Cybersecurity for the Healthcare Sector

Hospitals, clinics, laboratories and healthcare providers. 50-5000 employees.

Applicable Regulations

ACN Determination - NIS2 Security Measures

0 guides

Determina ACN 38565/2025

Soggetti essenziali e importanti registrati presso ACN. Authority: ACN - Agenzia per la Cybersicurezza Nazionale.

Penalties: Sanzioni previste dal D.Lgs. 138/2024
Authority: ACN - Agenzia per la Cybersicurezza Nazionale
Deadline: April 14, 2025
Explore guides

AI Act

4 guides

EU Regulation 2024/1689

Regulation of artificial intelligence systems in the EU with a risk-based approach. Phased application: prohibited practices from Feb 2, 2025, GPAI obligations from Aug 2, 2025, high-risk systems from Aug 2, 2026

Penalties: Up to €35M or 7% of turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (inaccurate information). SMEs: proportionate caps
Authority: AI Office (EU Commission) + AgID (Italy)
Deadline: August 2, 2026
Explore guides

Critical Infrastructure Act

0 guides

NN 56/2013

Operatori kljucnih infrastruktura. Authority: Ministarstvo unutarnjih poslova.

Penalties: HRK 50,000 to 500,000
Authority: Ministarstvo unutarnjih poslova
Deadline: May 18, 2013
Explore guides

Critical Infrastructure Act

0 guides

ZKI (Ur. l. RS 75/2017)

Operatorji kljucne infrastrukture. Authority: Ministrstvo za obrambo.

Penalties: EUR 10,000 to 60,000
Authority: Ministrstvo za obrambo
Deadline: December 30, 2017
Explore guides

GDPR

4 guides

EU Regulation 2016/679

Personal data protection in the European Union

Penalties: Up to €20M or 4% of annual global turnover
Authority: Data Protection Authority (Garante per la Protezione dei Dati Personali)
Explore guides

General Security Policy for Health Information Systems

0 guides

Art. L.1110-4-1 Code de la sante publique

Tous les acteurs du secteur sante manipulant des donnees de sante. Authority: ANS / Ministere de la Sante.

Penalties: Sanctions by ARS or administrative authorities
Authority: ANS / Ministere de la Sante
Deadline: February 1, 2013
Explore guides

Hebergement de Donnees de Sante (HDS Certification)

0 guides

HDS

Organizations hosting health data. Authority: ANS / Ministere de la Sante.

Penalties: National penalties apply
Authority: ANS / Ministere de la Sante
Deadline: April 1, 2018
Explore guides

HSE Data Protection and Cybersecurity Framework

0 guides

Health Act 2004 (as amended), HSE Policy

Healthcare organisations in the public health system. Authority: HSE (Health Service Executive).

Penalties: Compliance enforcement through HSE governance
Authority: HSE (Health Service Executive)
Deadline: June 1, 2021
Explore guides

ISO 27001

2 guides

ISO/IEC 27001:2022 - International standard

Information Security Management System (ISMS)

Penalties: N/A (voluntary standard)
Authority: Accredited certification bodies (Accredia in Italy)
Explore guides

KRITIS-Verordnung (BSI-KritisV)

0 guides

KRITISV

Critical infrastructure operators above threshold values. Authority: BSI.

Penalties: National penalties apply
Authority: BSI
Deadline: May 3, 2016
Explore guides

Legislative Decree 138/2024 - NIS2 Transposition

0 guides

D.Lgs. 138/2024

Soggetti essenziali e importanti nei 18 settori NIS2 (50+ dipendenti o 10M+ fatturato). Authority: ACN - Agenzia per la Cybersicurezza Nazionale.

Penalties: Fino a 10 milioni di euro o 2% del fatturato mondiale annuo
Authority: ACN - Agenzia per la Cybersicurezza Nazionale
Deadline: October 16, 2024
Explore guides

Ley 8/2011 de Proteccion de Infraestructuras Criticas

0 guides

LPIC

Critical infrastructure operators (12 strategic sectors). Authority: CNPIC / Ministerio del Interior.

Penalties: National penalties apply
Authority: CNPIC / Ministerio del Interior
Deadline: April 29, 2011
Explore guides

Loi de Programmation Militaire (LPM 2024-2030) - Art. cyber OIV

0 guides

LPM

Operateurs d'Importance Vitale (OIV). Authority: ANSSI / SGDSN.

Penalties: National penalties apply
Authority: ANSSI / SGDSN
Deadline: January 1, 2024
Explore guides

Loi du 1er juillet 2011 relative a la securite et la protection des infrastructures critiques

0 guides

LSRI

Critical infrastructure operators. Authority: Centre de crise national.

Penalties: National penalties apply
Authority: Centre de crise national
Deadline: July 1, 2011
Explore guides

NIS2

4 guides

EU Directive 2022/2555 - Legislative Decree 138/2024

Network and information security for essential and important entities

Penalties: Up to €10M or 2% of annual turnover
Authority: ACN - National Cybersecurity Agency
Deadline: October 17, 2024
Explore guides

Ordinance on Minimum Network and Information Security Requirements

0 guides

Naredba za MMIS (prieta s PMS 186/2019)

Operators of essential services and digital service providers. Authority: State Agency for Cybersecurity.

Penalties: BGN 5,000 to BGN 25,000 for first offence
Authority: State Agency for Cybersecurity
Deadline: August 2, 2019
Explore guides

Patient Data Act - Security Provisions

0 guides

SFS 2008:355

Vardgivare som behandlar patientdata. Authority: Socialstyrelsen / IMY.

Penalties: Regulatory sanctions by IVO and IMY
Authority: Socialstyrelsen / IMY
Deadline: July 1, 2008
Explore guides

PSNC - Perimetro Sicurezza Nazionale Cibernetica (D.L. 105/2019)

2 guides

PSNC

National cybersecurity and compliance obligations for organizations within the scope of this regulation.

Penalties: National penalties apply
Authority: Presidenza del Consiglio dei Ministri
Deadline: November 21, 2019
Explore guides

Sakerhetsskyddslag (2018:585) - Security Protection Act

0 guides

SAKERHETSSKYDDSLAGEN

Entities handling classified information, security-sensitive activities. Authority: Saekerhetspolisen (SAPO).

Penalties: National penalties apply
Authority: Saekerhetspolisen (SAPO)
Deadline: April 1, 2019
Explore guides

Sikkerhetsloven (Security Act)

0 guides

SIKKHETSLOV

Entities handling classified info, critical infrastructure. Authority: NSM.

Penalties: National penalties apply
Authority: NSM
Deadline: January 1, 2019
Explore guides

Wet op de geneeskundige behandelingsovereenkomst + NEN 7510

0 guides

WGS

Healthcare organizations, health data processors. Authority: Dutch Healthcare Authority.

Penalties: National penalties apply
Authority: Dutch Healthcare Authority
Deadline: January 1, 2017
Explore guides

Discover Your Compliance Level for Healthcare

Check in just a few minutes which regulations apply to your healthcare business and the priority actions to become compliant.

Start Free Assessment

Audit your website automatically

Scan your public website for GDPR cookie banner, accessibility (WCAG 2.1 AA), legal transparency and security headers — AI generates copy-pasteable fixes and a PDF report.

Discover the Website Compliance Audit