Certification and Audit Center (CAC HCPL)

Fast audit and certification model

Dedicated to small and medium-sized facilities
Micro-certification and accreditation centre
Staff training

About us

Find out what actions are taken by the Certification and Audit Centre (CAC HCPL)


Actions taken

⚖️ Legislation

Conformity assessment system, accreditation and amendment of certain acts.

National Cybersecurity System NCS Krajowy System Cyberbezpieczeństwa KSC graphics Healthcare Poland

NCS / KSC

National Cybersecurity System
(NCS / KSC)

The subject of the service is to examine the compliance of the Contracting Authority’s operations with the requirements of the Law of July 05, 2018 on the National Cyber Security System, advise on the preparation of documentation, and conduct an audit in accordance with Article 15. of the KSC Law.

As part of the implementation of the service, the following will be performed:

  1. Zero audit, for compliance with the UKSC.
  2. Advisory activities on:
    a. Documentation of risk analysis methodology and risk management policy in the area of cyber security;
    b. Procedure for management of cyber security breach incidents;
    c. Other documentation (policies and procedures) of the KSC in the area of information security and business continuity.
  3. The cyber security audit required by the KSC Law.
  4. The work will result in the following:
    – Zero audit report with recommendations for implementation of actions necessary to achieve full compliance with legal requirements in terms of the National Cyber Security System Act;
    – Documentation (policies and procedures) of information security and business continuity;
    – UKSC audit report.
  5. Completion date – 3 months from the date of signing the contract.

SELECTION CRITERIA AND REQUIREMENTS

Bid evaluation criterion: price – 100%

The contractor must demonstrate the ability to implement the contract.
The Contracting Authority will consider ability as meeting at least the following conditions:

  1. The audit can be carried out by persons or entity only meeting the conditions for an auditor mentioned in UKSC. It is required that the team conducting the audit has at least two specialists with certifications each of CISA, CRISC, ISO27001 LA. and at least one of them certifications: ISO22301 LA,
  2. At least one person from the auditing team has experience in auditing a medical entity.
  3. At least one of the persons directed to carry out the contract has in his portfolio at least one KSC audit service of a clinical hospital (consulting and/or auditing), with a contract value of at least PLN 40 thousand.
  4. Each of the persons carrying out the contract must meet the criterion of independence and declare the absence of conflict of interest.

Services

We offer a wide range of services

As part of our comprehensive cooperation with the Healthcare Poland Foundation (FHP), we offer a wide range of services:

1

Audit and accreditation

Audit and accreditation of products, services and staff.



2

Certification of formal requirements

Certification of formal requirements in the context of public procurement and legal regulations, in particular NIS2, EGS, GDPR, ISO.

3

Testing and certifications

Testing new medical devices, certifications, technical and cybersecurity audits, diagnostic services, development and evaluation of treatment protocols to improve patient care.

4

Research

Conducting research to validate new technologies and treatments, accelerating their path to market and ensuring they meet regulatory standards.

5

Presentation of technological solutions and health programmes

Presentation of technological solutions and health programmes during seminars and conferences organised by the HCPL/PFSz Foundation.

6

Micro-credentials and industry certifications

Micro-credentials and industry certifications facilitating access to the health market.


The model of rapid audits and certifications

🏥

Dedicated to small
and medium-sized facilities

Assists in assessing compliance with legal requirements.

📑

Micro-certification
and accreditation centre

A platform for certifying the competence of medical personnel, crucial for ensuring compliance with EU standards.

👩🏻‍⚕️

Staff
training

Training 20,000 employees in cyber hygiene and incident management.