ENISA publishes cybersecurity procurement guidelines for hospitals and healthcare providers

Original title: Procurement guidelines for the cybersecurity of hospitals and healthcare providers

ENISA has published procurement guidelines designed to help hospitals and healthcare providers incorporate cybersecurity objectives throughout their entire procurement lifecycle. The guidelines provide practical guidance for identifying and addressing cybersecurity risks comprehensively. They establish clear cybersecurity requirements for suppliers and specify necessary information to be provided, while maintaining alignment with NIS2 Directive, GDPR, medical device regulations, and the European health data space regulation. Healthcare organizations can use these guidelines to strengthen their supply chain security and reduce cyber risks in critical healthcare infrastructure.

What changed

  • ENISA published new procurement guidelines covering all phases of the procurement life cycle for healthcare organizations, providing practical guidance on integrating cybersecurity objectives into procurement processes.
  • The guidelines establish clear cybersecurity requirements that hospitals and healthcare providers must include in their procurement specifications.
  • Guidelines specify the information that suppliers must provide to demonstrate their cybersecurity capabilities and compliance with relevant standards.
  • The procurement guidelines are explicitly aligned with NIS2 Directive, GDPR, medical device regulations, and the European health data space regulation to ensure consistency with regulatory requirements.

What the document requires

ENISA procurement guidelines require hospitals and healthcare providers to integrate cybersecurity objectives into their procurement processes and set clear cybersecurity requirements for suppliers.

Who is affected

Hospitals and healthcare providers in the EU, including public and private healthcare institutions responsible for procurement of products and services with cybersecurity implications.

Summary generated by a language model; the official text prevails. Not legal advice.