MyHealth@EU: How Health Data Compliance Is Changing
On 21 September 2026, the European Commission published two new regulations in the Official Journal of the European Union, defining crucial operational aspects of the European Health Data Space.
Rules and regulations governing digital health are undergoing an unprecedented transformation: the European Union intends to enforce a material revision of legal compliance strategies for companies in the pharmaceutical, biotech, and clinical research sectors to ensure the operational readiness of the European Health Data Space (EHDS).
The aim of the new regulations, implementing the Framework Regulation No. 2025/327 is to create a single European health data space within the EU through a dual strategy.Oon the one hand, they regulate the “primary use” of data, allowing citizens instant and free access to their medical records (“Patient Summary”), while enabling medical staff to issue an electronic prescription in one Member State and distribute the medicines in another participating country (“ePrescription and eDispensation”). On the other hand, they regulate “secondary use”, granting pharmaceutical companies, universities, and research startups legal access to anonymized databases. This information will allow researchers to train artificial intelligence algorithms, develop precision medicines, and simulate advanced clinical trials using digital twins.
The MyHealth@EU network, acting as centralized digital infrastructure, is designed to ensure secure and immediate cross-border data exchange (for primary use) according to a technical architecture and governance provided by the said regulations, distinguishing two operational profiles of the EHDS: the first focusing on the functioning of MyHealth@EU and the second on the description of datasets intended for secondary use.
More particularly, Regulation (EU) 2026/2083 focuses on the “primary use” and establishes operational rules for MyHealth@EU, in compliance with privacy standards and compatibility across the entire EU territory, providing for a technical and semantic interoperability. It is required that (i) IT systems (hardware and software) in different Member States connect and communicate with each other (so-called “technical interoperability“), and that (ii) a common coding system is agreed ensuring that any clinical data retains the exact same meaning across the European Union (so-called “semantic interoperability“).
The second Regulation (EU) 2026/2098, focuses on the “secondary use” tailored for research purposes. The regulation clearly maps out which data will be available, who will hold them, and under what specific conditions they can be accessed.
Sanctions provided by the Framework Regulation are articulated and severe, imposing extraordinary attention on compliance with these regulations.
Article 64 of the Framework Regulation provides for administrative fines depending on the nature of the infringement, up to the amount of 10 million euros (or 2% of the total worldwide annual turnover of the preceding financial year, if higher than such amount) and, for certain more serious infringements, up to 20 million euros (or 4% of the total worldwide annual turnover).
In addition to these financial sanctions, the competent authorities are entitled, at their discretion, to prevent access permits to research datasets (for a period of up to five years), with a consequent huge impact on industrial and scientific development.
The first Regulation (2026/2083) will enter into force gradually, starting on 26 March 2027, whereas the second Regulation (2026/2098) on metadata will enter into force on 26 March 2029. Therefore, transition towards the EHDS requires a prompt planning, particularly regarding IT systems, data governance, and internal procedures.