Skip to main content
European Commission logo
European Commission

Cybersecurity of hospitals and healthcare providers

A healthcare sector resilient to cyber threats

Key figures

309 incidents affecting cybersecurity in the health sector were reported in 2023
54% of cyberattacks in the health sector involve ransomware

To address this, the EU is taking action to protect healthcare as critical infrastructure. A new European action plan aims to ensure that healthcare systems, institutions, and connected medical devices are resilient against cyber threats, safeguarding patient safety and trust in digital.

The action plan was among the first initiatives that the Commission presented during the first 100 days of the new mandate, as announced by President von der Leyen in her political guidelines.

What does the action plan propose?

The European action plan builds on existing legislation and aims to establish a pan-European cybersecurity support centre for hospitals and healthcare providers, offering tailored guidance, tools, services, and training. 

What's in it for you?

The action plan will create a safer and more secure environment for patients, ensuring that:

  • personal data and medical records are protected

  • healthcare services are not disrupted by cyberattacks

  • trust is strengthened in healthcare providers, who are taking steps to prevent and respond to cyber threats

How will it work?

The action plan will be implemented in close collaboration with healthcare providers, the healthcare sector, Member States and the cybersecurity community, with the European Union Agency for Cybersecurity (ENISA) at its centre.

The Commission ran a targeted consultation for the action plan in 2025 that collected views from relevant parties and citizens. The results of this consultation are published in a summary report.

Next steps

  1. 2025 Q1

    Set up a joint health cybersecurity advisory board

  2. 2025 Q2

    Begin work to establish a European cybersecurity support centre for hospitals and healthcare providers

    Launch of a stakeholder consultation – results summary

  3. 2025 Q4

    First meeting of joint health cybersecurity advisory board

    Present recommendations to further refine the action plan

  4. 2025-2026

    Roll out specific actions outlined in the plan

    Carry out an annual health cyber maturity assessment

This page was last updated on 12 March 2026