GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm
• training-data quality; • vulnerability to poisoning or tampering; and • potential biases and statistical weaknesses. Model security Both legal frameworks expect: • secure model deployment; • controlled access to the model (API security, rate limiting); and • robustness testing aligned with standards (eg, ISO/ IEC AI testing guidance referenced in Greek advi - sory documents).
A defining sector-specific element of healthcare cyber - security is the security of medical devices, especially as they become increasingly connected and software- driven. Under the EU Medical Device Regulation (MDR 2017/745), which applies directly in Greece, medical devices are subject to mandatory cybersecurity-by- design and life cycle-security obligations, established through the General Safety and Performance Require - ments (GSPRs) in Annex I. Incident reporting is one of the most operationally demanding obligations, as many cybersecurity inci - dents simultaneously trigger GDPR requirements. Furthermore, if a cybersecurity incident affects a medical device, MDR vigilance obligations may also apply. This means that a single incident may generate parallel reporting obligations, such as the following. • A significant cybersecurity incident must be report - ed to the NCSA/CSIRT following NIS2 timelines: an early warning within 24 hours, an incident notifica - tion within 72 hours, and a final report within one month. • In the healthcare sector, there is an additional national layer: incidents must also be reported to IDIKA (ΗΔΙΚΑ), which operates central Greek eHealth infrastructures such as the national ePre - scription system and the EHR ecosystem. • IDIKA must be notified whenever a local incident (eg, ransomware in a hospital) could affect inter - connected national systems. • A health data breach requires a risk assessment and, in many cases, notification to the Hellenic Data Protection Authority (HDPA) within 72 hours. • A cybersecurity incident involving a medical device that creates or risks causing serious harm to patient safety must be reported to the competent market surveillance authority.
Third-party components Where AI systems rely on: • pre-trained models; • open-source components; or • external AI APIs, the operator is still responsible for:
• verifying their security characteristics; and • ensuring they do not introduce vulnerabilities. 6.3 Cybersecurity in the Healthcare Sector Cybersecurity in the Greek healthcare sector is gov - erned by a multi-layered framework that combines: • horizontal cybersecurity rules (NIS2, GDPR); • sector-specific regulation for medical devices (MDR/IVDR reinforced by MDCG guidance); and • practical obligations arising from procurement pro - cesses and system-integration requirements. Under NIS2, healthcare providers – such as hospitals, clinics, and diagnostic centres – are categorised as essential entities. This designation entails enhanced security and reporting duties. At a minimum, such entities must implement risk-management measures including security policies, vulnerability management, monitoring, access controls, incident-response pro - cesses, and supply-chain assurance.
182 CHAMBERS.COM
Powered by FlippingBook