EU Adopts Implementing Regulation on MyHealth@EU Cross-Border Health Data Exchange
The European Commission has adopted Commission Implementing Regulation (EU) 2026/2083 of 18 September 2026 on MyHealth@EU.
The Regulation sets out detailed rules for the technical development and operation of MyHealth@EU, the EU infrastructure for cross-border exchange of personal electronic health data under the European Health Data Space (EHDS) framework.
It was published in the Official Journal on 21 September 2026 and will apply from 26 March 2027.
MyHealth@EU Under the EHDS
Regulation (EU) 2025/327 establishes MyHealth@EU as a central interoperability platform for the cross-border exchange of priority categories of electronic health data.
The new Implementing Regulation provides the operational detail needed to make that framework work in practice, including rules on:
cybersecurity;
technical interoperability;
semantic interoperability;
service management;
compliance testing;
incident management;
security and confidentiality;
personal data protection.
Building on Existing EU eHealth Infrastructure
MyHealth@EU builds on the earlier eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services, established under Implementing Decision 2019/1765.
That earlier infrastructure enabled voluntary exchange of:
patient summaries;
electronic prescriptions;
electronic dispensations.
The new framework expands and formalises this architecture under the EHDS.
Central Interoperability Platform
The Regulation requires the European Commission to provide four core services for the MyHealth@EU central interoperability platform:
reference implementation software;
a central terminology service;
a secure communication network;
a central configuration service.
National contact points for digital health may use the Commission’s reference software or alternative solutions, provided those alternatives comply with the applicable requirements catalogue and technical specifications.
Semantic Interoperability
The central terminology service is intended to support translation and mapping between national coding systems and the European electronic health record exchange format.
Member States remain responsible for maintaining and updating their own translations and mappings of coding systems and value sets.
This is intended to support consistent interpretation of exchanged health data across national systems.
Requirements Catalogue and Technical Specifications
The Commission, working with the MyHealth@EU Steering Group, must maintain a requirements catalogue for cross-border exchange of electronic health data.
The catalogue must cover at least:
implemented use cases;
technical requirements for data exchange;
testing frameworks;
compliance checking;
operations;
incident monitoring.
Technical specifications will be developed from this catalogue and approved by the Steering Group.
Major and Minor Releases
The Regulation introduces formal change-management rules.
A major release includes changes that are not backwards compatible or that significantly affect the exchange of personal electronic health data.
A minor release covers changes that do not have this level of impact.
Major changes require a structured proposal, implementation timeline and Steering Group approval.
Compliance Checks and Technical Tests
National contact points for digital health must demonstrate compliance before joining or continuing to operate within MyHealth@EU.
The Commission will conduct compliance checks and facilitate technical tests covering areas such as:
security;
confidentiality;
personal data protection;
conformity with technical specifications.
Findings are classified as:
minor;
medium;
critical.
Where findings are identified, the national contact point must submit an action plan within 15 working days.
Frequency of Compliance Checks
Compliance must be assessed:
before exchange begins;
every five years after the most recent compliance check;
whenever the Commission considers that a critical risk exists to security, confidentiality or data protection.
This creates an ongoing assurance mechanism rather than a one-time approval process.
Authorisation to Exchange Health Data
National contact points must obtain formal authorisation before beginning cross-border exchange of personal electronic health data.
Authorisation depends on:
technical test results without critical findings;
compliance check results without critical findings;
appropriate action plans for other findings.
Separate authorisation requirements also apply following major upgrades and after operational compliance checks.
Significant Incident Reporting
The Regulation introduces a specific reporting timeline for significant incidents.
A national contact point for digital health, or the Commission where relevant, must notify the Steering Group chair, the Commission and affected national contact points as soon as possible and no later than 24 hours after becoming aware of a significant incident.
Temporary suspension of cross-border health data exchange may be used as a mitigation measure.
A more detailed report must then be provided within one month, covering the incident’s severity, impact, likely cause and mitigation measures.
Categories of Health Data
Processing through MyHealth@EU is limited to priority and additional categories of personal electronic health data allowed under the EHDS framework, together with personal data needed to manage the service itself.
The phased EHDS timeline means mandatory exchange obligations will apply progressively.
2029 and 2031 Data Exchange Milestones
The Regulation confirms that EHDS obligations for cross-border exchange through MyHealth@EU will become applicable in stages.
From 26 March 2029, the mandatory exchange applies to:
patient summaries;
electronic prescriptions;
electronic dispensations.
From 26 March 2031, it expands to:
medical imaging studies and related reports;
medical test results, including laboratory and other diagnostic results;
discharge reports.
These dates are particularly important for organisations involved in digital health infrastructure, diagnostics, imaging and healthcare interoperability.
Data Protection and Joint Controllership
Under the EHDS framework, national contact points for digital health act as joint controllers, while the European Commission acts as processor for MyHealth@EU.
The Implementing Regulation clarifies their respective obligations.
National contact points must, among other things:
inform data subjects;
handle data subject rights requests;
implement organisational, physical and logical security controls;
systematically log data exchanges;
coordinate incident and breach handling.
Responsibilities of the European Commission
As processor, the Commission must provide and maintain the secure communication infrastructure and ensure appropriate technical and organisational safeguards.
These include:
risk assessment;
confidentiality controls;
protection against unauthorised access;
encryption of data in transit;
physical security;
change management;
real-time monitoring;
audit and review procedures;
security incident management.
Security Requirements
The Regulation explicitly requires data transported through the central secure communication service to be encrypted.
It also requires continuous monitoring, audit procedures, security reviews and mechanisms to detect and respond to security breaches.
MyHealth@EU must also comply with the European Commission’s internal IT security framework.
Transitional Arrangements
National contact points already exchanging health data under the previous eHealth Digital Service Infrastructure before 26 March 2029 may continue exchanging data under MyHealth@EU without repeating the initial authorisation process, provided they are designated as national contact points under the EHDS.
This is intended to support continuity during the transition from the existing infrastructure to the new EHDS framework.
Impact on Digital Health and Medical Device Stakeholders
For healthcare organisations, health IT providers, medical device and IVD manufacturers, digital health companies and regulatory teams, the Regulation is relevant because it creates the operational foundation for a more integrated European health data ecosystem.
Stakeholders should pay particular attention to:
MyHealth@EU interoperability requirements;
European electronic health record exchange formats;
terminology and coding-system mapping;
cybersecurity controls;
encrypted data exchange;
compliance checks and testing;
incident-reporting processes;
laboratory and diagnostic data exchange;
medical imaging interoperability;
EHDS implementation milestones;
data protection roles and responsibilities;
integration with national healthcare infrastructures.
For medical device and IVD organisations, the broader significance is the continued development of an EU-wide digital health environment in which diagnostic results, imaging data and other clinical information can increasingly move across borders through standardised and secure infrastructure.
Entry Into Force and Application
Commission Implementing Regulation (EU) 2026/2083 will enter into force on the twentieth day following publication in the Official Journal.
It will apply from 26 March 2027 and will be directly applicable in all EU Member States.