40 medical practices hit: cyberattack at an IT provider
On 22 August 2026, a cyberattack crippled the cloud infrastructure of BMS Engineering in Luxembourg. The company confirmed 40 practices affected, no confirmed leak, while one practice reported patient data loss.
On 22 August 2026, a cyberattack crippled part of the cloud infrastructure of BMS Engineering, an IT provider widely used by medical practices in Luxembourg. Six days later, the company confirmed 40 practices affected and no confirmed data leak; one practice nevertheless reported patient data loss.
Key facts
- Who/what: BMS Engineering, hosting practice management software (including eMed), suffered an attack targeting its cloud.
- Where/when: Luxembourg; attack detected on 22 August 2026; first reports published 7–9 September 2026.
- How many: 40 practices affected according to BMS; temporary data unavailability; police and CNPD notified; external experts engaged. Reporter.lu initially mentioned “at least 80” practices, later revised by BMS to 40. The Bohler Gynecology Group reported “destruction and loss of data (including personal data)” as of 22 August, while ensuring continuity of care. No ransom demand or public attribution at this stage.
Legal context
- NIS 2 in Luxembourg: Directive (EU) 2022/2555 was transposed by the law of 5 May 2026. Healthcare operators and their IT providers face cybersecurity, governance and incident notification duties. See NIS 2 in Luxembourg for applicable requirements.
- Incident notification (Art. 23 NIS 2): early warning within 24 h, notification within 72 h, and a final report within one month to ILR and the national CSIRT.
- GDPR (CNPD): any destruction, loss, alteration or unavailability of personal data triggers breach notification to the CNPD within 72 h (Art. 33) and data subject communication if high risk (Art. 34). The Bohler statement about “data loss” typically activates obligations under the GDPR.
What this changes for companies
- Real third‑party exposure: It was not a hospital but a network of practices and their host that were immobilized. Healthcare entities and IT subcontractors are squarely within NIS 2 and GDPR scope.
- Evidence and deadlines: When facing outages or data loss, leadership must evidence NIS 2 measures (governance, risk management, detection, logging) and meet tight timelines: 24 h/72 h under NIS 2; 72 h under GDPR if personal data are impacted.
- Clinical continuity and traceability: Patient record unavailability, even without “exfiltration,” has tangible effects. Business continuity plans (RPO/RTO), immutable backups, restoration tests and local failover procedures are now “auditable” and contractual. For 24/7 threat detection and response, consider a managed SOC for incident detection.
Immediate actions to take this week
- Map critical dependencies and healthcare IT contracts: Identify third‑hosted systems/practitioners (e.g., eMed), verify NIS 2 self‑registration, RPO/RTO clauses, reversibility, and joint ILR/CNPD notification within 24–72 h.
- Run an end‑to‑end restoration test: Perform a cold restore on a sample of records, validate integrity and logging, and document evidence (reports, timestamps) for ILR/CNPD.
- Harden operations: Enable phishing‑resistant MFA, deploy EDR on servers/endpoints, implement 24/7 monitoring and snapshot‑deletion detection; require attestations of immutable backups and network segmentation.
- Prepare regulatory communications: Update the incident playbook with ILR/CSIRT channels and the CNPD form, “significant incident” thresholds, legal escalation matrix, and patient notification templates.
Key takeaway
Healthcare IT supply chains are a systemic risk. Anticipating NIS 2 and GDPR obligations, proving technical and contractual resilience, and safeguarding clinical continuity have become non‑negotiable.
Article generated by Luxgap regulatory watch. For tailored guidance on this topic, contact us.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →