Compliance evidence for healthcare and health tech on Azure
Special category data under GDPR. Essential entity status under NIS2.
The regulatory driver
Health data is special category data under Article 9 GDPR, and healthcare providers are classified as essential entities under NIS2. That combination puts the highest supervisory expectations on the smallest compliance teams.
Evidence of encryption, access logging, retention limits and network isolation is what a supervisory authority asks for first.
What Equalis OpsReg shows you
- ✓GDPR Article 32 technical measures evaluated continuously
- ✓NIS2 essential-entity controls across 82 rules
- ✓Encryption at rest and in transit verified per resource, not assumed
- ✓Access and diagnostic logging gaps surfaced before an incident, not after
What exposure looks like
Health data is special category data under Article 9 GDPR. Serious infringements carry fines of up to 20 million euros or 4 percent of annual worldwide turnover, whichever is higher.
Healthcare providers are also essential entities under NIS2. Article 34 sets fines of at least 10 million euros or 2 percent of total worldwide annual turnover, whichever is higher, and those are floors: Member States may set higher national ceilings, and several have.
Article 20 NIS2 places personal accountability on management bodies for approving and overseeing cybersecurity measures.
Both regimes apply to the same estate at the same time.
Why generic tooling falls short here
Certification-first tooling
Platforms built around SOC 2 and ISO 27001 readiness treat GDPR and NIS2 as mappings rather than as the primary frameworks. In European healthcare that is the wrong way round.
Policies are not posture
Questionnaire and policy management shows what you intended. Article 32 asks what was actually configured.
Retention
Evidence written once and kept for seven years is a different engineering problem from a dashboard that reflects today.