Orphaned Access: The Silent Cybersecurity Gap
Benedikt Langer
5 Min. Read Time Service accounts, API keys, and AI agents often outnumber human accounts. Many of these ...
EHDS, ePA, NIS2: Three regulations set to fundamentally transform digital healthcare by 2029 – and three regulations whose implementation will land squarely on the shoulders of one person in most hospitals: the CIO. Anyone who fails to orchestrate this triple burden strategically won’t just lose compliance – they’ll forfeit strategic influence over the next five years.
This simultaneity is no coincidence. Europe is accelerating its digital health transformation – and Germany must catch up. The Bertelsmann Foundation’s Digital Health Index ranks Germany 16th out of 17 OECD countries. These three regulations represent a deliberate effort to close that gap through binding mandates.
For the CIO of a mid-sized hospital (400-800 beds), this means: an IT budget that hasn’t grown, a team that hasn’t expanded – and three major regulatory construction sites, all due for completion before 2029. ePA pilots are already underway; EHDS demands interoperability standards; and NIS2 requires cybersecurity structures most hospitals simply don’t yet possess.
The DKI rapid survey from March 2026 shows: 40% of hospitals are running ePA pilots; 90% have begun technical implementation. Yet 43% expect full hospital-wide deployment only from Q3 2026 onward. Meanwhile, digitalization penalties took effect in January: up to 2% per billing case if five mandatory digital services remain uncommissioned.
For the CIO, ePA isn’t a finished project – it’s the cornerstone upon which both EHDS and NIS2 are built. Whoever finalizes ePA integration into their hospital information system (KIS) today must tomorrow open those same interfaces for cross-border EHDS data exchange – and the day after, ensure those interfaces meet NIS2 security requirements. These three regulations aren’t parallel tracks. They’re layers of the same system.
The European Health Data Space (EHDS) requires patient data to be available in structured, interoperable formats. HL7 FHIR becomes the binding standard. By March 2029, patient summaries and electronic prescriptions must be accessible across borders. Medical imaging and discharge letters follow by 2031.
The strategic question for the CIO: Do I invest now in a KIS upgrade that supports only ePA – or in an FHIR-based architecture capable of serving both ePA and EHDS simultaneously? The short-term cheaper option (an ePA-only patch) becomes more expensive mid-term, requiring another overhaul in 2028. An FHIR-first strategy demands higher upfront investment – but avoids that second rebuild.
“The biggest challenge lies in technically and regulatorily integrating data from different sectors.” – Sebastian C. Semler, Managing Director, TMF e.V. (National Digital Health Symposium, 2025)
The NIS2 Implementation Act entered into force on 6 December 2025 – with no transition period. Hospitals and MedTech manufacturers with 50+ employees are classified as “essential entities.” The BSI registration deadline expired on 6 March 2026. Failure to register constitutes an immediate violation of current law.
Requirements are substantial: documented IT risk management – including supply chain assessments; mandatory reporting of cyber incidents within 24 hours; mandatory cybersecurity training for executive leadership; and a dedicated information system for affected patients. Fines for non-compliance reach up to €10 million.
For the CIO, this means cybersecurity is no longer a side project pursued alongside daily operations. It is now a board-level responsibility – with personal liability for executives. The February 2026 TI outage – triggered by a smoke alarm in Frankfurt that paralyzed the entire Telematics Infrastructure for eight hours – demonstrates a stark truth: Every new digital interface expands the attack surface.
The strategic CIO treats ePA, EHDS, and NIS2 not as three independent projects – but as a single architecture program with three compliance layers. The synergies are significant:
Shared data layer: FHIR as a unified format serves both ePA connectivity and EHDS cross-border exchange. One format, two regulations.
Shared risk management: NIS2 mandates IT risk management. The AI Act (effective 2027) mandates AI-specific risk management. Both can be integrated into a single ISO 27001 framework – which also satisfies MDR requirements for connected medical devices.
Shared infrastructure: Secure connection to the Telematics Infrastructure (ePA), EHDS gateways, and NIS2 reporting systems can all be built atop the same network architecture. Building three separate infrastructures triples cost and complexity.
The KHZG provided €4.3 billion – but those funds are fully allocated. What comes next – EHDS compliance, NIS2 implementation, AI governance – must be funded from operational budgets. For the CIO, this is a powerful argument for orchestration: an integrated program isn’t just technically elegant – it’s 30-40% less expensive than three parallel standalone projects.
2026: ePA digitalization penalties + NIS2 registration (already due). 2027: AI Act high-risk requirements (August). 2029: EHDS primary use phase – EU-wide exchange of patient summaries. 2031: EHDS expansion to include medical imaging and discharge letters.
Yes – and they should. FHIR as a common data format serves both ePA and EHDS simultaneously. An integrated risk management framework aligned with ISO 27001 covers NIS2, the AI Act, and MDR requirements. Infrastructure for TI connectivity, EHDS gateways, and incident reporting systems can be built jointly.
Fines of up to €10 million. Executive leadership bears personal liability for compliance. Cyber incidents must be reported within 24 hours. The NIS2 Implementation Act has applied without a transition period since 6 December 2025.
16th out of 17 in the Bertelsmann Foundation’s Digital Health Index. According to Black Book Research, only 43% of German institutions are connected to the national Spine (EU average: 58%; Finland: 97%).
Header Image Source: Pexels / Tima Miroshnichenko (px:5726794)