Cyber ​​Coalition (CyberC4HE)

#CyberC4HE Coalition · third year of operation · update September 2026

Hospital cybersecurity is patient safety and continuity of care, not just a task for the IT department. The Coalition brings hospital directors, IT teams, public institutions and technology providers to one table — to turn obligations under NIS2 and the amended Polish National Cybersecurity System Act (KSC) into concrete, achievable actions.

How the Coalition was founded

The Coalition for Cybersecurity in Healthcare was inaugurated on 29 May 2024 in Warsaw, at the headquarters of the Supreme Medical Chamber. It was initiated by the Healthcare Poland Foundation and co-founded by the Central Research, Innovation and Education Centre of the Supreme Medical Chamber (NIL IN), the Polish Hospital Federation (PFSz) and the National Chamber of Care Homes (KIDO). Participants in the inauguration included Dr Artur Drobniak (President of the Warsaw Regional Medical Chamber, Director of COBIK NIL), Prof. Jarosław J. Fedorowski (President of PFSz), Roman Łożyński (Director of the Finance Ministry IT Centre) and Michał P. Dybowski (President of the Healthcare Poland Foundation).

The goals set at the founding remain valid: education of medical staff and management, cybersecurity standards for hospitals, audits, and extending the work to infrastructure and telemedicine security.

Media coverage from the founding period (in Polish)

What has been achieved

26member organisations, including medical chambers and more than 20 hospitals
3,500+participants in educational activities by the end of 2025 (on-site and online)
ZUSthe Social Insurance Institution joined in February 2025
Year 3of operation — since May 2024

Figures from the Healthcare Poland Foundation press release of 8 July 2026.

  • Inauguration of the Coalition in Warsaw.
  • “NIS2 and cybersecurity in healthcare” trainings for directors, IT teams, lawyers and procurement staff — including Białystok (30 Sept) and Szczecin (16 Oct); later editions also in Łódź and Poznań.
  • #CyberC4HE session with hospital directors at the 13th PFSz Congress in Warsaw — recommendation of two-factor authentication and hardware security keys; participants received 100 hardware keys.
  • The Social Insurance Institution (ZUS) joined the Coalition.
  • Report on open and secure hospital information systems (HIS) in the context of NIS2 and the EHDS, and a position paper to the Ministry of Health on reducing hospitals’ dependence on single software vendors (vendor lock-in).
  • Cybersecurity strategy workshop at the Pomeranian Marshal’s Office — hospital directors and IT heads at one table with the e-Health Centre (CeZ); direction: a regional SOC and shared services model.
  • Cybersecurity workshop for hospitals of the Podlaskie region at the psychiatric hospital in Choroszcz — NIS2/KSC compliance pathway, IT service models, secure connectivity, de minimis training.
3 April 2026The amendment to the Polish National Cybersecurity System Act transposing the NIS2 Directive entered into force. Healthcare providers are, depending on their size, essential or important entities; responsibility for meeting the obligations rests with the head of the entity.
by 3 October 2026Self-identification and application for entry in the register of essential and important entities (wykaz-ksc.gov.pl).
by 3 April 2027Implementation of the security management system, risk management and incident handling procedures.
from 3 April 2028Deadline for the first audit of essential entities; most administrative penalties may be imposed.

The analysis and recommendations further down this page date from 2024–2025 and describe the situation before the amendment. Compliance is not the same as resilience — the Coalition works on both.

Join the Coalition

Healthcare providers and institutions — beneficiaries

Who: hospitals, care homes and long-term care facilities, primary and outpatient care providers, emergency medical services, founding bodies and regional governments.

What you gain:

  • Round Table meetings and regional workshops for directors and IT heads,
  • Coalition materials, checklists and reports, and access to working groups,
  • a NIS2/KSC readiness assessment pathway with the HCPL Quality, Audit and Certification Centre,
  • training for medical staff and management,
  • participation in developing the regional SOC and shared services model,
  • a voice in position papers to the Ministry of Health and the Ministry of Digital Affairs.

How to join:

  1. Email application: organisation name, region, contact person on the management and IT side.
  2. Introductory call (approx. 20 minutes) — needs and status under the KSC Act.
  3. Declaration of accession to the Coalition.
  4. Inclusion in a working group and the regional events calendar.

Apply

Market suppliers — technology and service partners

Who: providers of SOC/SIEM, EDR, backup and recovery, connectivity, HIS and cloud services, audit and advisory firms, law firms.

2026 partnership package:

  • use-case presentations at Coalition events,
  • exhibition presence and visibility in event materials,
  • networking sessions with hospital management,
  • participation in working groups and co-authoring expert papers,
  • event summary reports.

Rules of participation:

  • verification of competence and references by the HCPL Quality, Audit and Certification Centre,
  • neutrality — the Coalition does not endorse any single supplier; purchasing decisions are made by healthcare providers under their own procedures,
  • substantive case studies rather than sales pitches,
  • disclosure of conflicts of interest.

Package terms are available on request. Technology partners taking part in 2026 events included Ricoh and Comstellation.

Ask about partnership

Coalition Coordinator: Michał P. Dybowski, President of the Management Board, Healthcare Poland Foundation · centrum@healthcarepoland.pl · tel. +48 787 000 827


Expanded narrative of the CyberC4HE Coalition’s activities with reference to national laws and European regulations

✓ Establishment of the Cyber4HE Coalition
✓ NIS2 Directive
✓ Act on the National Cybersecurity System (KSC)
✓ RODO and eIDAS regulations
✓ Conclusions from the analysis of 140 hospitals in 2024
✓ Identification of good practices
✓ Recommendations for 2025
✓ Timeline for implementation of recommendations
✓ Forms of support offered by CyberC4HE

Establishment of the CyberC4HE Coalition

The CyberC4HE Coalition was formed in response to the rapidly growing cyber threats in the healthcare sector, which stem from the increasing dependence of medical systems on digital technologies and the outdated IT infrastructure of many facilities. The coalition acts as a platform for cooperation between the public and private sectors, state institutions, NGOs and experts.

Since its inception, the Coalition has brought together leading organizations such as the Center for e-Health (CeZ), the sector CSIRT, the Healthcare Poland Foundation, the Polish Federation of Hospitals (PFSz), regional Chambers of Physicians, and key experts in cyber security, risk management and digital transformation.

The goal of the Coalition is to gather information on the state of preparedness of healthcare entities and to develop an optimal process for implementing an integrated critical infrastructure protection system in accordance with the requirements of the NIS2 Directive, EU ENISA standards and national regulations, such as the National Cyber Security System Act (Journal of Laws 2018, item 1560, as amended) and RODO regulations (Regulation 2016/679 of the European Parliament and of the EU Council).


NIS2 Directive

The NIS2 Directive, adopted in December 2022, is a key piece of critical infrastructure protection legislation in the European Union, extending responsibilities to the healthcare sector. Key provisions include:


National Cybersecurity System NCS Krajowy System Cyberbezpieczeństwa KSC graphics Healthcare Poland

NCS / KSC

Act on the National Cybersecurity System
(NCS / KSC)

In Poland, the regulations of the NIS2 Directive are being implemented through amendments to the KSC Act, which will come into force on January 1, 2025. The most important provisions of the law:

  • Granting hospitals of particular importance to health protection the status of key service operators.
  • Introduction of the obligation to create risk management plans and incident response procedures.
  • The obligation to ensure compliance with the safety requirements specified in Article 8 of the Act.
  • The requirement to conduct reporting in accordance with ESG (Environmental, Social, Governance), which is a new element related to the financing of technological solutions.

Analysis

Conclusions from the analysis of 140 hospitals in 2024

Conclusions from the analysis of 210 hospitals in 2025

1

Deficiencies in IT infrastructure

62% of hospitals use IT systems that are more than five years old, which prevents them from being updated in accordance with security requirements.

48% of facilities have not implemented real-time threat monitoring systems.

2

Lack of integrated risk management procedures

Most hospitals do not have incident response plans or defined reporting procedures.

3

Insufficient funding

Only 30% of hospitals allocate more than 5% of their IT budget to cybersecurity, which is well below ENISA’s recommendation.


Recommendations for 2025/2026

?

Construction of distributed SOCs

Establishment of Provincial and Local Government SOCs integrated with CeZ and sectoral CSIRTs.

Financing the construction of SOCs from EU funds (Horizon Europe, Digital Europe) and the ESG component under the KPO (National Recovery Plan).

?

Simplified audit and certification model

Simplified audit: Dedicated to medium-sized hospitals, allowing for assessment of compliance with the NIS2 Directive and the KSC Act.

ESG certification: Facilities that meet IT security requirements will be able to obtain certificates confirming ESG compliance, which opens up access to additional funds.

??‍?

Isolated infrastructure and physical security measures

Air-gapped networks: For critical IT systems, such as patient data management systems.

USB port blocking: Mandatory on all medical and administrative devices, except for authorised hardware keys.

?

Digitisation and elimination of paper-based procedures

Digital documentation: Implementation of digital signatures in accordance with eIDAS, enabling a complete transition to electronic patient consent forms and medical documentation.

EZLA system: Expansion to all hospitals, elimination of risks associated with prescription machines.

??‍⚕️

Medical and administrative staff training and support

Nationwide training programme on cyber hygiene and incident management for medical and administrative staff.

Workshops for management on integrating cybersecurity with ESG management.

Short-term
(2025)

➜ Pilot project involving simplified audits in 10 hospitals

➜ Construction of 5 Provincial SOCs

➜ Training 20,000 healthcare workers in cybersecurity

Mid-term
(2026–2027)

➜ Certification of 80 hospitals in accordance with ESG

➜ Full implementation of isolated networks in key units

Long-term
(2028+)

➜ The development of the national cybersecurity system in healthcare as a model for other sectors

CyberC4HE

Summary

Based on national and EU regulations, the CyberC4HE coalition has developed a comprehensive plan for cybersecurity transformation in the Polish healthcare sector. Implementation of the recommendations will ensure compliance with the NIS2 directive, protect patient data, and increase the effectiveness of financing, including in preparation for ESG reporting.

Models of support offered by CyberC4HE

Find out what forms of support the CyberC4HE Coalition offers its members.

Comprehensive cybersecurity transformation plan

The plan includes the implementation of risk management systems, IT infrastructure protection and compliance with the NIS2 directive, supporting hospitals in improving their financing and preparing for ESG reporting.

CyberBook

A handbook of good practices and standards for cybersecurity that supports the implementation of obligations under EU regulations (NIS2, GDPR, eIDAS).

Construction of distributed SOCs

Local security centres in EU regions monitoring threats, co-funded by Horizon Europe and Digital Europe funds.