Sector Certifications by Healthcare Poland

CERTIFICATION AND AUDIT CENTER · CAC HCPL

Certification that opens tenders, markets and funding

The Certification and Audit Center of Healthcare Poland Foundation issues sector certificates for hospitals, long-term care facilities and medical technology suppliers. We audit from inside the healthcare ecosystem — which is why our attestation reads not as a formality, but as evidence of a provider’s operational maturity.

  • ✓ Formal proof of compliance in public procurement procedures
  • ✓ NIS2, GDPR, MDR, ESG and the AI Act covered by a single audit programme
  • ✓ Access to the international patient market and to a partner network across 56 countries

WHY OUR CERTIFICATE CARRIES MORE WEIGHT

Certification issued by an organisation rooted in the hospital ecosystem carries greater operational credibility than a certificate from an IT auditor with no clinical understanding.

Certification and Audit Center team
Healthcare Poland Foundation

520

hospitals in the Polish Hospital Federation network — our principal national partner

6,000

primary care providers within reach of our quality programmes

56

countries in the Global Healthcare Systems Hub network, opened by the TQAMS standard

IHF · HOPE

international partners providing benchmarking and a regulatory voice at EU level

Audit · Certification · Accreditation

We do not sell a single document. We guide the provider through the full quality cycle — from an independent diagnosis of compliance, through certification, to recognition of the standard on both the domestic and international market.

Audit

An independent assessment of quality, processes and compliance. The outcome is a map of risks and priorities the board can base an investment decision on — not a list of accusations.

Certification

An HCPL sector certificate — in selected schemes co-signed by the Polish Hospital Federation — recognised in tender procedures and in dialogue with the public payer.

Accreditation

Preparation for recognised accreditation schemes — national CMJ and JCI — as well as accreditation of staff and of medical technology manufacturers.

Who we work with

We scale audit and certification programmes to the size and character of the organisation. A university hospital, a private clinic network and an eighty-bed nursing facility all need the same level of credibility — but not the same effort.

Public and district hospitals

Providers for whom regulatory compliance translates directly into contracting, access to investment funding and standing in public procurement procedures.

Private providers and clinic networks

Operators building an advantage on quality and access to international patients, for whom certification is a sales argument rather than an administrative cost.

Long-term and nursing care

A segment without an accreditation programme of its own, subject to the same regulatory requirements as hospitals — and increasingly held to account on quality of care by patients’ families.

Primary care

Primary care networks and coordinated care providers, for whom quality certification is a way to stand out in the eyes of patients and of the payer.

Manufacturers and technology suppliers

Medical device manufacturers, software vendors and integrators who must demonstrate conformity before they are admitted to a procedure at all.

Local government and founding bodies

Founding authorities needing an independent assessment of the providers they oversee — ahead of an investment, restructuring or consolidation decision.

Certification and audit catalogue

Each area can be commissioned on its own or combined into a single programme. One review opens parallel pathways to NIS2, GDPR, ESG and TQAMS — without duplicating documentation and without tying up four separate teams inside the organisation.

Security, data and business continuity

NIS2 and national cybersecurity law

A hospital is an operator of essential services. NIS2 compliance has stopped being a differentiator — it has become a condition for taking part in tenders and for a calm conversation with the regulator. We audit and we attest.

Explore the CyberC4HE Coalition →

GDPR and patient data protection

Penalties of up to EUR 20 million or 4% of turnover are the most expensive line nobody budgets for. An HCPL certificate confirms that patient data protection will withstand an inspection — and a journalist’s questions.

Information security at HCPL →

Business continuity (ISO 22301)

No working hospital information system means no admissions, no e-prescriptions and suspended procedures. We certify the continuity and disaster recovery plans required of operators of essential services.

Clinical quality and accreditation

TQAMS — the cross-border care standard

A proprietary HCPL standard developed with the Global Healthcare Systems Hub. TQAMS certification is the entry ticket to the international patient market, which generates revenue several times higher per case than domestic care.

Medical tourism and TQAMS →

CMJ and JCI accreditation readiness

Accreditation is not a form to fill in; it is a change in how people work. We prepare the organisation to enter the formal process with a real chance of success — instead of paying for a false start.

Certified long-term care

Long-term care has been overlooked by national accreditation programmes, even though its regulatory obligations grow as fast as those of hospitals. Our certificate fills that gap as a sector-wide mark of quality.

Suppliers and medical technology

ISO 13485 · MDR · IVDR

A manufacturer without a complete evidence file loses the tender before the committee even looks at price. We audit the quality management system and the technical documentation — including readiness for the US market.

Certification for suppliers →

The AI Act and high-risk systems

Medical software with an artificial intelligence component falls into the high-risk category. We assess conformity and put the documentation in order before the market — or the supervisory authority — does it for you.

AI for Health →

ISO 27001 · ISO 37301

Information security and compliance management — two standards that decide whether a supplier is admitted to hospital infrastructure and to the tenders of large capital groups.

Market access, sustainability and competence

ESG, CSRD and GreenHospitals

ESG is ceasing to be a declaration and becoming a condition of eligibility in tenders and calls for funding. We audit the processes, validate the reporting and bring the provider into the GreenHospitals programme.

ESG for healthcare →

Public procurement

HCPL certificates serve as formal proof that technical requirements are met and that the contractor is capable — precisely at the points in the specification where procedures are most often won or lost.

Full legal analysis →

Micro-credentials and CPE points

Certified team knowledge is evidence of competence during audits and a real reduction of risk. Medical technology manufacturers can obtain HCPL accreditation to deliver authorised training.

Three cross-cutting programmes

Individual certifications can be bundled into one of three development programmes. Each takes the organisation through several areas at once, instead of closing them one at a time years apart.

Digital Hospital

Digital transformation: maturity of hospital systems, interoperability in HL7, DICOM and ICD-10, and readiness for the European Health Data Space. A programme for providers that want to exchange data, not merely accumulate it.

Cyber

Digital security taken as a whole: NIS2 audits, cyber hygiene training, hardware authentication and incident response procedures. The substantive backbone is the CyberC4HE Coalition.

The Cyber programme →

Safety

Patient safety: a just culture, clinical risk management, adverse event analysis and accreditation readiness. The programme addresses the cause rather than the symptom.

Expand and read more

Short accounts of each area — without procedural detail, but with an answer to the question that matters: what actually changes inside the organisation once the certificate is in place.

TQAMS — how certification translates into revenue

TQAMS (Tourism Quality Assurance & Management System) grew out of a simple observation: a patient choosing treatment abroad has no way of verifying the quality of the provider. The standard closes that gap and, in doing so, puts the organisation in order across four dimensions — data protection, cybersecurity, interoperability, and clinical quality with multilingual patient service.

For the board, the market effect is what counts: certification opens access to the Global Healthcare Systems Hub network across 56 countries, to medical facilitators and to insurers in the EU and EEA — and therefore to a revenue stream independent of the public payer. TQAMS is also modular and affordable for district hospitals, unlike global accreditations whose cost is often prohibitive.

Go to the medical tourism section →

NIS2 — why an external audit pays off before the inspection

Hospitals operate as providers of essential services, which brings enforceable obligations in risk management, incident handling and continuity of operations. Experience from auditing over a hundred facilities shows that the problem is rarely a lack of technology; the problem is the absence of a documented methodology and of evidence that the safeguards work in practice.

Our audit delivers two things at once: documentation that will withstand an inspection, and an attestation that can be attached to a tender submission. The substantive backbone is the CyberC4HE Coalition, bringing together hospitals, CSIRT teams and medical market stakeholders.

NIS2 / ENISA diagnostic questionnaire →

GDPR — data protection that holds up before the regulator

Patient records are worth many times more on the black market than financial data, which makes healthcare providers a target of first choice. Certification covers a review of policies, data flow mapping and data protection impact assessment — exactly what the supervisory authority asks about once a breach occurs.

GDPR compliance is also a precondition for processing data in European projects, including EU framework programmes. The certificate is therefore less a safeguard than a condition of entry into a research consortium.

Medical devices, MDR and the AI Act — certification for manufacturers

A medical technology supplier today competes not only on price and functionality, but above all on the completeness of its conformity evidence. We cover the full spectrum: a quality management system aligned with ISO 13485, conformity assessment and technical documentation under MDR and IVDR, and the requirements for high-risk artificial intelligence systems arising from the AI Act.

An added benefit is the cross-mapping of European requirements against United States regulation, which allows one quality system to serve two markets instead of maintaining two parallel documentation sets.

Our offer for medical technology suppliers →

ESG and CSRD — from a reputational report to a condition of eligibility

Environmental and social criteria are appearing in successive tenders and funding calls as admission requirements, not as bonus points. A provider unable to document waste management, energy efficiency and organisational governance loses access to part of the available financing — regardless of clinical quality.

We run the ESG audit alongside the GreenHospitals programme, combining the reporting obligation with a genuine reduction in operating costs. It is one of the few compliance areas that also pays back in the income statement.

Certified long-term care — the segment accreditation forgot

Poland has roughly eight hundred long-term nursing and care facilities. National accreditation programmes concentrate on hospitals, leaving long-term care without a recognisable quality mark — even though it is subject to the same obligations in data protection, cybersecurity and reporting.

The HCPL certification programme, co-signed with the Polish Hospital Federation, addresses quality and safety of care together with organisational standards. For owners and founding bodies it is a clear signal to patients’ families, to the payer and to insurers.

Readiness for CMJ and JCI accreditation

Accreditation verifies not the paperwork but whether the system actually works on the ward. Our role is unambiguous and free of any conflict of interest: we prepare the organisation, while the accreditation decision rests solely with the accrediting body.

The programme covers a gap analysis against accreditation requirements, support in implementing patient safety standards, training for quality teams, and a simulated accreditation survey. For providers already holding national accreditation we prepare a transition map towards the international standard.

Micro-credentials, CPE points and accredited manufacturer training

The best-designed procedure loses to habit if the team does not understand it. We deliver training concluded with a micro-credential in data protection, cybersecurity, ESG reporting, medical devices and anti-fraud — with continuing professional education points.

For medical technology manufacturers we offer accreditation to deliver authorised training to hospitals. For the supplier it is a sales argument; for the provider, documented evidence of staff competence during an audit.

HCPL certificates in public procurement procedures

Public procurement law allows the contracting authority to require confirmation that technical requirements are met and that the contractor has the necessary capability. A certificate issued after an audit is precisely such confirmation — legible to the tender committee and resistant to the charge of vagueness.

It works in both directions: the hospital demonstrates organisational maturity to the payer and to funding institutions, while the medical technology supplier demonstrates that its product meets quality, data protection and cybersecurity requirements.

Full analysis: public procurement, NIS2 and GDPR →

Governance and Just Culture

We build the structure of committees, policies and reporting in which an adverse event is reported rather than concealed. A just culture is a precondition of any serious accreditation and, at the same time, the cheapest insurance a board can buy — because the cost of an unreported error always exceeds the cost of analysing it.

Mediation and Arbitration Centre

We are establishing a dispute resolution body for the healthcare sector — covering medical devices, data protection, cybersecurity incidents, contracts and claims by international patients. A dispute settled by experts who understand both the standard and the reality of the ward ends faster and cheaper than litigation.

Poland as a certification hub for Central and Eastern Europe

Healthcare Poland Foundation is building its position as an international gateway to the Polish and regional healthcare and life sciences market. In that model certification is an instrument, not an end: a standard recognised on both sides of the border shortens the path for the patient, the investor and the manufacturer.

The ambition is to make Poland the quality reference point for the whole region — for hospitals receiving cross-border patients and for medical technology manufacturers exporting to EU and global markets alike.

PILLARS OF THE REGIONAL POSITION

  • A gateway into the Polish and regional market for international partners
  • A systemic partner in the Three Seas Initiative — a link between Central, Eastern and Southern Europe
  • The TQAMS standard, recognised across a network of 56 countries
  • International benchmarking through IHF and EU regulatory dialogue through HOPE

Who signs our certificate

The Centre’s audit team combines credentials rarely found under one roof: CISA, CGEIT, CRISC, CRMA and CDPSE certifications, ISO/IEC 27001 and ISO 22301 lead auditor qualifications, and audit experience gained in central banking and financial supervision, in aerospace and in healthcare.

The department is led by Piotr Welenc — auditor and lecturer at medical and law faculties, member of a Technical Committee of the Polish Committee for Standardization. It is this reference portfolio that makes the HCPL certificate recognisable well beyond the medical sector.

INSTITUTIONAL PARTNERS

  • Polish Hospital Federation — a network of 520 hospitals, joint certification schemes
  • International Hospital Federation — international benchmarking
  • HOPE — representation and regulatory dialogue at EU level
  • Global Healthcare Systems Hub — a 56-country network, the TQAMS standard

Standards and regulations in our portfolio

ISO 9001 · ISO 13485 · ISO 15189 · ISO/IEC 17025 · ISO/IEC 27001 · ISO 22301 · ISO 37301 · ISO 27799 · IEC 62304 · IEC 81001 · MDR 2017/745 · IVDR · NIS2 Directive · national cybersecurity act · GDPR · AI Act · CSRD · eIDAS · Directive 2011/24/EU · public procurement law

Frequently asked questions

The questions that come up in the first meeting — answered without marketing rounding.

How does an HCPL certificate differ from national or international accreditation?

National and international accreditation assesses the hospital as a whole against an extensive, uniform set of standards. Our certification is modular: it addresses a specific area — cybersecurity, data protection, cross-border care, sustainability — and can be obtained without undertaking a full accreditation process.

The two paths do not exclude one another; they complement each other. Many providers begin with a single area, build the experience of their quality team on it, and only then decide on full accreditation.

Is the certificate recognised outside Poland?

The TQAMS standard operates within the Global Healthcare Systems Hub network of 56 countries and is legible there to medical facilitators and insurers. Certificates referring to EU regulation — NIS2, GDPR, MDR, the AI Act, CSRD — rest on law that applies across the Union, so their content is intelligible to any partner in the EU and EEA.

Separately, we prepare providers for accreditation schemes of global reach, where the decision rests with the accrediting body rather than with us.

Can a single area be commissioned on its own?

Yes, and it is the most common scenario. Providers usually start with whatever is urgent — most often cybersecurity, or a requirement arising from a specific tender — and add the remaining areas in subsequent years.

It is worth knowing, however, that one review produces material used across several areas at once. Splitting them into separate, unconnected projects usually raises the total cost.

Who actually conducts the audit?

Audits are conducted by the Certification and Audit Center team, staffed by auditors holding recognised professional certifications and lead auditor qualifications for management systems. We hold ourselves to what we ask of those we audit: documented competence and experience in the healthcare sector.

The department is led by Piotr Welenc, an auditor with experience in central banking, financial supervision, aerospace and healthcare.

Do you prepare organisations for certification that you then issue yourselves?

We separate these roles deliberately and consistently. Where we prepare a provider for external accreditation, the decision rests solely with the accrediting body. Where we issue the certificate ourselves, the advisory team is kept separate from the audit team.

This is not a formality. A certificate whose credibility can be undermined by a conflict of interest is worth nothing — neither in a tender nor before a regulator.

Where should we start?

With a conversation about the problem, not about the catalogue. The most useful first meeting is one where the specifics come out: which procedure, which market, which inspection, which deadline.

On that basis we will point to the area worth starting with — and if certification will not solve your problem, we will say so before anything is signed.

Let’s start with a conversation, not with paperwork

Tell us which tender you are entering, which market you are targeting, or which inspection you are facing. We will point to the certification that genuinely solves the problem — and if none is needed, we will say so plainly.