Digitization has long been the “modernization project” for hospitals: better applications, electronic forms, quick access to documents, and shorter patient pathways. Today, however, digitization has also become a compliance project. This is because in healthcare, we work with information that cannot be “reset”: you can change a password, but you cannot change a medical history. This is where the real stakes lie: the continuity of care, data protection, and operational resilience—all under increasing legal pressure.
Three simple questions (which are, in fact, legal questions)
What standards do we need to meet when digitizing?
Who is responsible if a system is non-compliant, goes down, or an incident occurs that affects services?
How do we demonstrate (through procedures, contracts, and evidence) that we did what was required and reasonable?
This development explains why, in recent years, a comprehensive regulatory framework—both at the European and national levels—has taken shape, one that does not merely “encourage” digitization but actually governs it.
The European Union’s “Digital Decade”: A Roadmap of Obligations, Not Just a Slogan
The European Union has established the framework for digital transformation through 2030 via Decision (EU) 2022/2481 of the European Parliament and of the Council of December 14, 2022, establishing the 2030 Digital Decade policy program.
The decision establishes a mechanism for cooperation and monitoring and sets Union-wide targets in four areas: digital skills, digital infrastructure, the digitization of businesses, and digital public services.
What does this mean in practical terms for health?
The message is clear: digitization can no longer be fragmented and inconsistent. Systems must be designed with interoperability and secure access to data in mind, including in cross-border contexts.
“Legislative “Volume”: Why It Seems Like We Live in a World of Acronyms
The “Digital Decade” is not a single piece of legislation, but rather a collection of various regulatory instruments covering topics such as artificial intelligence governance, cybersecurity, operational resilience, data sharing, data protection, competition, and digital safety. We work with acronyms that can sometimes be hard to keep track of, such as: GDPR, NIS, AI Act, DORA, CRA, DMA, DSA, EDHS, etc.
For context and updates, DLA Piper has created a page dedicated to these legislative developments: DLA Piper – EU Digital Decade.
The real challenge for Romania’s healthcare system is not to simply “check off” yet another law, but to build a coherent set of internal mechanisms. It is essential that this system be designed correctly from the outset and treated as a living organism: we are not talking about compliance on paper, but about rules, responsibilities, and checks that function on a daily basis and can be demonstrated.
EHDS: Interoperability and Governance, Not Just “Software”
A major milestone is Regulation (EU) 2025/327 of the European Parliament and of the Council on the European Health Data Space (EDHS), which will be implemented in phases over the coming years.
Beyond the headline, the impact on the healthcare system is tangible:
- Digitization means aligning with European requirements for interoperability and governance
- The importance of the “data map” is growing: what data exists, where it is located, who has access to it, what logs are kept, and what rules apply to access and reuse for permitted purposes.
Romania: Digitalization Is Moving Forward, and the National Framework Is Being Strengthened
At the national level, the digitization of healthcare is also supported by legislation governing the financing and implementation of digital transformation investments.
But the real paradigm shift is this: as we digitize, the scope of risk increases, and the law requires that the risk be managed and demonstrated.
For hospital management, the bottom line is simple: investments in technology must be matched by investments in processes and oversight. In practice, “compliance” means, at a minimum:
- internal policies and procedures (access, audit, business continuity, incidents);
- ongoing training and testing of staff;
- clear roles and responsibilities (including in relations with suppliers);
- contracts that include security obligations, updates, and cooperation in the event of incidents;
- documentation that can be presented during an inspection (what, why, how, who).
NIS2 in Romania: Digitalization Must Be Secure
Romania was among the first countries to transpose the European NIS2 cybersecurity regime through Government Emergency Ordinance No. 155 of December 30, 2024, on the establishment of a framework for the cybersecurity of networks and information systems in the national civilian cyberspace.
For the healthcare sector, the practical implication is simple: the digital hospital naturally becomes more vulnerable to incidents, and the law treats this vulnerability as an area of mandatory compliance, with requirements that must be implemented and supported by evidence.
CRA: Safety of Products “with Digital Elements”
An area that is often overlooked in digitization projects is the security of products with digital components used in hospitals: applications, connected devices, and software components, including elements in the supply chain.
This is where Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital components (known as the “Cyber Resilience Act”) comes into play.
Why does this matter for healthcare? Because, in practice, the digitization of hospitals involves the procurement and use of products with digital components. And the legislative trend is clear: security is no longer left solely “in the technical manual,” but is mandated by regulations that extend into the areas of procurement, accountability, and oversight.
In digitization projects, a question that lawyers ask early on is: What are we buying, with what guarantees, what update obligations, what liability, and what remedy mechanism?
There is no digital world without governance (and governance is reflected in documents)
In a hospital, digital systems are essential for diagnosis, treatment, communication, reporting, and administration. In this context, cybersecurity is not merely a “technical issue,” but a prerequisite for operations.
The hospital must be able to demonstrate, in a verifiable manner, that:
- is aware of its risks and assesses them periodically;
- has rules governing data access and management;
- has a well-established contractual relationship with suppliers, particularly technology providers (including clauses that reflect security requirements and cooperation in the event of incidents);
- It has mechanisms for prevention, response, and continuity.
This is, in fact, the key legal issue: not just the implementation of the technology, but its implementation in a way that withstands scrutiny, audits, and incidents.
There is no digital transformation without staff training
NIS2 is a game-changer: it’s not enough to simply purchase technology; you must “equip” your organization with security reflexes—management must be trained and responsive, and all employees must receive ongoing training—so that cybersecurity becomes part of everyday work practices, not just a document gathering dust in a drawer.
In a new digitization project (especially one that involves laboratories), technology alone is not enough without the “human component” designed from the outset—what roles and responsibilities exist, what each employee needs to know in practice (cybersecurity hygiene, access rules, recognizing fraud attempts, rapid incident reporting), and how they are trained and tested—because the law imposes specific obligations on management (including accredited professional training) and requires regular training for all staff as an ongoing process, not just a compliance checkbox.
There is no such thing as digital without continuous exposure monitoring
In many organizations, digital security is assessed on a regular basis. However, risks are constantly changing: updates are released, configurations are modified, and new vendors and applications are added. In the healthcare sector, the pace of change is rapid, and the consequences of a data breach can be severe.
The law requires proportionate and appropriate measures for cyber risk management—including identification, assessment, and control—as well as for mitigating the impact of incidents on patients/beneficiaries and dependent services.
In this context, “repeated monitoring/verification” solutions (such as RedMesh, proposed by Ratio1 Ratio1 – The Ultimate AI OS Powered by Blockchain Technology and DLA Piper) can help transition from an occasional “snapshot” to a continuous approach that is easier to sustain within a framework of prevention, detection, and demonstrable control. The solution relies on distributed operation across multiple nodes, setting it apart from traditional tools that operate from a single point.
Conclusion: The digital hospital needs a legal strategy, not just technology
The digitization of hospitals is inevitable and, in the long run, beneficial. But digitization without a legal strategy leads to vulnerabilities, costs, and bottlenecks.
The European and national guidelines are clear: digital projects must be built with security by design, with defined responsibilities, vendor oversight, response procedures, and documentation demonstrating compliance. This is why the role of the legal professional is becoming central: not to “slow down” technology, but to make it sustainable and compliant with regulatory obligations.
Irina Macovei, Attorney, DLA Piper


