European Union
EHDS
The European Health Data Space regulates electronic health record (EHR) systems and the primary and secondary use of health data across the EU: patient access rights, EHR system interoperability and logging, and the conditions for secondary use in research, policymaking, and AI training. Applies from 26 March 2027, staggered through 2031 for specific provisions.
33 articles
Subject matter and scope
Establishes the European Health Data Space (EHDS): common rules, standards, infrastructures and governance to facilitate primary use (healthcare provision) and secondary use (research, innovation, policymaking) of electronic health data.
Definitions
Defines the EHDS's core terms: personal/non-personal/electronic health data, primary use, secondary use, EHR/EHR system, health data holder, health data user, data permit, secure processing environment, and the harmonised European interoperability/logging software components.
Right of natural persons to access their personal electronic health data
Patients have the right to free, immediate, easily readable access to at least the priority categories of their electronic health data, through an electronic health data access service, once registered in an EHR system.
Electronic health data access services for natural persons and their representatives
Member States must ensure free electronic health data access services (patient portals/apps) exist, including proxy services letting patients authorise others (e.g. family members, legal guardians) to access their data on their behalf.
Right of natural persons to insert information in their own EHR
Patients can add information to their own EHR, but it must be clearly distinguishable from health-professional-entered data and cannot be used to alter what a health professional recorded.
Right of natural persons to rectification
Patients can request online rectification of incorrect electronic health data, free of charge, per GDPR Article 16, with health-professional verification where needed.
Right to data portability for natural persons
Patients can direct any healthcare provider to transmit their electronic health data to another provider of their choice, free of charge, including cross-border in the standard European exchange format.
Right to restrict access
Patients can restrict which health professionals/providers can see all or part of their electronic health data; the fact a restriction exists is itself hidden from providers unless vital interests require emergency access.
Right to obtain information on accessing data
Patients have the right to see (via automatic notifications) who accessed their electronic health data, when, and which data -- retained for at least 3 years -- through the health professional access service.
Right of natural persons to opt out in primary use
Member States may let patients opt out of having their electronic health data registered/accessible in an EHR system for primary use, reversibly, subject to emergency-care safeguards.
Access by health professionals to personal electronic health data
Health professionals treating a patient must have access to that patient's relevant priority-category electronic health data, including cross-border, via a health professional access service.
Registration of personal electronic health data
Healthcare providers must register priority-category electronic health data in an EHR system electronically, keep it updated, and record which health professional/provider carried out each registration/update.
Priority categories of personal electronic health data for primary use
Defines the six mandatory priority data categories: patient summaries, electronic prescriptions, electronic dispensations, medical imaging studies/reports, medical test results, and discharge reports.
Harmonised software components of EHR systems
EHR systems must include two mandatory harmonised software components: a European interoperability component (exchanging priority-category data in the standard format) and a European logging component (recording access events).
Placing on the market and putting into service
EHR systems (including SaaS-delivered EHR systems and those manufactured/used within health institutions) may only be placed on the market or put into service if they comply with Chapter III.
Relation to Union law governing medical devices, in vitro diagnostic medical devices and AI systems
High-risk AI systems (under EU AI Act Article 6) that claim interoperability with the EHR harmonised software components must prove compliance with the same interoperability and logging essential requirements as EHR systems themselves.
Obligations of manufacturers of EHR systems
EHR system manufacturers must ensure conformity with Annex II essential requirements, draw up technical documentation, issue an EU declaration of conformity, affix CE marking, register in the EU database, and handle non-conformity/corrective action.
Common specifications
The Commission will adopt common technical specifications (datasets, coding systems, interoperability profiles, security/patient-safety requirements) that EHR systems, medical devices, and high-risk AI systems interacting with EHR data must follow.
CE marking of conformity
CE marking must be visibly, legibly, and indelibly affixed before an EHR system is placed on the market, subject to the general CE-marking principles in Regulation (EC) No 765/2008.
Handling of risks posed by EHR systems and of serious incidents
Manufacturers must report any serious incident involving an EHR system to market surveillance authorities no later than 3 days after becoming aware of it (once a causal link is established), and cooperate on corrective action.
Essential requirements for identification and authentication of health professionals
An EHR system used by health professionals must provide reliable mechanisms for identifying and authenticating those health professionals before granting access.
Essential requirements for logging of EHR systems
The EHR system's European logging software component must record, for every access event: who accessed the data (provider/individual and specific natural person), which data categories, when, and the origin of the data.
Applicability to health data holders
Individual researchers and legal persons qualifying as microenterprises are exempt from health-data-holder secondary-use obligations, unless a Member State opts to apply them anyway.
Minimum categories of electronic health data for secondary use
Health data holders must make available for secondary use a broad list of categories: EHR data, health determinants, healthcare-needs/resource data, pathogen data, genetic/genomic/molecular data, wellness-app data, and more.
Purposes for which electronic health data can be processed for secondary use
Secondary use is only permitted for specific purposes: public/occupational health, policymaking, statistics, education, scientific research (including training/testing/evaluating AI systems and algorithms), and care-delivery improvement.
Prohibited secondary use
Data obtained via a data permit can never be used for detrimental decisions about people, discriminatory decisions (insurance, credit, employment), advertising/marketing, harmful products (drugs, tobacco, weapons), or activities that breach national ethical rules.
Health data access bodies
Each Member State designates health data access body/bodies to decide on data access applications, issue data permits, and supervise secondary-use compliance -- these are external national regulators, not something a tenant operates.
Duties of health data users
Health data users may only access data under an issued permit, cannot pass access to unlisted third parties, must never attempt to re-identify patients, and must publish results within 18 months and acknowledge the EHDS as the data source.
General conditions for the imposition of administrative fines by health data access bodies
Health data access bodies can fine health data holders/users up to EUR 10M/2% of turnover for basic secondary-use non-compliance, and up to EUR 20M/4% of turnover for serious infringements like prohibited-use processing, data extraction, or re-identification attempts.
Data permit
A health data access body issues a data permit only after assessing purpose-legitimacy, data minimisation, GDPR compliance, applicant qualification, and adequate technical/organisational safeguards against misuse -- the core authorisation mechanism for secondary use.
Right to opt out from the processing of personal electronic health data for secondary use
Patients can opt out of secondary use of their electronic health data at any time, reversibly, without giving a reason, via an accessible national opt-out mechanism.
Secure processing environment
Secondary-use data access must go through a secure processing environment with strict security measures, including identifiable access logs kept for at least one year, regularly audited by the health data access body.
Penalties
Member States must set effective, proportionate, dissuasive penalties for EHDS infringements not already covered by the Article 63/64 administrative-fines regime, based on criteria like severity, duration, and prior infringements.
Turn EHDS into tracked tasks
eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.
Start free trial