Cybersecurity in Healthcare: Strategies Abound, But Implementation Falls Short — DMEA Panel Insights

Europe’s healthcare systems face a growing gap between cybersecurity strategy and practical implementation, a reality underscored during a recent panel discussion at the DMEA 2026 conference in Berlin. While numerous national and EU-level frameworks exist to strengthen digital defenses in hospitals, clinics, and health technology supply chains, experts warned that translating these plans into everyday operational resilience remains a significant challenge. The disconnect between policy design and frontline execution raises concerns about the sector’s ability to withstand evolving cyber threats, particularly as digital health services expand across the continent.

The discussion, moderated by Beatrice Kluge of Germany’s gematik agency, brought together cybersecurity leaders from Denmark, Finland, Norway, and Germany to examine why despite ample strategic guidance, healthcare organizations continue to struggle with implementation. Søren Bank Greenfield, head of cyber and information security at the Danish Health Data Authority, emphasized that while cooperation is essential, shared responsibility alone does not suffice in practice. He argued that unclear accountability often undermines even well-intentioned initiatives, noting that policymakers frequently establish rules without providing sufficient guidance on how institutions should adapt them to real-world workflows.

Greenfield advocated for pairing regulatory measures with concrete implementation tools, such as step-by-step guidelines, pilot programs, and practical workflows tailored to healthcare settings. “Regulations must be developed alongside practice, not in isolation from it,” he stated during the panel. His remarks echoed broader concerns raised across the DMEA 2026 agenda, where officials and industry representatives repeatedly highlighted the need for actionable support beyond high-level directives. The Bundesministerium für Gesundheit was represented at the event by Ministerin Nina Warken, who delivered a keynote on April 21, 2026, stressing that digital health innovations must deliver tangible benefits to both patients and providers to justify their adoption.

These implementation barriers are further illuminated by recent publications from Germany’s Federal Office for Information Security (BSI). In mid-April 2026, the BSI released its updated publication, “Cybersicherheit im Gesundheitswesen 2025,” which offers insights into threat landscapes affecting Germany’s healthcare sector. The document focuses on risks related to the telematics infrastructure, outpatient care providers, and manufacturers of connected medical devices. It similarly examines challenges surrounding the electronic prescription (E-Rezept) system, which became mandatory for all statutory health insurance holders in Germany starting in 2025. The BSI noted increasing reports of availability issues with E-Rezept services and called for targeted improvements to enhance reliability and security.

The brochure, which was physically available at the DMEA 2026 exhibition in Hall 2.2, Booth C-106 from April 21–23, 2026, builds on earlier BSI analyses, including findings from the AnMedPro working group. That initiative, concluded in 2025, developed a guideline for medical device manufacturers aiming to support compliance with regulatory requirements. The 2025 publication summarizes these outcomes and includes recommendations for strengthening security in networked medical products—a growing concern as more diagnostic and therapeutic devices become network-enabled.

Beyond technical safeguards, panelists stressed that human and organizational factors are equally critical to building cyber resilience. Greenfield pointed out that even the most advanced technical defenses can fail if staff lack proper training or if incident response plans are not regularly tested. He urged healthcare leaders to treat cybersecurity not as a one-time IT project but as an ongoing organizational capability requiring continuous investment, clear leadership, and cross-departmental coordination. This perspective aligns with guidance from the European Union Agency for Cybersecurity (ENISA), which has repeatedly emphasized that governance, awareness, and preparedness are as vital as firewalls and encryption in protecting health systems.

The DMEA 2026 conference itself served as a barometer for these challenges, drawing approximately 20,500 attendees and featuring over 470 speakers across three days in Berlin. As one of Europe’s largest digital health exhibitions, the event provided a platform for discussing not only technological innovation but also the systemic hurdles that impede its safe and effective deployment. Topics ranged from artificial intelligence in diagnostics to the security of health data exchanges, with cybersecurity emerging as a recurring theme in both formal sessions and informal conversations among attendees.

Looking ahead, stakeholders agree that closing the strategy-implementation gap will require sustained collaboration between regulators, healthcare providers, technology vendors, and cybersecurity agencies. Practical next steps include expanding access to implementation toolkits, funding regional cybersecurity readiness programs, and establishing feedback loops that allow frontline experiences to inform future policy updates. As of now, no single date has been set for a follow-up EU-wide assessment of healthcare cyber resilience, but national agencies like the BSI and Germany’s gematik continue to publish periodic updates and advisories through their official channels.

For healthcare professionals and policymakers seeking reliable guidance on strengthening digital defenses, official resources from the BSI, ENISA, and national health authorities remain the most credible starting points. These organizations regularly release threat analyses, best practice frameworks, and sector-specific advisories designed to support real-world decision-making. Readers interested in tracking developments in European healthcare cybersecurity are encouraged to consult these sources directly for the most accurate and up-to-date information.

As digital transformation accelerates across Europe’s health sector, ensuring that security measures keep pace with innovation will be essential to maintaining public trust and safeguarding patient safety. The conversation initiated at DMEA 2026 underscores that while the roadmap for cyber resilience exists, the real work lies in walking it—together, consistently, and with attention to the practical realities of healthcare delivery.

Stay informed. Share your thoughts. Join the conversation below.

Leave a Comment