SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal
Health‑Data Protection Overlay Health data constitutes special‑category personal data under the GDPR, triggering the highest level of security and accountability obligations. In Spain, these are further reinforced by the ENS for public healthcare systems and by mandatory data‑protection impact assessments (DPIAs) for significant clinical and AI‑enabled systems. Supervisory practice confirms that DPIAs must be substantive and risk‑focused; generic or superficial assessments are treated as compliance failures in their own right. Parallel Notification Complexity Healthcare entities face one of the most demanding regulatory notification landscapes across any sector. A single cyber incident may trigger NIS2 notification within 24 hours, CER notification for designated criti - cal entities and GDPR personal‑data breach notifica - tion within 72 hours. Managing these simultaneous obligations during an active clinical incident – when systems may be degraded and staff may be operat - ing manually – requires integrated incident‑response planning that includes clinical leadership alongside legal and cybersecurity teams. Under the current regulatory framework, such integration is not merely best practice; it is essential for both compliance and patient safety.
the integrity of patient records is presumptively signifi - cant because of the potential for patient harm. Connected Medical Devices and the CRA Interface A particularly complex issue for healthcare organi - sations is the interaction between the Cyber Resil - ience Act and connected medical devices. As a gen - eral rule, devices governed by the Medical Devices Regulation (MDR) or the In Vitro Diagnostic Medical Devices Regulation (IVDR) may fall outside the CRA where equivalent cybersecurity requirements already apply. However, equivalence is not automatic. While MDR and IVDR incorporate cybersecurity into clinical safety, the CRA introduces additional, standalone life cycle obligations – including co-ordinated vulnerability disclosure, defined security‑update support periods and active incident reporting. Until further clarification through delegated acts, manufacturers and health - care procurers must navigate a grey area in which MDR/IVDR compliance does not necessarily satisfy all CRA‑relevant requirements. Procurement and Life Cycle Risk Regardless of formal applicability, the CRA is already shaping healthcare procurement practices. Hospitals increasingly expect clear commitments regarding security‑update support, vulnerability‑management processes and product‑roadmap alignment with CRA expectations. Devices lacking defined support peri - ods pose medium‑term operational and clinical risks, particularly in healthcare environments where equip - ment life cycles extend far beyond those of typical consumer technology.
343 CHAMBERS.COM
Powered by FlippingBook