Any Questions?

Feel free to reach out if you would like to find out how Athereon GRC can support you with current governance, risk and compliance issues.

22.7.2026
11 minutes

ISMS for Clinics and Hospitals: How to Successfully Implement NIS2 Requirements

Hospitals are among the most at-risk institutions in the German cyberspace. In recent years, numerous ransomware attacks on German hospitals have been documented—from large university hospitals to regional hospital networks—resulting in cancelled surgeries, emergency rooms taken offline, and systems paralyzed for days. An IT outage here affects not only processes but directly impacts patient care. This is precisely why an ISMS in a hospital today is neither optional nor solely an IT task: An information security management system consolidates processes, responsibilities, and technical measures into an auditable system and provides the foundation for demonstrable compliance. This article outlines the regulatory requirements ranging from NIS2 and KRITIS to the KRITIS Umbrella Act and Section 391 SGB V through Article 9 GDPR, and shows how to build an ISMS for your hospital in a structured manner.

Why an ISMS is Indispensable in a Hospital

The digitalization of medicine has enormously expanded the attack surface of hospitals. Hospital information systems, networked medical devices, electronic patient records, and telematics connections are closely intertwined, and a single compromised access point can jeopardize the entire operation. Unlike in many other industries, when an outage occurs, revenue is not the top priority—continuity of care is, and with it, patient safety.

An ISMS addresses this challenge not with isolated measures but systematically. It defines which assets are worth protecting, what risks exist, who is responsible, and how measures are continuously reviewed and improved. For a hospital, this means that protection requirements and risks are not managed on an ad-hoc basis, but continuously. Regulatory authorities also demand precisely this demonstrability—making an ISMS for hospitals both a security and a compliance instrument.

NIS2 and hospitals: the new legal framework

The NIS2 Implementation Act (NIS2UmsuCG) has been in force in Germany since December 6, 2025—with no transition period. It transposes the European NIS2 Directive and, in doing so, comprehensively amends the BSI Act (BSIG). Approximately 29,500 organizations fall newly or more extensively within its scope, including the entire healthcare sector. We explain in detail what NIS2 means for the applicability assessment and the resulting obligations on our NIS2 regulatory page.

Hospitals are assigned to the healthcare sector (Annex 1 No. 4.1.1 BSIG) and are regularly classified as either essential or important entities. Two criteria are decisive: affiliation with the sector and size. In principle, NIS2 applies to organizations with 50 or more employees or with an annual turnover or annual balance sheet total exceeding €10 million. This brings a large portion of Germany's hospital landscape under the law, regardless of whether a facility was previously classified as critical infrastructure.

The obligations are concrete: Registration with the BSI, reporting of significant security incidents, implementation of technical and organizational risk management measures, and the obligation of executive management to approve and monitor these measures. This responsibility is personal and cannot be fully delegated to the IT department. An ISMS is the appropriate framework for meeting all of these requirements in a structured and auditable manner.

The tiered reporting obligation under Section 32 BSIG is particularly demanding: An early warning within 24 hours of becoming aware of a significant security incident, an evaluative follow-up report within72 hours, and a final report no later than one month afterward. Meeting these deadlines under crisis pressure is only possible with prepared processes and clearly defined responsibilities. These are core components of a functioning ISMS.

KRITIS hospitals: the 30,000-case threshold

For some hospitals, an additional layer of regulation comes into play. In Germany, an approved hospital within the meaning of Section 108 SGB V is considered an operator of a critical facility (KRITIS) as soon as it exceeds the BSI-Kritis V threshold of 30,000 inpatient cases per year. In this case, the hospital automatically qualifies as an essential entity under Section 28(1) No. 1 BSIG—a separate applicability assessment is not required.

The strictest requirements apply to KRITIS hospitals. In addition to registration and notification obligations, they must regularly demonstrate to the BSI that they have taken appropriate measures to prevent disruptions. This evidence must be provided on a recurring basis and requires a robust, documented security organization. In practice, this can hardly be achieved without an established ISMS. In addition, the KRITIS Umbrella Act (KRITIS-DachG) will take effect in 2026, implementing the EU CER Directive (2022/2557) and requiring CI operators to ensure physical resilience beyond IT security—covering everything from natural hazards and sabotage to the failure of external supply chains. For hospitals, this means that information security and business continuity management (BCM) must be considered together.

Hospitals below the 30,000-case threshold are not exempt from these obligations: It must be assessed whether they qualify as an essential entity (Section 28(1) No. 4 BSIG) or as an important entity (Section 28(2) No. 3 BSIG). The earlier assumption that only the roughly 90 largest German hospitals were regulated is therefore outdated.

§ 391 SGB V: IT security for every hospital

Regardless of NIS2 and KRITIS, a separate obligation under social law applies to all hospitals. Section 391 SGB V requires every hospital to take appropriate organizational and technical measures, in line with the state of the art, to prevent disruptions to the availability, integrity, and confidentiality of its information technology systems. This provision replaced the former Section 75c SGB V; it was transferred into the SGB V by the Digital Act (DigiG) and has applied in this version since March 26, 2024.

Its scope is decisive: Section 391 SGB V does not include a size threshold. It applies equally to the small specialty hospital and the maximum-care provider. Paragraph 2 requires mandatory measures to enhance security awareness; regular awareness-raising is therefore not optional. Paragraph 3 clarifies that measures are appropriate if the effort involved is not disproportionate to the consequences of a security incident. In other words, the larger and more critical to care delivery a hospital is, the higher the bar. Although Section 391 SGB V does not impose its own fines, responsibility remains with executive management. Management can delegate implementation, but not the responsibility itself.

B3S as the recognized state of the art

What "state of the art" means in concrete terms is spelled out in the German industry-specific security standard (B3S) "Medical Care." It is prepared by the German Hospital Federation (Deutsche Krankenhausgesellschaft, DKG) in coordination with the "Medical Care" industry working group and reviewed by the BSI for suitability under Section 8a BSIG (former version; as of December 6, 2025,continued in Section 39 BSIG). Suitability of the current version was confirmed at the end of 2025. Anyone who implements the B3S thereby fulfills the KRITIS requirements under Section 39 BSIG; at the same time, its implementation is also recognized in professional practice for facilities below the KRITIS threshold as an appropriate specification of the state of the art within the meaning of Section 391 SGB V.

The B3S defines full inpatient care of patients as the critical service to be protected and, on this basis, sets out concrete requirements—from risk management through emergency preparedness to attack detection systems (SzA). In doing so, it goes beyond an industry-neutral security concept and translates the protection objectives into everyday clinical practice.

Alignment with established standards is essential: The B3S is based on the structure of common ISMS standards such as ISO/IEC 27001. A hospital that sets up its ISMS from the outset to serve multiple reference frameworks at once avoids duplicated effort. This is precisely where a framework-agnostic approach pays off: NIS2/BSIG, Section 391 SGB V, B3S, and ISO 27001 are not mapped in separate silos but in a shared system.

The path to a NIS2-compliant hospital: five steps

Successfully implementing NIS2 means turning the tangle of regulations into a structured implementation path. In practice, a five-step approach has proven effective, leading from the initial status check to recurring evidence of compliance.

  1. Assess applicability and register. First, it must be determined whether the hospital qualifies as an essential or important entity under Section 28 BSIG and whether it additionally holds KRITIS status. Based on this classification, registration with the BSI is completed via the Reporting and Information Portal (MIP).
  2. Gap analysis against the B3S. A structured comparison between B3S requirements and actual implementation status makes gaps visible and allows for prioritization based on risk and maturity level. The BSI follows the same logic with its Maturity and Implementation Level Assessment. The gap analysis thus serves as both the starting point and the later benchmark for review.
  3. Establish the ISMS foundation. Scope, roles and responsibilities, asset register, risk methodology, and control set form the foundation. Designed to be framework-agnostic, an ISMS simultaneously covers NIS2/BSIG, Section 391 SGB V, B3S, and ISO 27001 without duplicating effort.
  4. Establish reporting processes and BCM. The 24h/72h/1M cascade under Section 32 BSIG only works with prepared reporting channels, clear escalation levels, and rehearsed procedures. Combined with business continuity management (BCM) for outages and crisis situations, response becomes routine.
  5. Build evidence and close the cycle. Documentation, internal audits, and preparation of the recurring evidence submissions required under Section 39 BSIG are part of regular operations and not an endpoint. The PDCA cycle of the ISMS sustains implementation over the long term.

This turns a compliance requirement into a robust operational process, and NIS2 implementation into a state that holds up when it matters most.

From mandatory obligation to opportunity: ISMS with Athereon GRC

For many hospitals, this tangle of requirements initially feels overwhelming. Yet information security can be viewed as an opportunity: A well-managed ISMS reduces real risks, builds trust with patients, and turns compliance into robust proof rather than an annual fire drill. For hospitals, compliance as an opportunity is not a marketing promise but a question of operational capability.

Athereon GRC, the leading European GRC platform, supports clinics and hospitals in building and operating exactly this kind of ISMS. The ISMS module maps the requirements from NIS2/BSIG, Section 391SGB V, the B3S "Medical Care," and ISO 27001 within a common structure. Because the platform is framework-agnostic, you work with a consistent set of controls, evidence, and risks instead of maintaining each requirement separately. Complementary modules such as BCM (Business Continuity Management) for emergency preparedness and DPM (Data Protection Management) for handling sensitive health data in accordance with Article 9 GDPR interlock seamlessly.

You are supported by the AI agent LAiKA. It operates according to a clear escalation logic: from the foundation through LAiKA Assist to the specialized agents such as the Infrastructure Mapper, the Compliance Assistant, and the Questionnaire Assistant. LAiKA takes routine tasks off your hands, for example when mapping the system landscape or answering recurring audit questions. Throughout, the guiding principle applies: "Nothing happens without your OK": Full control over every decision remains with you.

For hospitals, another point is decisive: Athereon GRC is 100% made in Germany. Sensitive patient data and security evidence remain in an environment governed by German law. This is an advantage that is increasingly demanded in tenders and audits.

Conclusion

Today, an ISMS in a hospital is both a twofold obligation and an opportunity: It fulfills the requirements of NIS2, KRITIS, and the KRITIS Umbrella Act, of Section 391 SGB V and Article 9 GDPR, while also protecting what matters most—the care of patients. Those who consolidate the various regulatory frameworks into a single system, rather than working through them individually, save effort and gain evidentiary certainty. With the ISMS module from Athereon GRC and the AI agent LAiKA, you implement NIS2 requirements in a structured way and build information security that holds up in an emergency.

Would you like to learn more?

Book a noncommittal demo appointment with our team to analyze your individual use case with us.