Healthcare Is Now an Essential Entity Sector. The Stakes Could Not Be Higher.
European healthcare organisations have faced an accelerating wave of cyberattacks over the past five years. Ransomware attacks on hospitals have cancelled surgeries, delayed diagnoses, and in documented cases contributed to patient harm. In 2024 and 2025, ENISA reported healthcare as the second most targeted sector in the EU, behind public administration.
NIS2 treats this reality with appropriate severity. Healthcare - including hospitals, clinical laboratories, pharmaceutical manufacturers, medical research institutes, and medical device manufacturers above certain size thresholds - is classified as an essential entity sector under Annex I. This means the strictest category of NIS2 obligations applies: proactive supervision, the highest financial penalties, and personal liability for management.
For healthcare organisations that were already NIS2-aware, the transition from the original NIS Directive was significant in scope. For those that were not, the obligations are now fully in effect and enforcement is underway in multiple member states.
What NIS2 Requires for Healthcare Entities
As essential entities under NIS2, healthcare organisations face the full Article 21 security obligation set:
Policies on information security. Documented, approved by the management body, regularly reviewed.
Incident handling. A functional security operations capability, incident response procedures, and the 24/72/30-day notification chain to national authorities.
Business continuity and crisis management. Healthcare must maintain patient care continuity even under active cyber incident. This includes backup strategies, disaster recovery, and crisis communications - with documented proof that these have been tested.
Supply chain security. Medical devices, clinical software, laboratory systems, and EHR platforms are all in scope. Healthcare organisations must assess and manage the cybersecurity of their supply chain - including medical device manufacturers, SaaS clinical tools, and IT service providers.
Cryptography and encryption. Patient data must be encrypted both in transit and at rest, with key management procedures documented and auditable.
Access control and authentication. Multi-factor authentication for access to clinical systems. Least-privilege access principles. Regular access reviews and privileged access management.
See the NIS2 use case overview and our healthcare data integrity guide for how these requirements translate to technical implementation.
The Data Integrity Gap in Healthcare AI
Healthcare is also the sector moving fastest toward AI deployment - diagnostic imaging analysis, clinical decision support, patient risk stratification, automated coding. This creates a specific intersection risk that NIS2 alone does not fully address.
AI systems in healthcare operate on patient data. If that data is compromised - tampered, corrupted, or poisoned - the consequences are not a financial penalty. They are a misdiagnosis, an incorrect treatment recommendation, or a missed critical finding.
Even outside AI contexts, the integrity of clinical data is a safety requirement. An electronic health record that has been modified without detection - whether by a ransomware actor, a misconfigured update process, or an insider - represents a direct patient safety risk.
Cryptographic data integrity provides the technical foundation for detecting any modification to clinical data assets. Unlike access controls (which prevent modification by unauthorised parties but cannot detect modification by authorised ones), cryptographic integrity creates a tamper-evident record of every data asset's state at every point in time.
This is what digital audit in healthcare means in practice: not just logging who accessed what, but providing mathematical proof that what was accessed had not been altered. Start building your healthcare data integrity foundation with ROOTKey's free tier.
Recebe insights de ciber-resiliência no teu email
Orientação prática e pronta para auditoria sobre integridade de dados, conformidade e continuidade - à medida que publicamos.





