News 24.09.2026 The European Health Data Space is becoming hospital governance

The European Health Data Space is moving from legislation to implementation. For hospitals, the immediate priority is not to wait for 2029: it is to build the governance, interoperability, data-quality and procurement capability needed to operate safely and effectively in a more connected European health-data environment.

European Union | 24 September 2026

Regulation (EU) 2025/327 establishing the European Health Data Space (EHDS) entered into force on 26 March 2025. Its application is deliberately phased: key implementing acts are due by March 2027, major primary- and secondary-use provisions begin to apply in March 2029, and further priority health-data categories follow in March 2031.

That timetable can create a false sense of distance.

Hospitals cannot build interoperability, improve data quality, redesign access controls, strengthen information governance, review EHR procurement and develop workforce capability in the final months before a legal deadline. The European Commission’s June 2026 implementation dialogue already identified resource constraints and a perceived lack of urgency among healthcare providers as practical implementation challenges.

EHDS is not only a digital-health project

EHDS affects patient rights, clinical information flows, EHR procurement, cybersecurity, research, data quality, organisational accountability and the ability of health systems to use data for improvement.

The central management question is therefore not simply “Are our systems connected?” It is “Can our organisation govern, exchange and reuse health data in a way that is reliable, secure, interoperable and trusted?”

What does the EHDS actually do?

The EHDS creates a common European framework for the use and exchange of electronic health data. It is built around three closely connected areas.

Primary use

Individuals gain stronger access to and control over their electronic health data, while healthcare professionals should be able to access relevant information more easily, including across borders.

Secondary use

Electronic health data can be reused under defined safeguards for research, innovation, policy-making, regulation and health-system improvement through a structured access-permit model.

EHR systems

The Regulation establishes harmonised legal and technical requirements for electronic health record systems, with a strong focus on interoperability and security.

Patient rights become an operational issue

The EHDS strengthens individuals’ ability to access their electronic health data, share it with healthcare professionals, request corrections, see who has accessed their data and view information in a standard European format. It also introduces rights to restrict access to all or parts of personal electronic health data exchanged through EHDS infrastructures, subject to the Regulation and national implementation choices.

For hospital management, these rights must eventually become operational processes rather than legal statements. That requires coordination between clinical services, health-information management, IT, data protection, patient services and governance teams.

Hospitals should start asking whether identity and access-management processes are robust, whether access logs are usable and auditable, whether correction workflows are clear, and whether patients receive understandable information about how their data is accessed and used.

Interoperability becomes a management capability

EHDS is closely linked to the European electronic health record exchange format and to a future in which priority categories of health information can move more consistently between systems and Member States.

For hospitals, interoperability is not achieved by purchasing a single interface. It depends on standards, architecture, terminology, structured information, data quality, workflow design and supplier cooperation.

Legacy systems may therefore become a strategic risk if they cannot exchange information reliably or if suppliers cannot support future European requirements.

Five management workstreams

  • Governance: define executive accountability for health-data strategy, access, quality and compliance.
  • Interoperability: identify where systems, standards and workflows prevent reliable exchange.
  • Data quality: treat structured, complete and trustworthy data as a clinical and organisational asset.
  • Procurement: make interoperability, portability, security and future EHDS readiness explicit purchasing requirements.
  • Workforce: prepare clinicians, managers and technical teams for new data-access, documentation and governance practices.

Secondary use changes the role of hospital data

EHDS creates a structured framework for reusing health data for purposes such as scientific research, innovation, public health, policy-making and regulatory activity. Access will be governed through Health Data Access Bodies and secure processing environments, with defined permitted and prohibited uses.

For organisations that are health data holders, this creates practical responsibilities. The Commission’s EHDS FAQ explains that data holders will need to submit descriptions of relevant datasets to Health Data Access Bodies according to the phased timetable and may be required to make data available following a permit or request decision.

Hospitals therefore need to understand what datasets they hold, how those datasets are described, how quality is assured, what documentation exists and who is responsible for responding to future data-access processes.

Secondary use should not be treated as a research-office issue alone. It intersects with data protection, information security, clinical governance, legal functions, research governance and institutional strategy.

EHDS does not replace GDPR or cybersecurity governance

The EHDS builds on existing horizontal European frameworks, including the General Data Protection Regulation. It adds health-sector-specific rules rather than creating a separate privacy universe.

Hospitals should avoid setting up parallel EHDS, GDPR, cybersecurity and AI governance structures that do not communicate with each other. Access control, data minimisation, security, incident response, secondary use, research and AI increasingly concern the same information assets and should have a connected escalation route.

EHR procurement needs to change before the deadlines

One of the clearest management implications is procurement. Hospitals entering long-term EHR, imaging, laboratory, pharmacy or interoperability contracts should avoid creating technology dependencies that become expensive barriers to EHDS implementation.

Procurement teams should increasingly ask suppliers to demonstrate:

  • support for relevant European interoperability standards and formats;
  • data portability and export capabilities;
  • clear responsibilities for updates and regulatory changes;
  • security controls and incident cooperation;
  • access to documentation needed to verify performance and compliance;
  • transparent subcontracting and hosting arrangements;
  • credible roadmaps for future EHDS-related requirements.

A practical 180-day agenda for hospital leaders

Days 1–60

Map and assign ownership

Create an executive EHDS readiness group. Map major clinical and administrative data flows, EHR dependencies, data owners, access arrangements and current interoperability barriers.

Identify where the organisation already depends on data that cannot be exchanged or reused reliably.

Days 61–120

Assess readiness and procurement

Review core systems, data quality, patient-access processes, identity and access management, supplier contracts and major procurements against the EHDS roadmap.

Prioritise gaps that require multi-year investment rather than short-term configuration.

Days 121–180

Build the implementation roadmap

Agree a multi-year roadmap covering interoperability, data quality, governance, procurement, workforce capability and secondary-use readiness.

Connect EHDS planning with GDPR, cybersecurity, AI governance, research and digital investment rather than creating a parallel compliance programme.

The implementation timetable

Date
Main implication
26 March 2025
EHDS Regulation entered into force and the transition period began.
March 2027
Deadline for the Commission to adopt several key implementing acts needed to operationalise the Regulation; several governance provisions also begin to apply.
26 March 2029
Key provisions begin to apply, including exchange of patient summaries and ePrescriptions/eDispensations for primary use and secondary-use rules for most data categories.
26 March 2031
Medical images, laboratory results and hospital discharge reports join the priority categories for primary-use exchange; remaining secondary-use categories also phase in.
March 2035
Third countries and international organisations may apply to join HealthData@EU for secondary use.

The timetable should be treated as an implementation runway. Hospitals should avoid investing now in systems, contracts or data models that make future interoperability more difficult.

Seven questions for every hospital board

  1. Who has executive accountability for EHDS readiness?
  2. Which of our core systems create the greatest interoperability or data-portability risk?
  3. Can we demonstrate the quality and provenance of the health data we rely on?
  4. Are patient access, correction, restriction and audit processes designed for a more connected data environment?
  5. Do current procurement contracts protect future interoperability, security and data-control needs?
  6. Are clinical leaders involved in data governance rather than leaving it solely to IT?
  7. How are EHDS, GDPR, cybersecurity, research governance and AI governance connected at executive level?

From compliance to data capability

The EHDS can support continuity of care, research, innovation and more evidence-informed management. But value will not result from regulation alone.

Hospitals will need strong information governance, interoperable infrastructure, high-quality data, competent professionals and clear accountability. The organisations that prepare early will be better placed not only to comply, but to use health data more effectively for patients, professionals and health-system improvement.

Map. Standardise. Govern. Connect. Prepare.

EHDS readiness begins long before the first major application deadlines.

This article reflects the EU implementation position in August 2026 and provides general information, not legal advice. Detailed obligations phase in over time and should be assessed together with applicable national law, GDPR, cybersecurity requirements and forthcoming EHDS implementing acts.

Secretary-General perspective

EHDS will test more than Europe’s digital infrastructure. It will test whether healthcare organisations have the governance and management capacity to turn connected data into safer care, better decisions and greater public value.

Leandro Luís · Secretary-General, European Association of Hospital Managers