Home/Case studies/Medical clinic network

Case study · IT Security

NIS2 compliance for a 30-clinic healthcare network: 24/7 SOC, data encryption and VPN with MFA for 72 doctors

A network of 30 medical clinics, where 72 doctors see 3,200 patients a month in person and online, now meets the requirements of the NIS2 directive. We delivered MediMed software in the cloud, encrypted production data and Veeam backups, and doctors sign in over VPN with Fortinet MFA. We run the servers and SOC 24/7/365.

NIS2 · 24/7 SOCHealthcare

Client

The client runs a network of 30 medical clinics and employs 72 doctors who see around 3,200 patients a month, both in the clinics and in online consultations. Every day it processes medical records and special-category data under the GDPR. Healthcare providers belong to the health sector, which the NIS2 directive lists among sectors of high criticality. The client’s name is covered by a non-disclosure agreement.

Challenge

With the NIS2 directive and the amended Polish National Cybersecurity System Act (KSC), the client had to show that it manages risk, protects data and is ready to handle an incident within the statutory deadlines. An environment spread across 30 locations, plus online visits run from outside the clinics, made it hard to control who connects to the systems and from where. Nor was there certainty that backups could be restored after a ransomware attack. Medical data ruled out ad hoc fixes: the client needed a single partner to take over security, infrastructure and the medical software, and to watch over them around the clock.

Scope of work

  • Full NIS2 implementation: gap analysis and risk assessment, security policies and procedures, an incident reporting procedure and documentation of the Article 21 measures. More about the service: NIS2 audit and implementation.
  • Penetration testing and vulnerability scanning: testing infrastructure and applications from an attacker’s perspective, followed by recurring scans with the Reconmore scanner that catch new vulnerabilities as they appear.
  • Data encryption: production data is encrypted, and backups in Veeam Backup & Replication are written encrypted (AES-256). Backups follow the 3-2-1 rule, and one copy is immutable, so ransomware can neither delete nor encrypt it.
  • Backup with automated restore testing: Veeam regularly and automatically restores backups in an isolated environment and checks that the systems boot. The client has proof that backups work, not just that they ran.
  • MediMed medical software in the cloud: we delivered the MediMed medical software together with the cloud that hosts it. Patient data stays in controlled infrastructure, and all clinics work on one shared system.
  • Secure access for doctors: each of the 72 doctors connects to the systems through an encrypted VPN tunnel (FortiClient and FortiGate) and confirms every sign-in with a second factor in the FortiToken app (MFA). A password alone is no longer enough, whether the doctor is seeing a patient in the clinic or running an online consultation.
  • 24/7/365 SOC and server administration: we monitor security events, respond to incidents and maintain the servers around the clock, 365 days a year.

How the engagement worked

NIS2 gap analysisInventory of systems and data across all 30 clinics, risk assessment and comparison of the current state with NIS2 requirements.
Penetration testingInfrastructure and application tests, a report with remediation priorities and the launch of recurring vulnerability scanning with Reconmore.
Cloud and MediMedMediMed medical software launched in a cloud maintained by Remote Admin, with access control and monitoring.
Encryption and backupEncryption of production data, Veeam 3-2-1 backup with an immutable copy and automated restore tests confirming that data can be recovered.
VPN and MFA for doctorsFortiClient VPN with FortiToken two-factor authentication rolled out to all 72 doctors.
24/7/365 SOC and administrationContinuous oversight of security and infrastructure, ready to handle and report incidents within NIS2 deadlines.

How we mapped NIS2 requirements to concrete safeguards

  • Risk analysis and security policies → gap analysis, policies and procedures, documentation of technical and organisational measures.
  • Incident handling → 24/7/365 SOC and a reporting procedure: early warning within 24 hours, notification within 72 hours, final report within one month.
  • Business continuity and backups → encrypted Veeam 3-2-1 backup with an immutable copy and automated restore testing.
  • Assessing the effectiveness of safeguards → penetration testing and recurring Reconmore vulnerability scanning.
  • Cryptography and encryption → encryption of production data and backups.
  • Access control and multi-factor authentication → FortiClient VPN and FortiToken (MFA) for every doctor.
  • Supply chain security → a single accountable provider for the MediMed medical software, cloud, infrastructure and SOC.

Results and value for the client

Data on around 3,200 patients a month is protected under one NIS2-aligned security standard, across all 30 clinics and in online consultations. Each of the 72 doctors works over VPN with MFA, so a stolen password is not enough to take over an account. Medical data is encrypted both in production systems and in backups, and the immutable copy plus automated restore tests prove that Veeam backups can be recovered even after a ransomware attack. The SOC and administrators watch the environment 24/7/365, so an incident is detected and reported within the deadlines NIS2 requires. The MediMed software, cloud, infrastructure and security sit with one partner, which simplifies board oversight and answering auditors’ questions.

Does your healthcare organisation need to meet NIS2? Let’s talk about implementation.

Frequently asked questions

Are healthcare providers covered by NIS2?

Yes. The health sector, including healthcare providers, is listed in Annex I of the NIS2 directive. Medium-sized and large clinics and clinic networks are generally in scope. In Poland, NIS2 is implemented through the amended National Cybersecurity System Act (KSC).

How long does NIS2 implementation take for a clinic network?

It depends on the number of locations, the systems in use and the starting point. We begin with a gap analysis that shows what needs to be done and in what order, and build the implementation schedule from it.

Why do doctors need a VPN and two-factor authentication?

A compromised password is one of the most common ways in. A VPN encrypts the connection to the clinic’s systems, and MFA requires a second confirmation for each sign-in, so a password alone grants no access. NIS2 explicitly lists multi-factor authentication among the recommended measures.

What is automated backup restore testing?

It is the regular, automatic restoration of backups in an isolated environment, with a check that the systems boot. That way you know backups will work after a ransomware attack before you actually need them.

What are the penalties for NIS2 non-compliance?

The directive provides for fines of up to EUR 10 million or 2% of worldwide turnover for essential entities, and up to EUR 7 million or 1.4% for important entities. Management bodies are also accountable for overseeing cybersecurity.

Other projects

See more case studies

All projects →
IT SecurityBanking · ING Bank Śląski S.A.

12-month penetration testing program for ING Bank Śląski

A year-long penetration testing cycle for critical infrastructure and web applications in a sprint model, aligned with DORA and OWASP, with official references.

12 monthscontinuous program
OWASPASVS · black-box
Read the case study →
IT SecurityCooperative banking

Annual security audit of a Cooperative Bank’s infrastructure and systems

A comprehensive annual security audit of a cooperative bank's critical infrastructure, banking application and email systems in light of DORA requirements.

3 monthstesting cycle
100%fix effectiveness in re-tests
Read the case study →
IT SecuritySoftware House · B2B applications

Securing the software development lifecycle (SDLC) with the Reconmore scanner

How Reconmore continuous vulnerability scanning supports developers: nearly 60 vulnerabilities found over 6 years with a software house building B2B apps.

~60vulnerabilities found
6 yearsof ongoing cooperation
Read the case study →