New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
← Legislation library

European Union

EHDS

The European Health Data Space regulates electronic health record (EHR) systems and the primary and secondary use of health data across the EU: patient access rights, EHR system interoperability and logging, and the conditions for secondary use in research, policymaking, and AI training. Applies from 26 March 2027, staggered through 2031 for specific provisions.

33 articles

Article 1

Subject matter and scope

Establishes the European Health Data Space (EHDS): common rules, standards, infrastructures and governance to facilitate primary use (healthcare provision) and secondary use (research, innovation, policymaking) of electronic health data.

Article 2

Definitions

Defines the EHDS's core terms: personal/non-personal/electronic health data, primary use, secondary use, EHR/EHR system, health data holder, health data user, data permit, secure processing environment, and the harmonised European interoperability/logging software components.

Article 3

Right of natural persons to access their personal electronic health data

Patients have the right to free, immediate, easily readable access to at least the priority categories of their electronic health data, through an electronic health data access service, once registered in an EHR system.

Article 4

Electronic health data access services for natural persons and their representatives

Member States must ensure free electronic health data access services (patient portals/apps) exist, including proxy services letting patients authorise others (e.g. family members, legal guardians) to access their data on their behalf.

Article 5

Right of natural persons to insert information in their own EHR

Patients can add information to their own EHR, but it must be clearly distinguishable from health-professional-entered data and cannot be used to alter what a health professional recorded.

Article 6

Right of natural persons to rectification

Patients can request online rectification of incorrect electronic health data, free of charge, per GDPR Article 16, with health-professional verification where needed.

Article 7

Right to data portability for natural persons

Patients can direct any healthcare provider to transmit their electronic health data to another provider of their choice, free of charge, including cross-border in the standard European exchange format.

Article 8

Right to restrict access

Patients can restrict which health professionals/providers can see all or part of their electronic health data; the fact a restriction exists is itself hidden from providers unless vital interests require emergency access.

Article 9

Right to obtain information on accessing data

Patients have the right to see (via automatic notifications) who accessed their electronic health data, when, and which data -- retained for at least 3 years -- through the health professional access service.

Article 10

Right of natural persons to opt out in primary use

Member States may let patients opt out of having their electronic health data registered/accessible in an EHR system for primary use, reversibly, subject to emergency-care safeguards.

Article 11

Access by health professionals to personal electronic health data

Health professionals treating a patient must have access to that patient's relevant priority-category electronic health data, including cross-border, via a health professional access service.

Article 13

Registration of personal electronic health data

Healthcare providers must register priority-category electronic health data in an EHR system electronically, keep it updated, and record which health professional/provider carried out each registration/update.

Article 14

Priority categories of personal electronic health data for primary use

Defines the six mandatory priority data categories: patient summaries, electronic prescriptions, electronic dispensations, medical imaging studies/reports, medical test results, and discharge reports.

Article 25

Harmonised software components of EHR systems

EHR systems must include two mandatory harmonised software components: a European interoperability component (exchanging priority-category data in the standard format) and a European logging component (recording access events).

Article 26

Placing on the market and putting into service

EHR systems (including SaaS-delivered EHR systems and those manufactured/used within health institutions) may only be placed on the market or put into service if they comply with Chapter III.

Article 27

Relation to Union law governing medical devices, in vitro diagnostic medical devices and AI systems

High-risk AI systems (under EU AI Act Article 6) that claim interoperability with the EHR harmonised software components must prove compliance with the same interoperability and logging essential requirements as EHR systems themselves.

Article 30

Obligations of manufacturers of EHR systems

EHR system manufacturers must ensure conformity with Annex II essential requirements, draw up technical documentation, issue an EU declaration of conformity, affix CE marking, register in the EU database, and handle non-conformity/corrective action.

Article 36

Common specifications

The Commission will adopt common technical specifications (datasets, coding systems, interoperability profiles, security/patient-safety requirements) that EHR systems, medical devices, and high-risk AI systems interacting with EHR data must follow.

Article 41

CE marking of conformity

CE marking must be visibly, legibly, and indelibly affixed before an EHR system is placed on the market, subject to the general CE-marking principles in Regulation (EC) No 765/2008.

Article 44

Handling of risks posed by EHR systems and of serious incidents

Manufacturers must report any serious incident involving an EHR system to market surveillance authorities no later than 3 days after becoming aware of it (once a causal link is established), and cooperate on corrective action.

Article Annex II §3.1

Essential requirements for identification and authentication of health professionals

An EHR system used by health professionals must provide reliable mechanisms for identifying and authenticating those health professionals before granting access.

Article Annex II §3.2

Essential requirements for logging of EHR systems

The EHR system's European logging software component must record, for every access event: who accessed the data (provider/individual and specific natural person), which data categories, when, and the origin of the data.

Article 50

Applicability to health data holders

Individual researchers and legal persons qualifying as microenterprises are exempt from health-data-holder secondary-use obligations, unless a Member State opts to apply them anyway.

Article 51

Minimum categories of electronic health data for secondary use

Health data holders must make available for secondary use a broad list of categories: EHR data, health determinants, healthcare-needs/resource data, pathogen data, genetic/genomic/molecular data, wellness-app data, and more.

Article 53

Purposes for which electronic health data can be processed for secondary use

Secondary use is only permitted for specific purposes: public/occupational health, policymaking, statistics, education, scientific research (including training/testing/evaluating AI systems and algorithms), and care-delivery improvement.

Article 54

Prohibited secondary use

Data obtained via a data permit can never be used for detrimental decisions about people, discriminatory decisions (insurance, credit, employment), advertising/marketing, harmful products (drugs, tobacco, weapons), or activities that breach national ethical rules.

Article 55

Health data access bodies

Each Member State designates health data access body/bodies to decide on data access applications, issue data permits, and supervise secondary-use compliance -- these are external national regulators, not something a tenant operates.

Article 61

Duties of health data users

Health data users may only access data under an issued permit, cannot pass access to unlisted third parties, must never attempt to re-identify patients, and must publish results within 18 months and acknowledge the EHDS as the data source.

Article 64

General conditions for the imposition of administrative fines by health data access bodies

Health data access bodies can fine health data holders/users up to EUR 10M/2% of turnover for basic secondary-use non-compliance, and up to EUR 20M/4% of turnover for serious infringements like prohibited-use processing, data extraction, or re-identification attempts.

Article 68

Data permit

A health data access body issues a data permit only after assessing purpose-legitimacy, data minimisation, GDPR compliance, applicant qualification, and adequate technical/organisational safeguards against misuse -- the core authorisation mechanism for secondary use.

Article 71

Right to opt out from the processing of personal electronic health data for secondary use

Patients can opt out of secondary use of their electronic health data at any time, reversibly, without giving a reason, via an accessible national opt-out mechanism.

Article 73

Secure processing environment

Secondary-use data access must go through a secure processing environment with strict security measures, including identifiable access logs kept for at least one year, regularly audited by the health data access body.

Article 99

Penalties

Member States must set effective, proportionate, dissuasive penalties for EHDS infringements not already covered by the Article 63/64 administrative-fines regime, based on criteria like severity, duration, and prior infringements.

Turn EHDS into tracked tasks

eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.

Start free trial