0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

German healthcare sector faces new cybersecurity obligations under NIS2 and KRITIS umbrella law (heise.de)

· 48d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Late 2025: revised BSI Act (NIS2) entered into force
  • March 2026: KRITIS umbrella law for physical security
  • Thresholds: 50/250 employees or €10M/€50M revenue
  • KRITIS threshold: 30,000 inpatient cases per year
  • Management is liable, must undergo training
  • Homeopathy excluded, emergency services included
  • Funding gaps threaten implementation

"Since late 2025, Germany's revised BSI Act (implementing the EU NIS2 directive) and since March 2026 the KRITIS umbrella law impose stricter security requirements on healthcare providers. Hospitals, emergency services, rehabilitation centers, and some outpatient clinics are affected based on staff size and revenue. Management bears responsibility and must establish risk management processes. Recent cyberattacks on service providers Unimed and Arwini highlight the urgency."

Discussion Matrix

0 segments

no comments yet.