What we do Pilot Technologies Blog About us Contact Write to us

Secondary use of health data for AI: a guide for hospitals

15 minConsdinamic

What secondary use of health data means, how the EHDS organises it (access bodies, data permits, secure environments) and how hospital data reach AI lawfully.

Sec­ondary use of health data means reusing data from patient care for research, sta­tis­tics, policy-making or training ar­ti­fi­cial in­tel­li­gence (AI) al­go­rithms. In the EU, access needs a permit from a health data access body and a secure en­vi­ron­ment that no personal data leave: from 26 March 2029 for most data, from 2031 for some cat­e­gories, such as genomic data.

What is sec­ondary use of health data?

Sec­ondary use is any pro­cess­ing of health data for a purpose other than the one for which the data were col­lect­ed. Reg­u­la­tion (EU) 2025/327 on the European Health Data Space (EHDS), pub­lished in the Official Journal of the EU on 5 March 2025, defines it in Article 2(2)(e) as the pro­cess­ing of elec­tron­ic health data for the purposes set out in Chapter IV, other than the initial purposes.

Article 53 lists the purposes for which an access body may grant data: public health, policy-making and reg­u­la­tion, official sta­tis­tics, ed­u­ca­tion, im­prov­ing care, and sci­en­tif­ic research. Under research, the text ex­plic­it­ly names two ac­tiv­i­ties that matter to industry: de­vel­op­ment of products and services, and the training, testing and eval­u­a­tion of al­go­rithms, in­clud­ing in medical devices and AI systems. The con­di­tion is that the research con­trib­utes to public health or health tech­nol­o­gy as­sess­ment.

Article 54 sets out what is pro­hib­it­ed, whatever the permit:

  • de­ci­sions detri­men­tal to a person or group based on their health data;
  • dis­crim­i­na­to­ry de­ci­sions on em­ploy­ment, in­sur­ance or credit;
  • ad­ver­tis­ing and mar­ket­ing;
  • products that may harm public health, such as tobacco, alcohol or weapons;
  • ac­tiv­i­ties contrary to national ethical rules.

For the full EHDS timeline, see our guide to the European Health Data Space.

How does the EHDS organise access: access body, permit, secure en­vi­ron­ment

The EHDS places a public in­ter­me­di­ary between the hospital and the re­searcher, the health data access body (HDAB), which decides who gets which data and where they process them. Each Member State des­ig­nates one or more such bodies and notifies the Com­mis­sion by 26 March 2027 (Art. 55).

The roles are pre­cise­ly defined:

  • Health data holder (Art. 2): any natural or legal person in the health sector that pro­cess­es elec­tron­ic health data as a con­troller, for example a hospital. Natural persons and mi­croen­ter­pris­es are exempt unless national law decides oth­er­wise (Art. 50).
  • Health data user: whoever has been granted lawful access through a permit or an approved request.
  • Data permit: an ad­min­is­tra­tive decision by the access body au­tho­ris­ing the pro­cess­ing of spec­i­fied data for spec­i­fied purposes.
  • Secure pro­cess­ing en­vi­ron­ment (SPE): the only place where the user works with the data (Art. 73).

The access ap­pli­ca­tion (Art. 67) de­scribes the purpose, the data, the period, the com­put­ing tools, the safe­guards against re-iden­ti­fi­ca­tion and, where the ap­pli­cant asks for pseudonymised data, why anonymised data would not be enough. For pseudonymised data, the ap­pli­cant also shows the legal basis under Article 6(1) of Reg­u­la­tion (EU) 2016/679, the General Data Pro­tec­tion Reg­u­la­tion (GDPR). There is a lighter route, the health data request (Art. 69), which yields only an anonymised sta­tis­ti­cal answer, with no access to in­di­vid­u­al records.

The timeline has two tiers. Under Article 105, the sec­ondary use chapter applies from 26 March 2029, while five cat­e­gories in Article 51(1) follow from 26 March 2031: health de­ter­mi­nants (socio-economic, en­vi­ron­men­tal, be­havioural), genetic and genomic data, other omics data, clinical trial data, and research cohort and survey data.

The pro­ce­dur­al dead­lines are also written into the Reg­u­la­tion. Under Articles 60 and 68, a full cycle can take several months, not a few weeks:

CHART­BLOCK0

A permit is granted for as long as the purpose requires, up to 10 years, with one possible ex­ten­sion, and the data are deleted within six months of expiry (Art. 68). In the secure en­vi­ron­ment, access uses in­di­vid­u­al iden­ti­ties and covers only the data in the permit, and access logs are kept for at least one year (Art. 73). Securing such an en­vi­ron­ment relies on the same prac­tices the NIS2 Di­rec­tive requires of hos­pi­tals, covered in our guide to hospital cy­ber­se­cu­ri­ty and NIS2.

CHART­BLOCK1

Only non-personal data can leave the secure en­vi­ron­ment. Ac­cord­ing to the European Com­mis­sion, no personal data can be down­load­ed from these en­vi­ron­ments.

How does a hospital record reach an AI model?

A record reaches an AI model in four steps: the hospital records it in struc­tured form, the re­searcher obtains a permit, the access body delivers de-iden­ti­fied data into a secure en­vi­ron­ment, and only the model or results that contain no personal data leave that en­vi­ron­ment. The panel below shows each step.

CHART­BLOCK2

For the training stages them­selves, from la­belling to external val­i­da­tion, see our guide to how a neural network is trained.

Pseudonymised is not anonymised: what the GDPR, the EDPB and the Court say

Pseudonymised data remain personal data for whoever can restore the link to the patient, so the GDPR con­tin­ues to apply. Pseudonymi­sa­tion means re­plac­ing direct iden­ti­fiers with a code while keeping the in­for­ma­tion that allows re-iden­ti­fi­ca­tion sep­a­rate­ly. Anonymi­sa­tion means the person can no longer be iden­ti­fied by any rea­son­able means. In this article, "de-iden­ti­fied" refers to data from which iden­ti­fiers have been removed but which can be linked back to the patient by whoever holds the key.

Four texts set the rule:

  1. EHDS, Article 66. The access body provides anonymised data where the purpose can be achieved with them. Only where it cannot does it provide pseudonymised data, and the in­for­ma­tion needed to reverse the pseudonymi­sa­tion stays only with the body or a trusted third party.
  2. EDPB guide­lines on pseudonymi­sa­tion, adopted in January 2025. The European Data Pro­tec­tion Board (EDPB) states that pseudonymised data, which could be at­trib­uted to a person with ad­di­tion­al in­for­ma­tion, remain in­for­ma­tion about an iden­ti­fi­able person. Pseudonymi­sa­tion does, however, reduce risks.
  3. Court of Justice, Case C-413/23 P (EDPS v SRB), 4 Sep­tem­ber 2025. Ac­cord­ing to the Court's press release, pseudonymised data must not be regarded as personal data in all cases and for every person: for a re­cip­i­ent who cannot identify the person, they may not be. For the hospital that holds the key, they remain personal data.
  4. EDPB Opinion 28/2024 on AI models, December 2024. A model trained on personal data is anony­mous only if it is very unlikely to identify the people in the data or to allow their data to be ex­tract­ed through queries. The as­sess­ment is made case by case.

A hospital there­fore cannot assume that a dataset "without names" has left the GDPR. For the dif­fer­ence between con­troller and pro­ces­sor, see our article on GDPR in health­care and de-iden­ti­fi­ca­tion.

The hospital is the con­troller of its patients' data and needs a legal basis both for care and for any reuse. Article 9 GDPR pro­hibits the pro­cess­ing of health data in prin­ci­ple and allows ex­cep­tions.

Care relies on point (h). For research, point (j) allows pro­cess­ing for sci­en­tif­ic research purposes in line with Article 89(1), on the basis of Union or Member State law, with suitable safe­guards.

Point (i) covers public interest in public health, in­clud­ing the quality and safety of medical devices. Para­graph (4) allows Member States to add their own con­di­tions for health data, which is why the rules differ from country to country.

Until 26 March 2029, reuse relies on these GDPR bases and on national law, not on EHDS permits. After that date, the EHDS adds its own route:

  • The hospital is the con­troller for making data avail­able to the access body, and the body is the con­troller for its own tasks (Art. 74).
  • In the secure en­vi­ron­ment, the body acts as pro­ces­sor for the user, who becomes the con­troller for the pro­cess­ing under the permit.
  • The patient can opt out of sec­ondary use at any time, without giving a reason (Art. 71). An opt-out does not affect permits already issued. Member States may provide limited public-interest ex­cep­tions, with safe­guards.

In the Republic of Moldova, ac­cord­ing to guidance from the National Centre for Personal Data Pro­tec­tion (CNPDCP), Law No. 195/2024 on personal data pro­tec­tion applies from 23 August 2026, follows the rea­son­ing of the GDPR, treats pseudonymised data as data about an iden­ti­fi­able person, and allows consent for areas of sci­en­tif­ic research, in line with ethical stan­dards.

What have Austria, Poland, Moldova and Romania prepared?

We found no des­ig­nat­ed access body in any of the four coun­tries in the official sources con­sult­ed on 7 October 2026, but they are at very dif­fer­ent stages. Austria already has access in­fra­struc­ture for re­searchers, Poland has an in­sti­tu­tion­al plan, Moldova has targets with dead­lines, and Romania has ac­knowl­edged the problem in a draft strategy.

Country What exists or is being built Status (7 Oct 2026) Source
Austria The HealthData@AT project, led by Gesundheit Österreich GmbH (GÖG), has been preparing the future access body since January 2023, through the end of 2027: applications, catalogue, secure environments, data quality. The Austrian Micro Data Center (AMDC) at Statistics Austria offers remote access to accredited research institutions. EHDS body in preparation; AMDC operating, decision within a month, projects of up to five years GÖG; Statistics Austria
Poland The Ministry of Health analysed the tasks in Q3-Q4 2025 and assigns them first to existing institutions. It is preparing laws to establish the bodies and amendments to the 2008 patients' rights act and the 2011 health information system act. Preparation; laws to establish the bodies in progress; deadline 26.03.2027 Ministry of Health, March 2026
Moldova The programme approved by Government Decision No. 556/2025 provides for a national Health Data Access Body-type entity, with the draft decision establishing it scheduled for Q4 2025, and an authorisation and controlled-access mechanism for accredited researchers in Q4 2026 to Q4 2027, at an estimated cost of 2,000 thousand lei. Programme approved; we found no decision establishing the entity; mechanism due by Q4 2027 Decision No. 556/2025
Romania The explanatory note to the National Digital Health Strategy 2026-2030 notes a "lack of use of secondary data for public health purposes" and a "misinterpretation of GDPR that limits access to patient data". Draft decision put to consultation in January 2026; we found no official act designating an access body Ministry of Health, January 2026

Statuses in the table were verified on 7 October 2026 in the official sources cited.

The Moldovan pro­gramme also sets mea­sur­able in­di­ca­tors. Under Decision No. 556/2025, specific ob­jec­tive 3.3 aims, by the end of 2029, for an ecosys­tem of "anonymised" (the pro­gramme's term) and reusable health data, with at least five struc­tured datasets made avail­able each year. The result in­di­ca­tors start from 0 in 2024 and have targets for 2030, with pub­li­ca­tion on date.gov.md:

CHART­BLOCK3

What this means for a hospital in Romania or Moldova

A hospital that wants its data to serve research and AI should prepare now, because requests will come with three-month dead­lines. The steps below follow from the articles cited. The EHDS Reg­u­la­tion does not apply directly in Moldova, which is not an EU Member State: the dead­lines in the list bind hos­pi­tals in Romania, while for hos­pi­tals in Moldova they are a ref­er­ence for align­ment, in line with the national pro­gramme. Costs depend on existing systems, and the sources do not estimate them for in­di­vid­u­al hos­pi­tals.

Check­list

  1. Dataset in­ven­to­ry. List the data you hold in struc­tured form (coded di­ag­noses, lab­o­ra­to­ry results, imaging, pathol­o­gy) and what exists only as free text or PDF. Prepare a de­scrip­tion for each dataset, to be updated yearly (Art. 60).
  2. Legal basis for today's projects. For every research or AI col­lab­o­ra­tion before 2029, document the basis under Article 6 and Article 9(2) GDPR or, in Moldova, under Law 195/2024, plus ethics approval where the law requires it.
  3. De-iden­ti­fi­ca­tion pro­ce­dure. Decide who pseudonymis­es, where the key is kept and who can access it. Do not call a dataset "anony­mous" if it can be linked back to the patient.
  4. Sep­a­ra­tion of roles. Make the contract state who is con­troller and who is pro­ces­sor at each stage, fol­low­ing the model of Article 74.
  5. Opt-out register. Prepare a way to flag patients who opt out of sec­ondary use, to comply with Article 71 from 2029.
  6. A three-month delivery route. Appoint a person re­spon­si­ble and an internal route through which an extract re­quest­ed by the access body leaves on time (Art. 60).

Ques­tions to ask an AI or software vendor

  • Where is the model trained, and who has access to the working en­vi­ron­ment? How is access logged?
  • Do you receive pseudonymised or anonymised data? Who holds the re-iden­ti­fi­ca­tion key?
  • What leaves the working en­vi­ron­ment: the model, ag­gre­gat­ed results or in­di­vid­u­al records? How do you show that the model does not allow personal data to be ex­tract­ed, in the sense of the EDPB opinion?
  • Do the data remain under the hospital's control after the project ends? How are they deleted?

Cons­d­i­nam­ic, a company from the Republic of Moldova that builds software and AI to order, works with Aiforia (Finland) on de-iden­ti­fied oncology pathol­o­gy datasets for AI, and the hospital remains the data con­troller. Data pro­tec­tion is part of the project from the first day, in line with the GDPR, with access limited to what is strictly nec­es­sary and the data under the client's control. For AI in pathol­o­gy, see our article on neural networks in digital pathol­o­gy.

The topic is also on the agenda in Vienna on 15 October 2026, at "Digital Health Trans­for­ma­tion in Europe: Lessons Learned and Future Op­por­tu­ni­ties from Poland, Austria and Moldova", where the Austrian In­sti­tute of Tech­nol­o­gy (AIT) presents "AI and Sec­ondary Use of Health Data in Europe".

Con­clu­sion

Since 2025, sec­ondary use of health data for AI has had a clear European frame­work: per­mit­ted purposes and pro­hi­bi­tions (Articles 53 and 54), access bodies des­ig­nat­ed by 26 March 2027, permits with fixed dead­lines and secure en­vi­ron­ments that no personal data leave, applying from 26 March 2029 for most data cat­e­gories and from 26 March 2031 for others, such as genomic data and clinical trial data. The GDPR remains the foun­da­tion: pseudonymised data are personal data for whoever holds the key, and an AI model has to demon­strate, not assume, that it is anony­mous. Austria and Poland are building their access bodies, Moldova has targets and dead­lines in its 2025-2030 pro­gramme, and Romania has ac­knowl­edged the problem in its draft strategy. For a hospital, prepa­ra­tion starts with struc­tured data, a doc­u­ment­ed de-iden­ti­fi­ca­tion pro­ce­dure and con­tracts that state clearly who is re­spon­si­ble for the data.

Frequently asked questions

What does secondary use of health data mean?

It is the processing of health data for a purpose other than the one for which they were collected, such as research, statistics, policy-making or training algorithms. Regulation (EU) 2025/327 (EHDS) defines it in Article 2 and lists the permitted purposes in Article 53.

Can electronic health records be used to train an AI model?

Yes, when the purpose is scientific research in health that contributes to public health or health technology assessment. Article 53(1)(e) of the EHDS explicitly mentions training, testing and evaluating algorithms, including in medical devices and AI systems. Access is granted through a data permit and takes place in a secure processing environment.

What is a health data access body (HDAB)?

It is the public authority designated by each EU Member State to decide on applications for secondary use, issue data permits and make data available in a secure processing environment. Member States must notify the Commission of their access bodies by 26 March 2027 (Article 55 of Regulation (EU) 2025/327). Data holders, such as hospitals, deliver the requested data to it within three months, extendable by three.

Is pseudonymised data the same as anonymised data?

No. Under the GDPR and the EDPB's 2025 guidelines, pseudonymised data remain information about an identifiable person for whoever can restore the link. The Court of Justice clarified in 2025 that, for a recipient who cannot identify the person, the assessment depends on the circumstances.

Can patients opt out of their data being used for research and AI?

Yes. Article 71 of the EHDS gives everyone the right to opt out at any time, without giving a reason, from the secondary use of their data. Member States may provide limited exceptions for public-interest purposes, with strict safeguards.

When do the EHDS rules on secondary use apply?

Member States must notify their health data access bodies by 26 March 2027. The chapter on secondary use applies from 26 March 2029, and for some categories, such as genomic data and clinical trial data, from 26 March 2031.

Sources
  1. Regulation (EU) 2025/327 on the European Health Data Space, EUR-Lex, 2025 — published in the Official Journal on 5 March 2025; Art. 2(2)(e), 50, 51, 53, 54, 55, 60, 66, 67, 68, 69, 71, 73, 74 and 105: definitions, purposes, prohibitions, deadlines, permits, secure processing, opt-out, roles
  2. European Commission, European Health Data Space Regulation (EHDS), 2025 — secondary use applies from 2029 for most data categories and from 2031 for the rest; no personal data can be downloaded from secure environments; simple, reversible opt-out
  3. Regulation (EU) 2016/679 (GDPR), Article 9, gdpr-info.eu — general prohibition on processing health data and the exceptions in Art. 9(2)(h), (i), (j); Art. 9(4) further national conditions
  4. EDPB, EDPB adopts pseudonymisation guidelines, 17 January 2025 — pseudonymised data remain information relating to an identifiable person; pseudonymisation reduces risks
  5. EDPB, Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models, 18 December 2024 — an AI model is anonymous only if identification and extraction of personal data through queries are very unlikely; case-by-case assessment
  6. Court of Justice of the EU, Press Release No 107/25, Case C-413/23 P, EDPS v SRB, 4 September 2025 — pseudonymised data are not personal data in all cases and for every person; it depends on whether the recipient can identify the person
  7. Gesundheit Österreich GmbH (GÖG), HealthData@AT, 2026 — preparing Austria's future access body from January 2023 to the end of 2027, EU co-funded; four capabilities: applications, catalogue, secure processing environments, data quality
  8. Statistics Austria, Austrian Micro Data Center (AMDC), 2026 — remote access for accredited research institutions, decision within a month, projects of up to five years
  9. Ministry of Health of Poland, e-Health Department, Wdrożenie EHDS w Polsce, 25 March 2026 — analysis in Q3-Q4 2025, internal report, tasks assigned first to existing institutions, laws to establish the bodies, deadline 26.03.2027
  10. Government of the Republic of Moldova, Decision No. 556/2025 approving the National Programme for Digitalisation and Innovation in Health 2025-2030, Official Monitor No. 506-509/640 of 26.09.2025 (text hosted by USMF) — Health Data Access Body-type entity (action 1.2.1, Q4 2025); controlled access mechanism for researchers, Q4 2026-Q4 2027, 2,000 thousand lei (action 3.3.3); specific objective 3.3 by the end of 2029; indicators 3.3.1 and 3.3.2, 2024 reference = 0, 2030 targets
  11. CNPDCP (Republic of Moldova), Guidance on applying Law No. 195/2024 on personal data protection, 2026 — Law 195/2024 applies from 23 August 2026; pseudonymised data relate to an identifiable person; consent for areas of research
  12. Ministry of Health (Romania), Explanatory note to the draft Government Decision on the National Digital Health Strategy 2026-2030, January 2026 — notes the lack of secondary data use for public health and a misinterpretation of GDPR that limits access to patient data
EHDSsecondary useartificial intelligencehealth data
Do you have a similar problem in your institution?

Tell us what you need. We come back with a prototype, not with slides.

Write to us

Other articles