Secondary use of health data for AI: a guide for hospitals
What secondary use of health data means, how the EHDS organises it (access bodies, data permits, secure environments) and how hospital data reach AI lawfully.
Secondary use of health data means reusing data from patient care for research, statistics, policy-making or training artificial intelligence (AI) algorithms. In the EU, access needs a permit from a health data access body and a secure environment that no personal data leave: from 26 March 2029 for most data, from 2031 for some categories, such as genomic data.
What is secondary use of health data?
Secondary use is any processing of health data for a purpose other than the one for which the data were collected. Regulation (EU) 2025/327 on the European Health Data Space (EHDS), published in the Official Journal of the EU on 5 March 2025, defines it in Article 2(2)(e) as the processing of electronic health data for the purposes set out in Chapter IV, other than the initial purposes.
Article 53 lists the purposes for which an access body may grant data: public health, policy-making and regulation, official statistics, education, improving care, and scientific research. Under research, the text explicitly names two activities that matter to industry: development of products and services, and the training, testing and evaluation of algorithms, including in medical devices and AI systems. The condition is that the research contributes to public health or health technology assessment.
Article 54 sets out what is prohibited, whatever the permit:
- decisions detrimental to a person or group based on their health data;
- discriminatory decisions on employment, insurance or credit;
- advertising and marketing;
- products that may harm public health, such as tobacco, alcohol or weapons;
- activities contrary to national ethical rules.
For the full EHDS timeline, see our guide to the European Health Data Space.
How does the EHDS organise access: access body, permit, secure environment
The EHDS places a public intermediary between the hospital and the researcher, the health data access body (HDAB), which decides who gets which data and where they process them. Each Member State designates one or more such bodies and notifies the Commission by 26 March 2027 (Art. 55).
The roles are precisely defined:
- Health data holder (Art. 2): any natural or legal person in the health sector that processes electronic health data as a controller, for example a hospital. Natural persons and microenterprises are exempt unless national law decides otherwise (Art. 50).
- Health data user: whoever has been granted lawful access through a permit or an approved request.
- Data permit: an administrative decision by the access body authorising the processing of specified data for specified purposes.
- Secure processing environment (SPE): the only place where the user works with the data (Art. 73).
The access application (Art. 67) describes the purpose, the data, the period, the computing tools, the safeguards against re-identification and, where the applicant asks for pseudonymised data, why anonymised data would not be enough. For pseudonymised data, the applicant also shows the legal basis under Article 6(1) of Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR). There is a lighter route, the health data request (Art. 69), which yields only an anonymised statistical answer, with no access to individual records.
The timeline has two tiers. Under Article 105, the secondary use chapter applies from 26 March 2029, while five categories in Article 51(1) follow from 26 March 2031: health determinants (socio-economic, environmental, behavioural), genetic and genomic data, other omics data, clinical trial data, and research cohort and survey data.
The procedural deadlines are also written into the Regulation. Under Articles 60 and 68, a full cycle can take several months, not a few weeks:
CHARTBLOCK0
A permit is granted for as long as the purpose requires, up to 10 years, with one possible extension, and the data are deleted within six months of expiry (Art. 68). In the secure environment, access uses individual identities and covers only the data in the permit, and access logs are kept for at least one year (Art. 73). Securing such an environment relies on the same practices the NIS2 Directive requires of hospitals, covered in our guide to hospital cybersecurity and NIS2.
CHARTBLOCK1
Only non-personal data can leave the secure environment. According to the European Commission, no personal data can be downloaded from these environments.
How does a hospital record reach an AI model?
A record reaches an AI model in four steps: the hospital records it in structured form, the researcher obtains a permit, the access body delivers de-identified data into a secure environment, and only the model or results that contain no personal data leave that environment. The panel below shows each step.
CHARTBLOCK2
For the training stages themselves, from labelling to external validation, see our guide to how a neural network is trained.
Pseudonymised is not anonymised: what the GDPR, the EDPB and the Court say
Pseudonymised data remain personal data for whoever can restore the link to the patient, so the GDPR continues to apply. Pseudonymisation means replacing direct identifiers with a code while keeping the information that allows re-identification separately. Anonymisation means the person can no longer be identified by any reasonable means. In this article, "de-identified" refers to data from which identifiers have been removed but which can be linked back to the patient by whoever holds the key.
Four texts set the rule:
- EHDS, Article 66. The access body provides anonymised data where the purpose can be achieved with them. Only where it cannot does it provide pseudonymised data, and the information needed to reverse the pseudonymisation stays only with the body or a trusted third party.
- EDPB guidelines on pseudonymisation, adopted in January 2025. The European Data Protection Board (EDPB) states that pseudonymised data, which could be attributed to a person with additional information, remain information about an identifiable person. Pseudonymisation does, however, reduce risks.
- Court of Justice, Case C-413/23 P (EDPS v SRB), 4 September 2025. According to the Court's press release, pseudonymised data must not be regarded as personal data in all cases and for every person: for a recipient who cannot identify the person, they may not be. For the hospital that holds the key, they remain personal data.
- EDPB Opinion 28/2024 on AI models, December 2024. A model trained on personal data is anonymous only if it is very unlikely to identify the people in the data or to allow their data to be extracted through queries. The assessment is made case by case.
A hospital therefore cannot assume that a dataset "without names" has left the GDPR. For the difference between controller and processor, see our article on GDPR in healthcare and de-identification.
What legal basis does a hospital need to use its data for AI?
The hospital is the controller of its patients' data and needs a legal basis both for care and for any reuse. Article 9 GDPR prohibits the processing of health data in principle and allows exceptions.
Care relies on point (h). For research, point (j) allows processing for scientific research purposes in line with Article 89(1), on the basis of Union or Member State law, with suitable safeguards.
Point (i) covers public interest in public health, including the quality and safety of medical devices. Paragraph (4) allows Member States to add their own conditions for health data, which is why the rules differ from country to country.
Until 26 March 2029, reuse relies on these GDPR bases and on national law, not on EHDS permits. After that date, the EHDS adds its own route:
- The hospital is the controller for making data available to the access body, and the body is the controller for its own tasks (Art. 74).
- In the secure environment, the body acts as processor for the user, who becomes the controller for the processing under the permit.
- The patient can opt out of secondary use at any time, without giving a reason (Art. 71). An opt-out does not affect permits already issued. Member States may provide limited public-interest exceptions, with safeguards.
In the Republic of Moldova, according to guidance from the National Centre for Personal Data Protection (CNPDCP), Law No. 195/2024 on personal data protection applies from 23 August 2026, follows the reasoning of the GDPR, treats pseudonymised data as data about an identifiable person, and allows consent for areas of scientific research, in line with ethical standards.
What have Austria, Poland, Moldova and Romania prepared?
We found no designated access body in any of the four countries in the official sources consulted on 7 October 2026, but they are at very different stages. Austria already has access infrastructure for researchers, Poland has an institutional plan, Moldova has targets with deadlines, and Romania has acknowledged the problem in a draft strategy.
| Country | What exists or is being built | Status (7 Oct 2026) | Source |
|---|---|---|---|
| Austria | The HealthData@AT project, led by Gesundheit Österreich GmbH (GÖG), has been preparing the future access body since January 2023, through the end of 2027: applications, catalogue, secure environments, data quality. The Austrian Micro Data Center (AMDC) at Statistics Austria offers remote access to accredited research institutions. | EHDS body in preparation; AMDC operating, decision within a month, projects of up to five years | GÖG; Statistics Austria |
| Poland | The Ministry of Health analysed the tasks in Q3-Q4 2025 and assigns them first to existing institutions. It is preparing laws to establish the bodies and amendments to the 2008 patients' rights act and the 2011 health information system act. | Preparation; laws to establish the bodies in progress; deadline 26.03.2027 | Ministry of Health, March 2026 |
| Moldova | The programme approved by Government Decision No. 556/2025 provides for a national Health Data Access Body-type entity, with the draft decision establishing it scheduled for Q4 2025, and an authorisation and controlled-access mechanism for accredited researchers in Q4 2026 to Q4 2027, at an estimated cost of 2,000 thousand lei. | Programme approved; we found no decision establishing the entity; mechanism due by Q4 2027 | Decision No. 556/2025 |
| Romania | The explanatory note to the National Digital Health Strategy 2026-2030 notes a "lack of use of secondary data for public health purposes" and a "misinterpretation of GDPR that limits access to patient data". | Draft decision put to consultation in January 2026; we found no official act designating an access body | Ministry of Health, January 2026 |
Statuses in the table were verified on 7 October 2026 in the official sources cited.
The Moldovan programme also sets measurable indicators. Under Decision No. 556/2025, specific objective 3.3 aims, by the end of 2029, for an ecosystem of "anonymised" (the programme's term) and reusable health data, with at least five structured datasets made available each year. The result indicators start from 0 in 2024 and have targets for 2030, with publication on date.gov.md:
CHARTBLOCK3
What this means for a hospital in Romania or Moldova
A hospital that wants its data to serve research and AI should prepare now, because requests will come with three-month deadlines. The steps below follow from the articles cited. The EHDS Regulation does not apply directly in Moldova, which is not an EU Member State: the deadlines in the list bind hospitals in Romania, while for hospitals in Moldova they are a reference for alignment, in line with the national programme. Costs depend on existing systems, and the sources do not estimate them for individual hospitals.
Checklist
- Dataset inventory. List the data you hold in structured form (coded diagnoses, laboratory results, imaging, pathology) and what exists only as free text or PDF. Prepare a description for each dataset, to be updated yearly (Art. 60).
- Legal basis for today's projects. For every research or AI collaboration before 2029, document the basis under Article 6 and Article 9(2) GDPR or, in Moldova, under Law 195/2024, plus ethics approval where the law requires it.
- De-identification procedure. Decide who pseudonymises, where the key is kept and who can access it. Do not call a dataset "anonymous" if it can be linked back to the patient.
- Separation of roles. Make the contract state who is controller and who is processor at each stage, following the model of Article 74.
- Opt-out register. Prepare a way to flag patients who opt out of secondary use, to comply with Article 71 from 2029.
- A three-month delivery route. Appoint a person responsible and an internal route through which an extract requested by the access body leaves on time (Art. 60).
Questions to ask an AI or software vendor
- Where is the model trained, and who has access to the working environment? How is access logged?
- Do you receive pseudonymised or anonymised data? Who holds the re-identification key?
- What leaves the working environment: the model, aggregated results or individual records? How do you show that the model does not allow personal data to be extracted, in the sense of the EDPB opinion?
- Do the data remain under the hospital's control after the project ends? How are they deleted?
Consdinamic, a company from the Republic of Moldova that builds software and AI to order, works with Aiforia (Finland) on de-identified oncology pathology datasets for AI, and the hospital remains the data controller. Data protection is part of the project from the first day, in line with the GDPR, with access limited to what is strictly necessary and the data under the client's control. For AI in pathology, see our article on neural networks in digital pathology.
The topic is also on the agenda in Vienna on 15 October 2026, at "Digital Health Transformation in Europe: Lessons Learned and Future Opportunities from Poland, Austria and Moldova", where the Austrian Institute of Technology (AIT) presents "AI and Secondary Use of Health Data in Europe".
Conclusion
Since 2025, secondary use of health data for AI has had a clear European framework: permitted purposes and prohibitions (Articles 53 and 54), access bodies designated by 26 March 2027, permits with fixed deadlines and secure environments that no personal data leave, applying from 26 March 2029 for most data categories and from 26 March 2031 for others, such as genomic data and clinical trial data. The GDPR remains the foundation: pseudonymised data are personal data for whoever holds the key, and an AI model has to demonstrate, not assume, that it is anonymous. Austria and Poland are building their access bodies, Moldova has targets and deadlines in its 2025-2030 programme, and Romania has acknowledged the problem in its draft strategy. For a hospital, preparation starts with structured data, a documented de-identification procedure and contracts that state clearly who is responsible for the data.
Frequently asked questions
What does secondary use of health data mean?
It is the processing of health data for a purpose other than the one for which they were collected, such as research, statistics, policy-making or training algorithms. Regulation (EU) 2025/327 (EHDS) defines it in Article 2 and lists the permitted purposes in Article 53.
Can electronic health records be used to train an AI model?
Yes, when the purpose is scientific research in health that contributes to public health or health technology assessment. Article 53(1)(e) of the EHDS explicitly mentions training, testing and evaluating algorithms, including in medical devices and AI systems. Access is granted through a data permit and takes place in a secure processing environment.
What is a health data access body (HDAB)?
It is the public authority designated by each EU Member State to decide on applications for secondary use, issue data permits and make data available in a secure processing environment. Member States must notify the Commission of their access bodies by 26 March 2027 (Article 55 of Regulation (EU) 2025/327). Data holders, such as hospitals, deliver the requested data to it within three months, extendable by three.
Is pseudonymised data the same as anonymised data?
No. Under the GDPR and the EDPB's 2025 guidelines, pseudonymised data remain information about an identifiable person for whoever can restore the link. The Court of Justice clarified in 2025 that, for a recipient who cannot identify the person, the assessment depends on the circumstances.
Can patients opt out of their data being used for research and AI?
Yes. Article 71 of the EHDS gives everyone the right to opt out at any time, without giving a reason, from the secondary use of their data. Member States may provide limited exceptions for public-interest purposes, with strict safeguards.
When do the EHDS rules on secondary use apply?
Member States must notify their health data access bodies by 26 March 2027. The chapter on secondary use applies from 26 March 2029, and for some categories, such as genomic data and clinical trial data, from 26 March 2031.
- Regulation (EU) 2025/327 on the European Health Data Space, EUR-Lex, 2025 — published in the Official Journal on 5 March 2025; Art. 2(2)(e), 50, 51, 53, 54, 55, 60, 66, 67, 68, 69, 71, 73, 74 and 105: definitions, purposes, prohibitions, deadlines, permits, secure processing, opt-out, roles
- European Commission, European Health Data Space Regulation (EHDS), 2025 — secondary use applies from 2029 for most data categories and from 2031 for the rest; no personal data can be downloaded from secure environments; simple, reversible opt-out
- Regulation (EU) 2016/679 (GDPR), Article 9, gdpr-info.eu — general prohibition on processing health data and the exceptions in Art. 9(2)(h), (i), (j); Art. 9(4) further national conditions
- EDPB, EDPB adopts pseudonymisation guidelines, 17 January 2025 — pseudonymised data remain information relating to an identifiable person; pseudonymisation reduces risks
- EDPB, Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models, 18 December 2024 — an AI model is anonymous only if identification and extraction of personal data through queries are very unlikely; case-by-case assessment
- Court of Justice of the EU, Press Release No 107/25, Case C-413/23 P, EDPS v SRB, 4 September 2025 — pseudonymised data are not personal data in all cases and for every person; it depends on whether the recipient can identify the person
- Gesundheit Österreich GmbH (GÖG), HealthData@AT, 2026 — preparing Austria's future access body from January 2023 to the end of 2027, EU co-funded; four capabilities: applications, catalogue, secure processing environments, data quality
- Statistics Austria, Austrian Micro Data Center (AMDC), 2026 — remote access for accredited research institutions, decision within a month, projects of up to five years
- Ministry of Health of Poland, e-Health Department, Wdrożenie EHDS w Polsce, 25 March 2026 — analysis in Q3-Q4 2025, internal report, tasks assigned first to existing institutions, laws to establish the bodies, deadline 26.03.2027
- Government of the Republic of Moldova, Decision No. 556/2025 approving the National Programme for Digitalisation and Innovation in Health 2025-2030, Official Monitor No. 506-509/640 of 26.09.2025 (text hosted by USMF) — Health Data Access Body-type entity (action 1.2.1, Q4 2025); controlled access mechanism for researchers, Q4 2026-Q4 2027, 2,000 thousand lei (action 3.3.3); specific objective 3.3 by the end of 2029; indicators 3.3.1 and 3.3.2, 2024 reference = 0, 2030 targets
- CNPDCP (Republic of Moldova), Guidance on applying Law No. 195/2024 on personal data protection, 2026 — Law 195/2024 applies from 23 August 2026; pseudonymised data relate to an identifiable person; consent for areas of research
- Ministry of Health (Romania), Explanatory note to the draft Government Decision on the National Digital Health Strategy 2026-2030, January 2026 — notes the lack of secondary data use for public health and a misinterpretation of GDPR that limits access to patient data
Tell us what you need. We come back with a prototype, not with slides.