AsteronAsteron

    EHDS readiness for European healthtech

    Asteron helps healthtech companies determine how the European Health Data Space applies to their products, data and market roles. We separate primary use, secondary use and EHR-system obligations, then translate the applicable requirements into a practical roadmap aligned with the 2027-2031 implementation timeline. The service is designed for companies operating in the Netherlands, Germany and the wider European health-data market.

    View EHDS pricing
    • EHDS applicability and roles mapped
    • Primary and secondary use separated
    • EHR-system obligations identified
    • 2027-2031 readiness roadmap created

    EHDS readiness from €6,900

    What is the European Health Data Space?

    Regulation (EU) 2025/327 establishes the European Health Data Space, or EHDS. It creates a common European framework for access to, exchange of and reuse of electronic health data.

    The regulation has three connected objectives:

    1. give individuals greater access to and control over their electronic health data for healthcare;
    2. enable defined secondary uses of health data for research, innovation, public health, policy and regulatory work;
    3. create harmonised requirements for electronic health record systems and interoperable health-data exchange.

    EHDS entered into force on 26 March 2025, but most obligations do not apply immediately. Implementation depends on further European implementing acts, national infrastructure and phased application dates.

    EHDS readiness is not a single compliance checklist. The obligations depend on whether the organisation is an EHR-system manufacturer, healthcare provider, health data holder, health data user, wellness-application provider or a combination of these roles.

    The three parts of EHDS

    Primary use

    Primary use concerns electronic health data used to provide healthcare. EHDS strengthens individuals’ rights to access, download, share and correct their data and to see who has accessed it. It also supports cross-border exchange through MyHealth@EU and the European electronic health record exchange format.

    Secondary use

    Secondary use concerns reuse of electronic health data for permitted purposes such as research, innovation, public health, patient safety, policymaking, statistics and regulatory activity. Access will generally require a permit or approval and use within an authorised secure processing environment.

    EHR-system market requirements

    Manufacturers of EHR systems will need to meet harmonised requirements for interoperability and logging, maintain technical documentation, complete the applicable conformity process, issue an EU declaration of conformity and apply CE marking before placing covered systems on the market.

    An organisation may be affected by more than one pillar. A platform may provide an EHR system, hold health data and later apply to use other datasets for research.

    Who needs an EHDS applicability assessment?

    EHDS may be relevant to:

    • manufacturers of EHR systems used by healthcare professionals
    • patient applications providing access to electronic health records
    • digital-health platforms storing or exchanging priority health-data categories
    • medical-device and IVD companies holding product or clinical data
    • developers of wellness applications and connected health products
    • hospitals, clinics, laboratories and other healthcare providers
    • clinical research, registry and real-world-data organisations
    • companies seeking health-data access for research or AI development
    • organisations controlling data from wearables, apps or health devices
    • processors whose technical architecture enables a data holder to meet EHDS duties

    Not every appointment system, administrative platform or wellness application is automatically an EHR system. Applicability depends on intended use, data categories, users, functionality and claimed interoperability.

    EHDS implementation timeline

    March 2025
    Regulation (EU) 2025/327 entered into force and the transition period began.
    March 2027
    The general application date arrives and the European Commission is due to adopt key implementing acts defining detailed technical and operational rules.
    March 2029
    Key requirements begin to apply. For primary use, the first priority categories-patient summaries, electronic prescriptions and electronic dispensations-enter the European exchange framework. Secondary-use rules start applying to most data categories, including EHR data.
    March 2031
    The second primary-use group-medical images and reports, laboratory results and discharge reports-joins the framework. Secondary-use obligations extend to remaining categories such as genomic data.
    March 2035
    Third countries and international organisations may apply to participate in HealthData@EU for secondary use.

    The timeline should be treated as a delivery sequence, not a reason to delay. Product architecture, data inventories, contracts and interoperability decisions made today may be expensive to reverse once implementing specifications are final.

    Primary-use readiness

    Primary-use obligations focus on electronic health data used for healthcare delivery and on individuals’ ability to exercise control over that information.

    A readiness assessment should consider:

    • whether the product processes an EHDS priority data category;
    • how patients access, download and share their data;
    • correction and access-restriction workflows;
    • identity, authentication and professional access;
    • access logging and the ability to show who viewed data;
    • export and import using the required European format;
    • compatibility with national and cross-border health-data infrastructure;
    • product and supplier responsibilities for responding to individual rights.

    Do not imply that every product must immediately connect to MyHealth@EU. Connectivity depends on the product role, national implementation and applicable phase.

    Secondary-use readiness

    EHDS introduces a structured route for approved reuse of health data. Organisations may be affected as health data holders, health data users or both.

    Health data holders

    Depending on the applicable role and exemptions, a health data holder may need to identify covered datasets, maintain descriptions and metadata, support data-quality information and make data available following an authorised request.

    Health data users

    A health data user seeking access must define a permitted purpose, request only necessary data, obtain the required permit or approval and use data within the authorised secure processing environment.

    Operational safeguards

    Secondary use requires clear governance for minimisation, pseudonymisation or anonymisation, access restrictions, security, publication and prohibited uses. Data may not be used for advertising or to make detrimental decisions about individuals or groups.

    EHDS does not create unrestricted access to European health data. It creates a controlled application and permit system administered through national Health Data Access Bodies and HealthData@EU.

    EHR systems and wellness applications

    EHDS introduces product requirements for covered EHR systems. The scope includes systems intended for healthcare providers to store, access or manage priority electronic health-data categories and patient-facing products that provide access to those records.

    Covered EHR systems will require:

    • European interoperability and logging components;
    • conformity with EHDS essential requirements;
    • technical documentation kept current;
    • testing of harmonised components;
    • an EU declaration of conformity;
    • CE marking under the EHDS route;
    • product information and instructions;
    • registration in the relevant EU database.

    Wellness applications are not automatically subject to the full EHR-system route. Where a manufacturer claims interoperability with EHR systems, EHDS introduces a mandatory labelling route addressing interoperability and security.

    There is no general “EHDS certificate” for an organisation. Readiness is role-specific, while covered EHR products follow their own conformity, declaration, registration and CE-marking requirements.

    From applicability to an implementation roadmap

    1. Product, data and role baseline

      Map products, legal entities, users, health-data categories, purposes, systems and European markets. Identify potential EHR manufacturer, health data holder, health data user and processor roles.

    2. Applicability assessment

      Determine which EHDS chapters and phased dates may apply. Separate confirmed requirements from dependencies awaiting implementing acts or national designation.

    3. Data-flow and architecture review

      Review access, exchange, logging, export, metadata, identity, security and secure-processing-environment dependencies.

    4. Governance and responsibility design

      Assign ownership across product, privacy, security, regulatory, clinical, research and data teams. Connect EHDS decisions with GDPR, MDR, IVDR and AI governance.

    5. Gap and dependency plan

      Record current gaps, implementing-act dependencies, national requirements, supplier changes and technical work. Prioritise irreversible product decisions first.

    6. Readiness roadmap

      Create phased actions for 2027, 2029 and 2031 with owners, decision gates and review triggers. Update the roadmap as European and national specifications become final.

    What Asteron delivers

    The readiness project identifies applicable obligations and creates the delivery plan. Full technical implementation, conformity testing, dataset preparation and individual data-access applications are included only when expressly stated in the proposal.

    Applicability and governance

    • EHDS role and applicability assessment
    • Product and legal-entity scope
    • Primary and secondary-use separation
    • Health-data category and purpose map
    • Regulatory dependency register
    • Responsibility and decision model
    • GDPR, MDR, IVDR and AI Act interface map
    • Phased implementation roadmap

    Product and evidence readiness

    • EHR-system scope assessment
    • Interoperability and logging gap analysis
    • Data-holder and data-user workflow mapping
    • Metadata and data-quality readiness review
    • Secure-processing-environment requirements
    • Supplier and contract dependencies
    • Evidence and technical-documentation plan
    • Prioritised remediation actions

    Netherlands, Germany and wider European deployment

    EHDS is an EU regulation, but implementation depends on national digital-health authorities, Health Data Access Bodies, healthcare infrastructure and technical services.

    For the Netherlands, readiness should account for Dutch electronic-health exchange, NEN 7510, national healthcare infrastructure and the eventual Dutch implementation of EHDS access and secondary-use processes.

    For Germany, the roadmap may need to consider the electronic patient record ecosystem, gematik specifications, German healthcare infrastructure and the designated national bodies responsible for primary and secondary use.

    Do not present current Dutch or German systems as automatically EHDS-compliant. Track confirmed national designations, implementing rules and technical specifications as they develop.

    A European product should maintain one core EHDS architecture with traceable national integrations rather than separate and conflicting country implementations.

    How EHDS connects to existing frameworks

    GDPR Article 9
    Governs the lawfulness and safeguards for processing special-category health data. EHDS complements rather than replaces GDPR.
    ISO/IEC 27701
    Provides an operational privacy-management system for controller and processor responsibilities.
    ISO/IEC 27001
    Provides information-security governance but does not establish EHDS interoperability or data-access duties.
    NEN 7510
    Supports health-information security within the Dutch healthcare environment.
    MDR and IVDR
    Govern medical-device and IVD safety and performance. Some products may also have separate EHDS obligations.
    EU AI Act
    Applies separate requirements to relevant AI systems and does not create automatic permission to access health data.
    Data Act
    May overlap with connected-product and data-access questions, but has a different scope and purpose.

    EHDS readiness from €6,900

    The starting project covers applicability, role mapping, key data flows, priority gaps and a phased implementation roadmap.

    Final scope depends on
    • number of products and legal entities;
    • EHR-system and wellness-application functionality;
    • primary and secondary-use roles;
    • volume and variety of health-data categories;
    • number of European markets;
    • supplier and interoperability complexity;
    • research, AI and data-access plans.

    This is a readiness and planning project, not an EHDS certification.

    Payment terms (fixed-scope)
    • 40% at signing
    • 40% when the agreed applicability and gap baseline is delivered
    • 20% after the contracted readiness roadmap is completed

    Prices exclude VAT where applicable.

    View all pricing

    External costs and implementation boundaries

    Asteron provides the applicability assessment, governance model and implementation roadmap. Asteron does not issue an EHDS certificate, grant a data permit or make decisions on behalf of a national Health Data Access Body or market-surveillance authority.

    Formal legal opinions, national regulatory interpretations, conformity testing, external laboratories, specialised interoperability implementation and secure-processing-environment services remain separate unless expressly included.

    Production changes—such as export functionality, access logging, identity integration, European exchange-format support or data-platform migration—remain with the client’s engineering and product teams unless separately scoped.

    If the contracted readiness outcome is not reached because an Asteron deliverable is incomplete or deficient, Asteron corrects that work at no additional professional fee within the agreed scope. This does not cover future implementing acts, changed product functionality, new markets or decisions by public authorities.

    Responsibilities

    Asteron

    • Assesses EHDS roles and phased applicability
    • Maps regulatory and national dependencies
    • Reviews governance, data flows and product readiness
    • Connects EHDS with existing privacy and security systems
    • Produces the prioritised implementation roadmap
    • Updates assumptions when included in ongoing operations

    Your organisation

    • Provides accurate product, data and market information
    • Confirms intended use and commercial plans
    • Assigns accountable product and regulatory owners
    • Approves legal and strategic decisions
    • Implements technical and contractual changes
    • Tracks national and European implementation developments
    • Operates the resulting controls and processes

    Frequently asked questions

    What is the European Health Data Space?

    EHDS is the EU framework for primary use, secondary use and cross-border exchange of electronic health data, together with market requirements for EHR systems.

    Is EHDS already fully applicable?

    No. It entered into force in March 2025, but implementation is phased. Key implementing acts are expected by March 2027, with major obligations applying from 2029 and 2031.

    Does EHDS replace GDPR?

    No. GDPR continues to govern personal-data processing. EHDS adds health-sector rights, infrastructure, access and product requirements.

    Is our software an EHR system under EHDS?

    Possibly. The assessment depends on intended use, users, functionality and whether the system processes priority electronic health-data categories for healthcare delivery.

    Are appointment-booking systems EHR systems?

    Not merely because they are used in healthcare. Systems processing only administrative information may fall outside the EHR-system definition.

    Does every wellness application need EHDS labelling?

    No. The labelling route is relevant where the manufacturer claims interoperability with EHR systems under the EHDS framework.

    What is a health data holder?

    A health data holder is an organisation meeting the EHDS definition and controlling relevant electronic health data or the technical ability to make certain non-personal data available. Applicability and exemptions require assessment.

    Can a company access EHDS data for AI development?

    Potentially, when the proposed purpose is permitted and the organisation obtains the required data permit or approval. Access is not automatic and normally occurs within a secure processing environment.

    What is a Health Data Access Body?

    A Health Data Access Body is a national organisation responsible for managing applications and permits for secondary use of health data under EHDS.

    Is there an EHDS certification?

    There is no general organisational EHDS certificate. Covered EHR systems have product conformity, declaration, registration and CE-marking obligations.

    How much does EHDS readiness cost?

    The service starts from €6,900. Final scope depends on products, roles, data categories, countries and technical complexity.

    Official references

    • – Regulation (EU) 2025/327 — EUR-Lex
    • – European Commission EHDS overview and implementation timeline
    • – European Commission guidance on primary use
    • – European Commission guidance on secondary use
    • – European Commission guidance on EHR-system certification
    • – European Commission EHDS FAQ, March 2026
    • – Official Dutch and German EHDS implementation sources as they become available

    Last reviewed: July 2026

    Asteron is not endorsed by or partnered with the European Commission, any national Health Data Access Body, competent authority or certification body.

    Identify your EHDS obligations before product architecture becomes expensive to change

    We will assess your products, data, market roles and target countries, then create a phased roadmap for the requirements that apply to your organisation.

    View EHDS pricing