FactBox.

EUR-Lex · 21 Sep 2026 · 3 vistas

Brussels sets security and data rules for cross-border MyHealth@EU platform

Por FactBox Admin

Brussels sets security and data rules for cross-border MyHealth@EU platform

The European Commission has adopted Commission Implementing Regulation (EU) 2026/2083 of 18 September 2026 on MyHealth@EU, the central interoperability platform for the cross-border exchange of electronic health data. Published in the Official Journal of the European Union, L series, of 21 September 2026, the text lays down the cybersecurity, technical and semantic interoperability, operations and data-protection rules that Member States must meet to join and remain connected to the platform. It applies from 26 March 2027.

The regulation is adopted under Article 23(4) and (8) of Regulation (EU) 2025/327 of 11 February 2025 establishing the European Health Data Space, which tasked the Commission with setting up MyHealth@EU. The platform builds on the architecture of the eHealth Digital Service Infrastructure created by Commission Implementing Decision 2019/1765, which allowed Member States to exchange patient summaries, electronic prescriptions and electronic dispensations on a voluntary basis. The text is signed in Brussels on 18 September 2026 by Commission President Ursula von der Leyen, carries EEA relevance, and follows an opinion delivered by the European Data Protection Supervisor on 18 May 2026.

Four central services and a shared requirements catalogue

The Commission must provide four services of the central platform:

  • a reference implementation software for national contact points for digital health;
  • a central terminology service for mapping and translating coding systems;
  • a secure communication network;
  • a central configuration service.

The Commission, in cooperation with the MyHealth@EU steering group established by Article 95(1) of Regulation (EU) 2025/327, draws up and maintains a requirements catalogue covering use cases, implementation requirements and frameworks for testing, compliance checking, operations and incident monitoring. Technical specifications are proposed by the Commission and approved by the steering group. A major change to the catalogue may be proposed by the Commission on its own initiative or at the request of five or more members of the steering group.

Compliance checks, authorisations and incident reporting

National contact points for digital health must pass technical tests and compliance checks, whose findings are classified as minor, medium or critical. An action plan to close findings must be submitted to the Commission within 15 working days of receiving the results. Checks are carried out before the start of data exchange, every five years thereafter, and whenever the Commission identifies a critical risk to security, confidentiality or data protection.

Authorisations are granted by the steering group: to start exchanging data, to upgrade to a new major release — requested no later than one month before the end of the implementation timeline — and to continue after an operational compliance check, within two months of receiving the result. Significant incidents must be notified to the chair of the steering group, the Commission and affected contact points within 24 hours, with a detailed report within one month.

Data protection roles and phased deadlines

National contact points for digital health act as joint controllers and the Commission as processor, with processing limited to the priority and additional categories of personal electronic health data for primary use and to data needed to manage the platform. The processing is subject to Regulation (EU) 2016/679 and Regulation (EU) 2018/1725, while IT security follows Commission Decision (EU, Euratom) 2017/46.

The obligations to exchange data through MyHealth@EU become applicable on 26 March 2029 for patient summaries, electronic prescriptions and electronic dispensations, and on 26 March 2031 for medical imaging studies and related reports, medical test results and discharge reports. Contact points already connected under Implementing Decision 2019/1765 before 26 March 2029 and designated as national contact points for digital health are deemed to comply with the authorisation requirements.

For patients, hospitals and health-data providers, the regulation fixes the technical and legal conditions under which a prescription issued in one Member State can be dispensed in another, and sets the security and accountability standards the platform must meet before that exchange becomes mandatory.


Source: Official Journal of the European Union, L series, 2026/2083, 21 September 2026, p. 1 (official reference: CELEX:L_20262083).