When NIS2 comes up in a medical practice, everyone looks toward the server room. Backups, hospital systems, image archives, multi-factor authentication. Those matter, and I have written about them in the piece on NIS2 in 2026 and who it applies to.
Here, though, I want to look somewhere else entirely, somewhere almost nobody mentions in those conversations. At the desk at the front of the clinic.
Because there, between a paper book, a spreadsheet on a shared drive and a mailbox, several hundred pieces of information pass every day about who is going to see which doctor. The server room is usually in better shape than that part.
First, to be clear: this is genuinely how it looks
I am not writing this from the position of somebody passing judgement. I am writing it because we have seen it in several clinics and it looks similar everywhere, including where people work very well indeed.
Four phone lines. A paper book or a printed rota the receptionist adds to in pen. A spreadsheet on a shared drive where somebody keeps the waiting list, because doing it in the practice management system is awkward. A bookings@ mailbox receiving requests for slots, rescheduling and questions about results. A group chat where receptionists arrange cover and, along the way, pass each other information about patients. A note with the system password stuck under a keyboard, because the password changes every thirty days and nobody can remember it.
All of this works. It has worked for years and patients get seen. The problem is that part of this arrangement is an inconvenience and part of it is something else entirely.
What is an inconvenience and what is not
This distinction is the heart of the whole text, so let me put it plainly.
An inconvenience is the receptionist copying a slot from the paper book into the system. The waiting list living in a spreadsheet. A queue forming when two people are off. That costs time and nerves, but it endangers nobody.
Something else entirely is not knowing who has had access to the patient list. The spreadsheet on the shared drive being visible to everyone with an account, including the person who left six months ago and whose account nobody disabled. The contents of the bookings@ mailbox sitting on the private phone of whoever happens to be on duty. Nobody being able to say what a departing employee took with them, because there is no way to check.
The difference is not that one is more dramatic than the other. It is that the first is your internal affair and the second is processing health data without control over who can reach it. And that is subject to rules somebody will eventually check.
One more thing that is easy to forget: the mere fact that Mr Kowalski has an appointment with an oncologist tomorrow is information about his health. You do not need medical records for that. A rota is enough.
NIS2 seen from the front desk
NIS2 is the EU cybersecurity directive. In Poland it was implemented by an amendment to the national cybersecurity act that entered into force on 3 April 2026. Health care is one of the sectors covered, and many clinics are falling under these obligations for the first time in their history.
Who exactly is covered and against what thresholds is a separate subject. What interests me here is narrower: which of these obligations touch the desk at the front of the clinic rather than the server room.
Access control. Who has access to the patient list and how you know that. This is not about a declaration, it is about being able to answer that question at any moment. Named accounts instead of shared ones, permissions granted per person, and a list somebody can open and read.
An employee leaving. This is the moment the whole arrangement gets tested. A receptionist leaves. Somebody disables her account in the practice management system, because that one is remembered. Access to the shared drive, the bookings@ mailbox, the group chat and the waiting list spreadsheet stays, because nobody ever wrote it down. A leaver procedure covering every location rather than only the most obvious one is explicitly one of the expected elements.
Copies and retention. Where the copies of that spreadsheet live. How many versions the document history on the shared drive holds. How long emails from three years ago hang in the bookings@ mailbox. „I do not know" is the most common answer here and simultaneously the worst one, because it means nothing can be erased on request or restored after an outage.
Incidents. The front desk is where an incident is most likely to start and most likely to be noticed. A call from somebody claiming to be from the health fund and asking for patient data. An attachment in an email that looked like a referral. Somebody leaving the rota open on a monitor facing the waiting room. The person on reception has to know who to report it to and within what time, and that takes one sheet of paper, not a system.
Team awareness. The training that genuinely makes a difference at the front desk is not about encryption. It is about what a call sounds like when somebody is trying to extract data, and what to say then.
What changes when bookings go through a system
I do not want to sell the idea that deploying online booking solves any of the points above. It does not. It does change the shape of the problem, and it is worth knowing how.
When bookings go through one system instead of a paper book, a spreadsheet and a mailbox at once, you get three things you did not have before.
One place instead of five. The question „who has access to the patient list" stops requiring an inventory of drives and mailboxes. It has a single answer.
Per-person permissions and a change history. You can see who moved an appointment and when. This is the same function that saves an hour of explaining during a patient complaint, and during an incident is the only source of facts.
An employee leaving becomes one click instead of a list of places to remember.
On top of that comes something operational rather than regulatory: a text reminder instead of a confirmation call. With one trap few people think about. The content of a text is visible on a lock screen. „Reminder: your appointment at the addiction treatment clinic tomorrow at 2pm" is health information displayed to whoever happens to be sitting next to them. The name of the specialty should not appear in a reminder.
What this does not solve
Let me say this plainly, because this is where it is easy to be dishonest.
Online booking does not close NIS2. It is one element in a much larger whole, alongside risk analysis, procedures, backups, supplier management and incident handling. If somebody is selling you a booking system as the answer to NIS2, they are selling you something it is not.
It also does not replace the practice management system and it should not. The patient-facing layer stands in front of it, never instead of it.
And something that tends to be unwelcome: you gain a supplier. Every new system is a new entity processing patient data, a new processing agreement and a new entry in the risk analysis. That is not an argument against, it is a line in the calculation you need to know before the decision rather than after.
A deadline worth knowing about now
One specific date, because it is close. The amendment gave entities six months from entry into force to apply for entry in the register of essential and important entities. That deadline falls on 3 October 2026. Full implementation of the obligations, including an information security management system, runs to 3 April 2027, and the first audit to 3 April 2028.
I am not writing this to frighten anyone, but because several clinics we talk to simply did not know the first of those dates was so close. If you are not sure whether it applies to you, this is exactly the week to ask.
Where to start, with no invoice attached
Three things you can do yourself within a week, worth more than many a deployment.
Write down where patient data lives today. Not as a twenty-page document, just a list on one sheet. Practice management system, paper book, spreadsheet on the drive, mailbox, group chat, private phones. That list alone tends to surprise management and is the way into every subsequent conversation.
Check the accounts of people who have left. Every location from the list above, not only the practice management system. This is the most common hole we see and the cheapest to close.
Write one sheet for the front desk. What to do when somebody calls asking for patient data on the authority of an institution. Who to report it to. Within what time. One sheet taped up at the workstation does more here than an hour of training once a year.
None of this needs a budget or a supplier. It needs one afternoon and a decision that the front desk is part of the clinic's security rather than just the place where the phone gets answered.
If you would like to walk this list through for your own clinic, or you are wondering where a booking system and an assistant answering the phone fit into all this, write to me. The conversation costs nothing and usually shortens the subject by a few weeks, because the person at the table has done this rather than sold it.
What we do for medical practices is described here.



