← Back to Home
EHDS — Regulation EU 2025/327

European Health Data Space

The most transformative EU healthcare regulation since GDPR — primary and secondary use of health data, EHR certification, interoperability requirements, and the new patient rights framework.

What the EHDS Means for Healthcare

The European Health Data Space Regulation (EU 2025/327), published on 5 March 2025, creates a uniform framework for accessing, sharing, and using electronic health data across the entire European Union. It distinguishes between primary use (patient care, with enhanced citizen rights and cross-border portability) and secondary use (research, public health, innovation, and regulation, through a new governance framework with Health Data Access Bodies).

For healthcare organisations, the EHDS introduces binding obligations around EHR system certification, data quality standards, interoperability requirements, and new patient rights that go beyond GDPR. For MedTech and digital health companies, it creates both compliance obligations and market opportunities through harmonised data access frameworks.

Key Obligations for Healthcare Organisations

By Jan 2026

EHR System Certification

Manufacturers and operators of electronic health record systems must certify conformity with EHDS interoperability and security requirements. Self-certification with CE-like marking and EU declaration of conformity.

By Mar 2027

Data Quality Standards

Healthcare organisations must ensure clinical data meets EU-defined quality standards for semantics, consistency, accuracy, and completeness. Technical specifications to be adopted by the Commission through implementing acts.

By Mar 2027

European Exchange Format

Adoption of the European electronic health record exchange format for cross-border health data portability. Machine-readable, standardised format enabling data transmission between providers across Member States.

Ongoing

Enhanced Patient Rights

Citizens gain the right to access, download, transmit, and restrict access to their electronic health data across any EU Member State. Organisations must implement mechanisms for cross-border patient data portability.

EHDS Implementation Roadmap

Mar 2025
Regulation Published
Jun 2025
National Authorities
Jan 2026
EHR Certification
Mar 2027
Quality & Format
2028
Secondary Use Live

Penalties for non-compliance may reach EUR 20 million or 4% of annual global turnover, mirroring the GDPR sanctions regime. The Commission will adopt delegated and implementing acts to detail technical requirements throughout the implementation period.

Integrated Healthcare Compliance Network

Clinical compliance across the EU integrates with a specialised ecosystem covering every dimension of healthcare regulation — from data protection and cybersecurity to sector-wide compliance and dedicated officer services.

Healthcare Compliance

Central hub for comprehensive healthcare regulatory compliance

Visit healthcarecompliance.pt →

Clinical Data Protection

Data protection in clinical research and healthcare practice

Visit clinicaldataprotection.pt →

Health Cybersecurity

Specialised cybersecurity for hospitals and healthcare organisations

Visit healthcybersecurity.pt →

Healthcare DPO

Specialised Data Protection Officer services for healthcare

Visit healthcaredpo.pt →

Clinical Compliance PT

Clinical compliance platform for Portuguese healthcare organisations

Visit clinicalcompliance.pt →

Get in Touch

Need support preparing for the EHDS across multiple EU jurisdictions? Contact us for a cross-border impact assessment and implementation roadmap.

By submitting this form, you authorise the processing of your personal data in accordance with our Data Protection Policy.

Direct Contacts

Offices
Lisbon · Brussels · San Francisco
The information provided is for informational purposes only and does not constitute legal or professional advice on clinical compliance matters. Legislation cited may have been amended. Always consult the current version of legal instruments through official channels.