[{"data":1,"prerenderedAt":544},["ShallowReactive",2],{"navigation-docs_en":3,"/en/blog/hospital-nis2-microsoft-365-sovereign-cloud-alternative-2026-posts_en":51,"/en/blog/hospital-nis2-microsoft-365-sovereign-cloud-alternative-2026-surround-posts_en":533},[4],{"title":5,"path":6,"stem":7,"children":8,"page":25},"En","/en","en",[9],{"title":10,"path":11,"stem":12,"children":13,"page":25},"Docs","/en/docs","en/1.docs",[14,26],{"title":15,"path":16,"stem":17,"children":18,"icon":25},"Getting Started","/en/docs/getting-started","en/1.docs/1.getting-started/1.index",[19,21],{"title":20,"path":16,"stem":17,"children":-1},"Introduction",{"title":22,"path":23,"stem":24,"children":-1},"Migration Roadmap","/en/docs/getting-started/migration-fahrplan","en/1.docs/1.getting-started/2.migration-fahrplan",false,{"title":27,"path":28,"stem":29,"children":30,"page":25},"Technologies","/en/docs/technologies","en/1.docs/2.technologies",[31,35,39,43,47],{"title":32,"path":33,"stem":34,"children":-1},"Nextcloud","/en/docs/technologies/nextcloud","en/1.docs/2.technologies/1.nextcloud",{"title":36,"path":37,"stem":38,"children":-1},"Matrix / Element","/en/docs/technologies/matrix","en/1.docs/2.technologies/2.matrix",{"title":40,"path":41,"stem":42,"children":-1},"ONLYOFFICE","/en/docs/technologies/onlyoffice","en/1.docs/2.technologies/3.onlyoffice",{"title":44,"path":45,"stem":46,"children":-1},"Ubuntu Linux","/en/docs/technologies/ubuntu","en/1.docs/2.technologies/4.ubuntu",{"title":48,"path":49,"stem":50,"children":-1},"Keycloak","/en/docs/technologies/keycloak","en/1.docs/2.technologies/5.keycloak",{"id":52,"title":53,"authors":54,"badge":60,"body":62,"date":461,"description":462,"extension":463,"faq":464,"howto":482,"image":525,"meta":527,"navigation":528,"path":529,"seo":530,"stem":531,"__hash__":532},"posts_en/en/3.blog/23.hospital-nis2-microsoft-365-sovereign-cloud-alternative-2026.md","Hospitals caught between NIS-2, KHZG expiry and mandatory ePA – Why German clinics should exit Microsoft 365 now",[55],{"name":56,"to":57,"avatar":58},"europioneer Team","/",{"src":59},"/favicon.svg",{"label":61},"Healthcare & Regulation",{"type":63,"value":64,"toc":451},"minimark",[65,69,98,117,122,125,167,173,177,184,223,231,235,242,274,281,285,288,328,331,335,338,422,430,434,437],[66,67,53],"h1",{"id":68},"hospitals-caught-between-nis-2-khzg-expiry-and-mandatory-epa-why-german-clinics-should-exit-microsoft-365-now",[70,71,72,73,77,78,81,82,85,86,89,90,93,94,97],"p",{},"German hospital IT in 2026 is at an inflection point: the ",[74,75,76],"strong",{},"NIS-2 registration deadline with the BSI"," expired on ",[74,79,80],{},"6 March 2026",", the ",[74,83,84],{},"electronic patient record (ePA)"," becomes the flat standard under an ",[74,87,88],{},"opt-out procedure",", and the ",[74,91,92],{},"funding from the Hospital Future Act (KHZG)"," is winding down. Meanwhile, the Federal Office for Information Security reports in its latest status document ",[74,95,96],{},"at least 18 documented ransomware attacks"," on German hospitals in 2024 alone, with several forcing emergency departments offline.",[70,99,100,101,104,105,108,109,112,113,116],{},"For ",[74,102,103],{},"hospital CIOs, IT leadership and executive management",", three regulatory strands converge into a single operational mandate: to put in place an ",[74,106,107],{},"auditable, European-sovereign, resilient cloud foundation"," before the next incident triggers personal management liability under ",[74,110,111],{},"§38 of the NIS-2 Implementation Act",". In this regulatory context, Microsoft 365 is no longer a viable target architecture – not because of the price increase on ",[74,114,115],{},"1 July 2026",", but because of three structural conflicts.",[118,119,121],"h2",{"id":120},"why-the-regulatory-density-is-unique-for-hospitals-in-2026","Why the regulatory density is unique for hospitals in 2026",[70,123,124],{},"No other sector in Germany carries a comparable combination:",[126,127,128,135,141,151,161],"ul",{},[129,130,131,134],"li",{},[74,132,133],{},"NIS-2 Implementation Act"," – in force since late 2025, registration deadline 6 March 2026, personal management liability under §38.",[129,136,137,140],{},[74,138,139],{},"B3S – sector-specific security standard"," – developed by the German Hospital Association, recognised by the BSI, mandatory for all KRITIS hospitals with 30,000+ inpatient cases.",[129,142,143,146,147,150],{},[74,144,145],{},"Hospital Future Act (KHZG)"," – 4.3 billion euros funding volume, of which ",[74,148,149],{},"15 percent mandatory for cybersecurity",", application deadlines expiring.",[129,152,153,156,157,160],{},[74,154,155],{},"Electronic patient record (ePA)"," – opt-out standard since ",[74,158,159],{},"15 January 2025",", regular operation from 2026 for all statutorily insured.",[129,162,163,166],{},[74,164,165],{},"GDPR Article 9"," – patient data as a special category with a strengthened justification requirement.",[70,168,169,170],{},"These five frameworks all bear down at the same time – and they all hit the same question: ",[74,171,172],{},"where is patient data processed, who has access, and how is the evidence maintained?",[118,174,176],{"id":175},"the-structural-conflict-between-microsoft-365-and-hospital-regulation","The structural conflict between Microsoft 365 and hospital regulation",[70,178,179,180,183],{},"The core point: the three frameworks GDPR Article 9, B3S and NIS-2 all require the same three properties – ",[74,181,182],{},"purpose limitation, auditability, access control",". Microsoft 365 delivers none of the three without substantial additional effort.",[126,185,186,192,198],{},[129,187,188,191],{},[74,189,190],{},"Purpose limitation under Article 5(1)(b) GDPR"," is undermined by Microsoft's processing for \"legitimate business purposes\" under its own definition. For the health data category, this is, on the Data Protection Conference's reading, not permissible.",[129,193,194,197],{},[74,195,196],{},"Auditability under §30 BSIG (NIS-2)"," requires a complete, verifiable record of all data flows. Microsoft's sub-processor cascade – occasionally over 30 levels, spread globally – is barely defensibly documentable in a B3S context.",[129,199,200,203,204,207,208,211,212,217,218,222],{},[74,201,202],{},"Access control under IT-Grundschutz building block SYS.1.5"," requires that access by non-EU authorities is excluded. The ",[74,205,206],{},"US CLOUD Act"," and ",[74,209,210],{},"FISA Section 702"," structurally break this precondition – see our detailed analyses of the ",[213,214,216],"a",{"href":215},"/en/blog/cloud-act-2026","CLOUD Act 2026"," and the ",[213,219,221],{"href":220},"/en/blog/bsi-it-grundschutz-microsoft-365","BSI IT-Grundschutz conflict with Microsoft 365",".",[70,224,225,226,230],{},"On top comes the ",[213,227,229],{"href":228},"/en/blog/nis2-gdpr-microsoft-paradox","NIS-2/GDPR paradox",", which is particularly acute for hospitals: the two frameworks impose opposing chains of accountability if the cloud foundation is not sovereign.",[118,232,234],{"id":233},"what-the-khzg-expiry-changes-economically","What the KHZG expiry changes economically",[70,236,237,238,241],{},"By mid-2026 many hospitals had invested KHZG money in systems built on top of Microsoft 365 – cloud directory services, Teams integrations for wards, SharePoint-based quality management systems. These investments are not lost, but they now have to be measured against the ",[74,239,240],{},"regulatory follow-on cost",":",[126,243,244,250,256,262,268],{},[129,245,246,249],{},[74,247,248],{},"Increased effort for GDPR evidence"," – empirically 0.3 to 0.8 full-time equivalents per year at a mid-sized hospital.",[129,251,252,255],{},[74,253,254],{},"B3S audit cost"," – 50,000 to 150,000 euros per cycle, annual.",[129,257,258,261],{},[74,259,260],{},"NIS-2 legal advice"," – 30,000 to 80,000 euros per year for board liability documentation.",[129,263,264,267],{},[74,265,266],{},"1 July 2026 price increase"," – Business Standard +12 percent, Business Basic +16 percent.",[129,269,270,273],{},[74,271,272],{},"Residual fine exposure"," – up to 2 percent of annual revenue under §60 BSIG.",[70,275,276,277,280],{},"A move to a European sovereign stack typically reaches positive cash flow within ",[74,278,279],{},"14 to 20 months"," – primarily because the compliance evidence burden drops dramatically.",[118,282,284],{"id":283},"the-target-architecture-for-hospitals-in-2026","The target architecture for hospitals in 2026",[70,286,287],{},"Realistic for hospital operations in 2026, built on open standards and operated in German data centres with KRITIS experience:",[126,289,290,295,305,311,317,322],{},[129,291,292,294],{},[74,293,32],{}," as file, forms and collaboration platform, with end-to-end encryption for patient record attachments.",[129,296,297,300,301,222],{},[74,298,299],{},"Element/Matrix"," for internal communication between wards, with auditable chat histories held in German data centres – along the lines of the ",[213,302,304],{"href":303},"/en/blog/eu-commission-matrix","EU Commission's Matrix architecture",[129,306,307,310],{},[74,308,309],{},"Jitsi Meet"," for telemedicine appointments and case conferences.",[129,312,313,316],{},[74,314,315],{},"Collabora Online"," for document editing, LibreOffice compatible.",[129,318,319,321],{},[74,320,48],{}," as central identity provider, connecting to the eGK electronic health card and HBA via the telematics infrastructure connectors.",[129,323,324,327],{},[74,325,326],{},"Local backup chain plus a cold-store copy in a second German data centre",", to enable ransomware reconstruction in under 24 hours.",[70,329,330],{},"Unlike proprietary suites, these building blocks can be swapped individually at any time and integrated with hospital information systems (KIS) via open interfaces.",[118,332,334],{"id":333},"the-economic-comparison-for-a-500-bed-hospital","The economic comparison for a 500-bed hospital",[70,336,337],{},"Reference calculation, magnitude 800 staff, 500 beds, existing Microsoft 365 E3 contract:",[339,340,341,357],"table",{},[342,343,344],"thead",{},[345,346,347,351,354],"tr",{},[348,349,350],"th",{},"Line item",[348,352,353],{},"Microsoft 365 (36 months)",[348,355,356],{},"Sovereign stack (36 months)",[358,359,360,372,383,394,405],"tbody",{},[345,361,362,366,369],{},[363,364,365],"td",{},"Licences/operation",[363,367,368],{},"460,000 €",[363,370,371],{},"210,000 €",[345,373,374,377,380],{},[363,375,376],{},"B3S audit overhead",[363,378,379],{},"240,000 €",[363,381,382],{},"90,000 €",[345,384,385,388,391],{},[363,386,387],{},"GDPR documentation FTE",[363,389,390],{},"220,000 €",[363,392,393],{},"60,000 €",[345,395,396,399,402],{},[363,397,398],{},"One-time migration",[363,400,401],{},"–",[363,403,404],{},"180,000 €",[345,406,407,412,417],{},[363,408,409],{},[74,410,411],{},"Total",[363,413,414],{},[74,415,416],{},"920,000 €",[363,418,419],{},[74,420,421],{},"540,000 €",[70,423,424,425,429],{},"Break-even at 17 months. This pattern mirrors what we showed in our post on the ",[213,426,428],{"href":427},"/en/blog/euro-office-microsoft-365-alternative-2026","EuroOffice alternative"," for administrative environments – for hospitals, the saving on the audit side is markedly higher.",[118,431,433],{"id":432},"conclusion-and-next-steps","Conclusion and next steps",[70,435,436],{},"For German hospitals, exiting Microsoft 365 in the second half of 2026 is no longer a sovereignty luxury but a regulatory necessity. The combination of NIS-2 registration, ePA regular operation, KHZG expiry and personal management liability closes the window for strategic hesitation.",[70,438,439,440,443,444,447,448,222],{},"Any hospital starting the migration now can reallocate the last KHZG residuals, get the target architecture audited by the next B3S round in 2027, and discharge the board's liability under §38 of the NIS-2 Implementation Act. For a first assessment of your hospital stack, we recommend the categorised provider overview at ",[213,441,442],{"href":442},"/en/alternativen",", the live analysis of your current Microsoft 365 data flows at ",[213,445,446],{"href":446},"/en/microsoft",", and an initial conversation via ",[213,449,450],{"href":450},"/en/contact",{"title":452,"searchDepth":453,"depth":453,"links":454},"",2,[455,456,457,458,459,460],{"id":120,"depth":453,"text":121},{"id":175,"depth":453,"text":176},{"id":233,"depth":453,"text":234},{"id":283,"depth":453,"text":284},{"id":333,"depth":453,"text":334},{"id":432,"depth":453,"text":433},"2026-08-04T00:00:00.000Z","NIS-2 registered, ePA in regular operation, KHZG funding ending – for hospital IT, Microsoft 365 is no longer a viable target architecture. The sovereign path.","md",[465,468,471,474,477],{"q":466,"a":467},"Do all hospitals fall under NIS-2 – or only the large KRITIS operators?","All hospitals with at least 50 employees and 10 million euros in annual revenue fall under the amended BSI Act (NIS-2 Implementation Act). The stricter KRITIS obligations apply additionally from 30,000 inpatient cases per year. The deadline for registration with the German Federal Office for Information Security (BSI) was 6 March 2026. Any hospital that has not registered is already in breach of §33 BSIG in conjunction with §60 – with fines of up to 10 million euros or 2 percent of global annual revenue.",{"q":469,"a":470},"What does \"personal liability of management\" actually mean?","§38 of the NIS-2 Implementation Act makes boards and managing directors personally responsible for the implementation of security measures. In the case of an incident traceable to a demonstrable breach of due diligence – for example missing multi-factor authentication, no emergency drills, no business continuity plan – the individual is liable with their private assets. This provision is new and the sharpest instrument in German cybersecurity law. The supervisory board or hospital owner cannot contract out of this liability.",{"q":472,"a":473},"Why is Microsoft 365 regulatorily problematic for hospitals – we already know the standard arguments?","For clinics, three sector-specific aggravations apply on top of the general debate. First, patient data is a special category under Article 9 GDPR – the bar for justifying US-cloud processing is higher than for ordinary administrative data. Second, the sector-specific security standard B3S from the German Hospital Association (DKG) requires evidence of data-processor controls under Article 28 GDPR that are hard to produce given Microsoft's sub-processor cascade. Third, the electronic patient record (ePA) operates on the gematik telematics infrastructure – a sovereign, Germany-bounded system. A hospital background stack in a US cloud creates a structural break with the ePA architecture.",{"q":475,"a":476},"Is a migration still fundable through KHZG money?","The Hospital Future Act (KHZG) provided 4.3 billion euros for digitalisation, of which 15 percent had to go into cybersecurity. Application deadlines are gradually expiring. A move to a European alternative platform is still eligible for funding if the application is filed under KHZG funding category 10 as a security measure – for example, replacement of cloud services with an unsafe access situation. Hospitals should clarify in parallel with the Federal Office for Social Security and the responsible state authority whether residual funds from active grants can be reallocated.",{"q":478,"a":479},"What became of the 18 hospitals hit by ransomware in 2024 – is there any public evaluation?",{"The Federal Office for Information Security documents the affected sectors annually in its status report, but without naming individual institutions":480},{" Recurring patterns include":481},"initial access via compromised Microsoft 365 accounts without multi-factor authentication, lateral movement via Active Directory, and encryption of file servers and backup chains. In at least three cases the emergency department had to be closed. Not a single documented case was successfully rebuilt via cloud provider support – reconstruction happened in every case through on-premises backups.",{"name":483,"description":484,"totalTime":485,"steps":486},"Set up a regulatorily viable hospital cloud stack in nine months","A step-by-step path for hospital IT leadership to move from the Microsoft 365 status quo to an NIS-2 and B3S compliant sovereign collaboration platform.","P270D",[487,490,493,498,503,506,509,514,519,522],{"name":488,"text":489},"Complete NIS-2 registration and self-classification","In month one, complete the BSI registration if missed and document the self-classification under §28 BSIG – important or particularly important entity, employee and revenue thresholds, additional KRITIS obligations. This classification determines reporting obligations and fine ranges. Without it, every subsequent step is formally exposed.",{"name":491,"text":492},"Separate the data catalogue by GDPR Article 9","In month two, classify every data category of the existing Microsoft 365 installation by sensitivity level. Isolate patient data and health information as special categories under Article 9 GDPR – this category may not, per Data Protection Conference interpretation, be processed in a US cloud without a strengthened legal basis. Assess administrative data, personnel data and communications separately.",{"name":494,"text":495},"Determine the B3S delta",{"In month three, use the existing B3S audit reports from the DKG to identify the concrete requirements Microsoft 365 does not meet today, or only meets with additional measures":496},{" Critical points":497},"data processor obligations under Article 28 GDPR, sub-processor transparency, deletion concepts, access control under IT-Grundschutz building block SYS.1.5. The delta is the business case foundation for the switch.",{"name":499,"text":500},"Define the target architecture",{"In month four, decide the target architecture":501},{" Realistic for hospital operations in 2026":502},"Nextcloud as a file and collaboration platform in a German data centre, Element on Matrix for internal communication between wards, Jitsi Meet for case conferences and telemedicine appointments, Collabora Online for document editing. The categorised overview of sovereign providers at /en/alternativen provides the list – for hospital operations, extended by certified data centre operators with KRITIS experience.",{"name":504,"text":505},"Verify integration with the telematics infrastructure","In month five, verify connectivity to the telematics infrastructure and the ePA. gematik connectors are protocol-open – there was never a Microsoft-specific lock-in, but many hospitals have built middleware integrations against Exchange or SharePoint. These integrations must be included in the migration plan and moved onto open APIs. Without this step, access to ePA and e-prescriptions breaks during the migration window.",{"name":507,"text":508},"File the KHZG reallocation request","In month six, file the reallocation request for active KHZG grants if applicable. Funding category 10 – IT security – permits reallocation if the switch is documented as a security measure. The justification includes the B3S delta analysis from step 3 and the documented assessment of the US cloud access situation. Approval typically takes eight to twelve weeks.",{"name":510,"text":511},"Deploy a pilot ward",{"In month seven, roll out a pilot ward or department":512},{" Our recommendation":513},"radiology or administration, because both have clearly bounded user groups and defined workflows. Parallel operation with Microsoft 365 for four weeks, user training, feedback capture. The pilot is the stress test for later fleet-wide rollout.",{"name":515,"text":516},"Fleet rollout and data migration",{"From month eight, migrate in waves":517},{" Recommended sequence":518},"administrative areas first, then clinical departments, then emergency medicine last. Exchange mailboxes via PST or IMAP migration, OneDrive contents via Microsoft Graph export, SharePoint libraries as OpenXML. The EU Data Act has guaranteed export without additional fees since 12 September 2025 – detailed analysis in our post on the [Data Act switching window](/en/blog/eu-data-act-cloud-switching-microsoft-365-exit-january-2027).",{"name":520,"text":521},"Introduce emergency drills and incident reporting","In month nine, implement the full NIS-2 reporting workflow – first report within 24 hours, interim report within 72 hours, final report within one month. Run a scenario-based ransomware drill and document it. This drill also doubles as compliance evidence for the personal exoneration of management under §38 of the NIS-2 Implementation Act.",{"name":523,"text":524},"Shutdown and deletion confirmation","After the migration is complete, deactivate the Microsoft tenant and obtain written confirmation of full data deletion under Article 28(3)(g) GDPR. Keep the deletion confirmation on file for the retention period of patient records – as a rule 30 years under §630f BGB. Without it, an open GDPR item remains in the record of processing activities.",{"src":526},"https://images.unsplash.com/photo-1587351021355-a479a299d2f9?w=1200&q=80",{},true,"/en/blog/hospital-nis2-microsoft-365-sovereign-cloud-alternative-2026",{"title":53,"description":462},"en/3.blog/23.hospital-nis2-microsoft-365-sovereign-cloud-alternative-2026","TFBHBQLbyC4xXJTkZ2c7_VSE8f_r-q-L9-T4jtIJiOk",[534,539],{"title":535,"path":536,"stem":537,"description":538,"children":-1},"Six Months to 12 January 2027 – How the EU Data Act Rewrites the Microsoft 365 Exit Math for German SMEs and Public-Sector Bodies","/en/blog/eu-data-act-cloud-switching-microsoft-365-exit-january-2027","en/3.blog/22.eu-data-act-cloud-switching-microsoft-365-exit-january-2027","On 12 January 2027 the EU Data Act bans egress and switching fees outright. What that means for Microsoft 365 contracts and how IT leaders should plan now.",{"title":540,"path":541,"stem":542,"description":543,"children":-1},"Sovereignty Washing 2026 – Why Microsoft 365 Local and the Munich Sovereignty Studio do not release German municipalities from the CLOUD Act","/en/blog/sovereignty-washing-microsoft-365-local-municipalities-2026","en/3.blog/24.sovereignty-washing-microsoft-365-local-municipalities-2026","M365 Local is GA, the Munich Sovereignty Studio is open, openDesk 1.17 is in the Chancellery – municipalities need a fact-check, not marketing.",1788852143375]