Ransomware Attack on a Hospital: Which NIS2 Duties Apply?

A ransomware attack on Nipigon Hospital (Canada) knocked out lab and diagnostics. Which NIS2 duties (§§30, 32, 65 BSIG) apply to German hospitals.
A ransomware attack on Nipigon District Memorial Hospital in Ontario, Canada, knocked out lab and diagnostic services in mid-September 2026. For German hospitals, the rule has applied since December 2025: from 50 employees, the NIS2 duties under §391 SGB V kick in, including a reporting obligation within 24 hours.
What Happened at Nipigon District Memorial Hospital?
The attack encrypted patient files containing personal and health data. Outpatient lab services and diagnostic imaging have been closed until further notice ever since, and the hospital is working with external cybersecurity experts and law enforcement. The perpetrators and the attack vector remain unknown.
The hospital first published a "Code Grey Notice – Cybersecurity Incident" on Facebook, describing an incident in progress. On September 16, 2026, an update post followed, dating the start of the incident to the previous morning.
Mayor Suzanne Kukko confirmed to journalist Al Cresswell that the incident involves ransomware (DataBreaches.net). CEO Shannon Cormier stated, according to SNNewsWatch: "Immediate priorities remain the safe delivery of patient care, containment of the incident and the secure restoration of hospital systems." According to the same report, affected individuals will be notified "as required and appropriate."
For entities subject to NIS2 in Germany, the central question is which measures could have cushioned an incident like this:
Which §30 BSIG Measures Help Against an Attack Like This?
§30 BSIG obligates entities subject to NIS2 in Germany to ten minimum measures. For an incident like the one in Nipigon, incident handling, backup and crisis management, vulnerability management for unpatchable medical devices, and multi-factor authentication would be especially relevant. No information is available about the Canadian hospital's actual IT setup.
§30 (2) No. 2 BSIG: Handling of security incidents. This measure requires a structured response, including internal and external communication. Bringing in external cybersecurity experts and keeping the public informed through the hospital's update posts show what this kind of incident handling looks like in practice.
§30 (2) No. 3 BSIG: Business continuity. This includes backup management and disaster recovery, precisely for situations where lab and imaging services have to switch to manual procedures.
§30 (2) No. 5 BSIG: Vulnerability management. For unpatchable medical devices such as CT and MRI scanners, or lab IT running on outdated operating systems, compensating controls are needed when vendor patches are missing or delayed.
§30 (2) No. 10 BSIG: Multi-factor authentication. It addresses the most common ransomware entry vector in practice: compromised credentials.
How the attackers gained access to Nipigon District Memorial Hospital's systems is not publicly known. The measures listed above are general minimum requirements under German NIS2 law, not a statement about what the Canadian hospital had or lacked.
Nationwide, the BSI reported 950 ransomware incidents for the period from July 2024 to June 2025, 72 percent of them with an additional data leak. For German hospitals, these measures aren't optional. They've been a legal requirement since December 2025.
Which NIS2 Duties Apply to Hospitals in Germany?
Since December 2025, §391 SGB V has referred hospitals directly to §§30, 31, and 39 BSIG. An incident like the one in Nipigon would, in Germany, trigger a reporting cascade under §32 BSIG as well as a parallel GDPR notification. Whether a fine would follow is pure hypothetical speculation, never a statement of fact about any specific organization.
Hospitals are covered via the generic §28 BSIG thresholds, not via a bed count:
- Essential entity: from 250 employees, or from €50 million in annual revenue and €43 million in balance sheet total.
- Important entity: from 50 employees, or from €10 million each in revenue and balance sheet total.
- Exception: only gematik is exempt under §28 (6) BSIG.
In practice, this covers nearly all hospitals except the smallest operations.
An incident involving encrypted patient data triggers two parallel reporting channels. The §32 BSIG cascade requires an early warning within 24 hours, a notification within 72 hours, and a final report within one month, submitted to the BSI (all deadlines in detail). In parallel, the GDPR notification under Art. 33 applies within 72 hours to the state data protection authority, potentially supplemented by the data subject notification under Art. 34. Two recipients, two sets of deadlines, no coordinated process.
§38 BSIG personally involves hospital management. Management must implement and oversee the §30 measures itself and is liable for culpable breaches of duty; regular training is mandatory.
If a German hospital were affected by a comparable incident and failures under §30 or §32 were found, §65 BSIG could impose a fine of up to €10 million (essential entity) or €7 million (important entity); the NIS2 fine calculator helps with a rough estimate. In the reporting period from October 2024 to September 2025, the BSI recorded 43 situation reports involving healthcare providers, with an assumed number of unreported cases given the previous lack of a reporting obligation (BSI, Cybersecurity in Healthcare 2025, pp. 1–2). For details, see NIS2 applicability for healthcare.
What Can German Hospitals Check Now?
German hospitals should check whether backups are stored offline from the network and tested regularly, whether crisis communication is prepared for the failure of core systems, as became necessary in Nipigon, and whether their own §32 BSIG reporting cascade works within 24 hours. The NIS2Compass Pre-Check identifies gaps in under 15 minutes. This is about preparation, not panic.
Two steps pay off: test emergency procedures for core systems, including manual fallback processes for lab and diagnostics as became necessary in the Nipigon case (§30 (2) No. 3 BSIG). And separate the dual reporting obligation organizationally: who reports to the BSI within 24 hours in an emergency, and who informs the state data protection authority under GDPR Art. 33 in parallel? For details, see the article NIS2 Incident Reporting: When, What, and to Whom?
Finally, it's worth taking a look at your own NIS2 applicability: the Pre-Check shows which of the 124 implementation steps you already meet.
Sources:
- DataBreaches.net, 09/16/2026: Canada: Nipigon hospital hit by ransomware attack
- SNNewsWatch.com, Mike Stimpson (Local Journalism Initiative): Nipigon hospital hit by ransomware attack
- Nipigon District Memorial Hospital, Facebook: Cybersecurity Incident Update
- Nipigon District Memorial Hospital, Facebook: Code Grey Notice – Cybersecurity Incident
- §28 BSIG (Besonders wichtige Einrichtungen und wichtige Einrichtungen)
- §30 BSIG (Risikomanagementmaßnahmen)
- §32 BSIG (Meldepflichten)
- §38 BSIG (Umsetzungs-, Überwachungs- und Schulungspflicht für Geschäftsleitungen)
- §65 BSIG (Bußgeldvorschriften)
- §391 SGB V
- BSI: Die Lage der IT-Sicherheit in Deutschland 2025 (Kurzfassung)
- BSI: Cybersicherheit im Gesundheitswesen 2025
Implement NIS2 step by step
NIS2Compass guides you step by step through implementation – with an Implementation Guide, templates and Knowledge Hub.
Get startedRelated Articles
NIS2 Crisis Communication: What Role Does Telfo Play?
NIS2 requires crisis management and secure emergency communication under §30 BSIG: escalation matrix, redundant channels, crisis communication plan — plus where Telfo fits in.
10 min read
Rhysida Berlin Leak: Is Redistributing the Data a Crime?
Rhysida published Berlin government data after the city refused a ransom. Redistributing it is a crime under §202d StGB and §42 BDSG — the legal analysis, plus NIS2 lessons.
4 min read
Blossom Health cyberattack: the extortion note landed in patients' inboxes
An extortionist sent his demand directly through Blossom Health's patient messaging. What is reported, what remains open, and which obligations would apply in Germany.
12 min read