Compliance requirements for the healthcare sector.
Sector Profile
| Attribute | Value |
|---|
| AI Act impact | CRITICAL (High-Risk) |
| NIS2 category | Essential (Annex I — Health) |
| GDPR impact | CRITICAL (Special category data) |
| Other regulations | Health Services Act, MDR |
AI Act for Healthcare
High-Risk AI Systems (Annex III)
| System | Classification | Obligations |
|---|
| Diagnostic AI | HIGH-RISK | Full obligations, CE marking |
| AI for patient triage | HIGH-RISK | DPIA, human oversight |
| Predictive analytics (prognosis) | HIGH-RISK | Testing, documentation |
| AI assistant for physicians | MEDIUM | Transparency |
| Administrative AI | LOW | Minimal |
High-Risk AI in Healthcare — Requirements
NIS2 for Healthcare
Scope
- Essential entity (Annex I, sector 5 — Health)
- Hospitals, laboratories, health insurers
- Medical device manufacturers (if >250 employees)
Specific Requirements
| Area | Requirement | Priority |
|---|
| System availability | RTO <4h for critical systems | Critical |
| Patient data protection | Encryption + access control | Critical |
| Network segmentation | Medical devices isolated | Critical |
| Incident response | 24h notification to national CSIRT | Critical |
| Supply chain | Audit medical device vendors | High |
| Business continuity | Paper backup procedures | High |
Medical Device Cybersecurity
GDPR for Healthcare
Special Category Data (Art. 9)
Health data = special category — stricter rules apply
| Legal basis | When to use |
|---|
| Explicit consent | Research, secondary use |
| Necessary for healthcare | Primary care, diagnostics |
| Public interest in health | Epidemiology, public health |
| Legal obligation | Reporting of infectious diseases |
Specific GDPR Requirements
| Area | Requirement | Status |
|---|
| Retention | Medical records min. 10 years | Legal obligation |
| Access control | Role-based, need-to-know | Required |
| Audit trail | Who accessed a patient record | Required |
| Patient portal | DSAR self-service recommended | Recommended |
| Cross-border | SCCs for transfer outside EU | If applicable |
DSAR in Healthcare
Checklist for Healthcare
Short-term (Months 1-3)
Medium-term (Months 3-6)
Long-term (Months 6-12)
Typical Costs
| Item | Estimate |
|---|
| ISMS + ISO 27001 | EUR 50-80k |
| Medical device security audit | EUR 20-40k |
| AI compliance (per system) | EUR 15-30k |
| GDPR health data audit | EUR 15-25k |
| Staff training | EUR 10-20k |
| Total Y1 | EUR 110-195k |
Resources