
Fast audit and certification model
✓ Dedicated to small and medium-sized facilities
✓ Micro-certification and accreditation centre
✓ Staff training
About us
Find out what actions are taken by the Certification and Audit Centre (CAC HCPL)
Actions taken
Medical tourism
Scope of analysis and verification for hospital certification
Responsibility: Healthcare Poland Audit and Certification Center.
Healthcare Poland Audit and Certification Center, offers a comprehensive analysis and verification of the compliance of hospitals with the requirements of the international standards of the Global Healthcare Travel Council (GHTC).
The goal of the process is to classify the facility as a GHTC-compliant provider, allowing the hospital to be included in the international medical tourism network.
1 GHTC compliance analysis and verification
The certification process will begin with a detailed analysis of the hospital’s operations in the following key areas:
(a) Compliance with RODO regulations and patient rights.
- Verification of patient data management systems, including medical records, for compliance with the European Regulation on the Protection of Personal Data (RODO).
- Evaluate procedures in place to ensure compliance with patient rights, such as the right to privacy, transparency of treatment processes and patient consent to data processing.
(b) Data security in accordance with NIS2
- Audit of the hospital’s IT infrastructure in terms of protecting medical records and securing data from cyber threats.
- Verification of encryption systems, access management and incident response plans in accordance with NIS2 requirements.
(c) Coding and interoperability standards
- Evaluate the medical record coding standards in use to ensure data interoperability, which is key in international patient circulation.
- Verify compliance with global standards, e.g. HL7, DICOM, ICD-10, which are required under GHTC.
(d) Quality of medical services
- Evaluation of clinical and organizational processes in the context of international quality standards, such as JCI (Joint Commission International) or ISO 9001 accreditations.
- Audit of procedures for receiving international patients, including service in foreign languages, access to translation, and processes for reporting and resolving complaints.
2 Proposed implementation model if deficiencies are identified
If the analysis reveals any gaps in compliance with GHTC requirements, the Center offers support in implementing appropriate corrective actions, which include:
(a) Planning corrective actions
- Preparation of a detailed plan to implement the missing items in accordance with international standards.
- Training of staff on GHTC standards and implemented procedures.
(b) Technical and operational support
- Implementing or upgrading IT systems to ensure compliance with data security and interoperability requirements.
- Development of internal documentation and policies in compliance with GHTC requirements, including data protection and quality management policies.
(c) Monitoring and pre-audit
- Conduct regular follow-up audits to assess the progress of implementations and prepare the facility for full certification.
3 Post-certification support
Once certified in accordance with GHTC requirements, the Center offers additional operational support to maximize the benefits of being part of the GHTC network:
(a) Collaboration with GHTC agents and networks
- The Center supports the process of establishing partnerships with agents and medical tourism brokers that provide access to international patients.
- Facilitate the hospital’s integration with GHTC platforms and recommender systems that refer patients to certified facilities.
(b) Direct patient referral
- Mediating the referral of international patients to the hospital through partner networks.
- Promoting the hospital as a facility that meets the highest quality standards in international rankings and on GHTC platforms.
(c) ESG strategy development (optional).
- Supporting the hospital in the development of a sustainability strategy, which further strengthens the image of the facility in terms of social and environmental responsibility.
The certification process conducted by the Healthcare Poland Audit and Certification Center provides a professional approach to analysis, implementation and operational support. Once successfully certified, the hospital will be fully prepared to provide services within the framework of the GHTC organization, which will open up new opportunities for international cooperation and increase accessibility for patients from all over the world. If you have any questions, we remain at your disposal and are ready to provide details of the process and quote the cost of the Certification.
EU
⚖️ Legislation
Conformity assessment system, accreditation and amendment of certain acts.

NCS / KSC
National Cybersecurity System
(NCS / KSC)
The subject of the service is to examine the compliance of the Contracting Authority’s operations with the requirements of the Law of July 05, 2018 on the National Cyber Security System, advise on the preparation of documentation, and conduct an audit in accordance with Article 15. of the KSC Law.
As part of the implementation of the service, the following will be performed:
- Zero audit, for compliance with the UKSC.
- Advisory activities on:
a. Documentation of risk analysis methodology and risk management policy in the area of cyber security;
b. Procedure for management of cyber security breach incidents;
c. Other documentation (policies and procedures) of the KSC in the area of information security and business continuity. - The cyber security audit required by the KSC Law.
- The work will result in the following:
– Zero audit report with recommendations for implementation of actions necessary to achieve full compliance with legal requirements in terms of the National Cyber Security System Act;
– Documentation (policies and procedures) of information security and business continuity;
– UKSC audit report. - Completion date – 3 months from the date of signing the contract.
SELECTION CRITERIA AND REQUIREMENTS
Bid evaluation criterion: price – 100%
The contractor must demonstrate the ability to implement the contract.
The Contracting Authority will consider ability as meeting at least the following conditions:
- The audit can be carried out by persons or entity only meeting the conditions for an auditor mentioned in UKSC. It is required that the team conducting the audit has at least two specialists with certifications each of CISA, CRISC, ISO27001 LA. and at least one of them certifications: ISO22301 LA,
- At least one person from the auditing team has experience in auditing a medical entity.
- At least one of the persons directed to carry out the contract has in his portfolio at least one KSC audit service of a clinical hospital (consulting and/or auditing), with a contract value of at least PLN 40 thousand.
- Each of the persons carrying out the contract must meet the criterion of independence and declare the absence of conflict of interest.
Services
We offer a wide range of services
As part of our comprehensive cooperation with the Healthcare Poland Foundation (FHP), we offer a wide range of services:
1
Audit and accreditation
Audit and accreditation of products, services and staff.
2
Certification of formal requirements
Certification of formal requirements in the context of public procurement and legal regulations, in particular NIS2, EGS, GDPR, ISO.
3
Testing and certifications
Testing new medical devices, certifications, technical and cybersecurity audits, diagnostic services, development and evaluation of treatment protocols to improve patient care.
4
Research
Conducting research to validate new technologies and treatments, accelerating their path to market and ensuring they meet regulatory standards.
5
Presentation of technological solutions and health programmes
Presentation of technological solutions and health programmes during seminars and conferences organised by the HCPL/PFSz Foundation.
6
Micro-credentials and industry certifications
Micro-credentials and industry certifications facilitating access to the health market.
The model of rapid audits and certifications
🏥
Dedicated to small
and medium-sized facilities
Assists in assessing compliance with legal requirements.
📑
Micro-certification
and accreditation centre
A platform for certifying the competence of medical personnel, crucial for ensuring compliance with EU standards.
👩🏻⚕️
Staff
training
Training 20,000 employees in cyber hygiene and incident management.