The threat picture Ransomware against clinical systems, phishing into shared inboxes, and third-party access nobody has reviewed since go-live.
What buyers ask for DSPT submissions, DPIAs, ISO 27001 certificates and evidence that clinical data stays where you say it does.
Where we help One accountable owner for the questionnaire pile, the certification project, and the incident plan you hope not to use.
Selling into the NHS or a private provider? Get the assurance pack in order before procurement asks. A four-week gap assessment usually tells you whether you’re weeks or months away. Book a consult
WHAT WE DO
Working with a healthtech team
1 Map the patient data. Where special category data enters, rests and leaves — including the processors and sub-processors you inherited from an integration nobody has revisited.
2 Build the assurance pack once. DPIAs, security annexes and the questionnaire answers procurement keeps asking for, written so they can be reused rather than rewritten per buyer.
3 Settle your NIS2 position. Whether you are in scope as a provider to essential entities, what that obliges you to do, and what the management-liability provisions mean for your directors.
4 Controls that do not obstruct care. Security designed around clinical workflow, so it survives contact with the people actually delivering treatment — and does not collide with medical device obligations.
5 Incident readiness. Notification paths that satisfy the regulator, the hospital contract and the clinical safety officer at the same time — agreed before you need them.
Health systems rarely reject a supplier outright. They defer — and a deferral while you assemble evidence costs a procurement cycle, not a meeting.
THE OBLIGATIONS
What actually reaches a company your size
GDPR Art. 9 Health data is special category data. A higher bar for lawful basis, safeguards and breach handling than ordinary personal data.
NIS2 The health sector is explicitly in scope, and supplying an essential entity can pull you in behind it.
MDR Where your software counts as a medical device, cybersecurity becomes part of the conformity assessment rather than a separate exercise.
Buyer contracts Hospital and health-system agreements carry their own security annexes, audit rights and notification clocks — often stricter than the regulation.
COMMON QUESTIONS
Healthcare & HealthTech, in short
Are we in scope for NIS2 as a healthtech supplier?
The health sector is explicitly in scope, and supplying an essential entity can pull you in behind it. Settling your position also means understanding what the management-liability provisions mean for your directors. Why is health data treated differently under GDPR?
Health data is special category data under Article 9. That means a higher bar for lawful basis, safeguards and breach handling than ordinary personal data. How long does it take to be ready for hospital procurement?
A four-week gap assessment usually tells you whether you are weeks or months away. Health systems rarely reject a supplier outright — they defer, and a deferral while you assemble evidence costs a procurement cycle. INSIGHTS · HEALTHCARE Writing for this sector
All insights → How we help