Certification and Audit Center (CAC HCPL)

Fast audit and certification model

Dedicated to small and medium-sized facilities
Micro-certification and accreditation centre
Staff training

About us

Find out what actions are taken by the Certification and Audit Centre (CAC HCPL)


Actions taken

⚖️ Legislation

Conformity assessment system, accreditation and amendment of certain acts.

National Cybersecurity System NCS Krajowy System Cyberbezpieczeństwa KSC graphics Healthcare Poland

NCS / KSC

National Cybersecurity System
(NCS / KSC)

The subject of the service is to examine the compliance of the Contracting Authority’s operations with the requirements of the Law of July 05, 2018 on the National Cyber Security System, advise on the preparation of documentation, and conduct an audit in accordance with Article 15. of the KSC Law.

As part of the implementation of the service, the following will be performed:

  1. Zero audit, for compliance with the UKSC.
  2. Advisory activities on:
    a. Documentation of risk analysis methodology and risk management policy in the area of cyber security;
    b. Procedure for management of cyber security breach incidents;
    c. Other documentation (policies and procedures) of the KSC in the area of information security and business continuity.
  3. The cyber security audit required by the KSC Law.
  4. The work will result in the following:
    – Zero audit report with recommendations for implementation of actions necessary to achieve full compliance with legal requirements in terms of the National Cyber Security System Act;
    – Documentation (policies and procedures) of information security and business continuity;
    – UKSC audit report.
  5. Completion date – 3 months from the date of signing the contract.

SELECTION CRITERIA AND REQUIREMENTS

Bid evaluation criterion: price – 100%

The contractor must demonstrate the ability to implement the contract.
The Contracting Authority will consider ability as meeting at least the following conditions:

  1. The audit can be carried out by persons or entity only meeting the conditions for an auditor mentioned in UKSC. It is required that the team conducting the audit has at least two specialists with certifications each of CISA, CRISC, ISO27001 LA. and at least one of them certifications: ISO22301 LA,
  2. At least one person from the auditing team has experience in auditing a medical entity.
  3. At least one of the persons directed to carry out the contract has in his portfolio at least one KSC audit service of a clinical hospital (consulting and/or auditing), with a contract value of at least PLN 40 thousand.
  4. Each of the persons carrying out the contract must meet the criterion of independence and declare the absence of conflict of interest.

Services

We offer a wide range of services

As part of our comprehensive cooperation with the Healthcare Poland Foundation (FHP), we offer a wide range of services:

1

Audit and accreditation

Audit and accreditation of products, services and staff.



2

Certification of formal requirements

Certification of formal requirements in the context of public procurement and legal regulations, in particular NIS2, EGS, GDPR, ISO.

3

Testing and certifications

Testing new medical devices, certifications, technical and cybersecurity audits, diagnostic services, development and evaluation of treatment protocols to improve patient care.

4

Research

Conducting research to validate new technologies and treatments, accelerating their path to market and ensuring they meet regulatory standards.

5

Presentation of technological solutions and health programmes

Presentation of technological solutions and health programmes during seminars and conferences organised by the HCPL/PFSz Foundation.

6

Micro-credentials and industry certifications

Micro-credentials and industry certifications facilitating access to the health market.


The model of rapid audits and certifications

🏥

Dedicated to small
and medium-sized facilities

Assists in assessing compliance with legal requirements.

📑

Micro-certification
and accreditation centre

A platform for certifying the competence of medical personnel, crucial for ensuring compliance with EU standards.

👩🏻‍⚕️

Staff
training

Training 20,000 employees in cyber hygiene and incident management.

CROSS-BORDER MEDICINE

Cross-border healthcare under Directive 2011/24/EU

A regulated market, not a marketing exercise. EU citizens have the right to be treated in another Member State and to be reimbursed under the rules of their country of affiliation. CAC HCPL turns that legal framework into working organisational practice.

🇪🇺

S2 route

The public insurer covers the treatment directly at a public provider abroad, once prior authorisation has been granted.

💶

Pay and claim

The patient pays and claims reimbursement. Private providers are covered too, but only up to the tariffs of the insuring country.

☎️

National Contact Points

Every Member State explains reimbursement, prior authorisation, provider registration, quality rules and the redress path.

📄

Prior authorisation

Usually required for overnight hospitalisation and highly specialised equipment – and decisive for the patient’s final cost.

🔐

GDPR and EHDS

Processing data of patients from other Member States requires auditable compliance and interoperable documentation.

🤝

Continuity of care

Follow-up, complaint handling and alternative dispute resolution after the patient has returned home.

MEDICAL TOURISM

Ready for the international patient

Medical tourism is a system, not a campaign. Before a facility advertises abroad it has to be organised for foreign patients. These are the areas verified by CAC HCPL during gap analysis.

🏥

Dedicated ward

A separate ward or sub-ward outside the NFZ contract, entered in RPWDL with the right code, covered by the organisational bylaws.

🗣️

Language competence

At least one English-speaking nurse on every shift and guaranteed access to specialist consultations in English.

🧾

Bilingual documentation

Questionnaires, consent forms with a description of the procedure, extended consents and discharge summaries in Polish and English.

🔬

Diagnostics in English

Access to the required laboratory and imaging examinations, with reports issued in English.

💳

Transparent pricing

A price list covering every possible service, including management of complications and, where relevant, repatriation.

🛏️

Patient standard

Single rooms with a private bathroom, patient rights charter and ward rules in English, orientation video, ID badges in English.

TQAMS

Transborder Quality Audit of Medical Services

The proprietary certification standard of the Healthcare Poland Foundation, dedicated to medical tourism and cross-border care. It standardises and certifies the quality of transborder medical services in Poland and the EU, in the context of Directive 2011/24/EU and the forthcoming European Health Data Space, and is developed in cooperation with the Global Healthcare Systems Hub (GHSH).

1

Gap analysis

Review of organisational documentation, formal requirements, infrastructure, language competences, availability of consultations and bilingual documentation. Result: a gap report with a corrective action plan.

2

Implementation

Organisation of the dedicated ward, operating procedures, staff training, bilingual documentation, pricing, safety and continuity-of-care procedures. Result: a facility ready for the audit.

3

Certification audit

Documentation audit, on-site visit using tracer methodology, verification of infrastructure and staff competences, patient interviews, review of emergency procedures. Result: the TQAMS certificate.

4

Surveillance

Annual surveillance audits, monitoring of quality indicators (KPI), verification of continued compliance and recertification every three years.

JCI Readiness – the road to international accreditation

🥇

Gold Seal
of Approval

Joint Commission International accreditation is recognised by insurers, governments and care coordinators in over 100 countries.

🔍

Gap analysis
and remediation

A review against more than 1,200 measurable elements in 14 standard areas, with a prioritised corrective action plan.

🎓

Training
and mock survey

Clinical standards, patient safety, medication management, quality management, documentation and event-reporting culture – verified in a mock survey.

JCI (Joint Commission International)

A global accreditation organisation awarding the Gold Seal of Approval for quality and safety in healthcare. In practice, a condition of entry to the medical tourism markets of the Middle East, Asia and the Americas.

CERTIFICATES & STANDARDS

Everything HCPL audits, implements and certifies

Certification is not an end in itself. Each pathway strengthens the others: TQAMS without GDPR is incomplete, NIS2 without ISO 27001 is fragmentary, JCI without a quality culture is cosmetic.

🛡️

NIS2

Directive (EU) 2022/2555. Healthcare entities as essential service operators – full audit and certification cycle based on the HCPL four-pillar model, delivered through the CyberC4HE coalition.

⚖️

KSC / UKSC

The Polish National Cybersecurity System Act: zero audit, risk methodology and risk-management policy, incident procedures and the statutory audit under Art. 15.

🔐

GDPR / RODO

From declarative to auditable compliance: data-flow mapping, risk assessment and DPIA, 72-hour breach notification, staff training, integration with the quality system.

📘

ISO & MDR

ISO 9001, 13485, 14001, 22301, 27001, 45001, 20000, ISO 31000 and COSO, plus MDR (EU) 2017/745 compliance for medical devices.

🌱

ESG

Environmental, social and governance reporting verified by financial institutions, investment funds and corporate partners, and required in EU programmes.

Accessibility & AI

WCAG 2.1/2.2, accessibility declarations and audits, the European Accessibility Act, and SDAI – the HCPL certification programme for AI suppliers in healthcare.

Contact – Department Director

👤

Piotr Welenc

Director of the Quality, Audit and Certification Department (CAC HCPL), Healthcare Poland Foundation.

✉️

p.welenc@
healthcarepoland.pl

Phone +48 787 000 827 · ul. Kawęczyńska 36 A003, 03-772 Warszawa.

🎖️

13 professional
certifications

CISA, CICA, CGEIT, CRISC, CRMA, CDPSE, ACO, AESGO, AAIO, IRCA ISO 22301 LA, IRCA ISO 27001 LA, ISO 20000 LA, QAVal.

Talk to the Certification and Audit Center

Piotr Welenc – one of Poland’s most versatile experts in internal audit, risk management, cybersecurity, corporate governance (GRC), quality systems and compliance. Over 20 years of senior-level practice (NBP, ZUS, ECB, Boeing), PhD candidate at IBS PAN, author of more than 30 publications, trainer accredited by APMG International for CISA, CRISC and CGEIT.