The project
Cybersecurity that understands what a hospital is
HEALTH-ER moves healthcare organisations from fragmented and reactive IT security towards proactive, measurable and patient-safety-aware cyber resilience, across the full lifecycle of preparedness, detection, response, recovery and continuous improvement.
- months
- 24Jun 2026 – May 2028
- partners
- 126 Member States
- total budget
- €10.0M€5.0M EU grant
- person-months
- 1,533across six work packages
The problem
A sector of high criticality, under pressure
The European healthcare sector is designated a sector of high criticality under the NIS2 Directive. Healthcare entities depend increasingly on electronic health records, telemedicine platforms, connected medical devices and AI-enabled diagnostic tools. That transformation improves efficiency and quality of care and simultaneously heightens exposure to ransomware, phishing and the exploitation of system vulnerabilities.
The 309 significant incidents reported in 2023 are a stark reminder of that exposure, with ransomware attacks alone projected to cost €250 billion annually by 2031. Unlike other sectors, cyberattacks in healthcare can have immediate and fatal consequences, as the attack on Düsseldorf University Hospital demonstrated.
A resilient and secure digital infrastructure is also a precondition for European strategic initiatives such as Health Technology Assessment, the EU Health Hub and the European Health Data Space.
The EU Action Plan on Cybersecurity of Hospitals
Launched by the European Commission in January 2025, and implemented with Member States, healthcare providers and the cybersecurity community. HEALTH-ER covers all four pillars.
- PreventPreparedness, systematic risk assessment, procurement guidance, supply-chain risk management and tailored training for healthcare professionals.
- DetectAdvanced monitoring, AI-enhanced detection and an EU-wide early-warning capability for the healthcare sector.
- Respond & RecoverIncident-response playbooks, business-continuity plans, CSIRT support and cyber-range exercises to contain and recover from attacks.
- DeterCompliance with NIS2 and GDPR, certification pathways, incident and ransom-payment reporting, and sector-wide deterrence measures.
The vision
“Delivered as a scalable and accessible service, the AI-based SOCaaS will democratise access to elite cybersecurity capabilities — making them available not only to large university hospitals, but also to the smaller regional clinics and specialised providers who form the backbone of European healthcare.”
Objectives
Five objectives, measured against agreed indicators
Each objective in the Grant Agreement carries its own KPIs. Progress against them is reported at month 12 and month 24, and tracked publicly on the impact page.
- 1PreventRespond & Recover
Understand where European healthcare actually stands
Establish a baseline of cybersecurity posture across EU healthcare providers — digital maturity, existing tools, security controls, staff awareness and regulatory compliance — then map the common needs and turn them into technical plans that are costed, actionable and tailored to the size and resources of each provider.
Key indicators
- Technical plans implemented for pilots: ≥ 4
- Improvement in incident response and business continuity: ≥ 30%
- Benefit-to-cost ratio of HEALTH-ER solutions: ≥ 20%
- 2PreventDetectRespond & RecoverDeter
Build an AI-based framework hospitals can actually afford to run
Deploy a SOC-as-a-Service tailored to healthcare, orchestrating AI modules for anomaly detection, behaviour analytics and attack prediction, with SOAR and standardised CACAO playbooks. It runs as a complete solution or as a complementary layer over existing tools, so smaller providers get capabilities previously reserved for large university hospitals.
Key indicators
- Cybersecurity tools deployed: ≥ 15
- CACAO playbooks: ≥ 8
- CTI sources integrated: ≥ 10
- Tools and practices adopted in healthcare institutions: ≥ 25
- 3PreventDetectRespond & RecoverDeter
Take the human factor seriously
Cyber-hygiene training for healthcare professionals, advanced courses for security experts, cyber-range exercises using realistic ransomware and medical-device scenarios, plus consulting, mentoring and awareness activities — delivered through the EU-INSPIRE Centre of Excellence, HOPE and the Cyprus Organisation for Standardisation.
Key indicators
- Dedicated healthcare training courses: ≥ 15
- Full-day training sessions: 4
- Workshops: 3 · Information days: ≥ 3
- 4PreventDetectRespond & RecoverDeter
Validate it in real hospitals, not in a lab
Two internal hospital pilots in Luxembourg and Estonia covering nine operational use cases, plus an EU-wide Open Pilot engaging at least fifteen external providers across at least six countries. Validation covers technical soundness, operational readiness and compliance with NIS2, GDPR, the MDR and the Cybersecurity Act.
Key indicators
- Pilot demo installations: 2 EU hospitals
- Open Pilot providers: ≥ 15 across ≥ 6 countries
- Operational scenarios: ≥ 9
- Validation rounds: 2 (MVP and prototype)
- 5Deter
Make sure it outlives the grant
Engage the EU healthcare industry, policy makers and regulators throughout, contribute to standardisation, and build the exploitation and sustainability plan that keeps the tools, services and training available after the project ends.
Key indicators
- Policy-making bodies engaged: ≥ 3
- Similarly themed projects identified: > 6
- Jointly organised workshops: > 2
Who HEALTH-ER supports
Four audiences, different needs
Healthcare providers
Hospitals, regional providers, clinics and specialised organisations that need scalable protection adapted to their size, maturity and operational constraints.
Healthcare IT and security teams
Technical staff needing better visibility, threat prioritisation, coordinated incident response and support for medical-device, IoMT and OT environments.
Clinical and non-technical staff
Personnel who need practical cyber-hygiene, awareness and role-specific training that does not disrupt clinical workflows.
Authorities and decision makers
Organisations that require structured evidence, compliance support, incident reporting and lessons from real healthcare deployments.
At a glance
Grant Agreement facts
- Project number
- 101299528
- Full name
- HEALTHcare cybersecurity framework for Enhanced preparedness and Resilience
- Call
- DIGITAL-ECCC-2025-DEPLOY-CYBER-08
- Topic
- DIGITAL-ECCC-2025-DEPLOY-CYBER-08-CYBERHEALTH
- Type of action
- DIGITAL JU Simple Grants
- Granting authority
- European Cybersecurity Industrial, Technology and Research Competence Centre (ECCC)
- Coordinator
- OBRELA Security Industries
- Start date
- 1 June 2026
- End date
- 31 May 2028
- Total eligible costs
- €9,988,683.26
- Maximum EU grant
- €4,994,341.63 (50%)
Explore further
The technical detail, the plan of work and the people behind it.
