Join our Newsletter — 33% off our NHI Course

NIS2 in hospitals: can you prove access controls are working?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: NIS2 is now national law across much of the EU, and hospital boards should expect supervisors to ask for evidence that access control, MFA decisions, leaver handling and privileged access are operating in practice, not just documented on paper, according to Crayonic. For essential entities, the burden has shifted from policy ownership to demonstrable control effectiveness.

Editorial analysis by NHI Mgmt Group, based on content published by Crayonic: “NIS2 has reached the hospital: the access control evidence a supervisor will ask for”.

By the numbers:

  • Member States reported 309 significant cybersecurity incidents affecting healthcare in 2023.

Key questions

Q: What breaks when a hospital cannot prove access controls are working under NIS2?

A: The failure is not only technical.

Q: Why do shared logins create a supervisory problem in healthcare access reviews?

A: Shared logins break the chain between action and person.

Q: How should hospitals evidence privileged and emergency access for NIS2 inspections?

A: Hospitals should keep separate privileged accounts, log every emergency access event, and review break-glass use after the fact.

Practitioner guidance

  • Document access control as an evidential control Maintain policies, approvals, review cycles and log evidence that show access control is operating, not just approved on paper.
  • Separate named, privileged and emergency access Use distinct accounts for daily work, administration and break-glass access so each path can be reviewed and attributed independently.
  • Eliminate shared ward logins Assign a named person behind every login where possible, and contain any unavoidable shared account to a tightly defined exception process.

Bottom line: NIS2 turns hospital access control into an evidence question, not a policy statement.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Access control has become an evidence obligation, not a policy exercise: NIS2 supervision turns the question from whether a hospital has written controls into whether it can prove those controls operated at the point of access. That changes the governance model for IAM, PAM and audit readiness alike. The practical conclusion is that access records, approval trails and review outputs now function as regulatory evidence, not optional hygiene.

A few things that frame the scale:

  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Should supplier access be treated differently from internal user access under NIS2?

A: Yes. Supplier access should be handled as a distinct risk path because external support can bypass normal staff lifecycle controls and introduce extra exposure into critical systems. Hospitals need documented authentication, approval and review for those connections, plus a clear justification for any continuous or elevated access granted to third parties.

👉 Read our full editorial: NIS2 access evidence in hospitals: what supervisors will ask for



   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.