04.08.2026

CyberSec Update#31: Cybersecurity in Healthcare

Cybersecurity by Design in Healthcare. ENISA Guidelines for Public Procurement

As Jan Kochanowski once observed, “Nothing is better, nothing is more precious than health.” Today, the healthcare sector continues to hold a special place in society and the economy. For this reason, it is classified as a critical sector under NIS2 and related national cybersecurity regulations.

Among the many challenges facing healthcare organizations, cybersecurity has recently become one of the most significant, particularly in the context of ongoing efforts to comply with NIS2 requirements and national cybersecurity frameworks.

Healthcare stakeholders are already familiar with the concept of cyber hygiene, especially following the publication of ENISA’s guidance on cyber hygiene in the health sector. Today, however, it is worth looking beyond those recommendations and examining one of ENISA’s most recent publications, released on 22 July 2026, concerning recommended cybersecurity requirements that healthcare providers should impose on suppliers during procurement procedures, including public procurement processes. Hereinafter, this document will be referred to as the “ENISA Guidelines”.

The ENISA Guidelines are non-binding recommendations based on European regulatory frameworks. Consequently, additional details may be introduced through national legislation implementing NIS2. Nevertheless, the Guidelines provide a valuable point of reference for the healthcare sector across Europe, including Poland.

Why Is ENISA Focusing on the Healthcare Sector?

It is worth considering why ENISA has devoted so much attention to healthcare and why procurement processes are so important from a cybersecurity perspective. According to European Commission estimates, there are currently more than 500,000 different types of medical devices on the European market. In 2023, the value of the European medical technology market was estimated at approximately EUR 160 billion.

Technology has become an integral part not only of administrative and office functions, but also of diagnosis and treatment processes. As a result, organizations must address legal and technical challenges related to the protection of patient data and operational security.

Key Cybersecurity Regulations in Healthcare

The most important legal instruments in this area include:

  • GDPR (General Data Protection Regulation),
  • NIS2 Directive and corresponding national cybersecurity legislation,
  • Regulations on medical devices and in vitro diagnostic medical devices (MDR and IVDR),
  • European Health Data Space Regulation (EHDS),
  • Cyber Resilience Act (CRA).

ENISA Guidelines for Procurement Processes

From a hospital’s perspective, the ENISA Guidelines are not merely a checklist of cybersecurity requirements to be included in procurement documentation and contract templates. They also provide a framework for developing a procurement strategy that incorporates cybersecurity requirements from the outset.

By applying these recommendations, healthcare providers can determine which security standards should be required from suppliers and their products or services, and consequently select solutions that best meet their cybersecurity expectations.

ENISA categorizes its recommendations into general requirements and requirements applicable during the three main phases of the procurement process:

  • Plan – identifying requirements and preparing the procurement procedure;
  • Source – evaluating suppliers against established cybersecurity requirements;
  • Manage – overseeing compliance with contractual obligations, service delivery, product maintenance, and incident response.

For each requirement, ENISA specifies whether it constitutes a minimum requirement or a recommended best practice (“nice-to-have”), depending on the type of procurement.

The Guidelines cover a broad range of services and products acquired by healthcare providers, including Clinical Information Systems (CIS), medical devices, network equipment, telehealth systems, mobile endpoints, identity and access management systems, healthcare infrastructure, ICS/SCADA systems, BMS platforms, professional services, cloud services, managed services (including managed security services), and products or services incorporating artificial intelligence.

Cybersecurity by Design in Supplier Relationships

The methodology proposed by ENISA is highly comprehensive. It enables healthcare organizations to make cybersecurity an integral part of their procurement processes and embed it within relationships with suppliers, as well as within the products, services, and systems they use.

This reflects the concept of “cybersecurity by design” in practice. For suppliers operating in the healthcare sector, compliance with cybersecurity requirements may become a prerequisite for winning contracts or achieving a favorable outcome in procurement procedures. This further highlights the growing importance of cybersecurity throughout the healthcare supply chain.

1 2 3 4 62

Newsletter

Want to stay up to date?
Subscribe to our newsletter.

By entering your e-mail address above and clicking ‘Subscribe!’ you declare that you have read and accept the Terms of Service and subscribe to the newsletter, i.e. information on legal topics, including information on important legal events, legislative changes and the Law Firm's activities, services and products, via e-mail communication.

The controller of your personal data is KWKR Konieczny Wierzbicki i Partnerzy S.K.A. with its registered office in Kraków, Kącik 4 Street, 30-549 Kraków. Your data will be processed in order to provide the newsletter service and thus send commercial and marketing information to the e-mail address provided, in accordance with the Privacy Policy and the Terms of Service. For more information on the principles of personal data processing, including your rights, please see the Privacy Policy.

Please wait...

Thank you for sign up!