Cybersecurity 2026

BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP

Procurement and Certification Belgium’s shift toward assurance-based cybersecu - rity also affects procurement. While certification is not mandatory for healthcare providers, the national CyFun® framework is increasingly used to demon - strate compliance and is relevant for suppliers of medical IT systems. Healthcare sector procurement increasingly includes requirements relating to secure development, patch management, supplier assur - ance and conformity assessment for MDR-regulated devices.

Manufacturers must also operate post-market sur - veillance systems, monitor emerging vulnerabilities, and implement corrective and preventative meas - ures when security flaws are identified. Cybersecurity weaknesses that could affect patient safety require immediate reporting to the FAMHP through the EU’s vigilance system. Electronic Health Record Systems EHR systems process large quantities of sensi - tive health data and therefore fall within the GDPR’s heightened security framework. Controllers must: • adopt state of the art technical and organisational measures; • conduct data protection impact assessments; • enforce strict access governance; and • maintain audit trails. If an EHR provider meets the criteria of an essential or important NIS 2 entity, or acts as a critical third-party ICT provider to a hospital, it must comply with Bel - gium’s NIS 2 risk management and incident reporting requirements.

50 CHAMBERS.COM

Powered by