Les DPO de la Santé
All articles
Cybersecurity

The NIS2 Directive: what impact on the healthcare sector?

Les DPO de la SantéPublished Updated 3 min
The NIS2 Directive: what impact on the healthcare sector?

Healthcare is one of NIS2’s “highly critical” sectors. New cybersecurity and governance obligations to anticipate.

Directive (EU) 2022/2555, known as NIS2, considerably widens the range of entities subject to cybersecurity obligations. The healthcare sector is listed among the highly critical sectors.

Governance and accountability

NIS2 makes management bodies accountable and imposes risk-management measures as well as an incident-reporting obligation. Governance becomes a board-level matter.

Who is in scope in healthcare

NIS2 changes scale compared with NIS1: beyond the hospitals already regulated, the scope now includes — subject to size and turnover thresholds — medical biology laboratories, manufacturers of critical medical devices, pharmaceutical research and development entities, and many players in the medicines supply chain. Organizations are classified as “essential” or “important” entities, with differentiated supervision and sanction regimes.

And even outside the direct scope, the chain effect applies: regulated entities must control the security of their supply chain — so their software vendors, managed-services providers and contractors will see NIS2 requirements arrive through their contracts.

The concrete obligations

The core of the framework has two parts. First, cyber risk-management measures: security and risk-analysis policies, incident handling, business continuity and crisis management, supply-chain security, encryption, access control and multi-factor authentication, training — including for executives. Second, an obligation to report significant incidents in three stages: early warning within 24 hours, detailed notification within 72 hours, final report within one month.

The most structural novelty lies elsewhere: management bodies are personally accountable for approving and overseeing these measures. Cybersecurity stops being an IT matter and becomes a board matter.

French transposition: where do things stand?

The directive was due to be transposed by October 2024; France has fallen behind: the bill on “resilience of critical infrastructure and strengthening of cybersecurity” — steered on the technical side by ANSSI, the French cybersecurity agency — is still going through Parliament in summer 2026, with a gradual ramp-up of requirements announced by the agency (roughly three years before the first sanctions). The exact scope of regulated entities and the enforceable timeline will be set by the law and then its decrees: exactly the kind of development our regulatory watch follows week after week for our clients.

NIS2, GDPR, HDS: three frameworks, one hygiene

A single incident — ransomware encrypting a patient data server — can simultaneously trigger a NIS2 notification (significant incident), a GDPR notification to the CNIL within 72 hours (personal data breach) and a review of the hosting provider’s HDS commitments. Rather than three compliance silos, the right approach is a single foundation: a shared map, a unified incident procedure that feeds all three obligations, and governance shared between the DPO, the CISO and management. That is exactly the articulation we build with our cybersecurity partners.

This article is provided for general information purposes and does not constitute personalized legal advice.

Turn your obligations into opportunities.

A free, no-obligation first conversation to review your compliance posture and identify your priorities — in English.

Response within 24 business hours · No obligation