Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2023-0395 → TA-9-2023-0462

From
A-9-2023-0395 Plenary report of 5 Dec 2023
To
TA-9-2023-0462 Adopted text of 13 Dec 2023
Changes
32 changes to the text
Paragraphs
+6 added · −39 removed · 30 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on the European Health Data Space
Title (to)
European Health Data Space

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 1 of 11: DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

RemovedDRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

AddedP9_TA(2023)0462

Removedon the proposal for a regulation of the European Parliament and of the Council on the European Health Data Space

AddedEuropean Health Data Space

Removed(COM(2022)0197 – C90167/2022 – 2022/0140(COD))

AddedCommittee on the Environment, Public Health and Food Safety, Committee on Civil Liberties, Justice and Home Affairs

AddedPE742.387

AddedAmendments adopted by the European Parliament on 13 December 2023 on the proposal for a regulation of the European Parliament and of the Council on the European Health Data Space (COM(2022)0197 – C9-0167/2022 – 2022/0140(COD))

(Ordinary legislative procedure: first reading)

RemovedThe European Parliament,

Removed– having regard to the Commission proposal to Parliament and the Council (COM(2022)0197),

Removed– having regard to Article 294(2) and Articles 16 and 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C90167/2022),

Removed– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,

Removed– having regard to the opinion of the European Economic and Social Committee of 22 September 2022,

Removed– having regard to the opinion of the Committee of the Regions of 9 February 2023,

Removed– having regard to Rule 59 of its Rules of Procedure,

Removed– having regard to the opinions of the Committee on Industry, Research and Energy and of the Committee on Internal Market and Consumer Protection,

Removed– having regard to the report of the Committee on the Environment, Public Health and Food Safety and the Committee on Civil Liberties, Justice and Home Affairs (A9-0395/2023),

Removed1. Adopts its position at first reading hereinafter set out;

Removed2. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;

Removed3. Instructs its President to forward its position to the Council, the Commission and the national parliaments.

6 unchanged paragraphs

Recital 1: (1) The aim of this Regulation is to establish the European Health Data Space (‘EHDS’) in order to improve access to and control by natural persons over their personal electronic health data in the context of healthcare (primary use of electronic health data), as well as for better achieving other purposes in the health sector that would benefit society such as research such as innovation, policy-making, health threats preparedness and response, patient safety, personalised medicine, official statistics or regulatory activities (secondary use of electronic health data). In addition, the goal is to improve the functioning of the internal market by laying down a uniform legal and technical framework in particular for the development, marketing and use of electronic health record systems (‘EHR systems’) in conformity with Union values.

Recital 1 a (new): (1a) The EHDS is intended to constitute a key component in the creation of a strong and resilient European Health Union to better protect the health of Union citizens, prevent and address future pandemics and improve the resilience of Union healthcare systems.

Recital 1 b (new): (1b) This Regulation should complement Union programmes such as the EU4Health Programme, Digital Europe Programme, Connecting Europe Facility and Horizon Europe. The Commission should ensure that Union programmes complement and facilitate the implementation of the European Health Data Space.

Recital 2: (2) The COVID-19 pandemic has highlighted the imperative of having timely access to quality electronic health data for health threats preparedness and response, as well as for prevention, diagnosis and treatment through the secondary use of health data. Such timely access can potentially contribute, through efficient public health surveillance and monitoring, to a more effective management of the pandemic, to a reduction of costs and to improving the response to health threats and ultimately can help to save more lives in the future. In 2020, the Commission urgently adapted its Clinical Patient Management System, established by Commission Implementing Decision (EU) 2019/126941, to allow Member States to share electronic health data of COVID-19 patients moving between healthcare providers and Member States during the peak of the pandemic, but this was only an emergency solution, showing the need for a structural and consistent approach at Member States and Union level on access to electronic health data in order to steer effective policy responses and contribute to high standards of human health.

Recital 3: (3) The COVID-19 crisis strongly anchored the work of the eHealth Network, a voluntary network of digital health authorities, as the main pillar for the development of mobile contact tracing and warning applications and the technical aspects of the EU Digital COVID Certificates. It also highlighted the need for sharing electronic health data that are findable, accessible, interoperable and reusable (‘FAIR principles’), and ensuring that the necessary electronic health data are available while respecting the principle of data minimisation. Synergies between the EHDS, the European Open Science Cloud42 and the European Research Infrastructures should be ensured, as well as lessons learned from data sharing solutions developed under the European COVID-19 Data Platform.

Recital 3 a (new): (3a) Given the sensitivity of personal health data, this Regulation seeks to provide sufficient safeguards at both Union and national level to ensure a high degree of data protection, security, confidentiality and ethical use. Such safeguards are necessary to promote trust in safe handling of the health data of natural persons for primary and secondary uses. To achieve those objectives, pursuant to Article 9(4) of Regulation (EU) 2016/679, Member States can impose further conditions, including limitations, with regard to the processing of genetic data, biometric data or data concerning health.

ChangedRecital 4: (4) The processing of personal electronic health data is subject to the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council43, , Regulation (EU) 2018/1725 of the European Parliament and of the Council44, as regards Union institutions, bodies, offices and agencies, and Regulation (EU) 2022/86844a of the European Parliament and of the Council. References to the provisions of Regulation (EU) 2016/679 should be understood also as references to the corresponding provisions of Regulation (EU) 2018/1725 for Union institutions, bodies, offices and agencies, where relevant. In relation to mixed datasets, where personal and non-personal data are inextricably linked, and where it is difficult to distinguish between those categories thereby resulting in the possibility of inferring personal data from non-personal data, the provisions of Regulation (EU) 2016/679 and of this Regulation concerning personal electronic health data should apply. / 44a Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance and amending Regulation (EU) 2018/1724 (Data Governance Act) (OJ L 152, 3.6.2022, p. 1).

Change 1

ChangedRecital 4 a (new): (4 a)(4a) The implementation of the EHDS should take into consideration the European ethical principles for digital health adopted by the eHealth network1a on 26 January 2022. Monitoring the application of those ethical principles should be one of the tasks of the EHDS Board. / 1a Established following Article 14 of Directive 2011/24/EU on the application of patients' rights in cross-border healthcare.

4 unchanged paragraphs

Recital 5: (5) More and more Europeans cross national borders to work, study, visit relatives or to travel. To facilitate the exchange of health data, and in line with the need for empowering citizens, they should be able to access their health data in an electronic format that can be recognised and accepted across the Union. Such personal electronic health data could include personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about their health status, personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question, as well as data determinants of health, such as behaviour, environmental, physical influences, medical care, social or educational factors. Electronic health data also includes data that has been initially collected for research, statistics, health threat assessment, policy making or regulatory purposes and may be made available according to the rules in Chapter IV. The electronic health data concern all categories of those data, irrespective to the fact that such data is provided by the data subject or other natural or legal persons, such as health professionals, or is processed in relation to a natural person’s health or well-being and should also inc…

Recital 5 a (new): (5a) The scope of this Regulation should not cover natural persons who are not Union citizens, or third-country nationals not legally residing on the territory of the Member States. Therefore, where Member States require electronic registration of health data or where health data holders register health data regarding those natural persons, processors can only process the electronic health data of such persons, in accordance with Articles 6(1) and 9(2) of Regulation (EU) 2016/679 including for any secondary use.

Recital 7: (7) In health systems, personal electronic health data is usually gathered in electronic health records, which typically contain a natural person’s medical history, diagnoses and treatment, medications, allergies, immunisations, as well as radiology images and laboratory results, and other complementary diagnosis and therapeutics results, spread between different entities from the health system (general practitioners, hospitals, pharmacies, care services). In order to enable that electronic health data to be accessed, shared and changed by the natural persons or health professionals, some Member States have taken the necessary legal and technical measures and set up centralised infrastructures connecting EHR systems used by healthcare providers and natural persons. Alternatively, some Member States support public and private healthcare providers to set up personal health data spaces to enable interoperability between different healthcare providers. Several Member States have also supported or provided health data access services for patients and health professionals (for instance through patients or health professional portals). They have also taken measures to ensure that EHR systems or wellness applications are able to transmit electronic health data with the central EHR system (some Member States do this by ensuring, for instance, a system of certification). However, not all Member States have put in place such systems, and the Member States that have implemented them have…

Recital 9: (9) At the same time, it should be considered that immediate access of natural persons to certain types of their personal electronic health data may be harmful for the safety of natural persons, unethical or inappropriate. For example, it could be unethical to inform a patient through an electronic channel about a diagnosis with an incurable disease that is likely to lead to their swift passing instead of providing this information in a consultation with the patient first. Therefore, a possibility for limited exceptions in the implementation of this right should be ensured. Such an exception may be imposed by the Member States where this exception constitutes a necessary and proportionate measure in a democratic society, in line with the requirements of Article 23 of Regulation (EU) 2016/679. Such restrictions should be implemented by delaying the display of the concerned personal electronic health data to the natural person for a limited period, for instance until the moment where the patient and the health professional get in contact. Member States should be encouraged to require that health data available prior to the implementation of this Regulation be converted into an electronic format through a process facilitated by Member States. Any digital transformation in the healthcare sector should aim to be inclusive and benefit also natural persons with limited ability to access and use digital services. Natural persons should be able to provide an authorisation to the natur…

Change 2

ChangedRecital 10: (10) Some Member States allow natural persons to add electronic health data to their EHRs or to store additional information in their separate personal health record that can be accessed by health professionals. However, this is not a common practice in all Member States and therefore should be established by the EHDS across the EU. Information inserted by natural persons may not be as reliable as electronic health data entered and verified by health professionals and does not have the same clinical or legal value as information provided by a health professional, therefore it should be clearly marked to indicate the source of such additional data and should be validated only bvby a health professional. More specifically, relevant fields in the EHR should be clearly marked. Enabling natural persons to more easily and quickly access their electronic health data also further enables them to notice possible errors such as incorrect information or incorrectly attributed patient records and have them rectified using their rights under Regulation (EU) 2016/679. In such cases, natural person should be enabled to request rectification of the incorrect electronic health data online, immediately and free of charge, for example through the personal health data access service. Data rectification requests should be assessed and, where relevant, implemented by the data controllers on case by case basis, if necessary involving health professionals, with a relevant specialisation, responsible f…

26 unchanged paragraphs

Recital 11: (11) Natural persons should be further empowered to exchange and to provide access to personal electronic health data to the health professionals of their choice, going beyond the right to data portability as established in Article 20 of Regulation (EU) 2016/679 and to download their health data. This is necessary to tackle objective difficulties and obstacles in the current state of play. Under Regulation (EU) 2016/679, portability is limited only to data processed based on consent or contract, which excludes data processed under other legal bases, such as when the processing is based on law, for example when their processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. It only concerns data provided by the data subject to a controller, excluding many inferred or indirect data, such as diagnoses, or tests. Finally, under Regulation (EU) 2016/679, the natural person has the right to have the personal data transmitted directly from one controller to another only where technically feasible. That Regulation, however, does not impose an obligation to make this direct transmission technically feasible. All these elements limit the data portability and may limit its benefits for provision of high-quality, safe and efficient healthcare services to the natural person.

Recital 12: (12) Natural persons should be able to exercise control over the transmission of personal electronic health data to other healthcare providers. Healthcare providers and other organisations providing EHRs should facilitate the exercise of this right. Stakeholders such as healthcare providers, digital health service providers, manufacturers of EHR systems or medical devices should not limit or block the exercise of the right of portability because of the use of proprietary standards or other measures taken to limit the portability. In accordance with Regulation (EU) 2016/679, healthcare providers should follow the data minimisation principle when accessing personal health data, limiting the data accessed to data that are strictly necessary and justified for a given service. For these reasons, the framework laid down by this Regulation builds on the right to data portability established in Regulation (EU) 2016/679 by ensuring that natural persons as data subjects can transmit their electronic health data, including inferred data, irrespective of the legal basis for processing the electronic health data. This right should apply to electronic health data processed by public or private controllers, irrespective of the legal basis for processing the data under in accordance with the Regulation (EU) 2016/679. This right should apply to all electronic health data.

Recital 13: (13) Natural persons may not want to allow access to some parts of their personal electronic health data while enabling access to other parts. Such selective sharing of personal electronic health data should be supported. However, natural persons should be informed of the patient safety risks associated with limiting access to health data. However, such restrictions may have life threatening consequences and, therefore, access to personal electronic health data should be possible to protect vital interests as an emergency override. According to Regulation (EU) 2016/679, vital interests refer to situations in which it is necessary to protect an interest which is essential for the life of the data subject or that of another natural person. Processing of personal electronic health data based on the vital interest of another natural person should in principle take place only where the processing cannot be manifestly based on another legal basis. More specific legal provisions on the mechanisms of restrictions placed by the natural person on parts of their personal electronic health data should be provided by Member States in national law, in particular as regards medical liability in the event that restrictions have been placed by the natural person, Because the unavailability of the restricted personal electronic health data may impact the provision or quality of health services provided to the natural person, he/she should assume responsibility for the fact that the healthcare …

Recital 14: (14) In the context of the EHDS, natural persons should be able to exercise their rights under this Regulation without prejudice to Regulation (EU) 2016/679. The supervisory authorities established pursuant to Article 51 of Regulation (EU) 2016/679 should remain competent, in particular to monitor the processing of personal electronic health data and to address any complaints lodged by the natural persons. In order to carry out their tasks in the health sector and uphold the natural persons’ rights, digital health authorities should cooperate with the supervisory authorities under Regulation (EU) 2016/679.

Recital 15: (15) Article 9(2), point (h), of Regulation (EU) 2016/679 provides for exceptions where the processing of sensitive data is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health care or treatment or the management of health care systems and services on the basis of Union or Member State law. This Regulation should provide conditions and safeguards for the processing of electronic health data by healthcare providers and health professionals in line with Article 9(2), point (h), of Regulation (EU) 2016/679 with the purpose of accessing personal electronic health data provided by the natural person or transmitted from other healthcare providers. However, this Regulation should be without prejudice to the national laws concerning the processing of health data outside the scope of this Regulation, including for other secondary use purposes established by this Regulation, including the legislation establishing categories of health professionals that can process different categories of electronic health data.

Recital 16: (16) Timely and full access of health professionals to the medical records of patients is fundamental for ensuring continuity of care, avoiding duplications and errors and reducing costs. However, due to a lack of interoperability, in many cases, health professionals cannot access the complete medical records of their patients and cannot make optimal medical decisions for their diagnosis and treatment, which adds considerable costs for both health systems and natural persons and may lead to worse health outcomes for natural persons. Electronic health data made available in interoperable format, which can be transmitted between healthcare providers can also reduce the administrative burden on health professionals of manually entering or copying health data between electronic systems. Therefore, health professionals should be provided with appropriate electronic means, such as appropriate electronic and digital devices and health professional portals, to use personal electronic health data for the exercise of their duties on a need-to-know basis. Moreover, the access to personal health records should be transparent to the natural persons and natural persons should be able to exercise full control over such access, including by limiting access to all or part of the personal electronic health data in their records. Health professionals should refrain from hindering the implementation of the rights of natural persons, such as refusing to take into account electronic health data or…

Recital 16 a (new): (16a) Health professionals are faced with a profound change in the context of digitalisation and implementation of the EHDS. Health professionals need to develop their digital health literacy and digital skills. Therefore, health professionals who qualify as micro enterprises, as defined in Article 2 of the Annex to Commission Recommendation 2003/361/EC1a, should be temporarily exempted from the obligations laid down in this Regulation, in order to avoid a disproportionate administrative burden for micro enterprises. During the period of exemption, Member States should enable health professionals working as micro enterprises to take digital literacy courses to be able to prepare to work in EHR systems. / 1a Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium sized enterprises (OJ L 124, 20.5.2003, p. 36)

Recital 17: (17) The relevance of different categories of electronic health data for different healthcare scenarios varies. Different categories have also achieved different levels of maturity in standardisation, and therefore the implementation of mechanisms for their exchange may be more or less complex depending on the category. Therefore, the improvement of interoperability and data sharing should be gradual and prioritisation of categories of electronic health data is needed. Categories of electronic health data such as patient summary, electronic prescription and dispensation, laboratory results and reports, hospital discharge reports, medical images and reports have been selected by the eHealth Network as most relevant for the majority of healthcare situations and should be considered as priority categories for Member States to implement access to them and their transmission. When further needs for the exchange of more categories of electronic health data are identified for healthcare purposes, the list of priority categories should be expanded, after analysing relevant aspects related to the necessity and possibility for the exchange of new datasets, such as their support by systems established nationally or regionally by the Member States. Particular attention should be given to the data exchange in border regions of neighbouring Member States where the provision of cross-border health services is more frequent and needs even quicker procedures than across the Union in general.

Recital 19: (19) The level of availability of personal health and genetic data in an electronic format varies between Member States. The EHDS should make it easier for natural persons to have those data available in electronic format as well as for them to have better control over accessing and sharing their personal electronic health data. This would also contribute to the achievement of the target of 100% of Union citizens having access to their electronic health records by 2030, as referred to in the Policy Programme “Path to the Digital Decade”. In order to make electronic health data accessible and transmissible, such data should be accessed and transmitted in an interoperable common European electronic health record exchange format, at least for certain categories of electronic health data, such as patient summaries, electronic prescriptions and dispensations, medical images and image reports, laboratory results and discharge reports, subject to transition periods. Where personal electronic health data is made available to a healthcare provider or a pharmacy by a natural person, or is transmitted by another data controller in the European electronic health record exchange format, the electronic health data should be read and accepted for the provision of healthcare or for dispensation of a medicinal product, thus supporting the provision of the health care services or the dispensation of the electronic prescription. Commission Recommendation (EU) 2019/24345 provides the foundations…

Recital 20: (20) While EHR systems are widely spread, the level of digitalisation of health data varies in Member States depending on data categories and on the coverage of healthcare providers that register health data in electronic format. In order to support the implementation of data subjects’ rights of access to and exchange of electronic health data, Union action is needed to avoid further fragmentation. In order to contribute to a high quality and continuity of healthcare, certain categories of health data should be registered in electronic format systematically and according to specific data quality requirements. The European electronic health record exchange format should form the basis for specifications related to the registration and exchange of electronic health data. The Commission should be empowered to adopt delegated acts for determining data quality requirements.

Recital 20 a (new): (20a) In order to support the successful implementation of the EHDS and the creation of effective conditions for European health data cooperation, the Commission and Member States should agree on time-based targets to implement conditions for improved health data interoperability across the Union with a range of objectives and milestones, including in respect of disease-specific registry interoperability, which should be reviewed and assessed in an annual report.

Recital 21: (21) Under Article 168 of the Treaty on the Functioning of the European Union (TFEU), Member States are responsible for their health policy, in particular for decisions on the services that they provide and reimburse. Different reimbursement policies should, however, not constitute barriers to the free movement of digital health services such as telemedicine, including online pharmacy services. When digital services accompany the physical provision of a healthcare service, the digital service should be included in the overall care provision. Telemedicine is becoming an increasingly important tool that can provide patients with access to care and tackle inequities and has the potential to reduce health inequalities and reinforce the free movement of Union citizens across borders. Digital and other technological tools can facilitate the provision of care in remote regions. However, telemedicine should not be viewed as a replacement for in-person medicine, as there are certain conditions and procedures that require in-person physical examination and intervention.

Recital 22: (22) Regulation (EU) No 910/2014 of the European Parliament and of the Council47 lays down the conditions under which Members States perform identification of natural persons in cross-border situations using identification means issued by another Member State, establishing rules for the mutual recognition of such electronic identification means. The EHDS requires a secure access to electronic health data, including in cross-border scenarios where the health professional and the natural person are from different Member States, to avoid cases of unauthorised access. At the same time, the existence of different means of electronic identification should not be a barrier for exercising the rights of natural persons and health professionals. Therefore, natural persons and health professionals should have the right to electronic identification using any recognised electronic identification, including eID schemes where such are offered. The rollout of interoperable, cross-border identification and authentication mechanisms for natural persons and health professionals across the EHDS requires strengthening cooperation at Union level in the European Health Data Space Board (‘EHDS Board’). As the rights of the natural persons in relation to the access and transmission of personal electronic health data should be implemented uniformly across the Union, a strong governance and coordination is necessary at both Union and Member State level.

Recital 22 a (new): (22a) Member States should establish relevant digital health authorities for the planning and implementation of standards for electronic health data access and transmission and the enforcement of the rights of natural persons and health professionals. In addition, governance elements are needed in Member States to facilitate the participation of national actors in the cooperation at Union level, channelling expertise and advising on the design of solutions necessary to achieve the goals of the EHDS. Digital health authorities exist in most of the Member States and they deal with EHRs, interoperability, security or standardisation. Digital health authorities should be established in all Member States, as separate organisations or as part of currently existing authorities.

Recital 23: (23) Digital health authorities should have sufficient technical skills, possibly bringing together experts from different organisations. The activities of digital health authorities should be well-planned and monitored in order to ensure their efficiency. Digital health authorities should take necessary measures to ensuring rights of natural persons by setting up national, regional, and local technical solutions such as national EHR, patient portals, data intermediation systems. When doing so, they should apply common standards and specifications in such solutions, promote the application of the standards and specifications in procurements and use other innovative means including reimbursement of solutions that are compliant with interoperability and security requirements of the EHDS. Member States should ensure that appropriate training initiatives are undertaken. In particular, health professionals should be informed and trained with respect to their rights and obligations under this Regulation. To carry out their tasks, the digital health authorities should cooperate at national and Union level with other entities, including with insurance bodies, healthcare providers, health professionals, manufacturers of EHR systems and wellness applications, as well as other stakeholders from health or information technology sector, entities handling reimbursement schemes, health technology assessment bodies, medicinal products regulatory authorities and agencies, medical devices auth…

Recital 24: (24) Access to and transmission of electronic health data is relevant in cross-border healthcare situations, as it may support continuity of healthcare when natural persons travel to other Member States or change their place of residence. Continuity of care and rapid access to personal electronic health data is even more important for residents in border regions, crossing the border frequently to get health care. In many border regions, some specialised health care services may be available closer across the border rather than in the same Member State. An infrastructure is needed for the transmission of personal electronic health data across borders, in situations where a natural person is using services of a healthcare provider established in another Member State. A voluntary infrastructure for that purpose, MyHealth@EU, has been established as part of the actions provided for in Article 14 of Directive 2011/24/EU. Through MyHealth@EU, Member States started to provide natural persons with the possibility to share their personal electronic health data with healthcare providers when travelling abroad. To further support such possibilities, the participation of Member States in the digital infrastructure MyHealth@EU should become mandatory. All Member States should join the infrastructure and connect healthcare providers and pharmacies to it, as this is necessary for the implementation of the rights of natural persons to access and make use of their personal electronic health d…

Recital 25: (25) In the context of MyHealth@EU, a central platform should provide a common infrastructure for the Member States to ensure connectivity and interoperability in an efficient and secure way. In order to guarantee compliance with data protection rules and to provide a risk management framework for the transmission of personal electronic health data, the Commission should, by means of implementing acts, allocate specific responsibilities with time-based targets among the Member States, as joint controllers, and prescribe its own obligations, as processor.

Recital 26: (26) In addition to services in MyHealth@EU for the exchange of personal electronic health data based on the European electronic health record exchange format, other services or supplementary infrastructures may be needed for example in cases of public health emergencies or where the architecture of MyHealth@EU is not suitable for the implementation of some use cases. Examples of such use cases include support for vaccination card functionalities, including the exchange of information on vaccination plans, or verification of vaccination certificates or other health-related certificates. This would be also important for introducing additional functionality for handling public health crises, such as support for contact tracing for the purposes of containing infectious diseases.

Recital 34 a (new): (34a) EHR systems could qualify as medical devices under Regulation (EU) 2017/745 or in-vitro diagnostic devices under Regulation (EU) 2017/746 of the European Parliament and of the Council1a. While those EHR systems need to fulfil the requirements under each applicable regulation, Member States should take appropriate measures to ensure that the respective conformity assessment is carried out as a joint or coordinated procedure, as appropriate, inter alia by encouraging the same notified bodies to become responsible for the conformity assessment under each applicable regulation. / 1a Regulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices and repealing Directive 98/79/EC and Commission Decision 2010/227/EU (OJ L 117, 5.5.2017, p. 176).

Recital 35: (35) Users of wellness applications, such as mobile applications, should be informed about the capacity of such applications to be connected and to supply data to EHR systems or to national electronic health solutions, in cases where data produced by wellness applications is useful for healthcare purposes. The capability of those applications to export data in an interoperable format is also relevant for data portability purposes. Where applicable, users should be informed about the compliance of such applications with interoperability and security requirements. However, given the large number of wellness applications and the limited relevance for healthcare purposes of the data produced by many of them, a certification scheme for these applications would not be proportionate. A mandatory labelling scheme for wellness applications claiming interoperability with EHR systems should therefore be established as an appropriate mechanism for enabling the transparency for the users of wellness applications regarding compliance with the requirements, thereby supporting users in their choice of appropriate wellness applications with high standards of interoperability and security. The Commission should set out in implementing acts the details regarding the format and content of such label.

Recital 36 a (new): (36a) The uptake of real-world data and real-world evidence, including patient-reported outcomes, for evidence-based regulatory and policy purposes as well as for research, health technology assessment and clinical objectives should be encouraged. Real-world data and real-world evidence have the potential to complement health data currently made available.

Recital 37: (37) For the secondary use of personal electronic health data for research, innovation, policy making, regulatory purposes, patient safety or the treatment of other natural persons, the possibilities offered by Regulation (EU) 2016/679 for a Union law should be used as a basis for rules and mechanisms providing suitable and specific measures to safeguard the rights and freedoms of the natural persons. For the purpose of processing electronic health data for secondary use, one of the legal bases set out in Article 6(1), points (a), (c), (e) or (f), of Regulation (EU) 2016/679 combined with Article 9(2) of that Regulation should be required. The most relevant processing condition listed in Article 9(2) of Regulation (EU) 2016/679 in this context is that of substantial public interest, the provision of health or social care, public interest in the area of public health and research. Hence, this Regulation provides the legal basis in accordance with Article 6 and Articles 9(2) (g), (h), (i) and (j) of Regulation (EU) 2016/679 for the secondary use of health data, establishing the safeguards for processing, in terms of lawful purposes, trusted governance for providing access to health data (through health data access bodies) and processing in a secure environment, as well as modalities for data processing, set out in the data permit. More specifically, for processing of electronic health data held by the health data holder pursuant to this Regulation, this Regulation creates the l…

Recital 37 a (new): (37a) In the case where the health data user has access to electronic health data for secondary use of data for one of the purposes defined in this Regulation, the health data user should demonstrate the specific legal ground on which it relies as part of the application for access to electronic health data pursuant to this Regulation, namely, on the basis of the applicable law, where the legal basis under Regulation (EU) 2016/679 is Article 6(1), point (e), or Article 6(1), point (f), thereof. If the health data user relies upon the ground provided for in Article 6(1), point (e), it should make reference to another Union or national law, requiring the user to process personal health data for the compliance of its tasks. If the ground for processing by the health data user is Article 6(1), point (f), of Regulation (EU) 2016/679, appropriate and necessary safeguards should be determined in accordance with this Regulation. In this context, the data permits issued by the health data access bodies should be an administrative decision defining the conditions for the access to the data.

Recital 38: (38) In the context of the EHDS, the electronic health data already exists and is being collected by healthcare providers, professional associations, public institutions, regulators, researchers, insurers etc. in the course of their activities. Some categories of data are collected primarily for the provisions of healthcare (e.g. electronic health records, genetic data, claims data, etc.), others are collected also for other purposes such as research, statistics, patient safety, regulatory activities or policy making (e.g. disease registries, policy making registries, registries concerning the side effects of medicinal products or medical devices, etc.). For instance, European databases that facilitate data (re)use are available in some areas, such as cancer (European Cancer Information System) or rare diseases (European Platform on Rare Disease Registration, ERN registries, etc.). These data should also be made available for secondary use. However, much of the existing health-related data is not made available for purposes other than that for which they were collected. This limits the ability of researchers, innovators, policy-makers, regulators and doctors to use those data for different purposes, including research, innovation, policy-making, regulatory purposes, patient safety or personalised medicine. In order to fully unleash the benefits of the secondary use of electronic health data, all health data holders should contribute to this effort in making different categori…

Recital 39: (39) The categories of electronic health data that can be processed for secondary use should be broad and flexible enough to accommodate the evolving needs of health data users, while remaining limited to data related to health or known to influence health. It can also include relevant data from the health system (electronic health records, claims data, disease registries, genomic data etc.), as well as data with an impact on health (for example consumption of different substances, socio-economic status, behaviour, including environmental factors (for example, pollution, radiation, use of certain chemical substances). They can also include automatically generated data from medical devices and person-generated data, such as wellness applications. The health data user who benefits from access to datasets provided under this Regulation could enrich the data with various corrections, annotations and other improvements, for instance by supplementing missing or incomplete data, thus improving the accuracy, completeness or quality of data in the dataset. Health data users should be encouraged to report critical errors in datasets to health data access bodies. To support the improvement of the original database and further use of the enriched dataset, the dataset with such improvements and a description of the changes should be made available free of charge to the original data holder. The data holder should make available the new dataset, unless it provides a justified notification …

Recital 39 a (new): (39a) In order to guarantee trust in the patient-physician relationship, the principle of professional secrecy and the patient's right to confidentiality should be safeguarded when digitalising healthcare services. A relationship of trust between patients and health professionals and healthcare providers and other holders of personal health data is a paramount element of the provision of health or social care or treatment. It is within that context that the patient or the legal representative of the patient should have a say in the processing of their health data for secondary use in the form of a right to opt-out of the processing of all or parts of their health data for secondary use for some or all purposes. An easily understandable and accessible opt-out mechanism in a user-friendly format should be provided for in this regard. However, due to the sensitive nature of human genetic, genomic and proteomic data, data from biobanks and to the nature of the use of data from wellness applications, it is appropriate to provide that the secondary use of such data can only occur following the consent of the natural person concerned in accordance with Article 4(11) of the Regulation (EU) 2016/679. An opt-in mechanism whereby data subjects explicitly consent or give their permission to the processing of part or all of such data for some or all secondary use purposes should be envisaged. Where data subjects explicitly consent to the use of parts or all of this data for some or all se…

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
26 September 2026

Cite as

European Parliament (2023). “Changes between A-9-2023-0395 and TA-9-2023-0462”. Text, 13 December 2023. from A-9-2023-0395, to TA-9-2023-0462. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462?all=1 (retrieved 26 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-12-13,
  author = {{European Parliament}},
  title = {{Changes between A-9-2023-0395 and TA-9-2023-0462}},
  year = {2023},
  date = {2023-12-13},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462?all=1}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462?all=1},
  urldate = {2026-09-26},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2023-0395, to TA-9-2023-0462. Data: European Parliament Open Data (CC BY 4.0)}
}