Written by the NIS2Compass Team ·
Hospitals and larger medical care centers fall under Annex 1 BSIG, Healthcare sector. §391 SGB V has, since December 2025, referenced §§30, 31 and 39 BSIG. The old §75c SGB V legacy must be consolidated. NIS2Compass delivers the structured implementation path and addresses the dual notification duty of GDPR Art. 33 plus §32 BSIG.
Sector
Annex 1 BSIG, Healthcare sector: healthcare providers, pharmaceutical wholesale, manufacturers of critical medical devices.
Size
50+ employees or > €10M revenue. Practically all hospitals except very small ones. Single practices are typically below.
Special regulation §391 SGB V
§391 SGB V directly references BSIG duties for hospitals. gematik is exempted per §28 (6) BSIG, a caveat relevant for pharmacies and TI providers.
The industry-specific security standard is not gone with NIS2, but duties overlap without a 1:1 replacement. The transition must be structured.
CT, MRI and lab IT run on legacy operating systems. §30 No. 5 cannot be implemented like in office IT. Compensating measures are required.
A patient data breach triggers §32 BSIG and GDPR Art. 33 in parallel. Two recipients, two timelines, often no coordinated process.
A hospital with 350 beds and 8 people in the IT team faces two challenges: consolidating §75c SGB V legacy evidence with the new §391 SGB V / BSIG duties, and steering parallel notifications to BSI and state data-protection authority cleanly on incidents. NIS2Compass structures the full NIS2 implementation path across 124 substeps. Articles A-17 and B-10a explain GDPR/NIS2 coordination concretely. The incident register template ensures uniform documentation, a foundation for both notifications. Without additional hospital-IT consulting at €700-1,200 per day.
NIS2 Guide
124 substeps, each with a template and article
GDPR and NIS2 coordination
Articles A-17 and B-10a explain the process
Incident register template
Uniform documentation base for both notifications
Two-sided for hospitals: office IT can be patched and segmented in the classic way. Medical devices (CT, MRI, lab equipment) often cannot. Compensating measures apply: network segmentation, strict access control, monitoring.
24 h early warning, 72 h full notification, 1 month final report to BSI, in parallel to the 72-h GDPR notification to the state data-protection authority. The coordinated process prevents duplicated work and contradictions.
Hospital management and supervisory board must approve risk management measures, monitor implementation and undergo regular training. Personal liability on breach of duty.
| Kriterium | NIS2Compass | Klassische Beratung | ISMS-Tool | Selbstumsetzung |
|---|---|---|---|---|
| Monthly cost | €29 | €700-1,200/day | €200-2,000/month | €0 |
| §391 SGB V context | explicit | depends on consultant | generic | build yourself |
| GDPR and NIS2 coordination | dedicated article cluster | individual | often omitted | build yourself |
| German templates | yes (45+) | tailored | mostly English | no |
| Onboarding | 10 minutes | weeks | days + setup | months |
| For 5-12-person hospital IT | yes | too expensive | too complex | capacity-challenged |
§391 SGB V, §32 BSIG, GDPR Art. 33: coordinated in one platform.