section 32 BSIG · Art. 33 GDPR

Two reporting clocks, both start at once

When patient data is affected, the NIS2 report and the data-protection report run in parallel. Both start the moment someone at your organisation becomes aware of it.

Example (fictional): The hospital and the Friday evening

At a hospital, appointment scheduling goes down on a Friday evening; shortly after, the image archive stops responding. IT first suspects a storage issue. Only by Saturday afternoon does it become clear: it's an attack, and the first systems were actually encrypted Thursday night.

The regulator's decisive question later won't be how good the firewall was — it will be when the hospital became aware, and what happened in the 24 hours after that. An organisation that logs the incident immediately, with the clock visibly running, isn't arguing about timestamps afterwards — it's working through a checklist.

A freely invented example for illustration — no real customer, no legal advice

Here's how Compliverse takes this off your plate.

  • 1

    The reporting assistant runs the NIS2 report and the GDPR report as one process — with a countdown from the moment of awareness.

  • 2

    Training for clinical staff runs on mobile in 15 minutes, with a completion record per person for audits and regulators.

  • 3

    The team matrix shows at a glance who's trained — including colleagues who joined last month.

NIS2 in Healthcare: frequently asked questions

Is my Healthcare company in scope for NIS2?

Your sector is covered by Germany's BSI Act: Annex 1 · Sector 4, sector Healthcare. That does not put you in scope automatically — a size threshold has to be met as well (Section 28(1), (2) BSIG). And no official notice arrives: you assess the classification yourself and register if it applies (Section 33 BSIG). Your sector also has an exception — it is set out on this page under “Are you in scope?”. Judging your individual case is a lawyer's job.

From what size does NIS2 apply to us?

You count as an essential entity from at least 250 employees — or annual turnover above €50 million and an annual balance sheet total above €43 million; as an important entity from at least 50 employees — or annual turnover and balance sheet total above €10 million (Section 28(1), (2) BSIG). Headcount and financial figures are alternatives to each other — but where the financial figures are used, both have to be exceeded. Some entity types are in scope regardless of size, among them operators of critical facilities and qualified trust service providers.

Which authority is responsible for us in Germany?

Registration and supervision sit with the Bundesamt für Sicherheit in der Informationstechnik (BSI) — Germany's Federal Office for Information Security (Section 33 BSIG). Security incidents, however, do not go there: they go to the joint reporting office of the BSI and the Federal Office of Civil Protection and Disaster Assistance (BBK) — early warning within 24 hours, report within 72 hours, follow-up report a month later (Section 32 BSIG). This is the most common misreading of the act — the supervisory authority and the reporting office are not the same body.

What happens if we do not implement NIS2?

The obligations do not go away: registration stays due (Section 33 BSIG), so do the risk-management measures (Section 30(2) BSIG), and reporting deadlines start running with the first significant incident (Section 32 BSIG). On top of that, Section 38 BSIG puts management personally on the hook: they have to approve the measures, oversee their implementation, and undergo training themselves. “I didn't know” does not carry here.

Find out in thirty seconds what applies to you.

Four questions, an honest first estimate — then you'll know which module to start with and what it costs.

What becomes important next

More industries

Legal status checked on 01/09/2026 · Every statement with a source · No legal advice