RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

Healthcare

Hospitals are most often essential entities, but the category is determined by the competent authority. Alongside the thirteen measures they hold a special category of personal data, and downtime here does not mean lost revenue but delayed care.

What the Act requires of this sector

Healthcare sits in Annex I of the Act, among the sectors of high criticality. The competent authority for cyber security requirements is the central state authority for cyber security, that is the Security and Intelligence Agency (SOA), and the competent CSIRT is the national cyber security centre (NCSC-HR).

Healthcare providers carrying out one of four activities, control of communicable diseases, supply of medicines and medical devices, medicinal preparations and transplants, and emergency medicine, may be classified as essential regardless of size, under Article 11 of the Act. Under Article 10 of the Regulation that is done on a reasoned request from the state body responsible for health, so it is not automatic. Other institutions are categorised by size, under Articles 9 and 10 of the Act.

Alongside the Cybersecurity Act, healthcare always carries the General Data Protection Regulation as well, because health data is a special category. That means a dual track for incidents and two sets of records that have to stand side by side.

Where this sector usually gets stuck

Ransomware in hospital systemsDowntime in the laboratory and imaging hits the patient immediately, so the pressure to pay quickly is highest here.
Networked medical devicesLegacy systems that may not be touched without the vendor, yet sit on the same network as office computers.
Access to health dataA special category of data, with an obligation to log access and answer patient requests.
External system maintainersVendor remote access without records and without security clauses in the contract.

What we do for you

01A readiness review across the thirteen measures and a remediation plan02A cyber security committee and a split of responsibilities03Incident handling with the 24 h, 72 h and 30 day deadlines04Alignment with data protection and access logging05A ransomware response exercise with the board06Preparing the evidence file for the audit

Who from the sector falls in scope

WHOCATEGORYNOTE
Institutions carrying out one of the four activities in the RegulationMay be essentialRegardless of size, under Article 11, on a reasoned request from the body responsible for health, Article 10 of the Regulation
Other healthcare providers above the ceilings for medium-sized enterprisesEssentialUnder Article 9 of the Act, by the size criterion
Healthcare providers that are medium-sizedImportantUnder Article 10, indent 2 of the Act
Manufacturers of medical devices and medicinesBy annex and sizeSome sit in Annex I and some in Annex II, so the category differs

The category is determined by the competent authority and notified to you, under Article 19(4) of the Act. Your own assessment does not decide it. The level of measures, basic, medium or advanced, is set by the national risk assessment during categorisation, under Article 38 of the Regulation.

CASE FROM PRACTICE · CROATIA, JUNE 2024

Ransomware at University Hospital Centre Zagreb

A ransomware attack interrupted the operation of hospital information systems. Some patients were diverted to other hospitals, and the competent authorities acted on the incident report. For emergency services, recovery time has to be measured in minutes, and a backup that has never been restored is not a backup.

SOURCE: Public incident reporting and statements by the competent authorities, June 2024.

Frequently asked questions

The questions hospitals and healthcare institutions ask first.

Is our hospital an essential entity?

Institutions carrying out one of the four critical healthcare activities may be classified as essential regardless of size, under Article 11 of the Act; under Article 10 of the Regulation that is done on a reasoned request from the body responsible for health. Other institutions are categorised by size, and the competent authority notifies you of the category.

Who do we notify of an incident, and within what deadline?

The competent CSIRT is NCSC-HR: early warning within 24 hours, notification within 72 hours, final report within 30 days. If patient data is affected, a parallel notification goes to the Personal Data Protection Agency (AZOP) within 72 hours.

What about medical devices that must not be patched?

Compensating measures apply: a separate network segment, traffic monitoring and restricted access. The device stays as it is and the risk is lowered around it, with a written justification.

Do we need a cyber security committee?

The law requires accountability to be clearly assigned at board level. In hospitals that is usually solved by a committee seating the board, IT, data protection and a clinical representative.

How does patient data protection connect to the law?

Through the same records. The asset register, access control and incident handling serve both regimes, so they are produced once and used twice. What differs is incident reporting: to the data protection authority within 72 hours, and to the competent CSIRT an early warning within 24 hours and a notification within 72.

Does the Act apply to private clinics too?

It applies if they are categorised. A private institution carrying out one of the four activities in the Regulation may be classified as essential regardless of size, on a reasoned request from the body responsible for health. The others fall in by size. Ownership is not the test; activity and size are.

Related pages

The pages that set out in full what hospitals and healthcare institutions have to do.

Let us talk about your institution.

Half an hour, no obligation. We go through where your institution stands and set the order of work.

Book a callINFO@RISKORIA.EU · +385 97 737 1345