Cybersecurity Standards in Public Health. Regulatory and Systemic Challenges in the Era of Data-driven Healthcare

Authors

  • Agnieszka Jankowska Ministerstwo Cyfryzacji image/svg+xml , Fundacja Digital Poland

DOI:

https://doi.org/10.61823/dpia.2026.2.553

Keywords:

cybersecurity, public health, health data, digital regulation

Abstract

The article examines cybersecurity in public health in the context of the dynamic development of digital technologies and the growing role of health data as a strategic resource. The starting point is the assumption that despite numerous legal regulations, technical standards and guidelines at the national and EU levels, the healthcare system operates in conditions of significant regulatory and organizational fragmentation. The varying levels of digital maturity among healthcare entities, limited financial and human resources and insufficient implementation coordination translate into a fragmented and inconsistent approach to cyber risk management. The article discusses the importance of health data for the innovation and competitiveness of the European Union and identifies key cyber threats in the healthcare sector. The conclusion presents directions for systemic change, pointing to the need for a more integrated regulatory model combining legal, technical and organizational standards with investments in competencies, infrastructure and building institutional resilience.

References

Act of 17 February 2005 on Computerisation of Activities of Entities Performing Public Tasks, Journal of Laws 2024, item 307.

Act of 6 November 2008 on Patients’ Rights and the Patients’ Rights Ombudsman, Journal of Laws 2024, item 581.

Act of 28 April 2011 on the Information System in Healthcare, Journal of Laws 2023, item 2465, as amended.

Act of 5 July 2018 on the National Cybersecurity System, Journal of Laws 2023, item 913, as amended.

Act of 10 May 2018 on the Protection of Personal Data, Journal of Laws 2019, item 1781, as amended.

Centre for e-Health (Centrum e-Zdrowia), VIII Survey on the Level of Digitalisation of Entities Performing Medical Activities, March 2025, https://cez.gov.pl/pl/page/publikacje [accessed on: 08.02.2026]. Code of Conduct for the Health Care Sector adopted pursuant to Article 40 of Regulation (EU) 2016/679, applicable to healthcare providers and data processors, 11 December 2023, https://uodo.gov.pl/pl/file/4525 [accessed on: 06.02.2026].

Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions, European strategy for data, COM/2020/66, Brussels, 19.02.2020.

Council for Digitalisation (Rada do Spraw Cyfryzacji) at the Ministry of Digital Affairs, Statement of the Council for Digitalisation on Cybersecurity in the Healthcare Sector, April 2025, https://www.gov.pl/attachment/cd8ef083-f370-49b7-b7c7-b17c97ebd404 [accessed on: 07.02.2026].

Checkpoint Research, Cybersecurity Report 2026, https://www.checkpoint.com/security-report/ [accessed on: 07.02.2026].

CERT Polska – NASK, Annual Report on the Activities of CERT Polska, April 2023.

CSIRT NASK (CERT Polska), Monthly Summary Report No. 4/2025, December 2025, pp. 5–6.

Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972 and repealing Directive (EU) 2016/1148 (NIS 2 Directive), OJ L 333, 27.12.2022, pp. 80–152. ENISA – European Union Agency for Cybersecurity, “Cyber Hygiene in the Health Sector”, September 2025, https://www.enisa.europa.eu/sites/default/files/2025-09/ENISA%20Cyber%20Hygiene%20in%20the%20Health%20Sector.pdf [accessed on: 06.02.2026].

European Commission, Communication from the Commission to the European Parliament and the Council: European Data Union Strategy – Unlocking Data for Artificial Intelligence, Brussels, 19 November 2025, COM(2025) 835 final, pp. 7–8.

European Commission, Data, https://digital-strategy.ec.europa.eu/en/factpages/data [accessed on: 03.02.2026].

International Data Corporation, https://www.businesswire.com/news/home/20200513005075/en/IDCs-Global-StorageSphere-Forecast-Shows-Continued-Strong-Growth-in-the-Worlds-Installed-Base-of-Storage-Capacity [accessed on: 02.02.2026].

Implementing the European Health Data Space across Europe, eitHealth Think Tank, https://eithealth.eu/wp-content/uploads/2024/04/EIT_Health_ThinkTank_Implementing_the_EHDS_across_Europe_23.04.24.pdf, April 2024 [accessed on: 07.02.2026].

Regulation (EU) 2025/327 of the European Parliament and of the Council of 11 February 2025 on the European Health Data Space and amending Directive 2011/24/EU and Regulation (EU) 2024/2847, https://eur-lex.europa.eu/eli/reg/2025/327/oj/eng [accessed on: 07.02.2026].

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), OJ L 119, 4 May 2016, p. 1, as amended. Regulation of the Council of Ministers of 21 May 2024 on the National Interoperability Framework, minimum requirements for public registers and electronic information exchange, and minimum requirements for ICT systems, Journal of Laws 2024, item 773.

Regulation of the Minister of Health of 6 April 2020 on the types, scope and models of medical documentation and the manner of its processing, Journal of Laws 2024, item 798.

Statista Global Data Platform, https://www.statista.com/statistics/871513/worldwide-data-created/ [accessed on: 01.02.2026].

TechSci Research LLC, https://www.techsciresearch.com/report/big-data-in-healthcare-market/4009.html [accessed on: 02.02.2026].

J. Thomason, “Data, Digital Worlds, and the Avatarization of Health Care”, Global Health Journal, Vol. 8, Issue 1, March 2024, pp. 1–3. https://www.cez.gov.pl/pl/page/o-nas/aktualnosci/csirt-cez-ostrzega-wzrasta-liczba-incydentow-cyberbezpieczenstwa-w-ochronie-zdrowia [accessed on: 28.01.2026].

https://commission.europa.eu/topics/digital-economy-and-society/cybersecurity-healthcare_pl [accessed on: 07.02.2026].

https://www.totalassure.com/blog/average-time-to-detect-cyber-attack-2025 [accessed on: 07.02.2026].

2025 Data Breach Investigations Report, Healthcare Snapshot, https://www.verizon.com/business/resources/infographics/2025-dbir-healthcare-snapshot.pdf [accessed on: 07.02.2026].

European Commission, The Impact of the European Health Data Space Regulation and the Open Data Directive on Citizens, data.europa.eu, Publications Office of the European Union, July 2025.

Kaźmierczyk P., Lukosek D., Czarnuch M., Horyń A., Medical Data in Physicians’ Practice: Current State and Desired Changes, Report of the Network of Physician Innovators, Supreme Medical Chamber, 2023.

Ryś A., “European Health Data Space – New Challenges and Opportunities”, Med. Prakt., 2025, no. 3, pp. 110–119.

Downloads

Published

2026-09-09

How to Cite

Cybersecurity Standards in Public Health. Regulatory and Systemic Challenges in the Era of Data-driven Healthcare. (2026). Discourse of Law and Administration, 2, 65-85. https://doi.org/10.61823/dpia.2026.2.553