Health is in Annex 1 to OUG 155/2024, among the sectors of high criticality. A medium-sized private clinic is an important entity and a large hospital is an essential entity. The assurance level, however, comes from the risk score: 145 points for a medium-sized organisation and 217.5 for a large one.
Who is covered by NIS2 in healthcare
Annex 1 to OUG 155/2024 takes over the list in the NIS2 Directive and adds to it. In health, it covers:
- healthcare providers: hospitals, clinics and other units providing healthcare;
- EU reference laboratories;
- entities carrying out research and development of medicinal products;
- manufacturers of basic pharmaceutical products and pharmaceutical preparations;
- manufacturers of medical devices considered critical during a public health emergency;
- holders of medicine distribution authorisations, wholesalers of pharmaceutical and medical goods (NACE 46.46) and pharmacies (NACE 47.73), added by Law No. 124/2025, in force since 10 July 2025.
Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.
Which assurance level applies
| Organisation size | Entity type | Standard risk score | Assurance level | At self-assessment |
|---|---|---|---|---|
| Small or micro | outside NIS2, except for the cases in the law | 72.5 | basic | 34 controls, threshold 2.5 |
| Medium | important | 145 | important | 133 controls, threshold 3 |
| Large | essential | 217.5 | essential | 218 controls, threshold 3.5 and at least 3 in every category |
The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.
Find your level and maturity score in a few minutes. The calculator opens with the “Health” sector already selected; you choose the size and answer 12 questions.
Calculate the level for healthcareWhich systems are usually assessed
The assessment and the audit cover the networks and information systems the medical service depends on. In a hospital or clinic, they usually include:
- the hospital information system and the electronic patient record;
- the laboratory, imaging and the medical image archive;
- networked medical devices;
- reporting to the National Health Insurance House, e-prescriptions and online appointments;
- remote access by software and maintenance suppliers;
- email and files with patient data, which are special-category data under the GDPR.
The lesson of February 2024
On the night of 11 to 12 February 2024, a ransomware attack on the Hipocrate hospital information system disrupted 26 hospitals. Another 79 units were disconnected from the internet as a precaution. The attackers asked for 3.5 bitcoin, and DNSC advised against paying the ransom.
The attack used the Backmydata variant, from the Phobos family, which spreads through Remote Desktop connections. Most hospitals had backups from 1–3 days earlier; one had a backup from 12 days earlier.
For NIS2, the lesson has three parts: suppliers’ remote access must be controlled and protected with multi-factor authentication, backups must be tested, and suppliers belong in the supply-chain risk assessment required by art. 13(d) of OUG 155/2024.
What comes next
- notification to DNSC, within 30 days from the date OUG 155/2024 becomes applicable to the organisation; the first DNSC fine sanctioned exactly this deadline;
- the risk-level assessment, within 60 days of the DNSC decision;
- the self-assessment, within the following 60 days, on the controls of your level;
- the audit, carried out by a DNSC-certified auditor.
How TRU helps
Hospitals and clinics run around the clock, and an incident is felt by patients straight away. That is why we usually start with:
- PenTest, external and internal, showing what is exposed to the internet, including remote access, with reports within 48 hours of the scan being completed;
- SOC 24/7/365, for detection and response at night, at weekends and on holidays, when teams are thin;
- Proton Workspace, for email and files with patient data, encrypted in transit and at rest, with zero access.
Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.
Frequently asked questions
Does a small medical practice fall under NIS2?
As a rule, no. Small and micro companies are covered only in the special cases in the law, for example if DNSC designates them. GDPR obligations for patient data apply anyway.
Does a pharmacy fall under NIS2?
Yes, if the company operating it is medium-sized or large. Law No. 124/2025 added retail sale of pharmaceutical products and wholesale of medicines to the health sector. What counts is the company, not the shop: a large pharmacy chain is an essential entity.
Does a medical device manufacturer fall under NIS2?
Yes, if its devices are considered critical during a public health emergency and the company is medium-sized or large. Other medical device manufacturers may be covered through the manufacturing sector, in Annex 2, as important entities.
Are the hospital’s medical devices part of the assessment?
Yes, if they are networked and support the medical service. You add them to the inventory, segment them on the network and control who connects to them remotely.
Sources
OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · HotNews, the attack on the Hipocrate system, 14 February 2024 (in Romanian) · CMS, the changes made by Law No. 124/2025.