Cybersecurity 2026

PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

These entities’ value and impact on basic societal func - tions make them prime targets for cyber-attacks, often aimed at compromising health data and the safety of individuals. As such, Regulations (EU) 745/2017 and 746/2017 on medical devices and in vitro diagnostic medical devices have introduced cybersecurity con - cerns. These regulations ensure that devices placed on the EU market are equipped to address new tech - nological challenges related to cybersecurity risks. The Medical Devices Regulation (MDR) requires medi - cal devices with electronic programmable systems and software to meet minimum cybersecurity require - ments. This includes devices such as pacemakers and insulin pumps. Consequently, these requirements cov - er hardware, IT network characteristics and IT security measures, including protection against unauthorised access, to ensure that the software works as intend - ed. In light of Commission Implementing Regulation (EU) 2021/2226, manufacturers of specific medical devices must perform and document a risk assess - ment covering the safety and back-up mechanisms in the event of a hardware or software fault, particularly if the instructions for use are provided in electronic form and integrated within the device. According to the guidance on cybersecurity for medi - cal devices (MDCG 2019-16 Rev 1, December 2019), manufacturers must implement state-of-the art cyber - security measures. This guidance is intended to help manufacturers comply with the essential cybersecu - rity requirements outlined in Annex I of the MDR and the In Vitro Diagnostic Medical Devices Regulation.

The MDR does not define “IT security”, so the Medi - cal Device Coordination Group document refers to the definition provided by ENISA. IT security is thus defined as the protection against threats to the techni - cal infrastructure of a cyber system that could change its characteristics to perform unintended activities (Definition of Cybersecurity – Gaps and Overlaps in Standardisation, December 2015). The same applies to the definitions of operational security and informa - tion security. In Portugal, Decree-Law No 29/2024 ensures the national implementation of the MDR and provides that healthcare entities deploying a medical device must report all security measures implemented and their performance to the competent authority (ie, INFARMED, I.P). Also at the national level, Order No 8877/2017 estab - lishes the governance model to be followed by the Shared Services of the Ministry of Health, in conjunc - tion with the National Security Office and the CNCS. The same Order requires all health entities of the national health service to adopt a cybersecurity policy and a contingency plan for cybersecurity incidents. Finally, it is important to highlight that the European Health Data Space, governed by Regulation (EU) 2025/327 of February 11th, complements the CRA. This is achieved by revising certain provisions and introducing new numbers that address cybersecurity requirements for products with digital elements clas - sified as electronic health record systems.

272 CHAMBERS.COM

Powered by