European Health Data Space
EU regulation establishing a common framework for health data sharing across member states. Effective 2026, enables secondary use of health data for research while maintaining patient privacy.
What EU EHDS draws on
This framework pulls on 2 pillars of the platform.
Compliance
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Secondary Use Logging
Health data access bodies MUST log all queries and data access for secondary use purposes.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Data Provenance
REQUIRES complete provenance tracking of health data from source through all processing stages.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Access Control
Organizations MUST implement technical measures to ensure only authorized researchers access data.
Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.
Security Requirements
REQUIRES appropriate technical and organizational measures to protect health data during secondary use.
Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.
What EU EHDS covers
Art. 2(2); priority categories at Annex I
Electronic health data — personal or non-personal data relating to health, in electronic form.
In scope
- Patient summaries
- Electronic prescriptions and dispensations
- Medical imaging and imaging reports
- Laboratory results
- Discharge reports
Categories excluded from secondary use (Art. 33(4))
The instrument's own term, kept as it writes it — these labels differ between frameworks on purpose.
- Genetic data of a person, where it would allow re-identification and the person opted out
What falls outside
Data held outside the health sector that merely relates to wellbeing is not electronic health data for the priority categories.
Regulation (EU) 2025/327 · as at 2026-08
How EU EHDS is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by National health data access bodies and market surveillance authorities.
| Published maximum | Charged | As at |
|---|---|---|
| EUR 20 million or 4% of total worldwide annual turnover | for the more serious infringements | 2026-08 |
| EUR 10 million or 2% of total worldwide annual turnover | for less serious infringements | 2026-08 |
The European Health Data Space carries a GDPR-shaped penalty structure of its own, with a lower tier of EUR 10 million or 2% for less serious infringements. Health data access bodies can also act against a data user directly, independently of the supervisory authority.
Obligations phase in over several years from entry into force, so which provisions are live depends on the date.
Uncapped exposure that sits outside this instrument
These come from company law rather than from EU EHDS, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for EU EHDS,
not configured for it afterwards
Research Data Access Monitoring
Track all secondary use data queries for medical research
EHDS Provenance Report
Complete data lineage and access history for compliance
EU Health Data Patterns
Identify health records across EU member state formats
Unauthorized Research Access
Alert on access outside approved research protocols
Other Healthcare frameworks
Walk into the EU EHDS audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.