Hospitals caught between NIS-2, KHZG expiry and mandatory ePA – Why German clinics should exit Microsoft 365 now
Hospitals caught between NIS-2, KHZG expiry and mandatory ePA – Why German clinics should exit Microsoft 365 now
German hospital IT in 2026 is at an inflection point: the NIS-2 registration deadline with the BSI expired on 6 March 2026, the electronic patient record (ePA) becomes the flat standard under an opt-out procedure, and the funding from the Hospital Future Act (KHZG) is winding down. Meanwhile, the Federal Office for Information Security reports in its latest status document at least 18 documented ransomware attacks on German hospitals in 2024 alone, with several forcing emergency departments offline.
For hospital CIOs, IT leadership and executive management, three regulatory strands converge into a single operational mandate: to put in place an auditable, European-sovereign, resilient cloud foundation before the next incident triggers personal management liability under §38 of the NIS-2 Implementation Act. In this regulatory context, Microsoft 365 is no longer a viable target architecture – not because of the price increase on 1 July 2026, but because of three structural conflicts.
Why the regulatory density is unique for hospitals in 2026
No other sector in Germany carries a comparable combination:
- NIS-2 Implementation Act – in force since late 2025, registration deadline 6 March 2026, personal management liability under §38.
- B3S – sector-specific security standard – developed by the German Hospital Association, recognised by the BSI, mandatory for all KRITIS hospitals with 30,000+ inpatient cases.
- Hospital Future Act (KHZG) – 4.3 billion euros funding volume, of which 15 percent mandatory for cybersecurity, application deadlines expiring.
- Electronic patient record (ePA) – opt-out standard since 15 January 2025, regular operation from 2026 for all statutorily insured.
- GDPR Article 9 – patient data as a special category with a strengthened justification requirement.
These five frameworks all bear down at the same time – and they all hit the same question: where is patient data processed, who has access, and how is the evidence maintained?
The structural conflict between Microsoft 365 and hospital regulation
The core point: the three frameworks GDPR Article 9, B3S and NIS-2 all require the same three properties – purpose limitation, auditability, access control. Microsoft 365 delivers none of the three without substantial additional effort.
- Purpose limitation under Article 5(1)(b) GDPR is undermined by Microsoft's processing for "legitimate business purposes" under its own definition. For the health data category, this is, on the Data Protection Conference's reading, not permissible.
- Auditability under §30 BSIG (NIS-2) requires a complete, verifiable record of all data flows. Microsoft's sub-processor cascade – occasionally over 30 levels, spread globally – is barely defensibly documentable in a B3S context.
- Access control under IT-Grundschutz building block SYS.1.5 requires that access by non-EU authorities is excluded. The US CLOUD Act and FISA Section 702 structurally break this precondition – see our detailed analyses of the CLOUD Act 2026 and the BSI IT-Grundschutz conflict with Microsoft 365.
On top comes the NIS-2/GDPR paradox, which is particularly acute for hospitals: the two frameworks impose opposing chains of accountability if the cloud foundation is not sovereign.
What the KHZG expiry changes economically
By mid-2026 many hospitals had invested KHZG money in systems built on top of Microsoft 365 – cloud directory services, Teams integrations for wards, SharePoint-based quality management systems. These investments are not lost, but they now have to be measured against the regulatory follow-on cost:
- Increased effort for GDPR evidence – empirically 0.3 to 0.8 full-time equivalents per year at a mid-sized hospital.
- B3S audit cost – 50,000 to 150,000 euros per cycle, annual.
- NIS-2 legal advice – 30,000 to 80,000 euros per year for board liability documentation.
- 1 July 2026 price increase – Business Standard +12 percent, Business Basic +16 percent.
- Residual fine exposure – up to 2 percent of annual revenue under §60 BSIG.
A move to a European sovereign stack typically reaches positive cash flow within 14 to 20 months – primarily because the compliance evidence burden drops dramatically.
The target architecture for hospitals in 2026
Realistic for hospital operations in 2026, built on open standards and operated in German data centres with KRITIS experience:
- Nextcloud as file, forms and collaboration platform, with end-to-end encryption for patient record attachments.
- Element/Matrix for internal communication between wards, with auditable chat histories held in German data centres – along the lines of the EU Commission's Matrix architecture.
- Jitsi Meet for telemedicine appointments and case conferences.
- Collabora Online for document editing, LibreOffice compatible.
- Keycloak as central identity provider, connecting to the eGK electronic health card and HBA via the telematics infrastructure connectors.
- Local backup chain plus a cold-store copy in a second German data centre, to enable ransomware reconstruction in under 24 hours.
Unlike proprietary suites, these building blocks can be swapped individually at any time and integrated with hospital information systems (KIS) via open interfaces.
The economic comparison for a 500-bed hospital
Reference calculation, magnitude 800 staff, 500 beds, existing Microsoft 365 E3 contract:
| Line item | Microsoft 365 (36 months) | Sovereign stack (36 months) |
|---|---|---|
| Licences/operation | 460,000 € | 210,000 € |
| B3S audit overhead | 240,000 € | 90,000 € |
| GDPR documentation FTE | 220,000 € | 60,000 € |
| One-time migration | – | 180,000 € |
| Total | 920,000 € | 540,000 € |
Break-even at 17 months. This pattern mirrors what we showed in our post on the EuroOffice alternative for administrative environments – for hospitals, the saving on the audit side is markedly higher.
Conclusion and next steps
For German hospitals, exiting Microsoft 365 in the second half of 2026 is no longer a sovereignty luxury but a regulatory necessity. The combination of NIS-2 registration, ePA regular operation, KHZG expiry and personal management liability closes the window for strategic hesitation.
Any hospital starting the migration now can reallocate the last KHZG residuals, get the target architecture audited by the next B3S round in 2027, and discharge the board's liability under §38 of the NIS-2 Implementation Act. For a first assessment of your hospital stack, we recommend the categorised provider overview at /en/alternativen, the live analysis of your current Microsoft 365 data flows at /en/microsoft, and an initial conversation via /en/contact.
Six Months to 12 January 2027 – How the EU Data Act Rewrites the Microsoft 365 Exit Math for German SMEs and Public-Sector Bodies
On 12 January 2027 the EU Data Act bans egress and switching fees outright. What that means for Microsoft 365 contracts and how IT leaders should plan now.
Sovereignty Washing 2026 – Why Microsoft 365 Local and the Munich Sovereignty Studio do not release German municipalities from the CLOUD Act
M365 Local is GA, the Munich Sovereignty Studio is open, openDesk 1.17 is in the Chancellery – municipalities need a fact-check, not marketing.