Cybersecurity Regulations in Healthcare
- Markéta Hrubá

- Jun 29
- 2 min read
Increasing digitization is revolutionizing the healthcare sector, but it also brings new risks. Connected electronic devices and hospital networks face cyber threats on a daily basis. Securing sensitive patient data and ensuring the reliability of life-saving equipment have become absolute priorities, as any vulnerability can have fatal consequences. The European Union and the Czech Republic are therefore building a strong defensive shield through legislative measures. In this article, we will focus on three regulations: the Cybersecurity Act (CSA), the Cybersecurity Resilience Act (CRA), and the national Cybersecurity Act (ZoKB). Although these regulations complement one another, they have different objectives.

While the CSA (whose main obligations took effect on June 28, 2021) primarily establishes an institutional framework and creates a generally voluntary pan-European framework for ICT certification, the CRA directly targets all hardware and software with data connectivity. The CRA ensures that the products we buy are safe from the design stage through their entire lifecycle. In terms of its impact, the CRA defines direct obligations for manufacturers and will take effect across the board on December 11, 2027. In the context of healthcare, however, the CRA has one absolutely crucial exception: the regulation explicitly does not apply to medical devices that are already subject to the strict certifications of the MDR and IVDR.
Furthermore, the new Czech Cybersecurity Act (ZoKB) entered into force on November 1, 2025, adding another piece to this mosaic. This law does not address the characteristics of the products themselves but applies to organizations providing so-called regulated services. Healthcare is clearly defined as a key sector here, and regulated entities thus explicitly include not only hospitals but also, upon meeting specific criteria, manufacturers of medical devices and in vitro diagnostic devices—provided they meet the basic legal requirements.
Exceptions and Obligations
The main difference between the regulations lies in their strict enforceability. Although economic operators could previously avoid the obligations under the voluntary CSA certification, they can no longer avoid those under the CRA and ZoKB. The CRA imposes strict requirements on all standard IT infrastructure supplied to hospitals, and the key obligation to actively report vulnerabilities and incidents will take effect as early as September 11, 2026.
The perspective of medical device manufacturers themselves is therefore highly specific. Although their medical devices as such are not subject to the CRA due to the aforementioned exemption, the manufacturer, as a company, will certainly not be exempt from the new ZoKB. Economic operators supplying general-purpose software—which is not covered by the medical device exemption—face strict obligations: they must ensure security from the design phase onward, conduct risk assessments, guarantee support with updates, and report vulnerabilities within 24 hours.
The era of voluntary compliance is coming to an end. Although medical devices are exempt from the CRA, manufacturers and their other IT products will not escape regulation.
Author: Markéta Hrubá


