Regulation on the European Health Data Space (EHDS)
Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cross-Border
Per EHDS: cross-border health data. Requirements include (a) implement Cross-Border Data Transfers per Article 7 + (b) cooperate with MyHealth@EU + (c) maintain inventory of cross-border flows + (d) implement appropriate safeguards + (e) cooperate with EHDS Board.
- EHDS evidence for EHDSREG-5
- EHR conformity + HDAB cooperation + MyHealth@EU partial
Cross-Border Telemedicine
Where telemedicine services are provided across borders, Member States must accept the identification, prescription, and data formats used by the Member State of treatment, with safeguards consistent with EHDS interoperability requirements.
- Telemedicine service catalogue and supported cross-border flows
- Cross-border prescription handling procedure aligned to MyHealth@EU
- Identification policy for telemedicine consultations
- Quality assurance and patient feedback records
- Incident handling for cross-border telemedicine
- Telemedicine services accept only domestic identifiers
- Cross-border prescriptions issued in unsupported formats
- No quality assurance specific to telemedicine
Data Holder Obligations and Secondary Use
Prohibited: decisions detrimental to natural persons, advertising/marketing, determining insurance premiums, developing products harmful to public health (Article 53).
- Data permit application records and approvals
- Secure processing environment configuration baseline
- Dataset catalogue entries with metadata
- Data altruism and anonymisation procedure
- Permit decisions not consistently documented
- Secure processing environments lack egress controls
- Catalogue entries missing quality indicators
- Anonymisation method not validated against re-identification risk
Health data holders shall make electronic health data available to health data access bodies for secondary use in accordance with the regulation.
- Data permit application records and approvals
- Secure processing environment configuration baseline
- Dataset catalogue entries with metadata
- Data altruism and anonymisation procedure
- Permit decisions not consistently documented
- Secure processing environments lack egress controls
- Catalogue entries missing quality indicators
- Anonymisation method not validated against re-identification risk
Data users shall access and process electronic health data only in secure processing environments provided by health data access bodies.
- Data permit application records and approvals
- Secure processing environment configuration baseline
- Dataset catalogue entries with metadata
- Data altruism and anonymisation procedure
- Permit decisions not consistently documented
- Secure processing environments lack egress controls
- Catalogue entries missing quality indicators
- Anonymisation method not validated against re-identification risk
Health data holders shall provide and regularly update dataset descriptions for inclusion in national data catalogues.
- Data permit application records and approvals
- Secure processing environment configuration baseline
- Dataset catalogue entries with metadata
- Data altruism and anonymisation procedure
- Permit decisions not consistently documented
- Secure processing environments lack egress controls
- Catalogue entries missing quality indicators
- Anonymisation method not validated against re-identification risk
EHR Requirements
Per EHDS Regulation: EHR system requirements. Requirements include (a) Mandatory requirements for EHR systems placed on the market (Article 14) including conformity + (b) Identification and Authentication (Article 12) of healthcare professionals + patients + (c) maintain interoperability per European Electronic Health Record Exchange Format (EEHRxF) + (d) implement Conformity Assessment per Articles 23-29 + (e) maintain CE marking + technical documentation.
- EHDS evidence for EHDSREG-1
- EHR conformity + HDAB cooperation + MyHealth@EU partial
Governance
Per EHDS Articles 8-9: Digital Health Authorities. Requirements include (a) Digital Health Authorities (Article 10) coordination + (b) participate in MyHealth@EU + (c) implement governance + roles + (d) cooperate with European Commission + EHDSB (EHDS Board) + (e) maintain documentation.
- EHDS evidence for EHDSREG-4
- EHR conformity + HDAB cooperation + MyHealth@EU partial
Phased Application
Per EHDS Article 105: phased application. Requirements include (a) understand Phased Application timeline + (b) implement requirements per phase + (c) cooperate with enforcement + (d) maintain compliance documentation.
- EHDS evidence for EHDSREG-6
- EHR conformity + HDAB cooperation + MyHealth@EU partial
Primary Use
Per EHDS Articles 8-13: primary use rights. Requirements include (a) implement Right to restrict access and rectification (Article 11) for primary use + (b) implement opt-out where applicable + (c) maintain access logs + audit trail + (d) implement appropriate consent management + (e) align with GDPR + national health law.
- EHDS evidence for EHDSREG-2
- EHR conformity + HDAB cooperation + MyHealth@EU partial
Secondary Use
Per EHDS Articles 33-56: secondary use. Requirements include (a) implement secondary use of electronic health data for research + innovation + policymaking + statistics + (b) implement data access permits + Health Data Access Bodies (HDABs) + (c) implement secure processing environments + (d) implement opt-out where required + (e) implement minimisation + pseudonymisation + (f) cooperate with HDABs.
- EHDS evidence for EHDSREG-3
- EHR conformity + HDAB cooperation + MyHealth@EU partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Regulation on the European Health Data Space (EHDS) framework page.