skip to content

the weekly eHealth brief

eHealth Cyber Brief — EU — 21 Sep 2026

Europe's hospital cyberattacks have crossed a line from stealing data to shutting down care: a pre-HIMSS26-Europe survey found four in five hospital security buyers now report very high or extreme concern, and the French hospital group CHI Haute-Comté — struck by ransomware a year ago…

Europe's hospital cyberattacks have crossed a line from stealing data to shutting down care: a pre-HIMSS26-Europe survey found four in five hospital security buyers now report very high or extreme concern, and the French hospital group CHI Haute-Comté — struck by ransomware a year ago — is still not expected to fully recover before 2027, its clinical systems degraded throughout. The sensitivity of what leaks was underlined across the Atlantic, where the extortion crew ShinyHunters stole data on 6.4 million people from healthcare-distribution giant McKesson — including patients' cancer information — while a single mis-sent email at Singapore's National Cancer Centre exposed hundreds of people as carriers of a hereditary cancer syndrome, the low-tech breach European regulators see most often. And the governance of health AI moved to the fore: a UK commission handed government 44 recommendations for lifecycle oversight of medical AI, Anthropic began gating access to its most capable models for biology work over biosecurity fears, and a survey warned that hospitals are deploying autonomous AI agents faster than they can control them — even as Europe's EHDS and NIS2 rules take hold.

Top Stories


Health Policy & Regulation

Europe's hospital cyber risk has moved from data theft to care disruption, pre-HIMSS26-Europe study warns — web_search (Black Book / HIMSS26 Europe survey)
Why it matters: A survey of nearly 300 European hospital cyber buyers finds the threat has decisively shifted from stealing data to shutting down care — 82% report very high or extreme concern, ransomware cuts patient volume by up to a quarter for weeks, and the worst-hit systems face year-long recoveries — the clearest statement yet that in Europe, health-sector cyberattacks are now a patient-safety problem, not just a privacy one.
A pre-HIMSS26-Europe study (Black Book) of 284 European hospital cybersecurity buyers found 82% reporting very high or extreme attack concern, with risk shifting decisively from data theft to care disruption: attackers target authentication, availability, recovery windows and third-party dependencies across the clinical workflows (emergency, labs, imaging, pharmacy, theatres, ICUs) that move patients through a hospital. Ransomware cuts patient volume 17-24% in week one (≈3-week average recovery, severe cases far longer); the Coalition for Health, Ethics & Society counted 289 cyber incidents hitting EU healthcare in 2024, average breach ≈€10.3M. Highest-pressure markets: UK, France, Germany, Spain, Italy, Netherlands, Ireland, Poland, Switzerland; pro-Russia groups (Killnet, Anonymous Sudan) have run DDoS on hospitals in Denmark, the Netherlands, Spain and Sweden. It matters because it reframes EU health-sector cybersecurity as continuity-of-care and patient safety, aligning with the EU Action Plan for hospital cybersecurity, NIS2 (health = essential) and ENISA's push for a pan-European Cybersecurity Support Centre. For European digital-health sovereignty, resilience and recoverability — not just data protection — must be the organising principle of health-sector defence.

EHDS in force and NIS2 in effect: Europe builds the legal-and-institutional scaffolding for health-sector cyber resilience — web_search (ENISA / European Commission / EHDS Regulation)
Why it matters: With the European Health Data Space regulation now in force, NIS2 designating healthcare essential, and an EU Action Plan standing up an ENISA cybersecurity support centre for hospitals, Europe is assembling the machinery to treat health-sector cyber resilience as a shared obligation rather than each hospital's lonely problem.
Europe's health-cyber governance is consolidating: the European Health Data Space (EHDS) Regulation (EU) 2025/327 entered into force March 2025 and phases into application from March 2027, the first EU-wide framework for primary and secondary use of electronic health data; NIS2 designates healthcare a critical/essential sector with security-and-reporting duties; and the EU Action Plan for the cybersecurity of hospitals and healthcare providers (proposed January 2025) tasks ENISA with a pan-European Cybersecurity Support Centre offering tailored guidance, tools and training, with ENISA's 11th eHealth Security Conference set for 7 October 2026. It matters because it moves EU health-sector cybersecurity from voluntary best-effort toward a governed, resourced regime tying data-sharing (EHDS) to security-and-resilience duties (NIS2) with central support (ENISA). For digital-health sovereignty, the scaffolding aims to make resilience, secure data-sharing and incident response baseline expectations across the bloc — the real test being implementation: funding, NIS2 transposition, and whether the ENISA centre reaches the small and mid-sized providers most exposed to care disruption.

STAT+: U.K. unveils recommendations for regulating AI in medicine — STAT health tech: Stories on AI, new medical devices and more
Why it matters: A UK commission has handed government 44 recommendations for regulating AI in healthcare — the product of a year-long consultation with 12,000 patients and clinicians — urging a shift from one-off pre-market approvals to lifecycle oversight of ever-changing AI, a template Europe's own medical-AI regulators will be watching.
The MHRA's National Commission into the Regulation of AI in Healthcare published 44 recommendations to the UK government on 10 September, the product of a year-long consultation with 12,000+ patients, clinicians and stakeholders — the largest UK exercise of its kind. Its core vision is a 'patient-centric, practitioner-enabling' system that moves from reliance on one-off pre-market assessments toward lifecycle-based oversight, continuously reviewing AI products that change after authorisation rather than clearing them once. It matters because regulating adaptive clinical AI is a challenge every health regulator faces, and the UK's lifecycle approach is a substantive attempt to solve it. For Europe — where clinical AI sits at the intersection of MDR/IVDR and the AI Act's high-risk provisions — the UK framework is an influential reference (and a post-Brexit divergence to watch): the EU must reconcile static device conformity assessment with AI systems that learn and change, and the MHRA model offers one blueprint for continuous, patient-centred oversight of medical AI.


Pharma & Biotech

CHMP backs Novo’s hemophilia A drug and seven other medicines — Endpoints News
Why it matters: Europe's medicines regulator recommending approval of a new haemophilia A therapy and seven other medicines is the routine but consequential machinery of EU drug access at work — the CHMP clearing a slate of treatments toward European patients even amid the sector's turbulence over pricing and US deals.
The European Medicines Agency's CHMP recommended for approval a new Novo Nordisk haemophilia A drug alongside seven other medicines, advancing a slate of treatments toward EU marketing authorisation. It matters as the regular but consequential work of European drug regulation — CHMP positive opinions are the gateway to EU-wide patient access — and it lands amid a turbulent pharma backdrop (pricing pressure, US 'most favoured nation' deals, transatlantic friction). For European patients and health systems, CHMP recommendations translate directly into new treatment options, a reminder that beneath the geopolitics and cyber threats the core function of Europe's health-regulatory apparatus — evaluating and clearing medicines — continues to shape the care European patients receive.

[P3] Xenon pauses phase 3 depression trials after psychosis events — Fierce Biotech
Why it matters: The biotech Xenon voluntarily halted enrolment in its late-stage depression trials after a small number of participants experienced psychosis and other neuropsychiatric effects — a patient-safety pause that wiped nearly a third off its share price, and a reminder that drug-safety signals caught in trials are the system working as intended.
On 17 September 2026 Xenon Pharmaceuticals paused new patient enrolment in its phase 3 trials of azetukalner for major depressive disorder and bipolar depression after evaluating neuropsychiatric adverse events — confusion, speech difficulties, motor-coordination issues, and a 'very small number' of psychosis cases (a rate the chief medical officer put at ~1% or under, describing the events as short-lived and reversible). Existing participants continue treatment and the company is exploring dose adjustments; its epilepsy program is unaffected. Xenon shares fell ~29%. It is a clinical-trial patient-safety event, not a cyber incident.
severity medium · EU: MDR/IVDR, AI Act

AZ, Daiichi's Enhertu scores long-awaited NICE blessing in HER2-low breast cancer — Fierce Pharma
Why it matters: AstraZeneca and Daiichi Sankyo finally winning England's cost-effectiveness watchdog over for Enhertu in HER2-low breast cancer is the other half of European drug access — not just whether a medicine is approved, but whether the health system will pay for it — resolved here in patients' favour after a long wait.
AstraZeneca and Daiichi Sankyo's Enhertu secured a long-awaited positive recommendation from England's NICE in HER2-low breast cancer, clearing the health-technology-assessment hurdle that determines NHS funding. It matters because European drug access is a two-step gate — regulatory approval (EMA/MHRA) then HTA/reimbursement (NICE and EU counterparts) — and NICE's blessing, after a protracted appraisal, means eligible NHS patients can now access the therapy. For European health systems the Enhertu appraisal illustrates the central tension of drug access: balancing clinical benefit against cost-effectiveness and budget impact, a negotiation that determines whether approved medicines actually reach patients and that plays out across every European reimbursement system weighing increasingly expensive targeted therapies.


Health Data & Breaches

[P2] McKesson Cyberattack: Stolen Data Includes 6.4 Million Unique Email Addresses — The HIPAA Journal
Why it matters: The extortion crew ShinyHunters stole data on 6.4 million people from healthcare-distribution giant McKesson — including patients' health details such as the locations of their cancers — after voice-phishing its way through single sign-on, a breach whose scale and health-data sensitivity carry a clear read-across for the European providers that rely on the same platforms.
McKesson disclosed (28 August 2026) a cybersecurity incident involving third-party applications and unauthorised access and exfiltration of data; HaveIBeenPwned reported the stolen data included 6.4 million unique email addresses (marketing lists, patients, staff) plus names, addresses, dates of birth, phone numbers, employer details, appointment dates and notes, and personal health information including the locations of patients' cancers. ShinyHunters claimed responsibility — using voice phishing to compromise employees' Okta single-sign-on accounts before reaching Salesforce and Snowflake — and allegedly demanded $55.2 million. McKesson is a US healthcare-distribution and technology giant; the breach is US-centred but globally significant given its scale, health-data sensitivity, and ShinyHunters' cross-border activity.
severity high · exploited in the wild · EU: GDPR Art.9, NIS2 · actor ShinyHunters (self-claimed) (70%)

[P3] National Cancer Centre e-mail lapse allegedly exposes patients’ details — DataBreaches.Net
Why it matters: A single mis-sent email at Singapore's National Cancer Centre — using CC instead of BCC — exposed the identities and contact details of hundreds of people living with a hereditary cancer syndrome, a small but painfully sensitive breach that is the most common way European health providers, too, leak special-category data.
The National Cancer Centre Singapore (NCCS) apologised after an 18 September invitation to a 'Living with HBOC' event (hereditary breast and ovarian cancer syndrome) was sent using CC instead of BCC, making recipients' email addresses — and some workplaces — visible to one another; one recipient estimated more than 500 addresses exposed (the centre cited 460+ affected). The data is limited (identities, contact details, association with a hereditary-cancer condition) and the cause was human error, not intrusion, but revealing individuals as carriers of a genetic cancer condition is sensitive special-category health information.
severity low · EU: GDPR Art.9


Clinical AI & Safety

Anthropic starts verification program for using Mythos in biology — Endpoints News
Why it matters: Anthropic launching a vetting program that gates access to its most capable models for biology work — more permissive safeguards for approved life-science teams, tighter limits for high-risk uses — is a concrete attempt to square medical-and-scientific benefit against biosecurity risk, and a model for how frontier-AI access to sensitive domains might be governed.
Anthropic announced (17 September 2026) a Life Sciences Verification Program: a beta scheme giving vetted life-science organisations access to its Mythos, Opus 5 and Sonnet 5 models under safeguards refined to be more permissive for legitimate biology work, with a tiered structure — 'Standard Use' for routine research (annual renewal) and a 'High-risk Use' add-on tied to a single named project (six-month renewal), with the most capable Mythos access reserved for extensively vetted entities. Anthropic had onboarded dozens of organisations via early access and formalised a US-government partnership (by August 2026) to vet access for sensitive biological research, saying its frontier biology capabilities are powerful enough that unrestricted access could create biosecurity risks. It matters as a concrete governance mechanism for the eHealth×AI biosecurity problem: letting AI accelerate biomedical research and drug discovery while preventing misuse toward dangerous pathogens. For Europe — where the AI Act's systemic-risk provisions, biosecurity concerns and life-sciences ambitions intersect — a vendor-run, government-partnered verification-and-tiering model is a notable data point, raising the question of whether such gating should be voluntary and vendor-defined or anchored in regulation.

Healthcare’s agentic AI boom is outpacing governance: report — MedTech Dive - Latest News
Why it matters: A survey finds healthcare is deploying autonomous AI agents faster than it can govern them — leaders overwhelmingly confident they have oversight, yet most admitting AI tools slip in without IT approval — a shadow-AI gap that, in a clinical setting, is a patient-safety problem waiting to happen.
A report (from digital-identity firm Imprivata, mid-September 2026) finds healthcare's adoption of agentic AI outpacing governance: 85%+ of leaders responsible for AI strategy say they are confident they have visibility into AI-agent activity and can fully control and govern autonomous agents, yet 72% admit AI tools are deployed without IT approval at least occasionally — a stark confidence-versus-reality gap. A separate Wolters Kluwer survey found 40% of medical workers aware of colleagues using unauthorised AI tools and nearly 20% having used one. The report warns patient safety could be at risk without proper guardrails. It matters because healthcare is pushing AI agents into clinical and administrative workflows faster than oversight, identity controls and accountability mature — the health-sector instance of the broader 'adoption outpaces governance' finding, with directly patient-safety-relevant stakes. For Europe, where the AI Act treats many clinical-AI uses as high-risk and demands human oversight and risk management, the shadow-AI-in-healthcare gap is a warning that governance must be operationalised in practice, and that identity-and-access controls over what AI agents can do in clinical systems are becoming a core patient-safety and compliance concern.


Hospitals & Care Disruption

[P1] French hospital CHI Haute-Comté still rebuilding a year after ransomware, normalisation not before 2027 — web_search (EPC / Black Book / sector reporting)
Why it matters: A French hospital still running on rebuilt systems a year after a ransomware attack — hundreds of applications and a thousand-plus workstations not expected to normalise before 2027 — is the clearest illustration of Europe's shift from health-data theft to prolonged care disruption, and of how long a hospital's recovery really takes.
The October 2025 ransomware attack on French hospital group CHI Haute-Comté (Pontarlier + seven associated sites) kept disrupting operations into 2026: by March 2026, 1,000+ workstations and ~200 applications were still being rebuilt, with full normalisation not expected before early 2027 — a representative case of the EU shift from health-data theft to sustained care disruption, where ransomware cuts patient volume 17-24% in week one, recovery averages ~3 weeks, and the worst cases run over a year.
severity high · exploited in the wild · EU: NIS2, EHDS, ENISA, GDPR Art.9


Telehealth & Digital Health

AI task force established for Liverpool City region — HTN Health Tech News
Why it matters: A new regional AI task force for the Liverpool City Region is a small but telling marker of how AI is being pushed into NHS care from the ground up — local health systems standing up governance and ambition for clinical and operational AI, the practical layer beneath the national regulatory debate.
An AI task force has been established for the Liverpool City Region to guide AI adoption across its health and care system, part of the push to embed AI in NHS clinical and operational workflows. It matters as a ground-level instance of the AI-in-health rollout that the UK's national regulatory debate (the MHRA's 44 recommendations) sits above: regional and local NHS bodies are increasingly standing up their own AI governance, pilots and ambitions. It fits the fortnight's UK-NHS-digital thread (fertility and occupational-health EPR procurements, DHSC 'neighbourhood health' trailblazers, digital-consent tools) and the reality that AI adoption in European health systems happens both top-down (regulation, national strategy) and bottom-up (regional task forces, trust pilots). For digital-health sovereignty, such structures are where AI governance meets practice — and where the AI Act's and national regulators' requirements will ultimately be operationalised in real clinical settings.

newsletter

subscribe to cyber/verso

subscribe to receive cyber/verso's articles by email. Free, no tracking pixels, no tracked links. You can unsubscribe at any time. privacy notice.