Health is in Annex 1 to OUG 155/2024, among the sectors of high criticality. A medium-sized private clinic is an important entity and a large hospital is an essential entity. The assurance level, however, comes from the risk score: 145 points for a medium-sized organisation and 217.5 for a large one.

Who is covered by NIS2 in healthcare

Annex 1 to OUG 155/2024 takes over the list in the NIS2 Directive and adds to it. In health, it covers:

Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.

Which assurance level applies

Organisation sizeEntity typeStandard risk scoreAssurance levelAt self-assessment
Small or microoutside NIS2, except for the cases in the law72.5basic34 controls, threshold 2.5
Mediumimportant145important133 controls, threshold 3
Largeessential217.5essential218 controls, threshold 3.5 and at least 3 in every category

The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.

Find your level and maturity score in a few minutes. The calculator opens with the “Health” sector already selected; you choose the size and answer 12 questions.

Calculate the level for healthcare

Which systems are usually assessed

The assessment and the audit cover the networks and information systems the medical service depends on. In a hospital or clinic, they usually include:

The lesson of February 2024

On the night of 11 to 12 February 2024, a ransomware attack on the Hipocrate hospital information system disrupted 26 hospitals. Another 79 units were disconnected from the internet as a precaution. The attackers asked for 3.5 bitcoin, and DNSC advised against paying the ransom.

The attack used the Backmydata variant, from the Phobos family, which spreads through Remote Desktop connections. Most hospitals had backups from 1–3 days earlier; one had a backup from 12 days earlier.

For NIS2, the lesson has three parts: suppliers’ remote access must be controlled and protected with multi-factor authentication, backups must be tested, and suppliers belong in the supply-chain risk assessment required by art. 13(d) of OUG 155/2024.

What comes next

How TRU helps

Hospitals and clinics run around the clock, and an incident is felt by patients straight away. That is why we usually start with:

Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.

Frequently asked questions

Does a small medical practice fall under NIS2?

As a rule, no. Small and micro companies are covered only in the special cases in the law, for example if DNSC designates them. GDPR obligations for patient data apply anyway.

Does a pharmacy fall under NIS2?

Yes, if the company operating it is medium-sized or large. Law No. 124/2025 added retail sale of pharmaceutical products and wholesale of medicines to the health sector. What counts is the company, not the shop: a large pharmacy chain is an essential entity.

Does a medical device manufacturer fall under NIS2?

Yes, if its devices are considered critical during a public health emergency and the company is medium-sized or large. Other medical device manufacturers may be covered through the manufacturing sector, in Annex 2, as important entities.

Are the hospital’s medical devices part of the assessment?

Yes, if they are networked and support the medical service. You add them to the inventory, segment them on the network and control who connects to them remotely.

Sources

OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · HotNews, the attack on the Hipocrate system, 14 February 2024 (in Romanian) · CMS, the changes made by Law No. 124/2025.