Action Plan on the Cybersecurity of Hospitals and Healthcare Providers
Summary
Healthcare cybersecurity action is centred on a European Cybersecurity Support Centre, sector-specific guidance, maturity assessment and incident-response support. Planned measures include a rapid-response service in the EU Cybersecurity Reserve, a Health Cybersecurity Advisory Board, a network of health CISOs, cyber exercises and a ransomware recovery subscription service. The plan also covers cyber hygiene, threat intelligence, procurement guidance, training, regulatory mapping and international cooperation.
Action items
1–6 of 33 items
Source order · D = digital dimension- Item 1
Ensure appropriate resources for the Cybersecurity Support Centre Work with the ECCC to launch pilot projects to develop best practices for cyber hygiene and security risk assessment, and to address the need for continuous cybersecurity monitoring, threat intelligence and incident response using state-of- the art cybersecurity solutions, for the development of the European Cybersecurity Support Centre’s service catalogue 2025
- Item 2
In consultation with the NIS Cooperation Group, EU-CyCLONe and ENISA, explore identifying health as a sector for which support can be given for coordinated preparedness testing under the Cyber Solidarity Act Q1 2025
- Item 3
Together with ENISA, ensure the EU Cybersecurity Reserve includes a Rapid Response Service specifically for the health sector Q4 2025
- Item 4
Supported by ENISA, set up a joint Health Cybersecurity Advisory Board Q1 2025
- Item 5
Launch a call for action for cybersecurity companies, foundations, educational institutions, and industry stakeholders to pledge actions to address the challenges in the health sector Q2 2025
- Item 6
Together with the High Representative, explore the use of Cyber Diplomacy Toolbox measures to prevent, discourage, deter and respond to malicious activities against health systems 2025