HEALTH-ER

The framework

An AI-based SOC-as-a-Service, built for the clinical environment

Traditional SOC systems focus purely on the IT perspective and miss the context of healthcare. HEALTH-ER runs either as a complete SOCaaS or as a complementary layer over the tools a hospital already has, with patient-safety logic built into the security picture.

HEALTH-ER operates either as a complete SOC-as-a-Service or as a complementary security layer on top of the tools a hospital already runs. Four technical blocks feed the SOCaaS, and a set of preparedness and assessment services surrounds it.

Capability blocks

Four blocks feeding one platform

Situational awareness and orchestration together form the SOCaaS itself. Information exchange connects it outward to the sector. Capacity building addresses the factor that no platform can patch: people.

Block 01

AI-based Situational Awareness & Prediction

Continuous analysis of system and user behaviour across hospital IT, medical devices and OT, turning raw telemetry into prioritised, explainable risk.

PreventDetect

Components

  • Cyber risk assessment and prioritisation

    Comprehensive risk assessment, proactive defence against emerging threats, and effective prioritisation and risk treatment, with customised long-term protection.

  • AI-based attack prediction for medical and IoT devices

    Ad-hoc behavioural models trained per system deliver an estimated probability that a device is behaving incorrectly, which may be an early warning of an attack. Because the models learn normal operation rather than parse protocols, they are unaffected by the diversity of medical device architectures and data formats.

  • User and entity behaviour analytics (UEBA)

    Machine learning builds a baseline of normal behaviour for users such as doctors, nurses and administrative staff, and for entities such as infusion pumps, EHR systems and IoT devices, then flags deviations such as unusual logins or unauthorised access to patient records. This matters in healthcare, where insider risk, compromised accounts and lateral movement bypass perimeter defences.

  • CTI-driven threat hunting

    Rather than relying solely on automated alerts, analysts use intelligence-driven hypotheses to actively search for anomalies and stealthy mechanisms, informed by attacker tactics, techniques and procedures, indicators of compromise and emerging vulnerabilities.

Block 02

Intelligent Orchestration, Automation & Response

Coordinated, partly automated response that keeps clinical services running, built on playbooks that can be shared between hospitals.

Respond & RecoverDeter

Components

  • Adaptive SOAR

    The core component for active protection: a central provisioning layer that coordinates security operations and service delivery, evolving the SOCaaS into a unified cyber operations and service provisioning fabric able to analyse many different environments.

  • Incident response and business continuity playbooks

    OASIS CACAO

    Standardised playbooks for the healthcare sector covering proactive actions triggered by predictive maintenance or attack prediction, and reactive actions to detected incidents, so that business processes are not disrupted.

Block 03

Information Exchange

Turning one hospital’s lesson into the sector’s defence, and meeting the reporting duties that come with NIS2.

DetectDeter

Components

  • EU-compliant reporting

    NIS2, Cyber Solidarity Act

    Standardised reporting processes and templates that let healthcare providers notify incidents, vulnerabilities and breaches in a timely and secure manner, supporting cross-border cooperation and trust between hospitals, national authorities and EU institutions.

  • CTI sharing

    STIX, TAXII

    Aggregating and analysing intelligence from consortium members and trusted sources such as ENISA, national CSIRTs and healthcare CERTs, so hospitals move from reactive to proactive defence.

  • Collaborative threat hunting

    Intelligence-driven hypotheses and shared playbooks let security teams detect what automated defences miss, and transfer lessons learned from one institution across the EU healthcare ecosystem, reducing dwell time at scale.

Block 04

Cyber Ranges, Knowledge & Capacity Building

The human factor: realistic exercises and role-specific training for clinical, technical and management staff.

PreventDetectRespond & RecoverDeter

Components

  • Cyber ranges

    Realistic scenarios such as ransomware outbreaks or attacks on connected medical equipment help IT teams and clinical staff identify, respond and recover faster. Incident response and business continuity playbooks can also be rehearsed in these environments.

  • Education and training

    From general cyber hygiene for healthcare professionals to advanced courses for security experts, plus material and guidelines on EU policies and regulations. Four full-day training sessions run at the pilot sites for pilot personnel.

  • Consulting services and mentoring

    Matching the real problems faced by healthcare providers and SMEs with the right expertise, plus advisory services connecting authorities and policy makers with providers, researchers and industry. A dedicated helpdesk operates at HOPE premises.

  • Awareness and knowledge transfer

    Activities that engage stakeholders across government, policy, academia, industry and civil society, promoting understanding of healthcare cybersecurity and generating demand for the technologies developed.

Preparedness and assessment

The services around the platform

Technology alone does not make a hospital resilient. These services wrap the SOCaaS and are available independently of it.

Cybersecurity maturity and risk assessment

Establish the baseline: digital maturity, existing tools and processes, security controls, staff awareness and regulatory compliance, across large hospitals, small providers and private clinics alike.

Penetration testing

Test the capacity to withstand cyber incidents while maintaining uninterrupted healthcare services, including resilience benchmarks and business continuity drills.

Compliance, policy and certification

Navigate NIS2, GDPR, the Medical Device Regulation, the Cybersecurity Act and the Cyber Resilience Act, with support for ISO/IEC 27001, 27701, 27799:2016 and 80001.

Supply-chain assessment

Methodologies for supply-chain risk assessment, vendor auditing and certification-based assurance, helping hospitals avoid long-term dependency on a limited number of providers.

Technical plans and roadmaps

Structured, practical roadmaps setting out the architecture, tools, processes and resources needed, tailored to the operational, financial and regulatory context of each provider.

Cost-benefit analysis

Capital and operational expenditure, return on investment, and avoided costs from reduced incidents, downtime and breaches, to build the business case for sustained investment.

Training and capacity building

Cyber-hygiene courses, cyber-range exercises, workshops and mentoring for technical, clinical and management personnel.

Threat intelligence and collaborative defence

Integration with trusted CTI sources, standards-based exchange and CTI-driven threat hunting to improve situational awareness across the sector.

Standards and regulation

Designed against the rules hospitals are actually held to

Compliance is not a separate workstream bolted on at the end. The framework's reporting, exchange formats and playbooks are built on the standards and regulations below.

  • NIS2 DirectiveHealthcare designated a sector of high criticality; multi-stage incident reporting.
  • GDPRProtection of patient data throughout the framework.
  • Medical Device Regulation (MDR)Security of connected medical devices.
  • Cyber Resilience Act (CRA)Product security requirements and certification pathways.
  • Cybersecurity Act (CSA)EU certification schemes.
  • Cyber Solidarity ActCyber reserve and early-warning system.
  • European Health Data Space (EHDS)Secure infrastructure for health data exchange.
  • OASIS CACAOStandardised, shareable incident-response playbooks.
  • STIX / TAXIIStructured threat intelligence exchange.
  • ISO/IEC 27001, 27701, 27799, 80001Information security and health informatics management.

Want to try this in your own environment?

The Open Pilot gives European healthcare providers access to the tools, services and methodologies described on this page.

Join the Open Pilot