CRA full compliance required 453 days left What it means for you
THZ Networks Under attack? SOS — incident response, any hour of any day

NIS2 · GDPR

Healthcare

Hospitals, laboratories and medical device makers are essential entities under NIS2, and they process the most sensitive category of personal data there is.

WHAT MAKES THIS SECTOR DIFFERENT

Where the pressure actually comes from

Two regimes land on the same incident. A ransomware outage is a NIS2 reportable event within 24 hours, and if patient records were reachable it is also a GDPR breach with a 72-hour clock and a different regulator. Device manufacturers pick up a third set of duties as the CRA phases in.