The European Health Data Space is moving from legislation to implementation. For hospitals, the immediate priority is not to wait for 2029: it is to build the governance, interoperability, data-quality and procurement capability needed to operate safely and effectively in a more connected European health-data environment.
European Union | 24 September 2026
Regulation (EU) 2025/327 establishing the European Health Data Space (EHDS) entered into force on 26 March 2025. Its application is deliberately phased: key implementing acts are due by March 2027, major primary- and secondary-use provisions begin to apply in March 2029, and further priority health-data categories follow in March 2031.
That timetable can create a false sense of distance.
Hospitals cannot build interoperability, improve data quality, redesign access controls, strengthen information governance, review EHR procurement and develop workforce capability in the final months before a legal deadline. The European Commission’s June 2026 implementation dialogue already identified resource constraints and a perceived lack of urgency among healthcare providers as practical implementation challenges.
EHDS is not only a digital-health project
EHDS affects patient rights, clinical information flows, EHR procurement, cybersecurity, research, data quality, organisational accountability and the ability of health systems to use data for improvement.
The central management question is therefore not simply “Are our systems connected?” It is “Can our organisation govern, exchange and reuse health data in a way that is reliable, secure, interoperable and trusted?”
What does the EHDS actually do?
The EHDS creates a common European framework for the use and exchange of electronic health data. It is built around three closely connected areas.
Primary use
Individuals gain stronger access to and control over their electronic health data, while healthcare professionals should be able to access relevant information more easily, including across borders.
Secondary use
Electronic health data can be reused under defined safeguards for research, innovation, policy-making, regulation and health-system improvement through a structured access-permit model.
EHR systems
The Regulation establishes harmonised legal and technical requirements for electronic health record systems, with a strong focus on interoperability and security.
Patient rights become an operational issue
The EHDS strengthens individuals’ ability to access their electronic health data, share it with healthcare professionals, request corrections, see who has accessed their data and view information in a standard European format. It also introduces rights to restrict access to all or parts of personal electronic health data exchanged through EHDS infrastructures, subject to the Regulation and national implementation choices.
For hospital management, these rights must eventually become operational processes rather than legal statements. That requires coordination between clinical services, health-information management, IT, data protection, patient services and governance teams.
Hospitals should start asking whether identity and access-management processes are robust, whether access logs are usable and auditable, whether correction workflows are clear, and whether patients receive understandable information about how their data is accessed and used.
Interoperability becomes a management capability
EHDS is closely linked to the European electronic health record exchange format and to a future in which priority categories of health information can move more consistently between systems and Member States.
For hospitals, interoperability is not achieved by purchasing a single interface. It depends on standards, architecture, terminology, structured information, data quality, workflow design and supplier cooperation.
Legacy systems may therefore become a strategic risk if they cannot exchange information reliably or if suppliers cannot support future European requirements.
Five management workstreams
- Governance: define executive accountability for health-data strategy, access, quality and compliance.
- Interoperability: identify where systems, standards and workflows prevent reliable exchange.
- Data quality: treat structured, complete and trustworthy data as a clinical and organisational asset.
- Procurement: make interoperability, portability, security and future EHDS readiness explicit purchasing requirements.
- Workforce: prepare clinicians, managers and technical teams for new data-access, documentation and governance practices.
Secondary use changes the role of hospital data
EHDS creates a structured framework for reusing health data for purposes such as scientific research, innovation, public health, policy-making and regulatory activity. Access will be governed through Health Data Access Bodies and secure processing environments, with defined permitted and prohibited uses.
For organisations that are health data holders, this creates practical responsibilities. The Commission’s EHDS FAQ explains that data holders will need to submit descriptions of relevant datasets to Health Data Access Bodies according to the phased timetable and may be required to make data available following a permit or request decision.
Hospitals therefore need to understand what datasets they hold, how those datasets are described, how quality is assured, what documentation exists and who is responsible for responding to future data-access processes.
Secondary use should not be treated as a research-office issue alone. It intersects with data protection, information security, clinical governance, legal functions, research governance and institutional strategy.
EHDS does not replace GDPR or cybersecurity governance
The EHDS builds on existing horizontal European frameworks, including the General Data Protection Regulation. It adds health-sector-specific rules rather than creating a separate privacy universe.
Hospitals should avoid setting up parallel EHDS, GDPR, cybersecurity and AI governance structures that do not communicate with each other. Access control, data minimisation, security, incident response, secondary use, research and AI increasingly concern the same information assets and should have a connected escalation route.
EHR procurement needs to change before the deadlines
One of the clearest management implications is procurement. Hospitals entering long-term EHR, imaging, laboratory, pharmacy or interoperability contracts should avoid creating technology dependencies that become expensive barriers to EHDS implementation.
Procurement teams should increasingly ask suppliers to demonstrate:
- support for relevant European interoperability standards and formats;
- data portability and export capabilities;
- clear responsibilities for updates and regulatory changes;
- security controls and incident cooperation;
- access to documentation needed to verify performance and compliance;
- transparent subcontracting and hosting arrangements;
- credible roadmaps for future EHDS-related requirements.
A practical 180-day agenda for hospital leaders
Map and assign ownership
Create an executive EHDS readiness group. Map major clinical and administrative data flows, EHR dependencies, data owners, access arrangements and current interoperability barriers.
Identify where the organisation already depends on data that cannot be exchanged or reused reliably.
Assess readiness and procurement
Review core systems, data quality, patient-access processes, identity and access management, supplier contracts and major procurements against the EHDS roadmap.
Prioritise gaps that require multi-year investment rather than short-term configuration.
Build the implementation roadmap
Agree a multi-year roadmap covering interoperability, data quality, governance, procurement, workforce capability and secondary-use readiness.
Connect EHDS planning with GDPR, cybersecurity, AI governance, research and digital investment rather than creating a parallel compliance programme.
The implementation timetable
The timetable should be treated as an implementation runway. Hospitals should avoid investing now in systems, contracts or data models that make future interoperability more difficult.
Seven questions for every hospital board
- Who has executive accountability for EHDS readiness?
- Which of our core systems create the greatest interoperability or data-portability risk?
- Can we demonstrate the quality and provenance of the health data we rely on?
- Are patient access, correction, restriction and audit processes designed for a more connected data environment?
- Do current procurement contracts protect future interoperability, security and data-control needs?
- Are clinical leaders involved in data governance rather than leaving it solely to IT?
- How are EHDS, GDPR, cybersecurity, research governance and AI governance connected at executive level?
From compliance to data capability
The EHDS can support continuity of care, research, innovation and more evidence-informed management. But value will not result from regulation alone.
Hospitals will need strong information governance, interoperable infrastructure, high-quality data, competent professionals and clear accountability. The organisations that prepare early will be better placed not only to comply, but to use health data more effectively for patients, professionals and health-system improvement.
Map. Standardise. Govern. Connect. Prepare.
EHDS readiness begins long before the first major application deadlines.
Official resources
This article reflects the EU implementation position in August 2026 and provides general information, not legal advice. Detailed obligations phase in over time and should be assessed together with applicable national law, GDPR, cybersecurity requirements and forthcoming EHDS implementing acts.
Secretary-General perspective
EHDS will test more than Europe’s digital infrastructure. It will test whether healthcare organisations have the governance and management capacity to turn connected data into safer care, better decisions and greater public value.
Leandro Luís · Secretary-General, European Association of Hospital Managers
