NIS2/KSC · Healthcare

NIS2 and the KSC Act in hospitals and healthcare providers

In Poland, NIS2 in healthcare means obligations under the National Cybersecurity System Act (KSC Act). A hospital run as an independent public healthcare institution (SP ZOZ) is an important entity if it employs 50-249 people and an essential entity if it employs 250 or more, while a hospital run as a company falls under the general rule for the health sector. We explain the status, the competent authority, incident reporting, the deadlines and how to prepare for the audit.

01Status

NIS2 in healthcare: is your hospital in scope?

Health is one of the sectors of high criticality (Annex 1). A hospital's status depends on its legal form and its size.

SP ZOZ and other healthcare providers that are not businesses

For a healthcare provider that is not a business - above all an independent public healthcare institution (SP ZOZ), the legal form in which many Polish public hospitals operate - the Act sets separate thresholds: with 50 to 249 people employed it is an important entity, and with 250 or more an essential entity (Art. 5(8)). According to the Ministry of Digital Affairs, a healthcare provider that is not a business counts all persons engaged - under employment contracts and civil-law contracts, full-time and part-time - as at the date on which the financial statements are prepared; an independent public healthcare institution (SP ZOZ) employing fewer than 50 people is not subject to the Act (Art. 5(5) and (8); Ministry of Digital Affairs, Q&A of 1 October 2026, questions 3.20 and 3.23).

Hospital companies and other businesses

A hospital run as a company - including one in which local government holds shares - is a business, so the general rule applies: a medium-sized enterprise is an important entity and a large one an essential entity (Art. 5(1)(1) and (2)(1)). Size is calculated according to the EU definition of SMEs, together with linked and partner enterprises - so a group company that is small on its own may still be in scope.

Exclusions

  • Special services and entities subordinate to or supervised by the Minister of National Defence are not essential or important entities; the minister designates, by a decision that is not published, the units that are considered to be such entities (Art. 5(10)-(11)).
  • The Act does not apply to entities performing medical activities that are established by the Head of the Internal Security Agency (ABW) or the Head of the Foreign Intelligence Agency (AW) (Art. 1(2)(3)).

Several types of activity

A hospital that also runs a community pharmacy, operates a laboratory serving other providers or supplies water has to take each of these activities into account. The Act covers every activity listed in the annexes, both principal and ancillary (for water, waste water and waste, the annex requires the activity to be a principal or essential part of the business); several types of activity are shown separately in the application for registration (Art. 7d(2); Ministry of Digital Affairs, KSC amendment Q&A, question 2.8).

You can check your status quickly with our NIS2 scope checker, which opens with the health sector highlighted.

Types of entity in the health sector (Annex 1 to the KSC Act)
Type of entity When it is subject to the Act Legal basis
Healthcare provider (hospital, outpatient clinic, other medical facility) - including providers with hospital emergency departments (SOR) and trauma centres. Business: large - essential, medium-sized - important; non-business entity (e.g. SP ZOZ): 250 people or more - essential, 50-249 - important Annex 1, Health sector, Healthcare provision and public health subsector; Art. 5(8)
Subcontractor of essential or important entities in healthcare - an entity that provides healthcare services as a subcontractor, e.g. a laboratory or diagnostic services. Large enterprise - essential, medium-sized - important Annex 1, Health sector (Art. 133 of the Act on Healthcare Services Financed from Public Funds)
Designated EU reference laboratory Business: large enterprise - essential, medium-sized - important; non-business entity - essential regardless of size Annex 1, Health sector (Art. 15 of Regulation (EU) 2022/2371)
Public health bodies - The Minister of Health's unit responsible for healthcare information systems, offices of the State Sanitary Inspection, the National Emergency Medical Services Monitoring Centre, public blood service units. Essential regardless of size Annex 1, Health sector
Medicinal products and active substances - manufacturer, importer (including parallel importer), distributor of active substances, marketing authorisation holder, manufacture of pharmaceuticals (NACE division 21), research and development of medicinal products. Large enterprise - essential, medium-sized - important Annex 1, Health sector, Manufacture and distribution of active substances, medicinal products and medical devices subsector
Pharmaceutical wholesaler Large enterprise - essential, medium-sized - important Annex 1, Health sector (Pharmaceutical Law)
Community pharmacy Large enterprise - essential, medium-sized - important Annex 1, Health sector (Pharmaceutical Law)
Manufacturer of medical devices considered critical during a public health emergency Large enterprise - essential, medium-sized - important Annex 1, Health sector (Art. 22 of Regulation (EU) 2022/123)
The Office for Registration of Medicinal Products (URPL) or a Pharmaceutical Inspection office Essential regardless of size Annex 1, Health sector

02Authority and incidents

Competent authority, CSIRT and registration

Who supervises

The competent cybersecurity authority for the health sector is the minister responsible for health, and for entities subordinate to the Minister of National Defence it is that minister (Art. 41(5)-(6)). The authority keeps the register of essential and important entities in its sector and supervises them: essential entities both ex ante and ex post, important entities ex post only.

Registration

Hospitals and other healthcare providers apply for registration themselves, in the S46 system. Registration is declaratory - the obligations arise from the Act, not from the entry in the register. According to the Ministry of Digital Affairs, self-registration in the register is available at all times; 3 October 2026 was the last day for entities that met the criteria on the date the amendment entered into force (Ministry of Digital Affairs, Q&A of 1 October 2026, question 2.32). If you missed the deadline, apply as soon as possible - we explain what this means in practice in our NIS2/KSC audit guide.

Incident reporting

In Poland, incident notifications go to CSIRTs (computer security incident response teams). In the health sector, the sectoral team is CSIRT Centrum e-Zdrowia (the e-Health Centre's CSIRT), set up by the Ministry of Health on 1 December 2023; sectoral teams set up before 2025 count as sectoral CSIRTs without an announcement of operational capability (Art. 44(3) and Art. 46 of the amending act; CSIRT CeZ). A hospital reports a significant incident through S46: an early warning within 24 hours of detection, an incident notification within 72 hours and a final report within one month (Art. 11(1)(4)-(4c)).

In practice, reporting falls to the same team that is responsible for business continuity in the hospital: when the hospital information system fails, it has to switch to contingency procedures and meet the reporting deadlines at the same time.

03Risks

Cybersecurity in hospitals: systems and risks

A hospital is not an ordinary office - downtime affects patients, and the data is covered by medical confidentiality.

Systems a hospital depends on

  • Hospital information system and electronic medical records - healthcare service providers are required to keep electronic medical records (Art. 11(1) of the Act on the Healthcare Information System).
  • Integration with P1 and the Medical Information System (SIM) - prescriptions and referrals, and data on their fulfilment, are entered by the service provider into SIM in real time and, after a platform failure, no later than 3 days after it has been resolved (Art. 11(5)(1) and (5a) of the Act on the Healthcare Information System).
  • Diagnostic systems - picture archives, radiology and laboratory systems, often connected to medical devices on the same network.
  • Remote access for suppliers - servicing systems and medical equipment usually requires external connections, and every such connection is a potential attack path.
  • Patient portals and apps - appointment booking, test results, video consultations.

Risks to assess first

  • Ransomware and downtime - encrypted systems mean working on paper; business continuity and recovery plans have to be tested, not just written down (Art. 8(1)(2)(f)).
  • Supply chain - the vendor of the hospital system, the cloud provider and the company that services medical equipment all have access to key data. An entity entrusted with processing data from medical records is bound by secrecy, and the performance of the data processing agreement must not disrupt access to the data, which must remain available without undue delay (Art. 24(5)-(6) of the Act on Patient Rights and the Patient Ombudsman).
  • Access rights - persons who maintain the ICT system holding medical records and ensure its security process the data on the basis of the controller's authorisation and are bound by secrecy, even after the patient's death (Art. 24(2)(2) and (3) of the Act on Patient Rights and the Patient Ombudsman).
  • Medical confidentiality - persons practising a medical profession keep information relating to the patient confidential, in particular information about their state of health - even after the patient's death (Art. 14(1) and (3) of the Act on Patient Rights and the Patient Ombudsman).

04Preparation

What to check in a hospital before the audit

This list follows from the obligations in Art. 8 of the Act and from the specific nature of a hospital. You will find the full list of questions in our NIS2/KSC checklist.

  1. Asset inventory - including network-connected medical devices and systems maintained by suppliers.
  2. Network segmentation - separating the medical equipment network, the administrative network and guest access.
  3. Supplier accounts and remote access - named accounts, multi-factor authentication, session logging and revoking access once the work is finished.
  4. Backups - kept separate from production systems and regularly test-restored.
  5. Downtime procedures - how to admit patients and dispense medicines when the systems are down, and who makes that decision.
  6. Supplier contracts - security requirements, incident reporting and access to data in line with the Act on Patient Rights and the Patient Ombudsman.
  7. Training for the head of the entity and staff - the head of the entity once every calendar year, staff on an ongoing basis (Art. 8(1)(2)(i), Art. 8e).
  8. Incident reporting procedure - with designated people and access to S46, rehearsed on a scenario.

All the questions, together with the relevant provisions, are collected in our printable NIS2/KSC checklist.

05How we help

Gap analysis, implementation and testing for hospitals

  • NIS2 gap analysis - a reasoned scope assessment, a comparison of the current state with Art. 8 of the Act and a prioritised implementation plan to meet the 3 April 2027 deadline.
  • NIS2 implementation - policies, incident and business continuity procedures, and supplier requirements.
  • Penetration testing - patient portals, integrations and the internal network, with a report for the board and the IT team.
  • Board training - the duties of the head of the entity under Arts. 8c-8e.

Essential entities undergo a security audit at least once every 3 years, the first one by 3 April 2028. We carry out the Art. 15 audit in cooperation with a partner whose auditors meet the statutory requirements - and we do not audit a hospital that we helped to implement its security management system in the year before the audit.

We also build software for the healthcare sector - see healthcare software development. A public hospital buys these services through public procurement - how to prepare the request for proposals is described in our NIS2 audit pricing guide.

06Deadlines

NIS2 and KSC Act deadlines for hospitals

  • Application for registration: 3 October 2026 for entities that met the criteria on 3 April 2026 - the deadline has passed, so apply without delay; other entities - within 6 months from meeting the criteria.
  • Implementing the obligations in Chapter 3 of the Act: by 3 April 2027, and for entities that meet the criteria later - within 12 months from meeting the criteria (Art. 16).
  • First audit of an essential entity: by 3 April 2028, then at least once every 3 years.
  • Moratorium on fines: fines under Art. 73(1)-(4), Arts. 73a-73c and Art. 76b may be imposed for the first time 2 years after the amendment entered into force (according to the Ministry of Digital Affairs - after 3 April 2028). The moratorium does not cover the fine of up to PLN 100 million (Art. 35 of the amending act).

Frequently asked questions

Is every hospital subject to NIS2 and the KSC Act?

Not every one. An independent public healthcare institution (SP ZOZ) or another healthcare provider that is not a business is subject to the Act if it employs at least 50 people: with 50-249 people it is an important entity, and with 250 or more an essential entity (Art. 5(8)). According to the Ministry of Digital Affairs, an SP ZOZ employing fewer than 50 people is not subject to the Act. A hospital run as a company is a business - a medium-sized one is an important entity and a large one an essential entity. You can check this quickly with our NIS2 scope checker.

How is headcount counted in an SP ZOZ for the purposes of the KSC Act?

According to the Ministry of Digital Affairs, a healthcare provider that is not a business counts everyone it engages - under employment contracts and civil-law contracts, full-time and part-time - without converting them into full-time equivalents, as at the date on which the financial statements are prepared (Ministry of Digital Affairs Q&A of 1 October 2026, question 3.23). This is a different method from the one used by companies, which count staff according to the EU definition of SMEs.

Who is responsible for the KSC Act obligations in a hospital?

The head of the entity - in an SP ZOZ, the head of the public finance sector unit, usually the director; in a company, the management board (Art. 2(8a)). The head of the entity remains responsible for obligations entrusted to other people and undergoes documented training once every calendar year (Arts. 8c and 8e). They face a fine of up to 300% of their remuneration, although fines can only be imposed after 3 April 2028.

Where does a hospital report a significant incident?

Through the S46 system: an early warning within 24 hours of detection, an incident notification within 72 hours and a final report within one month (Art. 11). The health sector has its own computer security incident response team, CSIRT Centrum e-Zdrowia (the e-Health Centre's CSIRT), set up as a sectoral team before 2025 - such teams count as sectoral CSIRTs without a separate announcement of operational capability (Art. 44(3) and Art. 46 of the amending act).

Is an outpatient clinic, a laboratory or a pharmacy subject to the KSC Act?

It can be. Healthcare providers run as companies, community pharmacies, pharmaceutical wholesalers and subcontractors of essential or important entities in the health sector (e.g. laboratories) are listed in Annex 1, but as businesses they are subject to the size rule, with size calculated together with linked enterprises: a medium-sized one is an important entity and a large one an essential entity. A small clinic or a single pharmacy generally remains outside the Act - unless it belongs to a larger group.

Sources

  1. Act of 23 January 2026 amending the National Cybersecurity System Act and certain other acts (Dz.U. 2026 item 252) (in Polish) ()
  2. National Cybersecurity System Act - act metadata and amending acts (Sejm ELI API) (in Polish) ()
  3. Ministry of Digital Affairs - Q&A on the amendment to the KSC Act, October 2026 update (1 October 2026; explanatory document, not legally binding) (in Polish) ()
  4. CSIRT of the e-Health Centre (CSIRT CeZ) - About CSIRT CeZ (sectoral team for healthcare) (in Polish) ()
  5. Act of 6 November 2008 on Patient Rights and the Patient Ombudsman (consolidated text: Dz.U. 2024 item 581, as amended) (in Polish) ()
  6. Act of 28 April 2011 on the Healthcare Information System (consolidated text: Dz.U. 2026 item 1304) (in Polish) ()

Legal status as of Updated

Related services

Let's talk about your project or audit

Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.

or call +48 575 621 877