NIS2Compass — NIS2-Compliance-Plattform
Use CasesPricing
Go to platform

Weiterführende Seiten

  • Blog
  • FAQ
  • Glossar
  • Use Cases
  • Branchen
  • Preisgestaltung

Offizielle Quellen

  • BSI – Bundesamt für Sicherheit in der Informationstechnik
  • NIS2-Richtlinie (EUR-Lex)
  • NIS2UmsuCG (Bundesgesetzblatt)
NIS2Compass — NIS2-Compliance-Plattform

Ihr Navigator durch die NIS2-Compliance

Rechtliches

  • Datenschutzerklärung
  • Allgemeine Geschäftsbedingungen
  • Cookie-Richtlinie
  • Impressum

Ressourcen

  • Blog
  • Use Cases
  • Branchen
  • Preise
  • FAQ
  • Glossar

Kontakt

Kontakt

kontakt@nis2compass.de

NIS2Compass bietet Informationen und Orientierungshilfen zur NIS2-Compliance. Die Inhalte stellen keine Rechtsberatung im Sinne des Rechtsdienstleistungsgesetzes (RDG) dar und ersetzen keine individuelle rechtliche oder fachliche Beratung.

© Copyright 2026 NIS2Compass. Alle Rechte vorbehalten.

Entwickelt in DeutschlandAllianz für Cyber-Sicherheit — Teilnehmer
HomeIndustriesHealthcare

NIS2 in Hospitals and Healthcare

Written by the NIS2Compass Team · Last updated: April 2026

Hospitals and larger medical care centers fall under Annex 1 BSIG, Healthcare sector. §391 SGB V has, since December 2025, referenced §§30, 31 and 39 BSIG. The old §75c SGB V legacy must be consolidated. NIS2Compass delivers the structured implementation path and addresses the dual notification duty of GDPR Art. 33 plus §32 BSIG.

  • §30 BSIG duties from §391 SGB V structured end-to-end
  • GDPR and NIS2 notifications coordinated: BSI plus state data-protection authority
  • Map existing B3S evidence to NIS2 substeps yourself
  • For IT teams of 5-12 people without hospital-IT consulting
Try Pro · €29/monthBlog: Am I affected by NIS2?
Hosted in Germany·GDPR-compliant·cancellable monthly

Are you as a hospital or medical center affected by NIS2?

Sector

Annex 1 BSIG, Healthcare sector: healthcare providers, pharmaceutical wholesale, manufacturers of critical medical devices.

Size

50+ employees or > €10M revenue. Practically all hospitals except very small ones. Single practices are typically below.

Special regulation §391 SGB V

§391 SGB V directly references BSIG duties for hospitals. gematik is exempted per §28 (6) BSIG, a caveat relevant for pharmacies and TI providers.

Classification for medical centers and hospital groups: „Am I affected by NIS2?" in the blog

Typical NIS2 challenges in hospitals

B3S legacy consolidation

The industry-specific security standard is not gone with NIS2, but duties overlap without a 1:1 replacement. The transition must be structured.

Unpatchable medical devices

CT, MRI and lab IT run on legacy operating systems. §30 No. 5 cannot be implemented like in office IT. Compensating measures are required.

Dual notification duty

A patient data breach triggers §32 BSIG and GDPR Art. 33 in parallel. Two recipients, two timelines, often no coordinated process.

How NIS2Compass helps hospitals

A hospital with 350 beds and 8 people in the IT team faces two challenges: consolidating §75c SGB V legacy evidence with the new §391 SGB V / BSIG duties, and steering parallel notifications to BSI and state data-protection authority cleanly on incidents. NIS2Compass structures the full NIS2 implementation path across 124 substeps. Articles A-17 and B-10a explain GDPR/NIS2 coordination concretely. The incident register template ensures uniform documentation, a foundation for both notifications. Without additional hospital-IT consulting at €700-1,200 per day.

NIS2 Guide

124 substeps, each with a template and article

GDPR and NIS2 coordination

Articles A-17 and B-10a explain the process

Incident register template

Uniform documentation base for both notifications

Which §30 BSIG obligations apply to hospitals?

§30 No. 5

Network security and vulnerability management

Two-sided for hospitals: office IT can be patched and segmented in the classic way. Medical devices (CT, MRI, lab equipment) often cannot. Compensating measures apply: network segmentation, strict access control, monitoring.

§32

Notification procedure (coupled with GDPR Art. 33)

24 h early warning, 72 h full notification, 1 month final report to BSI, in parallel to the 72-h GDPR notification to the state data-protection authority. The coordinated process prevents duplicated work and contradictions.

§38

Management body responsibility

Hospital management and supervisory board must approve risk management measures, monitor implementation and undergo regular training. Personal liability on breach of duty.

More in the blog: Am I affected by NIS2?, NIS2 implementation step by step, NIS2 in Germany: what companies need to know.

NIS2Compass in comparison for hospitals

Comparison NIS2Compass vs. hospital-IT consulting, ISMS tool and self-implementation for hospitals
KriteriumNIS2CompassKlassische BeratungISMS-ToolSelbstumsetzung
Monthly cost€29€700-1,200/day€200-2,000/month€0
§391 SGB V contextexplicitdepends on consultantgenericbuild yourself
GDPR and NIS2 coordinationdedicated article clusterindividualoften omittedbuild yourself
German templatesyes (45+)tailoredmostly Englishno
Onboarding10 minutesweeksdays + setupmonths
For 5-12-person hospital ITyestoo expensivetoo complexcapacity-challenged

Frequently asked questions on NIS2 in hospitals

Ready to implement NIS2 in your hospital?

§391 SGB V, §32 BSIG, GDPR Art. 33: coordinated in one platform.

Try Pro · €29/monthBlog: Am I affected by NIS2?
cancellable monthly·no setup fee·Hosted in Germany

Official sources

  • §391 SGB V in full text (German)
  • §30 BSIG in full text (German)
  • BSI guide on NIS2 regulation (German)
  • GDPR Art. 33 (German)