Healthcare sector participants will soon face new obligations as the European Health Data Space Regulation moves closer to the finish line. Experts warn that organisations should already be preparing for the changes. The new rules will primarily affect healthcare providers managing patients’ health records, medical device manufacturers processing non-personal electronic health data through medical devices, and pharmaceutical companies handling clinical trial data. Although the relevant provisions are expected to apply only from around 2028, organisations should not leave preparations until the last minute, says Juras Žymančius, Senior Associate at COBALT.

According to Žymančius, failure by health data holders to comply with the obligations set out in the Regulation may lead to significant penalties. Similarly to the General Data Protection Regulation, fines may reach up to EUR 10 million or, in the case of an undertaking, up to 2% of its total worldwide annual turnover for the preceding financial year, whichever is higher.

Following the European Parliament’s adoption of the final version of the European Health Data Space Regulation on 24 April, only formal approval by the Council and publication in the Official Journal of the European Union remained before the Regulation could enter into force.

Allocate internal resources now

One of the key aims of the new framework is to make it easier for patients to share their health data with healthcare providers and professionals across borders. However, the Regulation also places considerable emphasis on the secondary use of health data, explains Žymančius.

“Secondary health data refers to patients’ electronic health data that has been pseudonymised or anonymised so that individuals cannot be identified. Such data may be used for purposes including scientific research in the health or care sectors, product and service development, and innovation. This also includes training, testing and evaluating algorithms used in medical devices, artificial intelligence systems and digital health applications, as well as the production of statistics and other activities relevant to the health and care sectors,” says Žymančius.

To enable the secondary use of health data for these purposes, the European Health Data Space Regulation introduces a number of obligations for health data holders.

They will be required to make secondary health data available to health data access bodies designated by Member States. Once a health data user has obtained the necessary authorisation, the relevant access body will make the data available to that user.
These requirements will be particularly relevant to healthcare providers that maintain patient health records, as well as medical device manufacturers processing non-personal electronic health data through their devices. Pharmaceutical companies handling clinical trial data may also fall within the scope of the definition of health data holders.

Upon receiving a request, health data holders will be required to provide electronic health data to the relevant health data access body within three months.
They will also need to review, at least once a year, whether descriptions of their datasets in the relevant dataset catalogue remain accurate and update them where necessary. This will require organisations to monitor and maintain information contained in national catalogues, including details on the sources, scope, key characteristics and nature of electronic health data, as well as the conditions under which it can be made available.

Although the obligations relating to the secondary use of health data are expected to apply only around 2028, four years after the Regulation enters into force, organisations should start preparing well in advance, says the COBALT lawyer.
Businesses and institutions falling within the scope of the Regulation should already be monitoring how Member States are preparing for its implementation. They should also allocate internal resources to follow regulatory developments, understand the new processes and requirements, and engage proactively with the relevant national authorities.

Starting this work early will help organisations assess what changes may be required to their internal processes, data governance and responsibilities before the new framework becomes fully applicable.