Skip to main content
European Commission

Cybersecurity of hospitals and healthcare providers

A healthcare sector resilient to cyber threats

Key figures

309 incidents
affecting cybersecurity in the health sector were reported in 2023
54%
of cyberattacks in the health sector involve ransomware

To address this, the EU is taking action to protect healthcare as critical infrastructure. A new European action plan aims to ensure that healthcare systems, institutions, and connected medical devices are resilient against cyber threats, safeguarding patient safety and trust in digital.

The action plan is the first among the initiatives the Commission will present during the first 100 days of the new mandate, as announced by President von der Leyen in her political guidelines.

What does the action plan propose?

The European action plan builds on existing legislation and aims to establish a pan-European cybersecurity support centre for hospitals and healthcare providers, offering tailored guidance, tools, services, and training. 

What's in it for you?

The action plan will create a safer and more secure environment for patients, ensuring that:

  • personal data and medical records are protected

  • healthcare services are not disrupted by cyberattacks

  • trust is strengthened in healthcare providers, who are taking steps to prevent and respond to cyber threats

How will it work?

The action plan will be implemented in close collaboration with healthcare providers, the healthcare sector, Member States and the cybersecurity community, with the European Union Agency for Cybersecurity (ENISA) at its centre.

Contribute to the consultation

To gather input, the Commission has launched a targeted consultation. The results will further contribute to the recommendations that the Commission plans to present by the end of the year.

Go to the survey

Next steps

  1. 2025 Q1

    Set up a joint health cybersecurity advisory board

  2. 2025 Q2

    Begin work to establish a European cybersecurity support centre for hospitals and healthcare providers

    Launch of a skateholder consultation

  3. By end 2025

    Present recommendations to further refine the action plan

  4. 2025-2026

    Roll out specific actions outlined in the plan

    Carry out an annual health cyber maturity assessment