EU To Strengthen Cyber Defence In Healthcare  

The European Commission has published a comprehensive plan to fortify the cyber security of hospitals and healthcare providers across the EU. 

Recognising the increasing frequency of cyber attacks on healthcare systems, the EU Action Plan aims to safeguard patient care, improve response capabilities, and establish trust in digital healthcare solutions. 

The Plan is intended to demonstrate the EU's  a commitment to building a secure and resilient healthcare sector.  

The healthcare sector has witnessed a rise in cyber attacks in recent years. In 2023 alone, EU Member States reported 309 significant cyber security incidents targeting healthcare providers, more than any other critical industry.  These disruptions, which can delay medical procedures and endanger lives, highlight the pressing need for resilient cybersecurity strategies. 

Enhanced Prevention

The plan emphasises strengthening the healthcare sector’s preparedness to prevent cyber security incidents.  This includes: 

  • Guidance on Critical Cyber Security Practices: Hospitals and healthcare providers will receive tailored guidelines to implement best practices for cyber security. 
  • Cyber Security Vouchers: Financial assistance in the form of vouchers will be made available to micro, small, and medium-sized healthcare providers to enhance their cyber security capabilities. 
  • Learning Resources: New educational tools and training programs will be developed to equip healthcare professionals with the knowledge needed to navigate cybersecurity challenges. 

Improved Threat Detection: The EU Action Plan proposes the establishment of a Cybersecurity Support Centre for Hospitals and Healthcare Providers under the guidance of ENISA, the EU Agency for Cybersecurity.  

  • By 2026, the Centre will provide an EU-wide early warning system, offering near-real-time alerts about potential cyber threats. 

Effective Response to Cyber Attacks: To minimise the impact of cyber incidents, the Action Plan includes the following measures: 

  • A rapid response service under the EU Cybersecurity Reserve, leveraging private incident response providers to support healthcare organisations. 
  • Development of response playbooks to guide healthcare organisations in handling specific threats, such as ransomware. 
  • National cyber security exercises to strengthen incident response capabilities across Member States. 
  • Encouragement for Member States to mandate the reporting of ransom payments, enabling authorities to provide support and conduct follow-ups with law enforcement. 

Deterrence: To discourage cyber attacks on the EU healthcare systems, the plan includes the use of the Cyber Diplomacy Toolbox, a coordinated EU diplomatic response to malicious cyber activities.  

  • This framework aims to hold cyber threat actors accountable and protect critical healthcare infrastructure. 

Collaborative Implementation 

The success of the EU Action Plan will depend on collaboration amongst healthcare providers, Member States, and the cyber security community.  To ensure the plan is effective and addresses the needs of all stakeholders, the Commission will soon launch a public consultation open to citizens and industry experts. The feedback gathered will help refine the proposed measures, with specific actions scheduled for rollout in 2025 and 2026. 

Legislative Framework 

The EU Action Plan builds on existing EU legislation.  Healthcare providers are identified as a sector of high criticality under the NIS2 Directive, which works in tandem with the Cyber Resilience Act, a landmark EU regulation that mandates cyber security requirements for digital products.  

The recently established Cyber Emergency Mechanism under the Cyber Solidarity Act will play a crucial role in detecting, preparing for, and responding to cyber security threats. The initiative also supports the broader goal of creating a European Health Data Space, a framework designed to empower citizens with control over their health data while ensuring the security of sensitive information. 

Executive Vice-President for Tech Sovereignty, Security, & Democracy, Henna Virkkunen, emphasised the importance of resilience in healthcare systems: “We are launching an Action Plan to ensure that healthcare systems, institutions, and connected medical devices are resilient... Prevention is better than cure, so we need to prevent cyber-attacks from happening. But if they happen, we need to have everything in place to detect them and to quickly respond and recover.” 

By addressing cyber security challenges through prevention, detection, response, and deterrence, the plan lays the groundwork for a safer healthcare environment where technology empowers patients, enhances care, and supports professionals. 

EU Commision   |    IndustrialCyber   |    Cyber Express  |  SC Magazine  |    Infosecurity Magazine 

Image: Mart-Production

You Might Also Read: 

Protecting Patient Privacy: Cybersecurity Priorities For Healthcare:


If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

 


Cyber Security Intelligence: Captured Organised & Accessible


 


 

« Thermodynamic Computing - A New Computer Architecture
Data Broker Discloses A Major Breach Of App User Data »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

WireX Systems

WireX Systems

WireX is an innovative network intelligence and forensics company that is changing the way businesses resolve cyber-attacks.

UZCERT

UZCERT

UZCERT is the national Computer Emergency Response Team for Uzbekistan.

Emerson Electric Co

Emerson Electric Co

Emerson provides industrial automation systems and associated cybersecurity solutions to protect critical process control systems from cyber attack.

Soracom

Soracom

Soracom offers secure, scalable, cloud-native connectivity developed specifically for the Internet of Things.

Cyber Forensic & Investigation (CFI)

Cyber Forensic & Investigation (CFI)

Cyber Forensic & Investigation (CFI) is recognized as Thailand’s leader in cyber investigations and digital forensics.

Veritas Technologies

Veritas Technologies

Veritas provide industry-leading solutions that cover all platforms with backup and recovery, business continuity, software-defined storage and information governance.

European Healthcare Fraud & Corruption Network (EHFCN)

European Healthcare Fraud & Corruption Network (EHFCN)

EHFCN is the only organisation dedicated to combating fraud, corruption and waste in the healthcare sector across Europe.

Montreal International

Montreal International

You’re an entrepreneur planning to launch a company in an innovative sector such as AI, cybersecurity, 'deeptech' or fintech? You’ve found the right place!

Cybersecure Policy Exchange (CPX)

Cybersecure Policy Exchange (CPX)

Cybersecure Policy Exchange is a new initiative dedicated to advancing effective and innovative public policy in cybersecurity and digital privacy.

AlertSec

AlertSec

AlertSec Ensure is a U.S. patented technology that allows you to educate, verify and enforce encryption compliance of third-party devices.

Jacobs

Jacobs

Jacobs is at the forefront of the most important security issues today. We are inspired to be the best and deliver innovative, mission-focused outcomes that matter to our clients.

Fasken

Fasken

Fasken is one of the largest business law firms in Canada and a recognized leader in privacy and cybersecurity law.

Two Six Technologies

Two Six Technologies

Two Six Technologies delivers R&D, innovation, productization and implementation expertise in cyber, data science, mobile, microelectronics and information operations.

Dion Training Solutions

Dion Training Solutions

Dion Training Solutions offer comprehensive training in areas such as project management, cybersecurity, agile methodologies, and IT service management.

Operational Systems (OpSys)

Operational Systems (OpSys)

OpSys is a leading Managed IT and Cyber Security provider protecting the critical elements of businesses across the globe.

Redport Information Assurance

Redport Information Assurance

Redport Information Assurance is an information assurance and cyber security solutions provider offering integrated business solutions for all levels of government.