Skip to content

Phone bookings in a clinic covered by NIS2: where convenience ends and risk begins

9 min readIntermediate

With NIS2 everyone looks toward the server room. Meanwhile a paper book, a spreadsheet on a shared drive and a bookings mailbox say more about patients than anyone assumes. Which obligations touch the front desk.

Hands on a keyboard at a bright wooden desk in morning sunlight, the monitor blurred and blank

When NIS2 comes up in a medical practice, everyone looks toward the server room. Backups, hospital systems, image archives, multi-factor authentication. Those matter, and I have written about them in the piece on NIS2 in 2026 and who it applies to.

Here, though, I want to look somewhere else entirely, somewhere almost nobody mentions in those conversations. At the desk at the front of the clinic.

Because there, between a paper book, a spreadsheet on a shared drive and a mailbox, several hundred pieces of information pass every day about who is going to see which doctor. The server room is usually in better shape than that part.

First, to be clear: this is genuinely how it looks

I am not writing this from the position of somebody passing judgement. I am writing it because we have seen it in several clinics and it looks similar everywhere, including where people work very well indeed.

Four phone lines. A paper book or a printed rota the receptionist adds to in pen. A spreadsheet on a shared drive where somebody keeps the waiting list, because doing it in the practice management system is awkward. A bookings@ mailbox receiving requests for slots, rescheduling and questions about results. A group chat where receptionists arrange cover and, along the way, pass each other information about patients. A note with the system password stuck under a keyboard, because the password changes every thirty days and nobody can remember it.

All of this works. It has worked for years and patients get seen. The problem is that part of this arrangement is an inconvenience and part of it is something else entirely.

What is an inconvenience and what is not

This distinction is the heart of the whole text, so let me put it plainly.

An inconvenience is the receptionist copying a slot from the paper book into the system. The waiting list living in a spreadsheet. A queue forming when two people are off. That costs time and nerves, but it endangers nobody.

Something else entirely is not knowing who has had access to the patient list. The spreadsheet on the shared drive being visible to everyone with an account, including the person who left six months ago and whose account nobody disabled. The contents of the bookings@ mailbox sitting on the private phone of whoever happens to be on duty. Nobody being able to say what a departing employee took with them, because there is no way to check.

The difference is not that one is more dramatic than the other. It is that the first is your internal affair and the second is processing health data without control over who can reach it. And that is subject to rules somebody will eventually check.

One more thing that is easy to forget: the mere fact that Mr Kowalski has an appointment with an oncologist tomorrow is information about his health. You do not need medical records for that. A rota is enough.

NIS2 seen from the front desk

NIS2 is the EU cybersecurity directive. In Poland it was implemented by an amendment to the national cybersecurity act that entered into force on 3 April 2026. Health care is one of the sectors covered, and many clinics are falling under these obligations for the first time in their history.

Who exactly is covered and against what thresholds is a separate subject. What interests me here is narrower: which of these obligations touch the desk at the front of the clinic rather than the server room.

Access control. Who has access to the patient list and how you know that. This is not about a declaration, it is about being able to answer that question at any moment. Named accounts instead of shared ones, permissions granted per person, and a list somebody can open and read.

An employee leaving. This is the moment the whole arrangement gets tested. A receptionist leaves. Somebody disables her account in the practice management system, because that one is remembered. Access to the shared drive, the bookings@ mailbox, the group chat and the waiting list spreadsheet stays, because nobody ever wrote it down. A leaver procedure covering every location rather than only the most obvious one is explicitly one of the expected elements.

Copies and retention. Where the copies of that spreadsheet live. How many versions the document history on the shared drive holds. How long emails from three years ago hang in the bookings@ mailbox. „I do not know" is the most common answer here and simultaneously the worst one, because it means nothing can be erased on request or restored after an outage.

Incidents. The front desk is where an incident is most likely to start and most likely to be noticed. A call from somebody claiming to be from the health fund and asking for patient data. An attachment in an email that looked like a referral. Somebody leaving the rota open on a monitor facing the waiting room. The person on reception has to know who to report it to and within what time, and that takes one sheet of paper, not a system.

Team awareness. The training that genuinely makes a difference at the front desk is not about encryption. It is about what a call sounds like when somebody is trying to extract data, and what to say then.

What changes when bookings go through a system

I do not want to sell the idea that deploying online booking solves any of the points above. It does not. It does change the shape of the problem, and it is worth knowing how.

When bookings go through one system instead of a paper book, a spreadsheet and a mailbox at once, you get three things you did not have before.

One place instead of five. The question „who has access to the patient list" stops requiring an inventory of drives and mailboxes. It has a single answer.

Per-person permissions and a change history. You can see who moved an appointment and when. This is the same function that saves an hour of explaining during a patient complaint, and during an incident is the only source of facts.

An employee leaving becomes one click instead of a list of places to remember.

On top of that comes something operational rather than regulatory: a text reminder instead of a confirmation call. With one trap few people think about. The content of a text is visible on a lock screen. „Reminder: your appointment at the addiction treatment clinic tomorrow at 2pm" is health information displayed to whoever happens to be sitting next to them. The name of the specialty should not appear in a reminder.

What this does not solve

Let me say this plainly, because this is where it is easy to be dishonest.

Online booking does not close NIS2. It is one element in a much larger whole, alongside risk analysis, procedures, backups, supplier management and incident handling. If somebody is selling you a booking system as the answer to NIS2, they are selling you something it is not.

It also does not replace the practice management system and it should not. The patient-facing layer stands in front of it, never instead of it.

And something that tends to be unwelcome: you gain a supplier. Every new system is a new entity processing patient data, a new processing agreement and a new entry in the risk analysis. That is not an argument against, it is a line in the calculation you need to know before the decision rather than after.

A deadline worth knowing about now

One specific date, because it is close. The amendment gave entities six months from entry into force to apply for entry in the register of essential and important entities. That deadline falls on 3 October 2026. Full implementation of the obligations, including an information security management system, runs to 3 April 2027, and the first audit to 3 April 2028.

I am not writing this to frighten anyone, but because several clinics we talk to simply did not know the first of those dates was so close. If you are not sure whether it applies to you, this is exactly the week to ask.

Where to start, with no invoice attached

Three things you can do yourself within a week, worth more than many a deployment.

Write down where patient data lives today. Not as a twenty-page document, just a list on one sheet. Practice management system, paper book, spreadsheet on the drive, mailbox, group chat, private phones. That list alone tends to surprise management and is the way into every subsequent conversation.

Check the accounts of people who have left. Every location from the list above, not only the practice management system. This is the most common hole we see and the cheapest to close.

Write one sheet for the front desk. What to do when somebody calls asking for patient data on the authority of an institution. Who to report it to. Within what time. One sheet taped up at the workstation does more here than an hour of training once a year.

None of this needs a budget or a supplier. It needs one afternoon and a decision that the front desk is part of the clinic's security rather than just the place where the phone gets answered.

If you would like to walk this list through for your own clinic, or you are wondering where a booking system and an assistant answering the phone fit into all this, write to me. The conversation costs nothing and usually shortens the subject by a few weeks, because the person at the table has done this rather than sold it.

What we do for medical practices is described here.

Frequently asked questions

Is online booking enough to satisfy NIS2?
No. Online booking tidies up one area, namely access to the patient list and a change history, but NIS2 covers risk analysis, procedures, backups, supplier management, incident handling and management accountability. Treating a booking system as the answer to NIS2 is a misunderstanding that usually surfaces at the first audit.
Is an appointment rota in a spreadsheet on a shared drive a problem?
It depends on whether you can say who has access to it and how long copies are kept. The spreadsheet itself is not prohibited. The problem is the absence of control over access and retention, because a patient list with clinic names is information about their health.
What happens when a front desk employee leaves?
A procedure should kick in covering every place that person had access to: the practice management system, the shared drive, the team mailbox, the group chat, the work phone. In practice only the practice management account gets disabled and the rest stays. That is the gap worth checking first.
By when does a medical practice have to register as an essential or important entity?
The amendment to the Polish national cybersecurity act entered into force on 3 April 2026 and allowed six months to apply, so the deadline falls on 3 October 2026. Full implementation of the obligations is due by 3 April 2027 and the first audit by 3 April 2028. Whether a given practice is covered, and as an essential or an important entity, depends on its type and size.
Can a text reminder include the name of the clinic department?
Better not. The content of a text appears on a phone's lock screen, so the name of a specialty can reveal health information to a bystander. Safe content contains the date, the time and the name of the practice, without naming the department or the doctor.
Does a voice assistant answering the phone help or hinder under NIS2?
It does both. It tidies up booking, because everything lands in one register with a change history, while at the same time adding a supplier, a processing agreement and a new entry in the risk analysis. I have described this at greater length in the pieces on what a voice assistant actually does and what you have to settle with its supplier.