EHDS in healthcare: preparing your IT strategy for the years ahead

IT Strategy · 3 min

Industry: Healthcare

Articles by Fábio Ribeiro

The European Health Data Space applies in phases. Learn how healthcare providers can sequence investments, software contracts and clinical data work.

EHDS in healthcare: preparing your IT strategy for the years ahead

TL;DR

The EHDS enters the healthcare IT plan

For hospitals, clinics, laboratories and private healthcare groups in Portugal, Regulation (EU) 2025/327, which establishes the European Health Data Space (EHDS), is no longer just a legal matter and now shapes the IT roadmap. The regulation entered into force on 26 March 2025 and applies, as a general rule, from 26 March 2027, with several obligations taking effect later. For IT teams, the practical question is how to sequence investments in clinical record systems, integration and data quality across this timeline, without incurring unnecessary costs too early or accumulating delays that are hard to recover.

A phased timeline calls for phased decisions

The gradual application is the main planning variable. The rules applicable to the first priority categories (patient summaries, electronic prescriptions and electronic dispensations) take effect from 26 March 2029. For medical imaging studies and related reports, test results, associated reports and discharge reports, application takes place from 26 March 2031. The provisions on secondary use, for purposes such as research, innovation or public policy, apply mainly from 2029. This suggests treating the EHDS as a multi-year programme, with milestones aligned with these dates and periodic reviews, because the European Commission has yet to adopt implementing acts with technical specifications, including the European electronic health record exchange format. Planning around evolving specifications requires room for adjustment.

Electronic health record systems now have their own requirements

The regulation requires electronic health record systems that process priority categories to include a European interoperability component and a European logging component, and it assigns manufacturers obligations such as the EU declaration of conformity and CE marking. For the provider, the most relevant decision tends to be contractual: when renewing or acquiring electronic health record systems covered by the EHDS, it is good practice to ask the vendor for an EHDS compliance roadmap, expected dates and update conditions. In environments with many local integrations or custom developments, it is advisable to confirm who ensures the compliance of those extensions and to include portability clauses, in line with an exit and reversibility strategy.

Know your data before you integrate it

The regulation strengthens individuals' rights regarding access to and transmission of their electronic health data. In the cross-border context, MyHealth@EU is the European infrastructure designed to support the exchange of priority categories of data between national contact points for digital health. In practice, this requires knowing where the priority-category data is, in what format, with what coding, and which systems produce it. Reports stored only as scanned documents, inconsistent clinical terminologies or information scattered across departmental applications can become a bigger obstacle than the integration technology itself. A mapping of systems and data flows, similar to what is maintained in a CMDB, can help prioritise where to intervene first.

Security, traceability and compliance converge

The EHDS does not replace the GDPR and does not override other rules, such as those applicable to medical devices or artificial intelligence. Certain healthcare-sector entities may also fall under the NIS2 regime, so it makes sense to align the applicable requirements in areas such as access management, event logging, supplier management and incident response. Secondary use introduces another dimension: the data holders concerned will have obligations to make certain categories of data available through the mechanisms provided for in the EHDS, and citizens also have a right to opt-out of secondary use, subject to the conditions and exceptions set out in the regulation. The scope of these obligations depends on the type and size of the entity, and a gap assessment, carried out internally or with specialist support, helps separate what is a legal obligation from what is good practice.

Prepare with method, without over-anticipating

The EHDS can help make electronic health data more interoperable to access and share, including in cross-border contexts, but preparation requires coordination between IT, clinical leadership and data protection. For most providers, the most balanced path is to link the regulation's timeline to software renewal cycles, understand data quality and follow the technical specifications as they are published. Since part of the rules still depends on implementing acts and national frameworks, decisions should be reviewed periodically and validated with legal support whenever they involve concrete obligations.

Related

References

  1. Regulamento (UE) 2025/327 relativo ao Espaço Europeu de Dados de Saúde (EUR-Lex)
  2. A&O Shearman: European Health Data Space Regulation sets requirements for electronic health record systems
  3. Regulamento Espaço Europeu de Dados de Saúde (EEDS)