The European Health Data Space (EHDS) marks the beginning of a progressive transformation in the way electronic health data can be accessed and exchanged in Europe.
Discover the key aspects of the EHDS, its implementation schedule, and the main challenges it presents.
What is EHDS and why does it affect an entity with health data?
The European Health Data Area (EHDS) is the first European regulatory framework specifically designed to facilitate access, sharing and reuse of electronic health data across the EU.
It is not a recommendation or a directive for voluntary transposition: it is a regulation that is directly applicable in all Member States.
The EHDS affects any entity that generates, manages, or controls electronic health data (health data providers). These entities have specific obligations in two areas:
- Primary use: The health data it manages must be available to other healthcare providers. In turn, patients will have rights regarding access to their own clinical information, portability, and control over who can see it.
- Secondary use: the health data it manages must be made available to researchers, health authorities and other authorized users for research, innovation or public health policy.
What data will I need to be able to share?
The categories defined for sharing are subdivided according to:
- Primary use: clinical summaries, electronic prescriptions and dispensing, medical images and radiology reports, test and laboratory results, and hospital discharge reports.
- Secondary uses: electronic health record data, medical records, health administration data, medical device data, wellness app and biobank data, genetic, genomic and molecular data, completed clinical trial data, cohort and research data, and health determinants data
When do these obligations come into effect?
- March 2029:
- Primary use: clinical summaries, electronic prescriptions and dispensing.
- Secondary use: electronic health record data, medical records, health administration data, medical device data, wellness application data, and biobank data, among other categories.
- March 2031:
- Primary use: medical images and radiology reports, test and laboratory results, and hospital discharge reports.
- Secondary use: genetic, genomic and molecular data, data from completed clinical trials, cohort and research data, and data on determinants of health.
Does this include only new data or also historical data? The obligation includes historical data already in digital format, not just data generated from 2029 onwards.
What are the consequences of not complying with the EHDS?
The EHDS establishes effective and dissuasive sanctions for entities that do not comply with their obligations: significant financial fines, exclusion from European healthcare interoperability platforms, and the right of any patient to claim compensation if their rights under the EHDS have not been respected.
What technical interoperability requirements does the EHDS imply for the electronic health record?
Healthcare providers must ensure that their EHR systems are interoperable within the European Health Data Area. Specifically:
- Adopt the EEHRxF (European Electronic Health Record Exchange Format) format, the common standard that makes clinical data readable and interchangeable anywhere in the European health data space.
- Keep data updated and accessible in real time , avoiding outdated records that could compromise continuity of care.
- Ensure data portability : the patient must be able to download and transfer their data to any other EU provider.
What rights will citizens have over their health data?
Citizens will have greater control, access and decision-making power over their health information.
Primary use (direct healthcare)
- Immediate access: access your digital health data immediately, free of charge and in a common electronic format readable throughout the European Union.
- Portability: Download your health data in a standard format and transfer it to another EU healthcare provider.
- Add your own information: you should be able to incorporate health data into your medical record.
- Access control and traceability: they must be able to check who has accessed the data, when and from which health center.
- Access restriction: limiting which healthcare professionals can access which parts of your medical record, without informing the professional. In emergency situations, the provider can lift the restriction through an emergency access mechanism (breaking the glass).
Secondary use (Research, innovation and public policy)
This refers to the reuse of anonymized or pseudonymized data for the purposes of scientific research, medical innovation, or public health planning:
- Right to opt out: You have the right to object to your data being used for secondary purposes. Once exercised, no new access permissions may include your data, but data already included in previously approved datasets is not affected retroactively. Opting out is reversible at any time.
- Guarantee of anonymity and privacy: Data is processed in secure processing environments (SPEs), in strict compliance with the GDPR. Researchers and authorized users access the data without the possibility of extracting it or directly identifying the patient.
Which actors are involved in exchanging data with Europe?
The EHDS distinguishes two exchange circuits with their own infrastructures and actors.
Primary use
MyHealth@EU is the EU's digital infrastructure that enables the cross-border exchange of health data for healthcare. It functions as a network of interconnected national nodes, ensuring that a patient's clinical data is available to the healthcare professional treating them in another Member State.
When a patient receives care in another Member State, the actors involved are:
- Patients: Your clinical data is available in any Member State connected to MyHealth@EU. You do not need to authorize each access, although you can restrict which data is visible or, if your Member State allows it, opt out of the exchange altogether.
- Healthcare providers: hospitals, primary care centers, specialists, pharmacies, and clinics that generate and consult patient clinical data. They are the direct contacts in the healthcare process.
- National Contact Points for eHealth (NCPeH): the organizational and technical gateway of each Member State for the exchange of health data in primary use. It connects to the NCPeHs of the other Member States and to the central MyHealth@EU platform, enables the exchange of priority data categories, and acts as a joint controller for the processing of personal data circulating through the infrastructure.
Secondary use
Data sharing for research, health policy, or innovation is channeled through HealthData@EU , the EU's digital infrastructure for accessing health data for secondary use. It operates as a federated network: data remains under national custody and is accessed through secure processing environments (SPEs) connected to a central platform managed by the European Commission.
- Health data holders : entities required to make their data available, with the obligation to catalog and review it annually.
- Health data users (health data users): researchers, academic institutions, pharmaceutical companies and health authorities requesting access for an approved legitimate purpose.
- Health data access bodies (HDAB) : National authorities that assess applications, grant permits, and monitor the use of data within the EPS. The EHDS allows for the designation of more than one HDAB per Member State, opening the door to a model with a coordinating HDAB at the Ministry of Health level and its own bodies in each Autonomous Community.
Which entities may be affected by the EHDS? Does it also affect private entities?
EHDS can affect a wide range of organizations involved in the generation, management, exchange, or reuse of electronic health data.
These include, depending on the type of activity and the specific obligations applicable:
- hospitals and hospital groups,
- clinics and medical centers,
- primary care centers and clinics,
- laboratories,
- diagnostic and imaging centers,
- pharmacies and other healthcare providers,
- public and private entities in the healthcare sector,
- providers of electronic health record systems and other digital health solutions,
- other organizations that manage certain categories of electronic health data.
The fact that an organization is private does not mean it falls outside the scope of the EHDS. Its specific applicability will depend on factors such as its activities, the type of data it manages, its role within the healthcare ecosystem, and the specific obligations set out in the Regulation and its national implementation.
For these entities, one of the first questions should be: What role does our organization play within the health data ecosystem, and which EHDS obligations might apply to us? The answer will not necessarily be the same for everyone: a small specialist clinic, a laboratory, a private hospital, or a large healthcare group may have very different systems, data, and responsibilities.
Therefore, a recommended first step is to carry out an assessment that identifies what information the organization manages, where it is located, what systems support it, and what EHDS requirements may be applicable to its activity.
The EHDS should therefore be understood as a progressive transformation that affects the entire health and digital ecosystem involved in the management of electronic health data.
How will data security and privacy be guaranteed?
The EHDS establishes that access to and exchange of electronic health data must be carried out under strict security measures, data protection and access control.
The Regulation builds upon the General Data Protection Regulation (GDPR) and adds specific requirements for the healthcare sector. This means that the exchange of information must guarantee:
- Identification and authentication of users accessing information.
- Access is based , in the case of primary use, on a care purpose and on the corresponding permissions, avoiding indiscriminate access.
- Traceability of access: citizens must know who has accessed their data, in the cases provided for by the Regulation.
- Cybersecurity measures to protect the confidentiality, integrity, and availability of information.
- Secure exchange between systems and countries , using common infrastructures and standards.
- Strengthened rights for citizens , including mechanisms to access their information and exercise their rights.
- Specific measures for exceptional situations , such as the necessary access to protect vital interests, which must be duly recorded.
The goal of the EHDS is not for health data to be openly available, but to be accessible when needed for a legitimate purpose, by authorized persons and under security and traceability mechanisms.
For healthcare organizations, this means that adapting to EHDS will not only be an interoperability challenge. It will also require reviewing identity and access management capabilities, auditing, traceability, cybersecurity, and patient rights management.
Is having a digital medical record enough to be prepared for the EHDS?
Not necessarily. It's an important starting point, but it doesn't mean the organization is ready to meet EHDS requirements.
An organization may have clinical information in digital format and find that the data:
- They are distributed across different systems and repositories,
- They are stored in PDF documents or free text,
- They use local codes or terminology,
- They are not structured according to interoperability standards
- applicable,
- cannot be easily located or recovered,
- They present problems of quality, completeness, or consistency,
- They lack interfaces or mechanisms for secure exchange,
- They lack adequate traceability and access control mechanisms.
Therefore, preparing for the EHDS requires going beyond digitization. The goal is for information to be located, understood, structured, exchanged, and used securely and interoperably , in accordance with applicable specifications.
A healthcare organization should first determine what information it has, in what format, and what level of adaptation is needed to meet EHDS requirements. Answering this typically requires an analysis of information systems, the data they manage, its quality, its level of structure, and its interoperability capabilities.
Therefore, having a digital medical record is a good starting point, but it is not the end of the road to EHDS readiness.