NIS2 for medical care centers and practice networks: obligations, thresholds, roadmap
Around 1,000 medical care centers (MVZ) have been subject to NIS2 for the first time since 2026. Thresholds, obligations under Section 30 BSIG, managing director liability, reporting requirements — and an 8-week roadmap for outpatient structures.

NIS2 for Medical Centers and Practice Networks: Who is affected and what needs to be done by when
The German NIS2 Implementation Act (NIS2UmsuCG) has been in force since December 6, 2025. For hospitals, cybersecurity is nothing new as a mandatory discipline — CRITIS hospitals have been working with the sector-specific security standard B3S for years, and larger clinics have ISMS and CISO roles in place. For outpatient structures, the situation is different: estimates from the draft bill for the NIS2UmsuCG assume that around 1,000 Medical Centers (MVZs) will fall directly under the scope for the first time — and thus under a regime of obligations that did not previously exist in this form.
This guide is intended for managing directors, IT managers, and data protection officers in MVZs and practice networks. The goal: clarity on whether your facility is affected, what the obligations specifically mean, and which order of implementation makes sense — without bloating the project into an 18-month hanging game.
An important classification upfront: NIS2 does not turn outpatient medical centers into small hospitals. Most technical and organizational requirements can be met in an operationally leaner way than in a CRITIS clinic. But: The ten-measure catalog according to § 30 BSIG, the reporting obligations according to § 32 BSIG, and the personal liability of the management according to § 38 BSIG apply unchanged. Anyone standing here in 2026 without preparation has both an operational and a legal problem.
Who is affected? Thresholds and Classification
NIS2 distinguishes between two categories of obligated entities — both are relevant for MVZs and practice networks:
Important Entity: medium-sized enterprise according to the EU SME definition (50–249 employees, with turnover up to €50 million or balance sheet total up to €43 million) in a NIS2 sector. Maximum fine: €7 million or 1.4% of global annual turnover (whichever is higher).
Essential Entity: large enterprise (at least 250 employees or more than €50 million turnover and more than €43 million balance sheet total) in a NIS2 sector. Maximum fine: €10 million or 2%.
Concrete examples from MVZ practice:
MVZ with three locations and 60 full-time plus 15 part-time staff: important entity. Employees are counted in heads — 75 people, clearly above the 50-threshold.
Practice network with 220 employees and €28 million turnover: important entity — the employee threshold is in the medium range, as is the turnover.
Hospital group with an MVZ subsidiary: Here it becomes differentiated. If the MVZ is legally organized as its own GmbH, its own key figures count. If it is an integrated part of a NIS2-obligated clinic, it is covered through the parent group.
Large-scale MVZ with hospital-like structures (laboratory, imaging, surgical wing): regardless of the number of employees, potentially classified as a "practice with data processing on a substantial scale" — this definition comes from § 75b SGB V (now § 390 SGB V) and is a strong indicator for NIS2 classification.
Anyone unsure if the classification applies can use the official BSI NIS2 affectedness test. It guides you through the threshold logic and provides an initial assessment. Faster and tailored specifically to the healthcare sector: our NIS2 Affectedness Check - 3-4 questions, instant result. In cases of doubt, legal clarification is recommended — the classification directly impacts the level of fines and supervisory intensity.
Important: Self-classification is mandatory. No one will be written to by the BSI and politely asked if they are affected. Anyone who does not register themselves risks not only the fine in the event of a later incident — the management will stand there in the event of an incident without a documented safety shield regarding personal liability under § 38 BSIG.
§ 75b SGB V (§ 390 SGB V) and NIS2 — Not an Either-Or
The biggest misunderstanding in advisory practice in 2026: "We have implemented the KBV IT Security Guideline — surely that's enough for NIS2." It is not enough.
The IT Security Guideline according to § 75b SGB V (anchored in § 390 SGB V since October 2025) has applied to all contract medical and contract psychotherapeutic practices since January 1, 2021. It distinguishes between three practice sizes — small, medium, and large practices — as well as special cases for large-scale medical equipment and data processing on a substantial scale. The guideline is structured like an operational catalog of measures: specific technical and organizational measures per practice size, with template texts and checklists from the KBV.
NIS2 (implemented by the BSIG in the new version) is structured more generically. The law defines ten risk management areas (§ 30 BSIG), a three-stage reporting obligation (§ 32 BSIG), and personal obligations of the management (§ 38 BSIG). The law leaves the level of detail of the implementation to the facility — state of the art is the measure.
Practically, three constellations arise for a NIS2-obligated MVZ:
1. Identical requirements. Backup, virus protection, multi-factor authentication, network separation, access management — what the KBV guideline already requires is also covered by NIS2. Anyone who has cleanly implemented § 75b/§ 390 SGB V already has 60 to 70 percent of the basic NIS2 measures.
2. NIS2 gaps compared to the KBV guideline. The KBV guideline does not know a three-stage reporting system with a 24-hour early warning. It does not anchor personal managing director liability with a training obligation. It does not require BSI registration. It does not mandate systematic supplier management. It does not define fines in the millions.
3. KBV requirements that NIS2 does not have in this depth. The specific specifications for the telematics infrastructure, large-scale medical equipment, and patient data protection are formulated more concretely in the KBV guideline. Anyone setting up a NIS2 compliance project should not throw the KBV guideline overboard — but rather maintain both sets of regulations in parallel.
The pragmatic consequence: A common information security policy as a bracket, an operational catalog of measures based on § 75b/§ 390 SGB V, and a NIS2-specific supplementary document for the gaps (reporting system, supply chain, proof of managing director training, registration).
The Ten Obligations Under § 30 BSIG — Translated for MVZs
§ 30 BSIG lists ten mandatory risk management areas. In MVZ language:
Risk Analysis and Security Concept. Which systems process which data? Where are the critical points? A one-page risk register with 15 to 25 risks is sufficient for a start.
Handling of Security Incidents. Who is alerted when? Who decides on system separation? Which authorities are informed? A two-page incident response plan is mandatory.
Business Continuity. If the practice management system or the connector fails — how does patient care continue? Manual forms, emergency telephone list, alternative pathways for findings.
Supply Chain Security. Which IT service providers have access to patient data? Connector providers, PMS manufacturers, MFA maintenance companies. AVV according to Art. 28 GDPR is mandatory, supplemented by concrete security agreements and a minimum level of audit rights.
Security in Acquisition, Development, and Maintenance. Patch management, vulnerability handling, secure configuration of new acquisitions. This is where the biggest gap lies in many MVZs — no one feels structurally responsible.
Assessing the Effectiveness of Measures. Does what you have set up actually work? Quarterly internal reviews, annual testing of critical systems.
Cyber Hygiene and Training. Phishing awareness is explicitly anchored here. The workforce must be trained regularly, and the training sessions must be documented. Art. 21 para. 2(g) of the NIS2 Directive explicitly requires this.
Cryptography. Encryption in transit (TLS), at-rest (hard drives, backups), for email communication involving patient data. KIM and ePA bring parts of this, but not the entire spectrum.
Personnel Security, Access Control, and Asset Management. Who has which system access? Are permissions revoked when an employee leaves? Does a complete inventory of the systems used exist?
Multi-Factor Authentication and Secured Voice and Video Communications. MFA for all administrative accounts and remote access is the single most effective measure. Period.
In practice, points 1, 2, 5, and 7 are the most common vulnerabilities — this is where the implementation focus should lie.
Specific Risks in MVZ Structures
MVZs have a different threat landscape than acute care clinics. Four recurring patterns:
Telematics Infrastructure as an Attack Vector. KIM, ePA, e-prescription, and eAU run via connectors and gematik components. These are generally certified — but local access to them (PMS workstations, smartcards, eHBA) is not automatically. A successful phishing attack on an MFA employee can lead to manipulated e-prescription issues or unauthorized ePA access.
Distributed Locations with Centralized IT. Practice networks with three or more locations often run a centralized server infrastructure — VPN connections, shared Active Directory, split backup strategy. If the central server is compromised, all locations are affected. This is not hypothetical — the cyberattack on the Tirschenreuth/Kemnath MVZ in autumn 2025 followed exactly this pattern and led to the temporary closure of both locations.
High Staff Fluctuation, Many End Devices. In the outpatient sector, nursing staff, MFAs, and medical staff change more frequently than in hospital structures. Onboarding and offboarding are often not systematized on the IT side — former employees retain system access for weeks or months. Tablets, smartphones, and mobile devices additionally expand the attack surface.
Billing as an Economic Target. Outpatient structures are attractive for targeted CEO fraud attacks and manipulated invoices — the flow of money is easier to hijack compared to a clinic. A medium-sized MVZ chain with five locations quickly processes seven-figure monthly reimbursements.
Reporting System Under § 32 BSIG — 24/72/30 in Practice
§ 32 BSIG prescribes a three-stage reporting obligation:
Initial report within 24 hours of becoming aware of the significant security incident: a brief description of the incident, affected systems, suspected origin.
Assessment report within 72 hours: detailed assessment of the impact, measures taken, severity classification.
Final report after one month: complete analysis, cause, consequences, lessons learned, and adjustments to the security concept.
The report is made via the BSI reporting portal, which is accessed via the "Mein-Unternehmenskonto" (MUK) business account. Both registration and incident reports are handled there.
Operationally, this means three preparation points for an MVZ:
1. Set up the MUK account before the first incident occurs. Anyone who has to organize access data in a crisis loses hours. Access should be stored with the management and IT manager, with clearly defined deputies.
2. Document the escalation chain. Who triggers the report in the event of an incident should be clear beforehand. Typical chain: IT lead detects → management decides → data protection officer checks the GDPR reporting obligation in parallel.
3. Keep templates ready for the three reports. The 24-hour initial report often happens in crisis mode. A prepared text template, where only case-specific details need to be inserted, saves time and reduces errors.
Important: The NIS2 report does not replace the GDPR reporting obligation under Art. 33 GDPR in the event of patient data loss. In classic ransomware incidents, both reporting channels must be activated simultaneously — the BSI portal according to § 32 BSIG, and the responsible data protection supervisory authority according to GDPR.
§ 38 BSIG — Personal Liability of the Management
Perhaps the most uncomfortable part of NIS2: The management is personally liable for the implementation and compliance with the risk management measures. The BSIG explicitly anchors in § 38:
The management must monitor the implementation of the § 30 measures.
The management must regularly participate in cybersecurity training.
In the event of a breach of duty, the management is personally liable for damages.
The law leaves open the format and frequency of "regularly". An annual documented training session with an agenda and proof of attendance has proven effective, supplemented by written quarterly reports on the security situation.
In MVZ structures with multiple managing directors, the obligation applies to all of them. Delegation "to IT" is legally not possible — operational responsibility can be transferred, but the obligation to supervise and monitor cannot.
8-Week Roadmap for a Typical MVZ
In practice, the following workflow has proven effective — more compact than the hospital roadmap because outpatient structures are generally less complex and less frequently run several hundred care-critical systems in parallel.
Weeks 1 to 2: Inventory. Scope clarification (which locations, which subsidiaries, which practice areas), asset inventory (servers, workstations, connectors, mobile devices), supplier mapping (PMS manufacturers, IT service providers, cloud providers). A simple Excel sheet is sufficient — completeness is what matters.
Weeks 3 to 4: Quick Wins. MFA on all administrative accounts (Active Directory, PMS, backup system, VPN, RDP, Microsoft 365). Check backup strategy for 3-2-1 compliance, with at least one copy offline or immutable. Phishing awareness kick-off for the entire workforce — a brief kick-off format with documentation.
Weeks 5 to 6: Establish Documentation. Information security policy as a common bracket for § 75b/§ 390 SGB V and NIS2. Risk register with 15 to 25 risks. Emergency plan covering two pages. Supplier register with AVV status and risk assessment. Incident response flowchart with escalation chain and reporting templates.
Week 7: Management Training. Documented meeting on the cybersecurity situation, introduction to the obligations under § 38 BSIG, overview of the security concept. With agenda and list of participants filed for the records.
Week 8: Registration with the BSI. Via the "Mein-Unternehmenskonto" (MUK) business account, with master data, classification, and 24/7 contact point. With good preparation, the portal process takes 30 to 60 minutes.
Thereafter: No project phase is ever "finished". Quarterly updates of the risk register and emergency plan, annual phishing simulation, tabletop exercises at least once a year, and bi-annual external assessment of the measures.
Common Pitfalls
"Our IT service provider takes care of everything." This is not a NIS2-compliant answer. Responsibility cannot be outsourced — the provider implements measures, but oversight, risk assessment, and managing director liability remain with the MVZ.
"We'll wait and see if the BSI audits us." Fines do not just apply during BSI audits, but in the event of incidents without documented security measures. And in an incident, the 24/72/30-hour deadlines are relentless.
"Phishing simulation? The works council won't agree to that." Correct — and that is also true in MVZ structures. But with a clean works agreement that clearly regulates anonymization, purpose, and the ban on using it for personnel measures, co-determination is not a stopper, but an accelerator.
"We do the documentation first, then the measures." Wrong way around. Documentation arises from lived practice — implement measures, document them in the process, then condense them into a quarterly structure.
Conclusion
NIS2 for MVZs and practice networks is no longer an option in 2026, but a mandatory requirement. Operational implementation is doable — eight weeks are enough for a solid basic framework if scope, prioritization, and resource allocation are right from the start.
The biggest levers: MFA on all administrative accounts, a documented emergency plan, a well-thought-out supplier list, and annual training for management with proof. Much of the rest follows from the already implemented KBV IT Security Guideline according to § 75b/§ 390 SGB V.
Where things typically stall: Supplier management (often completely unorganized), awareness programs (rarely run systematically), and the reporting system with 24-hour logic (rarely set up). This is exactly where Managed Services for Phishing Simulation, Awareness Training, Vulnerability Management, and Incident Detection & Response come in — they deliver the operational modules that § 30 BSIG requires, without the MVZ needing to build its own security team.
At Entropy CS, we support MVZs and practice networks with exactly these Managed Services — the operational pillars of NIS2-compliant security work. Our free Risk Assessment takes 30 minutes and provides an honest baseline assessment for your facility — including concrete next steps.


