Cybersecurity 2026

FINLAND Law and Practice Contributed by: Rosa Lång, Joona Linner, Toni Tainio and Oliver Lönnblad, Lieke Attorneys Ltd

6.3 Cybersecurity in the Healthcare Sector Legislative Framework In addition to the general cybersecurity regulatory framework (such as the Cybersecurity Act), the health - care sector is subject to sector-specific cybersecu - rity obligations and requirements. The Client Data Act applies to data processing and information systems in healthcare and social welfare sectors, supplement - ing requirements under the Finnish Data Protection Act and the GDPR. The Act on the Secondary Use of Health and Social Data (552/2019, Laki sosiaali- ja terveystietojen toissijaisesta käytöstä ) facilitates effective and safe processing and access to per - sonal social and health data for steering, supervision, research, statistics and development in health and social sectors, whilst safeguarding individuals’ rights and freedoms in personal data processing. The Act on Information Management in Public Administration (906/2019, Laki julkisen hallinnon tiedonhallinnasta ) implements cybersecurity requirements of the NIS 2 Directive for public administration entities, including public healthcare entities. Cybersecurity Obligations Under Sector-Specific Legislation The sector-specific legislative instruments described above impose cybersecurity obligations on healthcare and social welfare entities. Under the Client Data Act, the integrity, immutability and indisputability of client and patient data must be secured when processing, transferring or storing data. Any information security breaches or disruptions affecting national informa - tion system services must be reported to the NCSC- FI of Traficom. Public agencies, pharmacies and ICT service providers subject to the Client Data Act are required to have an information security policy. The Act on the Secondary Use of Health and Social Data imposes obligations to ensure the security and integ - rity of health and social data processed for secondary purposes, including risk management, access control and active monitoring.

Applicability of the Cybersecurity Act The Cybersecurity Act applies to any healthcare organisation that meets the criteria for entities set out in the Act (see 2. Critical Infrastructure Cybersecu- rity Regulation regarding the obligations and require - ments under the Cybersecurity Act). Regulation (EU) 2017/745 on medical devices (MDR) and Regulation (EU) 2017/746 on in vitro diagnostic medical devices (IVDR) impose cybersecurity requirements on the manufacturers of medical devices. Pursuant to Article 2 (2) of the CRA, products falling within the scope of the MDR and the IVDR are excluded from the scope of the CRA and are accordingly not subject to the cybersecurity requirements set out therein. Incident Reporting in the Healthcare Sector Healthcare entities within the scope of the Cyberse - curity Act are subject to the incident reporting obliga - tions outlined in 2.3 Incident Response and Notifica - tion Obligations . In addition, under the Client Data Act, information security breaches and disruptions affecting national information system services must be reported to the NCSC-FI. Where a significant inci - dent also constitutes a personal data breach within the meaning of the GDPR, parallel notification obliga - tions to the Data Protection Ombudsman apply.

110 CHAMBERS.COM

Powered by