
Fast audit and certification model
✓ Dedicated to small and medium-sized facilities
✓ Micro-certification and accreditation centre
✓ Staff training
About us
Find out what actions are taken by the Certification and Audit Centre (CAC HCPL)
Actions taken
Medical tourism
Scope of analysis and verification for hospital certification
Responsibility: Healthcare Poland Audit and Certification Center.
Healthcare Poland Audit and Certification Center, offers a comprehensive analysis and verification of the compliance of hospitals with the requirements of the international standards of the Global Healthcare Systems Hub (GHSH).
The goal of the process is to classify the facility as a GHTC-compliant provider, allowing the hospital to be included in the international medical tourism network.
1 GHTC compliance analysis and verification
The certification process will begin with a detailed analysis of the hospital’s operations in the following key areas:
(a) Compliance with RODO regulations and patient rights.
- Verification of patient data management systems, including medical records, for compliance with the European Regulation on the Protection of Personal Data (RODO).
- Evaluate procedures in place to ensure compliance with patient rights, such as the right to privacy, transparency of treatment processes and patient consent to data processing.
(b) Data security in accordance with NIS2
- Audit of the hospital’s IT infrastructure in terms of protecting medical records and securing data from cyber threats.
- Verification of encryption systems, access management and incident response plans in accordance with NIS2 requirements.
(c) Coding and interoperability standards
- Evaluate the medical record coding standards in use to ensure data interoperability, which is key in international patient circulation.
- Verify compliance with global standards, e.g. HL7, DICOM, ICD-10, which are required under GHTC.
(d) Quality of medical services
- Evaluation of clinical and organizational processes in the context of international quality standards, such as JCI (Joint Commission International) or ISO 9001 accreditations.
- Audit of procedures for receiving international patients, including service in foreign languages, access to translation, and processes for reporting and resolving complaints.
2 Proposed implementation model if deficiencies are identified
If the analysis reveals any gaps in compliance with GHTC requirements, the Center offers support in implementing appropriate corrective actions, which include:
(a) Planning corrective actions
- Preparation of a detailed plan to implement the missing items in accordance with international standards.
- Training of staff on GHTC standards and implemented procedures.
(b) Technical and operational support
- Implementing or upgrading IT systems to ensure compliance with data security and interoperability requirements.
- Development of internal documentation and policies in compliance with GHTC requirements, including data protection and quality management policies.
(c) Monitoring and pre-audit
- Conduct regular follow-up audits to assess the progress of implementations and prepare the facility for full certification.
3 Post-certification support
Once certified in accordance with GHTC requirements, the Center offers additional operational support to maximize the benefits of being part of the GHTC network:
(a) Collaboration with GHTC agents and networks
- The Center supports the process of establishing partnerships with agents and medical tourism brokers that provide access to international patients.
- Facilitate the hospital’s integration with GHTC platforms and recommender systems that refer patients to certified facilities.
(b) Direct patient referral
- Mediating the referral of international patients to the hospital through partner networks.
- Promoting the hospital as a facility that meets the highest quality standards in international rankings and on GHTC platforms.
(c) ESG strategy development (optional).
- Supporting the hospital in the development of a sustainability strategy, which further strengthens the image of the facility in terms of social and environmental responsibility.
The certification process conducted by the Healthcare Poland Audit and Certification Center provides a professional approach to analysis, implementation and operational support. Once successfully certified, the hospital will be fully prepared to provide services within the framework of the GHTC organization, which will open up new opportunities for international cooperation and increase accessibility for patients from all over the world. If you have any questions, we remain at your disposal and are ready to provide details of the process and quote the cost of the Certification.
Organisational recommendations for cross-border and medical tourism wards
The checklist below summarises the organisational requirements verified by CAC HCPL during the gap analysis of a facility preparing to serve international patients. It is the operational core of the TQAMS standard.
- Place of service – a separate ward (or sub-ward) that does not simultaneously deliver the NFZ contract, entered into the RPWDL register with the appropriate code, included in the organisational bylaws and approved by the Social Council.
- Medical staff – compliance with the Ministry of Health regulation on guaranteed inpatient services; on duty, combining with other wards is possible.
- Nursing staff – at least one nurse with a command of English present at all times.
- Other staff – physiotherapist and care assistants proportional to the nursing team, with the scope depending on the clinical profile.
- Medical consultations – guaranteed access to the necessary specialist consultations in English, secured by contract clauses covering hours other than NFZ hours.
- Diagnostics and equipment – access to the required laboratory and imaging examinations, with reports issued in English.
- Ward standard – single rooms with a private bathroom.
- Medical documentation – questionnaires, consent forms with a description of the procedure and discharge summaries in Polish and English; extended consents (e.g. blood transfusion) in English.
- Operating theatre – organisationally separated so that it does not collide with services contracted by the NFZ (a separate theatre or separate hours).
- Pricing – a price list covering all possible services, including the management of complications and, where relevant, storage and transport of remains.
- Patient information – patient rights charter and ward rules in English, preferably available online.
- Recommended – an orientation video of the ward and a video describing the procedure in English; staff ID badges with photograph and role in English.
EU
Cross-border healthcare under Directive 2011/24/EU
Cross-border healthcare is a regulated market, not a marketing exercise. Directive 2011/24/EU gives EU citizens the right to be treated in another Member State and to be reimbursed under the rules of their country of affiliation. CAC HCPL helps Polish providers translate that legal framework into working organisational practice.
Two routes for planned treatment
- S2 route – the public insurer covers the treatment directly at a public provider, after prior authorisation has been granted.
- Pay and claim – the patient pays and applies for reimbursement; this route also covers private providers, but reimburses only up to the tariff level of the insuring country.
- Prior authorisation is frequently required for treatment involving an overnight stay or highly specialised equipment. Without S2 the patient may be treated as a private patient and pay private prices, while reimbursement stays limited to public tariffs.
National Contact Points
Every Member State operates at least one National Contact Point that explains reimbursement rules, prior authorisation, the registration status of the provider, quality and safety standards and the complaint and redress path. Providers that want to serve EU patients must be able to answer the same questions in a documented and verifiable way.
Key sources
⚖️ Legislation
Conformity assessment system, accreditation and amendment of certain acts.

NCS / KSC
National Cybersecurity System
(NCS / KSC)
The subject of the service is to examine the compliance of the Contracting Authority’s operations with the requirements of the Law of July 05, 2018 on the National Cyber Security System, advise on the preparation of documentation, and conduct an audit in accordance with Article 15. of the KSC Law.
As part of the implementation of the service, the following will be performed:
- Zero audit, for compliance with the UKSC.
- Advisory activities on:
a. Documentation of risk analysis methodology and risk management policy in the area of cyber security;
b. Procedure for management of cyber security breach incidents;
c. Other documentation (policies and procedures) of the KSC in the area of information security and business continuity. - The cyber security audit required by the KSC Law.
- The work will result in the following:
– Zero audit report with recommendations for implementation of actions necessary to achieve full compliance with legal requirements in terms of the National Cyber Security System Act;
– Documentation (policies and procedures) of information security and business continuity;
– UKSC audit report. - Completion date – 3 months from the date of signing the contract.
SELECTION CRITERIA AND REQUIREMENTS
Bid evaluation criterion: price – 100%
The contractor must demonstrate the ability to implement the contract.
The Contracting Authority will consider ability as meeting at least the following conditions:
- The audit can be carried out by persons or entity only meeting the conditions for an auditor mentioned in UKSC. It is required that the team conducting the audit has at least two specialists with certifications each of CISA, CRISC, ISO27001 LA. and at least one of them certifications: ISO22301 LA,
- At least one person from the auditing team has experience in auditing a medical entity.
- At least one of the persons directed to carry out the contract has in his portfolio at least one KSC audit service of a clinical hospital (consulting and/or auditing), with a contract value of at least PLN 40 thousand.
- Each of the persons carrying out the contract must meet the criterion of independence and declare the absence of conflict of interest.
Services
We offer a wide range of services
As part of our comprehensive cooperation with the Healthcare Poland Foundation (FHP), we offer a wide range of services:
1
Audit and accreditation
Audit and accreditation of products, services and staff.
2
Certification of formal requirements
Certification of formal requirements in the context of public procurement and legal regulations, in particular NIS2, EGS, GDPR, ISO.
3
Testing and certifications
Testing new medical devices, certifications, technical and cybersecurity audits, diagnostic services, development and evaluation of treatment protocols to improve patient care.
4
Research
Conducting research to validate new technologies and treatments, accelerating their path to market and ensuring they meet regulatory standards.
5
Presentation of technological solutions and health programmes
Presentation of technological solutions and health programmes during seminars and conferences organised by the HCPL/PFSz Foundation.
6
Micro-credentials and industry certifications
Micro-credentials and industry certifications facilitating access to the health market.
The model of rapid audits and certifications
🏥
Dedicated to small
and medium-sized facilities
Assists in assessing compliance with legal requirements.
📑
Micro-certification
and accreditation centre
A platform for certifying the competence of medical personnel, crucial for ensuring compliance with EU standards.
👩🏻⚕️
Staff
training
Training 20,000 employees in cyber hygiene and incident management.
CROSS-BORDER MEDICINE
Cross-border healthcare under Directive 2011/24/EU
A regulated market, not a marketing exercise. EU citizens have the right to be treated in another Member State and to be reimbursed under the rules of their country of affiliation. CAC HCPL turns that legal framework into working organisational practice.
🇪🇺
S2 route
The public insurer covers the treatment directly at a public provider abroad, once prior authorisation has been granted.
💶
Pay and claim
The patient pays and claims reimbursement. Private providers are covered too, but only up to the tariffs of the insuring country.
☎️
National Contact Points
Every Member State explains reimbursement, prior authorisation, provider registration, quality rules and the redress path.
📄
Prior authorisation
Usually required for overnight hospitalisation and highly specialised equipment – and decisive for the patient’s final cost.
🔐
GDPR and EHDS
Processing data of patients from other Member States requires auditable compliance and interoperable documentation.
🤝
Continuity of care
Follow-up, complaint handling and alternative dispute resolution after the patient has returned home.
Legal framework and official sources
MEDICAL TOURISM
Ready for the international patient
Medical tourism is a system, not a campaign. Before a facility advertises abroad it has to be organised for foreign patients. These are the areas verified by CAC HCPL during gap analysis.
🏥
Dedicated ward
A separate ward or sub-ward outside the NFZ contract, entered in RPWDL with the right code, covered by the organisational bylaws.
🗣️
Language competence
At least one English-speaking nurse on every shift and guaranteed access to specialist consultations in English.
🧾
Bilingual documentation
Questionnaires, consent forms with a description of the procedure, extended consents and discharge summaries in Polish and English.
🔬
Diagnostics in English
Access to the required laboratory and imaging examinations, with reports issued in English.
💳
Transparent pricing
A price list covering every possible service, including management of complications and, where relevant, repatriation.
🛏️
Patient standard
Single rooms with a private bathroom, patient rights charter and ward rules in English, orientation video, ID badges in English.
Operating theatre, staffing and other detailed requirements
- Operating theatre – organisationally separated so that it does not collide with services contracted by the NFZ: a separate theatre or separate hours of service.
- Medical staff – compliance with the Ministry of Health regulation on guaranteed inpatient services; combining duties with other wards is possible during on-call hours.
- Supporting staff – physiotherapist and care assistants proportional to the nursing team, with the scope depending on the clinical profile.
- Equipment – a clear answer to whether the equipment is dedicated or shared with the NFZ contract, and to its funding origin (e.g. KPO co-financing).
- Formalities – entry in the RPWDL register kept by the voivode, amendment of the organisational bylaws by the director and the consent of the Social Council.
- Redress – complaint handling and alternative dispute resolution (ADR) available to the patient after returning home.
TQAMS
Transborder Quality Audit of Medical Services
The proprietary certification standard of the Healthcare Poland Foundation, dedicated to medical tourism and cross-border care. It standardises and certifies the quality of transborder medical services in Poland and the EU, in the context of Directive 2011/24/EU and the forthcoming European Health Data Space, and is developed in cooperation with the Global Healthcare Systems Hub (GHSH).
1
Gap analysis
Review of organisational documentation, formal requirements, infrastructure, language competences, availability of consultations and bilingual documentation. Result: a gap report with a corrective action plan.
2
Implementation
Organisation of the dedicated ward, operating procedures, staff training, bilingual documentation, pricing, safety and continuity-of-care procedures. Result: a facility ready for the audit.
3
Certification audit
Documentation audit, on-site visit using tracer methodology, verification of infrastructure and staff competences, patient interviews, review of emergency procedures. Result: the TQAMS certificate.
4
Surveillance
Annual surveillance audits, monitoring of quality indicators (KPI), verification of continued compliance and recertification every three years.
What the TQAMS standard covers
- Organisational requirements – place of service and infrastructure.
- Staffing requirements – medical, nursing and supporting staff, including language competences.
- Medical documentation – mandatory bilingual (PL/EN) clinical and organisational documents, price list, emergency and risk-management procedures.
- Quality and safety – compliance with Directive 2011/24/EU, patient information standards, complaint handling and alternative dispute resolution.
- Cybersecurity and resilience – protection of patient data and continuity of IT systems in line with NIS2.
JCI Readiness – the road to international accreditation
🥇
Gold Seal
of Approval
Joint Commission International accreditation is recognised by insurers, governments and care coordinators in over 100 countries.
🔍
Gap analysis
and remediation
A review against more than 1,200 measurable elements in 14 standard areas, with a prioritised corrective action plan.
🎓
Training
and mock survey
Clinical standards, patient safety, medication management, quality management, documentation and event-reporting culture – verified in a mock survey.
JCI (Joint Commission International)
A global accreditation organisation awarding the Gold Seal of Approval for quality and safety in healthcare. In practice, a condition of entry to the medical tourism markets of the Middle East, Asia and the Americas.
National accreditation and complementary standards
- Centrum Monitorowania Jakości w Ochronie Zdrowia (CMJ) – national hospital accreditation in Poland.
- Joint Commission International – standards, accreditation and certification programmes.
- Clinical risk management, tracer methodology and event-reporting culture as the operational backbone of any accreditation programme.
CERTIFICATES & STANDARDS
Everything HCPL audits, implements and certifies
Certification is not an end in itself. Each pathway strengthens the others: TQAMS without GDPR is incomplete, NIS2 without ISO 27001 is fragmentary, JCI without a quality culture is cosmetic.
🛡️
NIS2
Directive (EU) 2022/2555. Healthcare entities as essential service operators – full audit and certification cycle based on the HCPL four-pillar model, delivered through the CyberC4HE coalition.
⚖️
KSC / UKSC
The Polish National Cybersecurity System Act: zero audit, risk methodology and risk-management policy, incident procedures and the statutory audit under Art. 15.
🔐
GDPR / RODO
From declarative to auditable compliance: data-flow mapping, risk assessment and DPIA, 72-hour breach notification, staff training, integration with the quality system.
📘
ISO & MDR
ISO 9001, 13485, 14001, 22301, 27001, 45001, 20000, ISO 31000 and COSO, plus MDR (EU) 2017/745 compliance for medical devices.
🌱
ESG
Environmental, social and governance reporting verified by financial institutions, investment funds and corporate partners, and required in EU programmes.
♿
Accessibility & AI
WCAG 2.1/2.2, accessibility declarations and audits, the European Accessibility Act, and SDAI – the HCPL certification programme for AI suppliers in healthcare.
Full list of standards with official sources
Cybersecurity and data protection
- NIS2 – Directive (EU) 2022/2555
- GDPR – Regulation (EU) 2016/679
- ISO/IEC 27001 – information security management; ISO/IEC 20000 – IT service management
- KSC / UKSC – Polish National Cybersecurity System Act of 5 July 2018 (zero audit, documentation, Art. 15 audit)
Quality, medical devices and continuity
- ISO 9001 – quality management systems
- ISO 13485 – quality management for medical devices; ISO 22301 – business continuity
- ISO 14001 – environmental management; ISO 45001 – occupational health and safety
- ISO 31000 – risk management; COSO – internal control framework
- MDR – Regulation (EU) 2017/745
- 5S / Lean – audits of work organisation (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
ESG, accessibility and emerging technologies
- ESG reporting and sustainability compliance
- WCAG 2.1 / 2.2 and the European Accessibility Act (Directive (EU) 2019/882)
- SDAI – Standard Dostawcy AI w Ochronie Zdrowia, the HCPL certification programme for AI suppliers
- Internal and clinical audit – IIA standards, IT audit (CISA/ISACA methodology), managerial control in the public sector
Contact – Department Director
👤
Piotr Welenc
Director of the Quality, Audit and Certification Department (CAC HCPL), Healthcare Poland Foundation.
✉️
p.welenc@
healthcarepoland.pl
Phone +48 787 000 827 · ul. Kawęczyńska 36 A003, 03-772 Warszawa.
🎖️
13 professional
certifications
CISA, CICA, CGEIT, CRISC, CRMA, CDPSE, ACO, AESGO, AAIO, IRCA ISO 22301 LA, IRCA ISO 27001 LA, ISO 20000 LA, QAVal.
Talk to the Certification and Audit Center
Piotr Welenc – one of Poland’s most versatile experts in internal audit, risk management, cybersecurity, corporate governance (GRC), quality systems and compliance. Over 20 years of senior-level practice (NBP, ZUS, ECB, Boeing), PhD candidate at IBS PAN, author of more than 30 publications, trainer accredited by APMG International for CISA, CRISC and CGEIT.
Areas of practice and related pages
- Cybersecurity – ISO 27001 / ISMS, NIS2 and DORA, critical infrastructure, IT security audit, incident management, GDPR, Data Protection Officer.
- Audit and control – internal audit (IIA), IT audit (CISA/ISACA), clinical and medical audit, quality audit (ISO 9001, ISO 13485), managerial control, GRC systems.
- Compliance and ethics – compliance systems, business ethics, anti-corruption, SOX, healthcare compliance (MDR, accreditation).
- Risk management and GRC – ERM, ISO 31000, COSO, operational, IT and clinical risk, ESG risk, antifragility and organisational resilience.
- Quality and healthcare – ISO 9001, ISO 13485, ISO 22301, MDR, hospital accreditation (JCI, CMJ), clinical risk management.
- IT governance – CGEIT/COBIT, process management, IT procurement, digital transformation and change management.
- Digital accessibility – WCAG 2.1/2.2, accessibility declarations, automated and manual testing, European Accessibility Act compliance.