NIS2 Directive
Directive (EU) 2022/2555 on the cybersecurity of critical infrastructure across the European Union. Transposed into Greek law by Law 5160/2024.
It imposes enhanced cybersecurity requirements on "essential" and "important" entities (such as hospitals, energy providers and digital infrastructure):
- Article 21: 10 minimum cybersecurity risk-management measures
- Article 23: Obligation to report significant incidents within 24 hours
- Article 20: Accountability and training of management bodies
- Article 24: Use of European certification schemes
- Administrative penalties: up to €10 million or 2% of global annual turnover
ISO/IEC 27001:2022
The international standard for Information Security Management Systems (ISMS). The 2022 edition significantly refreshed the controls in Annex A:
- 93 controls organized into 4 themes: Organizational, People, Physical, Technological
- 11 new controls covering threat intelligence, cloud security, ICT readiness, and secure development
- 5 attributes per control (control type, information security properties, cybersecurity concepts, operational capabilities, security domains)
- Certification by accredited bodies (Annex SL High-Level Structure)
ISO 27799:2016
A specialization of ISO 27002 exclusively for healthcare organizations. It provides guidance for protecting the confidentiality, integrity and availability of health information.
It particularly covers: electronic health records, medical devices, medical imaging, telemedicine services, and the cross-border transfer of health data.
GDPR — Regulation (EU) 2016/679
The General Data Protection Regulation, with Greek implementation through Law 4624/2019. Especially critical for healthcare organizations due to the processing of special-category data:
- Article 9: Health data as a special category with stricter requirements
- Article 32: Technical and organizational security measures
- Articles 33-34: Breach notification within 72 hours
- Article 35: Data Protection Impact Assessment (DPIA)
- Article 37: Data Protection Officer (DPO)
- Administrative fines: up to €20 million or 4% of global annual turnover
EU AI Act — Regulation (EU) 2024/1689
The world's first Regulation on Artificial Intelligence. It imposes graduated obligations depending on the risk level of the AI system:
- Prohibited practices (Article 5): social scoring, manipulative AI, real-time biometric identification
- High-risk systems (Annex III): many systems in healthcare, education and employment
- Transparency obligations for limited-risk systems
- General-Purpose AI Models: new obligations for foundation models
- Administrative fines: up to €35 million or 7% of global annual turnover
IEC 62443
The international standard for the security of industrial control systems (ICS/OT). It applies to SCADA, PLCs and industrial IoT systems. Critical for:
- Industrial facilities
- Energy infrastructure
- Building Management Systems (BMS) in hospitals and hotels
- IoMT devices using industrial protocols
MDR — Medical Device Regulation 2017/745
The European Regulation on medical devices. It significantly affects medical software (Software as a Medical Device, SaMD) and IoMT devices:
- New risk classification for SaMD
- Cybersecurity obligation as part of the design
- Alignment with the FDA Premarket Cybersecurity Guidance 2023
- UDI (Unique Device Identification) for traceability
ENISA Healthcare Cybersecurity Guidelines
The guidelines of the European Union Agency for Cybersecurity (ENISA) specifically for the healthcare sector:
- Procurement Guidelines for Cybersecurity in Hospitals (2020)
- Cloud Security for Healthcare Services (2021)
- Cybersecurity Threat Landscape: Health Sector
- Good practices for IoMT, electronic health records and medical imaging
HL7 FHIR & DICOM
International interoperability standards in healthcare with significant cybersecurity dimensions:
- HL7 FHIR: a RESTful API standard for electronic health records with built-in security profiles (SMART on FHIR)
- DICOM: a medical imaging standard with specific security requirements for PACS and RIS systems
NIST Cybersecurity Framework 2.0
The framework of the U.S. NIST, widely adopted internationally. Version 2.0 (2024) added a new Govern function alongside the existing Identify, Protect, Detect, Respond, and Recover.
NIST SP 800-66 Rev. 2
Implementing the HIPAA Security Rule — specialized guidance for cybersecurity in healthcare. Although HIPAA is a U.S. regulation, its technical guidance is used internationally as best practice.
A multi-framework compliance methodology
In most cases, organizations do not need to comply with a single framework, but with several at once. For example, a Greek hospital must simultaneously comply with NIS2/Law 5160, GDPR, ISO 27799, MDR (for devices) and the AI Act (for AI systems).
Our methodology follows a "unified controls framework" approach:
- Mapping the requirements of all frameworks to a common controls catalog
- Gap analysis against the unified catalog
- Priority-based implementation that covers multiple frameworks at once
- A single source of truth for audits and certifications
This approach saves significant time and resources compared with parallel, framework-by-framework compliance.
Need compliance with one or more frameworks?
We start with a current-state assessment and propose a targeted implementation plan.
Schedule an assessment →