Cybervize
NIS-2 for healthcare

Care delivery is Annex I, device makers mostly Annex II.

Annex 1 to the German BSIG ("Anlage 1") covers healthcare facilities, EU reference laboratories and pharma manufacturers as a sector of high criticality; medical device makers generally sit in Annex 2, only manufacturers of medical devices classed as critical during a public health emergency sit in Annex 1. MDR (the EU medical device regulation) and GDPR with special patient-data protection also apply. Our vCISO leads the implementation of the information security obligations and works with OdySecure, the security platform by Cybervize.

Book the NIS-2 risk check

NIS-2 classification: healthcare

Classification
Annex 1 BSIG: healthcare facilities, EU reference laboratories, pharma manufacturers
Medical devices
generally Annex 2 (no. 5.1.1) for manufacturers, special cases Annex 1 (no. 4.1.5)
Wichtige Einrichtung
from 50 employees, or annual turnover and annual balance sheet total each above €10M
Besonders wichtige Einrichtung
from 250 employees, or annual turnover above €50M and balance sheet total above €43M
Exception
tiered exemption for gematik and telematics infrastructure (§ 28 Abs. 6 Nr. 2 BSIG)
Reporting deadlines
initial report 24 hours, follow-up 72 hours, final report one month
Obligations
10 minimum measures under § 30 BSIG
On top
KRITIS from 30,000 inpatient cases per year, MDR for connected medical devices

Standard case under § 28 of the German BSIG. "Wichtige Einrichtung" is the standard tier, "besonders wichtige Einrichtung" the stricter tier; the figures are annual values. Calculating them in annual work units, attributing partner and linked enterprises, special cases and the final classification under German law all require a case-by-case legal review. Annex 1 no. 4.1.5 covers only manufacturers of medical devices classed as critical during a public health emergency. The reporting deadlines require a significant incident (§ 32 BSIG). The exception: §§ 30, 31, 32, 35, 36, 38 and 39 BSIG do not apply to gematik, the German digital health agency; to operators of telematics infrastructure (TI) services only for their approved services; to other operators only where they use the TI for confirmed applications.

Cybervize building blocks for healthcare

Your vCISO works with OdySecure: ISMS, BCM, assessment and supplier risk on one data foundation. Especially relevant for healthcare: clinical IT and medical devices in the risk register and supplier risk for device manufacturers.

Self-check available

NIS-2 maturity check: 30 questions, 10 §30 BSIG measures, instant traffic light

Free, no signup, around 5 minutes. Detailed evaluation by email if desired.

Start the check
More about NIS-2 for healthcare

What NIS-2 means in practice for healthcare

Hospitals with 30,000+ inpatient cases per year qualify as KRITIS operators and are then in the stricter tier ("besonders wichtige Einrichtung"); for the sector’s other entities, company size decides the tier. Medical device and IVD manufacturers generally fall under Annex 2 to the German BSIG (no. 5.1.1); only manufacturers of medical devices classed as critical during a public health emergency fall under Annex 1 (no. 4.1.5); for health IT, the classification depends on the type of entity. MDR cybersecurity requirements add up. Four consequences of this legal situation, relevant for hospitals, labs and parts of the pharma sector. Sector alone is not enough: the classification under German law depends on activity and size thresholds (BSIG Annexes 1 and 2, MDR, AMG). The legally binding evaluation remains a matter for specialised counsel.

01

The annex sets the sector, size sets the tier

Anlage-1 entities with 50 to 249 employees are usually in the standard tier ("wichtige Einrichtung"). The stricter tier ("besonders wichtige Einrichtung"), with the highest sanction level and proactive BSI supervision, starts at 250 employees, or at annual turnover above €50M and annual balance sheet total above €43M; KRITIS hospitals reach it regardless of size. Cyber incidents touching patient data carry double reporting obligations: the BSI under § 32 BSIG where it applies, plus the data-protection authority under GDPR.

02

Medical devices with IT interfaces in scope

Medical devices with IT interfaces (imaging, lab equipment, connected implants) fall under the MDR and sit in the operator’s cybersecurity scope. As entities, their manufacturers generally fall under Annex 2 to the German BSIG (no. 5.1.1); only manufacturers of medical devices classed as critical during a public health emergency fall under Annex 1 (no. 4.1.5). Manufacturers also carry post-market surveillance obligations, hospitals carry user obligations.

03

KRITIS regulation for large facilities

Hospitals with 30,000 or more inpatient cases per year fall under the German KRITIS regulation. Obligations under BSI standards and security audits add up.

04

Patient-data protection under GDPR special categories

Health data are special categories under Art. 9 GDPR. Processing requires specific legal grounds. A cyber incident with a data breach triggers tightened reporting obligations and higher GDPR sanction risks.

What applies in healthcare, and what sits in the catalogue

Patient data and continuity of care place two different demands on the same organisation, and data protection is not the same as information security. In OdySecure both strands sit in one catalogue.

  • ISO/IEC 27001The shared language of the management system.123 records, reference
  • BSI IT-GrundschutzModules and methodology of the BSI, where the German approach is used.74 modules, BSI methodology
  • ISO/IEC 27701A privacy management system of its own, integrable into the ISMS.35 records, reference
  • GDPRProtection of personal data, with health data in the special category.23 records, full catalogue
  • KRITIS umbrella actPhysical resilience of critical care. Cybersecurity is governed alongside it by the BSIG.16 records, full catalogue
  • CER DirectiveResilience of critical entities, beyond IT.14 records, full catalogue
  • SGB V Section 391IT security in hospitals.8 records, full catalogue

A sector standard B3S for healthcare is not held in the catalogue. The classification under § 28 BSIG is set out below.

Full catalogue with depth and type of assurance

Five minimum measures with healthcare examples

Five NIS-2 minimum measures per §30, translated for healthcare practice.

01

Risk analysis with medical-device context

Risk register separating office IT, clinical IT (HIS, RIS, PACS) and medical devices but tying them together. Patient safety risks from cyber incidents classified separately.

02

Supply chain security for medical devices

Supplier inventory with medical-device manufacturers, MDR status, cybersecurity bill of materials (CBOM) for connected devices, agreements on patches and vulnerability disclosure.

03

Cryptography for patient data

Patient data encrypted at rest and in transit, key management central and audit-ready, clinical backups in a dedicated security zone. § 391 SGB V (formerly § 75c) requires hospitals to take precautions in line with the state of the art.

04

Incident response with patient impact

Incident response plan distinguishing pure cyber incidents from incidents with patient safety impact. Escalation to BSI, data-protection authority, hospital supervisor. MDR manufacturers also notify BfArM.

05

Business continuity for clinical care

BCM plan with patient safety as the top priority. Fall-back processes for HIS outage (paper records, manual workflow), emergency care during ransomware. Restart sequence documented.

Why Cybervize fits healthcare

Methodology built for audit acceptance towards the BSI.

KRITIS
BSIG and KRITIS regulation coverage
MDR
interface documented (no catalogue)
§ 391 SGB V
hospital IT security (SGB V)
50
frameworks held as a catalogue

Frequently asked questions from healthcare

Most likely yes. Annex 1 of the German BSIG (NIS-2 Annex I) covers healthcare facilities as a sector of high criticality. From 50 employees, or when turnover and balance sheet total each exceed 10 million euros, the usual classification is important entity; essential entity follows from 250 employees, or annual turnover above 50 million euros and a balance sheet total above 43 million euros. From 30,000 inpatient cases per year, the German KRITIS regulation adds up. The legally binding evaluation remains a matter for counsel.

Hospital IT security has been regulated in German social law since 2022, first in § 75c SGB V and, since the 2024 Digital Act, in § 391 SGB V. In principle it covers all hospitals; KRITIS hospitals are exempt to the extent they already have to take measures under sections 30, 31 and 39 of the German BSIG (§ 391 Abs. 5 SGB V). Implementation can follow the B3S Krankenhaus, the sector-specific security standard. NIS-2 is a general law with minimum measures, the B3S is more concrete for the sector. In practice they largely overlap.

Legacy medical devices without patch capability are common. NIS-2 requires appropriate measures at the state of the art. Compensating controls (network segmentation, monitoring, restricted connectivity) are accepted. Documented risk acceptance instead of sweeping under the rug. On patient safety impact the MDR manufacturer must be notified.

Multiple escalation paths: staggered BSI report under § 32 BSIG (24-hour initial report, 72-hour report, final report), data-protection authority on data breach, hospital supervisor at state level, MDR manufacturer on device involvement. Plus patient-safety triage (ensure emergency care). A special rule covers the German telematics infrastructure (TI): § 28 Abs. 6 Nr. 2 BSIG exempts gematik, the German digital health agency, as a whole from core BSIG duties, operators of TI services for their approved services, and other operators only where they use the TI for confirmed applications. The platform supports with documented reporting paths inventory.

For a 250- to 500-bed hospital, typically 16 to 24 weeks to become audit-ready for NIS-2, depending on KRITIS status, IT modernisation level and number of sites. The platform licence is priced by modules and digitally connected people. The risk check gives you a specific indication.

Classify NIS-2 for healthcare in 30 minutes

Free risk check with indicative NIS-2 classification, KRITIS threshold indicator and path recommendation. Ideally with IT leadership or data protection officer plus management board present.

Book the NIS-2 risk check

In scope? How you get to a provable security posture

If the classification above fits your organisation, the first step is to establish where you stand. Once it is clear which obligations apply and where the gaps are, the question is who closes them: a vCISO working with OdySecure, or your own team with a platform licence.

Book a vCISO callSee the journey in five stations

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT