Cybersecurity in healthcare and social welfare

The Cybersecurity Act provides for the management of cybersecurity risks. It implements the minimum obligations required in the NIS2 Directive for risk management and non-compliance reporting by healthcare operators and EU reference laboratories.

NIS2 is the new Network and Information Security Directive, a cybersecurity directive replacing the current Network and Information Security Directive (NIS1). The aim of this legislation is to ensure a uniform level of cybersecurity across the European Union. At national level, the Finnish Supervisory Agency supervises compliance with the obligations of the Cybersecurity Act in the healthcare sector.

List of operators

Healthcare operators covered by the Cybersecurity Act are obliged to register in the list of operators of the Finnish Supervisory Agency. The obligations apply to welfare areas and all healthcare organisations employing more than 50 people or with a turnover of more than EUR 10 million.

The Act also requires operators to comply with the cybersecurity risk management obligations under the Directive and to report significant cybersecurity incidents to the Finnish Supervisory Agency. Operators must identify themselves as being covered by the law and register on their own initiative on the list of operators.

Kyberturvallisuuslain perusteella tehty rekisteröinti on maksullinen toimenpide. Maksun määrä perustuu vuosittain annettavaan asetukseen Lupa- ja valvontaviraston maksuista. 

Rekisteröinnin hinnat:

  • Toimijailmoituksen käsittely 300 euroa.
  • Toimijailmoituksen muutosilmoituksen käsittely 200 euroa.

Sign up to the list of operators

A separate form is used to register for the list of operators. Changes to the organisation's details are also reported on the same form. 

Sign up to the list of operators (in Finnish) 

Notification procedure

Incident notifications under the Cybersecurity Act must be made using the new Traficom form application. The notification procedure is a three-step process with time limits. The first notification must be made within 24 hours of the discovery of a significant incident. Organisations not subject to NIS2 obligations can submit voluntary incident notifications. 

Frequently asked questions about the NIS2 Directive

Contact information

Customer service for health and social services

Ask our customer service by using service form
By e-mail: [email protected]
By calling: +358 295 256 930 (Monday–Friday 9:00–15:00)​