Digitalization is transforming healthcare institutions into complex systems in which data, applications, and devices are constantly connected and deeply intertwined. Consequently, enormous benefits can be gained both by healthcare operators and by patients; likewise, many threats have to be faced in terms of information security and data protection. In this chapter, we address such topics in the European Union legal framework analyzing the impact in the field of endorobots of the most recent regulations, notably Directive (EU) 2016/1148 (Network Information Security Directive) and Regulation (EU) 2016/679 (GDPR), and assessing potential challenges and opportunities for engineers and designers.