HEALTH-ER

The project

Cybersecurity that understands what a hospital is

HEALTH-ER moves healthcare organisations from fragmented and reactive IT security towards proactive, measurable and patient-safety-aware cyber resilience, across the full lifecycle of preparedness, detection, response, recovery and continuous improvement.

months
24Jun 2026 – May 2028
partners
126 Member States
total budget
€10.0M€5.0M EU grant
person-months
1,533across six work packages

The problem

A sector of high criticality, under pressure

The European healthcare sector is designated a sector of high criticality under the NIS2 Directive. Healthcare entities depend increasingly on electronic health records, telemedicine platforms, connected medical devices and AI-enabled diagnostic tools. That transformation improves efficiency and quality of care and simultaneously heightens exposure to ransomware, phishing and the exploitation of system vulnerabilities.

The 309 significant incidents reported in 2023 are a stark reminder of that exposure, with ransomware attacks alone projected to cost €250 billion annually by 2031. Unlike other sectors, cyberattacks in healthcare can have immediate and fatal consequences, as the attack on Düsseldorf University Hospital demonstrated.

A resilient and secure digital infrastructure is also a precondition for European strategic initiatives such as Health Technology Assessment, the EU Health Hub and the European Health Data Space.

The EU Action Plan on Cybersecurity of Hospitals

Launched by the European Commission in January 2025, and implemented with Member States, healthcare providers and the cybersecurity community. HEALTH-ER covers all four pillars.

  • PreventPreparedness, systematic risk assessment, procurement guidance, supply-chain risk management and tailored training for healthcare professionals.
  • DetectAdvanced monitoring, AI-enhanced detection and an EU-wide early-warning capability for the healthcare sector.
  • Respond & RecoverIncident-response playbooks, business-continuity plans, CSIRT support and cyber-range exercises to contain and recover from attacks.
  • DeterCompliance with NIS2 and GDPR, certification pathways, incident and ransom-payment reporting, and sector-wide deterrence measures.

The vision

“Delivered as a scalable and accessible service, the AI-based SOCaaS will democratise access to elite cybersecurity capabilities — making them available not only to large university hospitals, but also to the smaller regional clinics and specialised providers who form the backbone of European healthcare.”

Objectives

Five objectives, measured against agreed indicators

Each objective in the Grant Agreement carries its own KPIs. Progress against them is reported at month 12 and month 24, and tracked publicly on the impact page.

  1. 1PreventRespond & Recover

    Understand where European healthcare actually stands

    Establish a baseline of cybersecurity posture across EU healthcare providers — digital maturity, existing tools, security controls, staff awareness and regulatory compliance — then map the common needs and turn them into technical plans that are costed, actionable and tailored to the size and resources of each provider.

    Key indicators

    • Technical plans implemented for pilots: ≥ 4
    • Improvement in incident response and business continuity: ≥ 30%
    • Benefit-to-cost ratio of HEALTH-ER solutions: ≥ 20%
  2. 2PreventDetectRespond & RecoverDeter

    Build an AI-based framework hospitals can actually afford to run

    Deploy a SOC-as-a-Service tailored to healthcare, orchestrating AI modules for anomaly detection, behaviour analytics and attack prediction, with SOAR and standardised CACAO playbooks. It runs as a complete solution or as a complementary layer over existing tools, so smaller providers get capabilities previously reserved for large university hospitals.

    Key indicators

    • Cybersecurity tools deployed: ≥ 15
    • CACAO playbooks: ≥ 8
    • CTI sources integrated: ≥ 10
    • Tools and practices adopted in healthcare institutions: ≥ 25
  3. 3PreventDetectRespond & RecoverDeter

    Take the human factor seriously

    Cyber-hygiene training for healthcare professionals, advanced courses for security experts, cyber-range exercises using realistic ransomware and medical-device scenarios, plus consulting, mentoring and awareness activities — delivered through the EU-INSPIRE Centre of Excellence, HOPE and the Cyprus Organisation for Standardisation.

    Key indicators

    • Dedicated healthcare training courses: ≥ 15
    • Full-day training sessions: 4
    • Workshops: 3 · Information days: ≥ 3
  4. 4PreventDetectRespond & RecoverDeter

    Validate it in real hospitals, not in a lab

    Two internal hospital pilots in Luxembourg and Estonia covering nine operational use cases, plus an EU-wide Open Pilot engaging at least fifteen external providers across at least six countries. Validation covers technical soundness, operational readiness and compliance with NIS2, GDPR, the MDR and the Cybersecurity Act.

    Key indicators

    • Pilot demo installations: 2 EU hospitals
    • Open Pilot providers: ≥ 15 across ≥ 6 countries
    • Operational scenarios: ≥ 9
    • Validation rounds: 2 (MVP and prototype)
  5. 5Deter

    Make sure it outlives the grant

    Engage the EU healthcare industry, policy makers and regulators throughout, contribute to standardisation, and build the exploitation and sustainability plan that keeps the tools, services and training available after the project ends.

    Key indicators

    • Policy-making bodies engaged: ≥ 3
    • Similarly themed projects identified: > 6
    • Jointly organised workshops: > 2

Who HEALTH-ER supports

Four audiences, different needs

Healthcare providers

Hospitals, regional providers, clinics and specialised organisations that need scalable protection adapted to their size, maturity and operational constraints.

Healthcare IT and security teams

Technical staff needing better visibility, threat prioritisation, coordinated incident response and support for medical-device, IoMT and OT environments.

Clinical and non-technical staff

Personnel who need practical cyber-hygiene, awareness and role-specific training that does not disrupt clinical workflows.

Authorities and decision makers

Organisations that require structured evidence, compliance support, incident reporting and lessons from real healthcare deployments.

At a glance

Grant Agreement facts

Project number
101299528
Full name
HEALTHcare cybersecurity framework for Enhanced preparedness and Resilience
Call
DIGITAL-ECCC-2025-DEPLOY-CYBER-08
Topic
DIGITAL-ECCC-2025-DEPLOY-CYBER-08-CYBERHEALTH
Type of action
DIGITAL JU Simple Grants
Granting authority
European Cybersecurity Industrial, Technology and Research Competence Centre (ECCC)
Coordinator
OBRELA Security Industries
Start date
1 June 2026
End date
31 May 2028
Total eligible costs
€9,988,683.26
Maximum EU grant
€4,994,341.63 (50%)

Explore further

The technical detail, the plan of work and the people behind it.