Luxembourg — Hôpitaux Robert Schuman
Securing biomedical devices, hospital OT and mobile care, from connected ambulances to medical implants at home.
- professionals employed
- 2,300professionals employed
- collaborating doctors
- 310collaborating doctors
When a hospital is attacked, the damage is not measured in downtime. HEALTH-ER builds an AI-based cybersecurity framework for European healthcare providers, so that detection, response and continuity of care are designed around patient safety rather than bolted on after it.
Why this matters
Hospitals now run on electronic health records, telemedicine, connected medical devices and AI-enabled diagnostics. Every one of those improves care, and every one widens the attack surface. Unlike other sectors, a cyberattack here can have immediate and fatal consequences.
significant cybersecurity incidents reported in the EU health sector in 2023
projected annual cost of ransomware attacks by 2031
pillars of the EU Action Plan, all four addressed by HEALTH-ER
of European hospital care represented through HOPE in the consortium
The framework
HEALTH-ER runs either as a complete SOCaaS or as a complementary layer over the tools a hospital already has, so smaller providers get access to capabilities that were previously the preserve of large university hospitals.
Continuous analysis of system and user behaviour across hospital IT, medical devices and OT, turning raw telemetry into prioritised, explainable risk.
4 components
Coordinated, partly automated response that keeps clinical services running, built on playbooks that can be shared between hospitals.
2 components
Turning one hospital’s lesson into the sector’s defence, and meeting the reporting duties that come with NIS2.
3 components
The human factor: realistic exercises and role-specific training for clinical, technical and management staff.
4 components
EU Action Plan alignment
In January 2025 the European Commission launched an Action Plan to strengthen the cybersecurity of hospitals and healthcare providers. HEALTH-ER covers all four of its pillars.
Preparedness, systematic risk assessment, procurement guidance, supply-chain risk management and tailored training for healthcare professionals.
Advanced monitoring, AI-enhanced detection and an EU-wide early-warning capability for the healthcare sector.
Incident-response playbooks, business-continuity plans, CSIRT support and cyber-range exercises to contain and recover from attacks.
Compliance with NIS2 and GDPR, certification pathways, incident and ransom-payment reporting, and sector-wide deterrence measures.
Validation
Two internal hospital pilots in Luxembourg and Estonia, plus an EU-wide Open Pilot that opens the tools to healthcare providers across Europe.
Securing biomedical devices, hospital OT and mobile care, from connected ambulances to medical implants at home.
A healthcare-specific SOC-as-a-Service that puts patient-safety logic into the cybersecurity context.
An open invitation to hospitals, clinics and healthcare providers across Europe to test the project’s tools in their own environment.
The Open Pilot gives healthcare providers across Europe free access to the SOCaaS, AI detection tools, self-assessment guidelines and training material — plus support in building your own technical plan. We are looking for at least 15 providers across at least 6 countries.

HEALTH-ER is one of seven projects funded under the CYBERHEALTH call, together running pilots in 14 EU countries and feeding a shared agenda on threat intelligence, playbooks, medical devices, training and compliance.