#CyberC4HE with hospital directors — conference summary

Posted by:

|

On:

|

The #CyberC4HE Coalition at the Polish Federation of Hospitals Autumn Conference 2024

The Coalition for Cybersecurity in Healthcare presented at the 13th congress of the Polish Federation of Hospitals on the current cybersecurity challenges facing hospitals, including the requirements arising from the NIS2 Directive

Protection of medical data

Physical security as the hardest safeguard to break. The Coalition #CyberC4HE is giving away 100 Yubico keys.

NIS2 through an auditor’s eyes

Piotr Welenc shared with conference participants the security expectations developed through HCPL’s coordination work

Electronic sick notes (e-ZLA) and cybersecurity in healthcare

At the Autumn Programme Conference of the Polish Federation of Hospitals, held on 28 November 2024 in Warsaw, representatives of the Coalition for Cybersecurity in Healthcare (CyberC4HE) presented key aspects of electronic sick notes (e-ZLA). CyberC4HE brings together experts from a range of fields — technology, healthcare and law — with the aim of raising the level of cybersecurity in the Polish health sector. The Coalition works to strengthen the security of the IT systems used in healthcare, such as the ZUS electronic services platform (PUE ZUS), and to counter the risks associated with processing patients’ personal data.

The presentation was delivered by Sławomir Wasielewski, Board Member for Operations and Systems, and Agnieszka Gębicka, Director of the Personal Data Protection Office and Data Protection Officer. It set out the history, operating principles and safeguards of the e-ZLA system, and discussed the role of physicians as controllers of patients’ personal data. The aim was to underline the importance of appropriate technological safeguards against a rising number of data breaches, and the role of physicians as key participants in the healthcare system.

Scope of the presentation

Rules and processes of e-ZLA
The obligations of physicians and institutions in relation to e-ZLA were discussed, including the role of medical assistants and the supporting tools available, such as PUE ZUS, practice management applications and the mZUS mobile app. Physicians are required to issue sick notes in electronic form only, and where technical problems arise must complete them within three days.

Security and personal data protection
The rules on protecting patients’ personal data were presented, including the introduction of two-factor authentication (2FA) and mechanisms limiting excessive data retrieval in practice management applications. The responsibility of physicians as controllers of patients’ personal data — accountable for processing it in accordance with the GDPR — was emphasised. ZUS has introduced additional anti-abuse measures, such as blocking users who retrieve data excessively.

Breach statistics
In 2024, 5,450 data protection breaches were recorded in the e-ZLA system. Each was analysed in detail by the Personal Data Protection Office, which underlines the importance of monitoring GDPR compliance.

Technological safeguards
The available authentication methods were discussed, including digital certificates, the trusted profile and the qualified electronic signature. To raise the level of security in systems such as PUE ZUS, the introduction of physical security keys (hardware security keys).

The presentation is attached.

Physical keys as a safeguard

The speakers argued that physical security keys could serve as an additional safeguard, providing a higher level of protection for patients’ personal data. Such keys minimise the risk of phishing attacks and are straightforward to use, working on the FIDO2/U2F protocols, which allows them to be integrated with existing two-factor login systems.

Against a rising number of personal data breaches and the need to secure the highest standards in healthcare systems, physical security keys appear to be one of the most effective solutions available. Their use can substantially reduce the risk of unauthorised access to patient data, in line with the wider trend towards raising cybersecurity standards in the medical sector.

#CyberC4HE

Healthcare Poland Logo