Cybersecurity Regulation in Healthcare II
- Markéta Hrubá

- Jul 31
- 2 min read
In the previous issue of the Newsletter, we described how digitalisation is transforming healthcare and the associated security risks, and how the CSA, the CRA and the new Cybersecurity Act differ from one another. It is now appropriate to examine their practical implications: the specific obligations they impose on medical device manufacturers, suppliers of associated digital products and healthcare providers, and the rights or claims that healthcare facilities may, in turn, assert against manufacturers and suppliers. It is precisely this practical dimension that will determine whether the new rules remain a mere administrative burden or genuinely strengthen the resilience of care, data and technologies in practice.

Although medical devices and in vitro diagnostic medical devices (IVDs) regulated by the MDR and IVDR are not subject to obligations arising from the CRA, manufacturers, as undertakings, do not fall outside the scope of cybersecurity regulation. Under Czech law, a manufacturer may be a provider of a regulated service, usually under the lower obligations regime; however, depending on its size, a manufacturer of medical devices considered critical during a public health emergency may fall under the higher obligations regime. If the statutory criteria are met, the manufacturer must notify NÚKIB of the provision of the regulated service, report changes to the notified information, manage assets and risks, implement security measures, handle incidents and reflect the requirements in contracts with suppliers.
The notification process itself has proved to be a weak point in practice. NÚKIB expected approximately 6,000 regulated organisations, but as at 8 February 2026, a total of 4,825 entities had submitted notifications. In 2026, NÚKIB is therefore identifying organisations that may be subject to the obligation and calling on them to assess whether they meet the notification criteria. So far, the approach appears to be more guidance-oriented than enforcement-oriented. Failure to submit a notification is, however, an administrative offence, and the penalty may reach CZK 250 million or 2% of turnover.
Additional rules apply to digital products used in healthcare that are not themselves medical devices under the MDR or IVDR—for example, general-purpose software, applications, network components, integration interfaces or remote data modules. If they fall within the scope of the CRA, their manufacturers must ensure cybersecurity by design, assess risks, maintain technical documentation, draw up an EU declaration of conformity, affix the CE marking to the product, determine the support period and provide security updates. They must also establish a point of contact, provide instructions for secure installation and operation, and inform users of the end of the support period. From 11 September 2026, manufacturers will also have to report actively exploited vulnerabilities and severe incidents within tens of hours. Voluntary certification obtained by the manufacturer under the CSA can then strengthen the product’s credibility and the manufacturer’s market position.
Healthcare Providers
Healthcare providers have a dual role. As potential providers of regulated services, they must comply with obligations under the Cybersecurity Act; in addition to the obligations already mentioned, these include staff training and supplier vetting. At the same time, as users of technology, they may require evidence of compliance with cybersecurity requirements, details of the support period, an update policy, a point of contact, a vulnerability-handling process and a contractual guarantee of incident response.
Author: Markéta Hrubá


