We don't talk. We execute.
Supply Chain News

EU regulation changes hospital procurement

EU regulation forces hospitals to redesign procurement and supply chains

Symbolic image

New EU laws (EHDS, NIS-2, AI Regulation, and CRA) are completely changing the rules for IT procurement in hospitals. Those purchasing new systems must consider data protection, IT security, and legal compliance from the outset. This transforms procurement from a simple ordering department into a decisive pacesetter for legal certainty in everyday hospital life.

The key facts at a glance:

 

  • EHDS & MyHealth@EU: Uniform EU standards oblige clinics to make systems fit for cross-border data exchange.
  • NIS2 Directive: Almost all hospitals will have to prove cybersecurity – not just in-house, but also with external service providers and software vendors.
  • AI Regulation: Medical AI is almost always counted as a high-risk technology. This brings strict control and documentation obligations for operators.
  • Cyber Resilience Act (CRA): Manufacturers must guarantee security updates. Hospitals must make this a mandatory requirement before purchase.
  • Rethinking procurement: Legal and IT must be involved early on, suppliers thoroughly vetted and contracts secured long-term.

European regulations require hospitals to have a data room and cybersecurity.

According to the information in the text, the European Health Data Space (EHDS) will finally create binding rules for the exchange of health data in the EU. For hospitals, this means in concrete terms: their IT must seamlessly interact with European data networks such as MyHealth@EU in the future and fulfil strict requirements for access protection and data formats.

In parallel, the NIS 2 Directive is tightening the screws on IT security. According to the press release, this will affect almost every hospital in the future, regardless of its size. Cybersecurity is thus becoming a top priority and an organisational obligation. Particularly sensitive: The responsibility does not end at one's own doorstep but includes the entire digital supply chain – from software providers to external service providers.

Strict requirements for artificial intelligence and digital products

According to the arguments in the contribution, the EU AI Regulation generally classifies medical AI systems as high-risk applications. For hospitals, this means they are no longer just users, but are responsible as operators. They must ensure transparency, data quality, and human oversight during ongoing operations. Simply put, only products that are fully certified may be purchased.

In addition, the Cyber Resilience Act (CRA) places obligations on hardware and software manufacturers. According to the press release, providers must supply their products with security updates throughout their entire lifecycle. Buyers in hospitals must therefore carefully examine whether a supplier can handle these ongoing tasks even before a contract is concluded, in order to avoid later liability pitfalls.

Clinic purchasing as a new strategic management tool

To manage this rulebook in everyday life, the authors advise a clear change of course in the purchasing department. Legal and technical expertise should be at the table from the first day of needs planning. Fixed compliance checks, safety certificates, and clear update guarantees must become standard in every procurement process.

According to reports, classic purchase agreements are no longer sufficient. Contracts must stipulate long-term obligations – such as clear emergency reporting duties, audit rights, and regulated exit scenarios. With clear internal guidelines and checklists, purchasing will thus transform from a bureaucratic bottleneck into a central lever for secure hospital digitisation.

Search

Simply type the desired search term into the field below and you will receive the matching search results live.