Skip to main content
Documentation

Other frameworks

EHDS: European Health Data Space

Regulation (EU) 2025/327 establishes the European Health Data Space (EHDS): patient rights to access and port their own electronic health data, requirements for EHR systems (interoperability, logging, CE marking), and a governed framework for secondary use of health data in research, policymaking, and AI training. It's important to get the timing right: the Regulation entered into force on 26 March 2025, but its obligations do not apply until 26 March 2027 at the earliest, with EHR system conformity (Chapter III) not applying until 26 March 2031 and secondary-use governance (Chapter IV) generally from 26 March 2029. Nothing in this platform claims you are 'EHDS compliant' today -- every obligation here is framed as preparation ahead of those dates.

Transcript

The European Health Data Space is different from every other framework here. It doesn't actually apply until March twenty twenty seven, but that is exactly why getting ready now matters.

Enabling it adds a curated set of obligations covering patient access rights, EHR system requirements, and secondary use, including AI training data governance.

The EHDS Readiness Statement is explicit about what it is: a preparation record, not a compliance certificate, because no EHDS obligation is legally binding yet.

A handful of provisions are platform managed today: special category health data identified through the PII scan, health professional authentication, and tamper evident access logging.

The rest are honest preparation tasks: EHR conformity, secondary use governance, and the prohibited uses your team should already understand before twenty twenty nine.

A high readiness score today just means you won't be scrambling in twenty twenty seven. This is preparation, not a claim that you are already compliant.

Why this is required

Articles 3-12 give patients rights over their electronic health data: free immediate access, rectification, portability, restriction, and visibility into who accessed their records.

Article 27 explicitly extends the EHR interoperability and logging requirements to high-risk AI systems (under the EU AI Act) that claim interoperability with EHR systems -- a direct link between EHDS and AI governance.

Article 53 permits secondary use of health data for a defined list of purposes, explicitly including 'training, testing and evaluation of algorithms, including in medical devices, in vitro diagnostic medical devices, AI systems and digital health applications' -- the primary route by which health-tech AI companies would access data for model development under the EHDS.

Article 73 and Annex II require tamper-evident, identifiable access logs for both the secondary-use secure processing environment and EHR systems themselves, kept for at least one year and open to audit.

What EuroCompliant does

Enabling EHDS adds a curated set of obligations to your Obligations page, covering patient access rights, EHR system requirements, secondary-use governance (including the AI-training purpose), and logging/accountability. A handful are platform-managed today: special-category/health data identification (via the PII + GLiNER scan), health-professional identification/authentication (via identity audit), tamper-evident access logging (via the platform's SHA-256 audit hash chain), and high-risk AI system inventory. Everything else is an honest tenant_action, phrased as 'in preparation for' the relevant 2027-2031 application date, not a current-compliance claim.

A note on the logging mechanism specifically: this platform's audit log is a SHA-256 hash chain (tamper-evident, verifiable), not an Ed25519-signed log. Ed25519 signing exists in this platform, but only for signing generated documents, not for the audit log itself -- worth knowing if you're mapping this to EHDS's logging requirements precisely.

An EHDS Readiness Statement & Data-Flow Inventory document is available from the Documents section: your registered systems, monitored connectors, and the same live obligation-readiness scorecard the Obligations page shows, explicitly labelled as a readiness statement rather than a compliance certificate.

Walking through it

1

Enable EHDS

Adds the curated obligation set, including the platform-managed checks, so you can start tracking readiness well ahead of the 2027 application date.

Open /settings/profile?tab=frameworks โ†’
2

Connect identity, PII-discovery, and logging evidence

An identity connector drives health-professional authentication readiness; a PII/special-category scan (Presidio + GLiNER) drives health-data-identification readiness; your platform audit trail already drives the tamper-evident logging checks.

Open /settings/integrations โ†’
3

Generate and review the Readiness Statement

Review the data-flow inventory and provision-readiness scorecard together -- this is preparation material for 2027-2031, not something to present as current compliance.

Open /compliance-docs โ†’

The law

Penalties for non-compliance

Health data access bodies can fine health data holders/users up to EUR 10,000,000 or 2% of worldwide annual turnover for basic secondary-use non-compliance, and up to EUR 20,000,000 or 4% for serious infringements (prohibited-use processing, extracting data from a secure processing environment, or re-identification attempts). Member States set separate penalty regimes for other infringements (Article 99), to be notified to the Commission by 26 March 2027.

Frequently asked

Do we need to do anything about EHDS right now?

Nothing is legally required yet -- the Regulation doesn't apply until 26 March 2027 at the earliest, and EHR system conformity not until 2031. If you're a health-tech company, EHR vendor, or handle health data for research/AI training, enabling this framework now gives you a multi-year head start on an unusually well-telegraphed compliance deadline, rather than scrambling in 2026-2027.

How does EHDS relate to GDPR for health data we already handle?

EHDS specifies and complements GDPR rather than replacing it (Article 1(2)(a)). Health data remains GDPR Article 9 special category data, and GDPR's lawful-basis and rights framework still applies -- EHDS adds EHR-specific technical requirements and a structured secondary-use access regime on top.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial