Solutions · HealthTech and providers
Health is an Annex I sector. Patient data is special-category data.
Hospitals, laboratories, medical device makers and the software that serves them. Health sits in NIS2 Annex I, GDPR treats health data as special category, and connected devices bring the Cyber Resilience Act into play.
Typical profile
- Sector
- Health
- Employees
- 50 to 249
- AI
- Uses AI tools
- Flags
- Products with digital elements
- Health is an Annex I sector; a medium-sized entity is an important entity.
- A connected device is a product with digital elements: CRA Article 14 reporting from 11 September 2026.
- Diagnostic or triage AI is high-risk territory under the AI Act.
Obligations to prove
66
NIS2 important entity on this profile.
- Regulation (EU) 2016/679 — data protection3
Applies to every organisation established in the EU that processes personal data.
- Directive (EU) 2022/2555 — cybersecurity8
You declared yourself a NIS2 important entity.
- Commission Implementing Regulation (EU) 2024/2690 — NIS2 Art 21(2) technical requirements48
The Implementing Regulation's 47 technical requirement sections elaborate NIS2 Art 21(2).
- Regulation (EU) 2024/1689 — artificial intelligence5
You build or use AI systems — Art 4 AI literacy already applies; other tiers depend on classification.
- Regulation (EU) 2024/2847 — Cyber Resilience Act2
You manufacture products with digital elements — Art 14 reporting applies from 11 Sep 2026.
First statutory clock if something goes wrong: NIS2 early warning, 24 hours (NIS2 Art 23(4)(a)).
Computed by the platform's scope finder. A starting point, not a legal determination.
The modules that matter here
Start with these 66 obligations.
Sign up, confirm the scope in onboarding, connect your first system.
Start free →