Articles 43 to 46: Regulation 2019/1020 applies to EHR systems; Member States designate empowered, resourced market surveillance authorities (possibly the digital health authority, with conflicts avoided) that report yearly to the Commission; authorities evaluate systems posing risks, require corrective action, act immediately on patient-safety or security incidents, inform the Commission, other Member States and data protection authorities, and, for non-compliance (Annex II, documentation, declaration, CE marking or registration failures), set deadlines and then prohibit, restrict, recall or withdraw; the Union safeguard procedure resolves objections. Economic operators must cooperate and correct across the whole Union.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.