Skip to main content

A healthcare sector resilient to cyber threats

Digitalisation has revolutionised healthcare, improving patient services through innovations such as electronic health records, telemedicine, and AI-driven diagnostics. However, cyberattacks can have severe consequences, including delays in medical procedures, gridlocks in emergency rooms, and disruptions to vital services.  

The healthcare sector is one of the most targeted by cyberattacks, with an increasing number of incidents in recent years — more than in any other critical sector in the EU. 

Key figures

309 incidents
affecting cybersecurity in the health sector were reported in 2023
54%
of cyberattacks in the health sector involve ransomware

To address this, the EU is taking action to protect healthcare as critical infrastructure. A new European Action Plan aims to ensure that healthcare systems, institutions, and connected medical devices are resilient against cyber threats, safeguarding patient safety and trust in digital.

The Action Plan is the first among the initiatives the Commission will present during the first 100 days of the new mandate, as announced by President von der Leyen in her political guidelines.

What does the Action Plan propose?

The European Action Plan builds on existing legislation and aims to establish a pan-European Cybersecurity Support Centre for hospitals and healthcare providers, offering tailored guidance, tools, services, and training. 

What's in it for you?

The Action Plan will create a safer and more secure environment for patients, ensuring that:

  • personal data and medical records are protected

  • healthcare services are not disrupted by cyberattacks

  • trust is strengthened in healthcare providers, who are taking steps to prevent and respond to cyber threats

How will it work?

The Action Plan will be implemented in close collaboration with healthcare providers, the healthcare sector, Member States and the cybersecurity community, with the European Union Agency for Cybersecurity (ENISA) at its centre.

Next steps

  1. 2025 Q1

    Launch a stakeholder consultation and continue exchanges with Member States and relevant networks

    Set up a joint Health Cybersecurity Advisory Board

  2. 2025 Q2

    Begin work to establish a European Cybersecurity Support Centre for hospitals and healthcare providers

  3. By end 2025

    Present recommendations to further refine the Action Plan

  4. 2025-2026

    Roll out specific actions outlined in the Plan

    Carry out an annual Health Cyber Maturity Assessment