A healthcare sector resilient to cyber threats Digitalisation has revolutionised healthcare, improving patient services through innovations such as electronic health records, telemedicine, and AI-driven diagnostics. However, cyberattacks can have severe consequences, including delays in medical procedures, gridlocks in emergency rooms, and disruptions to vital services. The healthcare sector is one of the most targeted by cyberattacks, with an increasing number of incidents in recent years — more than in any other critical sector in the EU. Key figures 309 incidentsaffecting cybersecurity in the health sector were reported in 202354%of cyberattacks in the health sector involve ransomware To address this, the EU is taking action to protect healthcare as critical infrastructure. A new European Action Plan aims to ensure that healthcare systems, institutions, and connected medical devices are resilient against cyber threats, safeguarding patient safety and trust in digital.The Action Plan is the first among the initiatives the Commission will present during the first 100 days of the new mandate, as announced by President von der Leyen in her political guidelines. What does the Action Plan propose? The European Action Plan builds on existing legislation and aims to establish a pan-European Cybersecurity Support Centre for hospitals and healthcare providers, offering tailored guidance, tools, services, and training. It is based on 4 priorities:Enhanced prevention. The plan helps to build the healthcare sector's capacities to prevent cybersecurity incidents through enhanced preparedness measures such as guidance on implementing critical cybersecurity practices. Secondly, the Member States may also introduce Cybersecurity Vouchers to provide financial assistance to micro, small, and medium-sized hospitals and healthcare providers. Finally, EU will also develop cybersecurity learning resources for healthcare professionals.Better detection and identification of threats. The Cybersecurity Support Centre for hospitals and healthcare providers will develop an EU-wide early warning service, delivering near-real-time alerts on potential cyber threats, by 2026.Response to cyberattacks to minimise impact. The plan proposes a rapid response service for the health sector under the EU Cybersecurity Reserve. Established in the Cyber Solidarity Act, the Reserve provides incident response services from trusted private service providers. As part of the plan, national cybersecurity exercises can take place along with the development of playbooks to guide healthcare organisations to respond to specific cybersecurity threats, including ransomware. Member States are encouraged to request reporting of ransom payments from entities, to be able to provide them the support they need and allow follow-up by law enforcement authorities.Deterrence: Protecting European healthcare systems by deterring cyber threat actors from attacking them. This includes the use of the Cyber Diplomacy Toolbox, a joint EU diplomatic response to malicious cyber activities. What's in it for you?The Action Plan will create a safer and more secure environment for patients, ensuring that: personal data and medical records are protectedhealthcare services are not disrupted by cyberattackstrust is strengthened in healthcare providers, who are taking steps to prevent and respond to cyber threats How will it work? The Action Plan will be implemented in close collaboration with healthcare providers, the healthcare sector, Member States and the cybersecurity community, with the European Union Agency for Cybersecurity (ENISA) at its centre. Next steps 2025 Q1Launch a stakeholder consultation and continue exchanges with Member States and relevant networksSet up a joint Health Cybersecurity Advisory Board2025 Q2Begin work to establish a European Cybersecurity Support Centre for hospitals and healthcare providersBy end 2025Present recommendations to further refine the Action Plan2025-2026Roll out specific actions outlined in the PlanCarry out an annual Health Cyber Maturity Assessment Related links A new plan for Europe's sustainable prosperity and competitivenessAction plan on the cybersecurity of hospitals and healthcare providersCybersecurityEuropean Union Agency for Cybersecurity (ENISA)
It is based on 4 priorities:Enhanced prevention. The plan helps to build the healthcare sector's capacities to prevent cybersecurity incidents through enhanced preparedness measures such as guidance on implementing critical cybersecurity practices. Secondly, the Member States may also introduce Cybersecurity Vouchers to provide financial assistance to micro, small, and medium-sized hospitals and healthcare providers. Finally, EU will also develop cybersecurity learning resources for healthcare professionals.Better detection and identification of threats. The Cybersecurity Support Centre for hospitals and healthcare providers will develop an EU-wide early warning service, delivering near-real-time alerts on potential cyber threats, by 2026.Response to cyberattacks to minimise impact. The plan proposes a rapid response service for the health sector under the EU Cybersecurity Reserve. Established in the Cyber Solidarity Act, the Reserve provides incident response services from trusted private service providers. As part of the plan, national cybersecurity exercises can take place along with the development of playbooks to guide healthcare organisations to respond to specific cybersecurity threats, including ransomware. Member States are encouraged to request reporting of ransom payments from entities, to be able to provide them the support they need and allow follow-up by law enforcement authorities.Deterrence: Protecting European healthcare systems by deterring cyber threat actors from attacking them. This includes the use of the Cyber Diplomacy Toolbox, a joint EU diplomatic response to malicious cyber activities.