Back to Frameworks

Regulation on the European Health Data Space (EHDS)

European Union (and EEA)
vRegulation (EU) 2025/327 (OJ L 5.3.2025), in force 26 March 2025, applies in stages 26 March 2027 to 26 March 2035; implementing acts 2026/771, 2026/2083, 2026/2098, 2026/2099
9 domains
63 controls

The EU regulation creating the European Health Data Space: patients get free, immediate access to and portability of their priority health data (summaries, e-prescriptions, imaging, results, discharge reports) with cross-border exchange through MyHealth@EU; EHR systems must carry harmonised interoperability and logging components with CE-marked self-declared conformity; and health data holders make data available for research, innovation and policy through health data access bodies, data permits and secure processing environments, with an opt-out. In force 26 March 2025; applies in stages from 26 March 2027 to 2035.

Verified

Regulation on the European Health Data Space (EHDS) is a compliance framework from European Union (and EEA) with 9 domains and 63 controls that map to 172 other frameworks. The largest domains are EHR systems: requirements and economic operators – Regulation on the European Health Data Space (EHDS) (18 controls), Secondary use: health data access bodies and procedures – Regulation on the European Health Data Space (EHDS) (12 controls), Primary use: rights of natural persons and healthcare duties – Regulation on the European Health Data Space (EHDS) (11 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (9)

EHR systems: requirements and economic operators – Regulation on the European Health Data Space (EHDS)

18 controls
Controls in the EHR systems: requirements and economic operators – Regulation on the European Health Data Space (EHDS) domain of Regulation on the European Health Data Space (EHDS) — 18 controls
CodeTitle
regulation-on-the-european-health-data-space-ehds::104Use the EHDS conformity route to show Cyber Resilience Act conformity for EHR systems
regulation-on-the-european-health-data-space-ehds::26Place or put into service only EHR systems whose harmonised components comply with Chapter III
regulation-on-the-european-health-data-space-ehds::27Medical devices and high-risk AI claiming EHR interoperability must meet the Annex II component requirements
regulation-on-the-european-health-data-space-ehds::28Make no misleading claims about an EHR system's purpose, interoperability or security
regulation-on-the-european-health-data-space-ehds::30Meet the manufacturer duties: conformity, documentation, declaration, CE marking, contact details and registration
regulation-on-the-european-health-data-space-ehds::30(1)(i)Correct, withdraw or recall non-conforming systems and keep complaint and non-conformity registers
regulation-on-the-european-health-data-space-ehds::31Non-EU manufacturers: appoint an EU authorised representative with a sufficient written mandate
regulation-on-the-european-health-data-space-ehds::32Importers: verify conformity before supply, keep records and act on non-conformity
regulation-on-the-european-health-data-space-ehds::33Distributors: check marking and documents before supply and report non-conformity
regulation-on-the-european-health-data-space-ehds::35Identify suppliers and customers of EHR systems to authorities for 10 years
regulation-on-the-european-health-data-space-ehds::37Draw up Annex III technical documentation and produce it within 30 days of a request
regulation-on-the-european-health-data-space-ehds::38Supply an information sheet stating identity, version, purpose, data categories and standards supported
regulation-on-the-european-health-data-space-ehds::39Issue an Annex IV EU declaration of conformity and affix the CE marking before placing on the market
regulation-on-the-european-health-data-space-ehds::40Test the harmonised components in the digital testing environment before placing on the market
regulation-on-the-european-health-data-space-ehds::43Designate market surveillance authorities and act on risk and non-compliance
regulation-on-the-european-health-data-space-ehds::44(7)Report serious incidents involving an EHR system within three days
regulation-on-the-european-health-data-space-ehds::Annex II-2Build the interoperability component to export, receive and not obstruct data in the exchange format
regulation-on-the-european-health-data-space-ehds::Annex II-3Authenticate professionals reliably and log every access event with the required fields

Member State measures, penalties and remedies – Regulation on the European Health Data Space (EHDS)

3 controls
Controls in the Member State measures, penalties and remedies – Regulation on the European Health Data Space (EHDS) domain of Regulation on the European Health Data Space (EHDS) — 3 controls
CodeTitle
regulation-on-the-european-health-data-space-ehds::83Train health professionals and promote patients' digital health literacy
regulation-on-the-european-health-data-space-ehds::85Reference the EHDS specifications in public procurement and funding conditions
regulation-on-the-european-health-data-space-ehds::99Lay down and notify penalties by 26 March 2027 and allow compensation claims

Primary use governance and MyHealth@EU – Regulation on the European Health Data Space (EHDS)

5 controls
Controls in the Primary use governance and MyHealth@EU – Regulation on the European Health Data Space (EHDS) domain of Regulation on the European Health Data Space (EHDS) — 5 controls
CodeTitle
regulation-on-the-european-health-data-space-ehds::19Designate resourced, independent digital health authorities by 26 March 2027
regulation-on-the-european-health-data-space-ehds::20Publish a biennial activity report of the digital health authority
regulation-on-the-european-health-data-space-ehds::21Receive and route complaints, and let data protection authorities enforce patient rights with GDPR-level fines
regulation-on-the-european-health-data-space-ehds::23Run a national contact point for digital health, connect every provider and dispense foreign e-prescriptions
regulation-on-the-european-health-data-space-ehds::IR2083Pass MyHealth@EU compliance checks, fix findings within set deadlines and report significant incidents within 24 hours

Primary use: rights of natural persons and healthcare duties – Regulation on the European Health Data Space (EHDS)

11 controls
Controls in the Primary use: rights of natural persons and healthcare duties – Regulation on the European Health Data Space (EHDS) domain of Regulation on the European Health Data Space (EHDS) — 11 controls
CodeTitle
regulation-on-the-european-health-data-space-ehds::11Give health professionals access to the relevant priority data of their patients, including across borders
regulation-on-the-european-health-data-space-ehds::13Register priority-category data electronically, keep it updated and record who changed it
regulation-on-the-european-health-data-space-ehds::15(4)Issue priority data in the European exchange format and accept it when received
regulation-on-the-european-health-data-space-ehds::16Identify patients and professionals electronically for cross-border exchange under the 2026 identification act
regulation-on-the-european-health-data-space-ehds::18Never charge patients or receiving providers for making or sharing health data
regulation-on-the-european-health-data-space-ehds::3Give patients immediate, free, readable access to and a download of their priority health data
regulation-on-the-european-health-data-space-ehds::4Operate free patient access services with proxy and legal-representative functions
regulation-on-the-european-health-data-space-ehds::5Let patients add information to their record and request rectification online
regulation-on-the-european-health-data-space-ehds::7Transmit patient data to another provider or reimbursement body immediately, free and without hindrance
regulation-on-the-european-health-data-space-ehds::8Honour patient restrictions and any national primary-use opt-out, with a vital-interest override that is logged
regulation-on-the-european-health-data-space-ehds::9Show patients who accessed their data, when and what, for at least three years

Secondary use: health data access bodies and procedures – Regulation on the European Health Data Space (EHDS)

12 controls
Controls in the Secondary use: health data access bodies and procedures – Regulation on the European Health Data Space (EHDS) domain of Regulation on the European Health Data Space (EHDS) — 12 controls
CodeTitle
regulation-on-the-european-health-data-space-ehds::55Designate health data access bodies by 26 March 2027 with resources and segregated functions
regulation-on-the-european-health-data-space-ehds::57Run the access body tasks: decide, prepare data, supervise, and publish permits and refusals
regulation-on-the-european-health-data-space-ehds::59Publish a biennial access body activity report with the required statistics
regulation-on-the-european-health-data-space-ehds::62Charge only transparent, cost-based fees and disclose estimates before issuing a permit
regulation-on-the-european-health-data-space-ehds::63Enforce against users and holders, with fines of up to 20 million euro or 4 percent of turnover
regulation-on-the-european-health-data-space-ehds::66Give only necessary data, anonymised where possible and pseudonymised only with justification
regulation-on-the-european-health-data-space-ehds::68Decide on permits within three months against the Article 68 criteria and set permit conditions
regulation-on-the-european-health-data-space-ehds::69Answer health data requests only in anonymised statistical form within the set periods
regulation-on-the-european-health-data-space-ehds::71Provide an easy, reversible opt-out from secondary use and apply it to later permits
regulation-on-the-european-health-data-space-ehds::72Trusted health data holders: assess requests within two months and provide the secure environment
regulation-on-the-european-health-data-space-ehds::73Provide permitted data only in a secure processing environment with the Article 73 controls and audits
regulation-on-the-european-health-data-space-ehds::74Document the controller and processor roles along the secondary-use chain

Secondary use: health data holders and users – Regulation on the European Health Data Space (EHDS)

5 controls
Controls in the Secondary use: health data holders and users – Regulation on the European Health Data Space (EHDS) domain of Regulation on the European Health Data Space (EHDS) — 5 controls
CodeTitle
regulation-on-the-european-health-data-space-ehds::51Make the minimum data categories available for secondary use unless exempt
regulation-on-the-european-health-data-space-ehds::52Flag data protected by IP, trade secrets or regulatory data protection and justify the protection
regulation-on-the-european-health-data-space-ehds::60Deliver requested data within three months and keep dataset descriptions accurate
regulation-on-the-european-health-data-space-ehds::61Health data users: process only under the permit, never re-identify, publish results within 18 months
regulation-on-the-european-health-data-space-ehds::67Submit complete access applications with purpose, data, safeguards and pseudonymisation justification

Secondary use: infrastructure, catalogues and quality – Regulation on the European Health Data Space (EHDS)

4 controls
Controls in the Secondary use: infrastructure, catalogues and quality – Regulation on the European Health Data Space (EHDS) domain of Regulation on the European Health Data Space (EHDS) — 4 controls
CodeTitle
regulation-on-the-european-health-data-space-ehds::75Designate a national contact point for secondary use and connect it to HealthData@EU
regulation-on-the-european-health-data-space-ehds::77Describe datasets with the HealthDCAT-AP minimum metadata in the national catalogue
regulation-on-the-european-health-data-space-ehds::78Label publicly funded datasets with a data quality and utility label
regulation-on-the-european-health-data-space-ehds::81Provide complaint tools on secondary use and route opt-out complaints to data protection authorities

Storage, international access and transfers – Regulation on the European Health Data Space (EHDS)

3 controls
Controls in the Storage, international access and transfers – Regulation on the European Health Data Space (EHDS) domain of Regulation on the European Health Data Space (EHDS) — 3 controls
CodeTitle
regulation-on-the-european-health-data-space-ehds::87Store and process personal data for secondary use inside the EU or an adequacy country
regulation-on-the-european-health-data-space-ehds::89Resist unlawful third-country access to non-personal health data and transfer personal data only under GDPR Chapter V
regulation-on-the-european-health-data-space-ehds::91Accept third-country applications only from authorised or reciprocal countries

Wellness applications and registration – Regulation on the European Health Data Space (EHDS)

2 controls
Controls in the Wellness applications and registration – Regulation on the European Health Data Space (EHDS) domain of Regulation on the European Health Data Space (EHDS) — 2 controls
CodeTitle
regulation-on-the-european-health-data-space-ehds::47Label wellness apps that claim EHR interoperability and never share data automatically
regulation-on-the-european-health-data-space-ehds::49Register EHR systems and labelled wellness apps in the EU database before placing on the market

Your Compliance Coverage

If you comply with Regulation on the European Health Data Space (EHDS), you already cover:

Maps to 172 other frameworks

74 total controls
TEFCA - Trusted Exchange Framework and Common Agreement
4 source controls mapped|2 target controls covered
5%
NAIC Insurance Data Security Model Law (MDL-668)
4 source controls mapped|1 target controls covered
5%
MDS2 (Medical Device)
4 source controls mapped|3 target controls covered
5%
Florida Digital Bill of Rights (FDBR)
4 source controls mapped|2 target controls covered
5%
Qatar DPL
4 source controls mapped|2 target controls covered
5%
Privacy Act 2020
4 source controls mapped|3 target controls covered
5%
POPIA
4 source controls mapped|5 target controls covered
5%
Personal Data Act (personopplysningsloven)
4 source controls mapped|3 target controls covered
5%
PDPA Thailand
4 source controls mapped|3 target controls covered
5%
PDPA Singapore
4 source controls mapped|3 target controls covered
5%
Oregon Consumer Privacy Act
4 source controls mapped|2 target controls covered
5%
NIST SP 800-122
4 source controls mapped|3 target controls covered
5%
Nigeria Data Protection Regulation (NDPR)
4 source controls mapped|4 target controls covered
5%
Nigeria Data Protection Act 2023 (NDPA)
4 source controls mapped|5 target controls covered
5%
Nebraska Data Privacy Act
4 source controls mapped|3 target controls covered
5%
New Jersey Data Privacy Act
4 source controls mapped|2 target controls covered
5%
New Hampshire Data Privacy Act
4 source controls mapped|3 target controls covered
5%
Montana Consumer Data Privacy Act
4 source controls mapped|2 target controls covered
5%
Minnesota Consumer Data Privacy Act
4 source controls mapped|2 target controls covered
5%
Mexico LFPDPPP
4 source controls mapped|3 target controls covered
5%
Mauritius DPA
4 source controls mapped|3 target controls covered
5%
Maryland Online Data Privacy Act of 2024
4 source controls mapped|3 target controls covered
5%
Malaysia PDPA 2010
4 source controls mapped|3 target controls covered
5%
Liechtenstein DPA
4 source controls mapped|3 target controls covered
5%
LGPD
4 source controls mapped|3 target controls covered
5%
South Korea PIPA
4 source controls mapped|4 target controls covered
5%
Kentucky Consumer Data Protection Act
4 source controls mapped|3 target controls covered
5%
Jamaica Data Protection Act 2020
4 source controls mapped|4 target controls covered
5%
Iowa Consumer Data Protection Act
4 source controls mapped|4 target controls covered
5%
Indiana Consumer Data Protection Act
4 source controls mapped|3 target controls covered
5%
5%
Family Educational Rights and Privacy Act (FERPA)
4 source controls mapped|5 target controls covered
5%
Bahrain PDPL
4 source controls mapped|4 target controls covered
5%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
4 source controls mapped|4 target controls covered
5%
Albania Law No. 124/2024 on Personal Data Protection
4 source controls mapped|4 target controls covered
5%
Armenia Law on Protection of Personal Data (2015)
4 source controls mapped|2 target controls covered
5%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
4 source controls mapped|2 target controls covered
5%
MTCS (Singapore)
4 source controls mapped|4 target controls covered
5%
Aged Care Quality Standards 2019 (repealed edition)
3 source controls mapped|3 target controls covered
4%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
3 source controls mapped|4 target controls covered
4%
ICH Q10 - Pharmaceutical Quality System
3 source controls mapped|3 target controls covered
4%
HITECH Act
3 source controls mapped|3 target controls covered
4%
GAMP 5 - Good Automated Manufacturing Practice
3 source controls mapped|2 target controls covered
4%
FDA Quality Management System Regulation (QMSR)
3 source controls mapped|3 target controls covered
4%
COSO Internal Control - Integrated Framework (2013)
3 source controls mapped|2 target controls covered
4%
IEC 60601-1 - Medical Electrical Equipment Safety
3 source controls mapped|3 target controls covered
4%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
3 source controls mapped|5 target controls covered
4%
Vietnam Law on Cybersecurity (No. 116/2025/QH15)
3 source controls mapped|2 target controls covered
4%
GLI-33 - Gaming Laboratories International Event Wagering Systems
3 source controls mapped|3 target controls covered
4%
ISMAP (Japan)
3 source controls mapped|2 target controls covered
4%
New Zealand Information Security Manual (NZISM)
3 source controls mapped|2 target controls covered
4%
NIST SP 800-144
3 source controls mapped|1 target controls covered
4%
NIST SP 800-145
3 source controls mapped|3 target controls covered
4%
NIST SP 800-146
3 source controls mapped|2 target controls covered
4%
Barbados Data Protection Act 2019
3 source controls mapped|2 target controls covered
4%
Azerbaijan Law on Personal Data (2010)
3 source controls mapped|2 target controls covered
4%
Australian Privacy Principles (APPs)
3 source controls mapped|1 target controls covered
4%
Israel Protection of Privacy Law (5741-1981)
3 source controls mapped|3 target controls covered
4%
OECD AI Principles
2 source controls mapped|2 target controls covered
3%
Japan AI Guidelines
2 source controls mapped|2 target controls covered
3%
Indonesia PDP Law
2 source controls mapped|2 target controls covered
3%
IEEE 7000
2 source controls mapped|3 target controls covered
3%
FedRAMP High
2 source controls mapped|2 target controls covered
3%
FedRAMP Moderate
2 source controls mapped|2 target controls covered
3%
NIST Privacy Framework
2 source controls mapped|2 target controls covered
3%
SWIFT CSCF
2 source controls mapped|2 target controls covered
3%
ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
2 source controls mapped|4 target controls covered
3%
Illinois Biometric Information Privacy Act (BIPA)
2 source controls mapped|2 target controls covered
3%
ISO/IEC 27400:2022
2 source controls mapped|2 target controls covered
3%
ISO/IEC 23837:2023
2 source controls mapped|2 target controls covered
3%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
2 source controls mapped|4 target controls covered
3%
FedRAMP Rev 5
2 source controls mapped|2 target controls covered
3%
FTC GLBA Safeguards Rule (16 CFR Part 314)
2 source controls mapped|2 target controls covered
3%
MITRE ATT&CK
2 source controls mapped|2 target controls covered
3%
NIST SP 800-123
2 source controls mapped|2 target controls covered
3%
NIST SP 800-137
2 source controls mapped|2 target controls covered
3%
NIST SP 800-61 Rev. 3
2 source controls mapped|2 target controls covered
3%
NIST SP 800-63-4
2 source controls mapped|2 target controls covered
3%
3%
NIST SP 800-88
2 source controls mapped|1 target controls covered
3%
NIST SP 800-92
2 source controls mapped|2 target controls covered
3%
O-RAN WG11 Security Specification
2 source controls mapped|3 target controls covered
3%
OpenSSF Scorecard
2 source controls mapped|2 target controls covered
3%
OWASP MASVS
2 source controls mapped|2 target controls covered
3%
OWASP SAMM
2 source controls mapped|2 target controls covered
3%
PTES
2 source controls mapped|2 target controls covered
3%
Singapore AI Governance Framework
1 source controls mapped|1 target controls covered
1%
Virginia CDPA
1 source controls mapped|2 target controls covered
1%
Vietnam PDPD
1 source controls mapped|1 target controls covered
1%
Uruguay DPL
1 source controls mapped|1 target controls covered
1%
UNESCO Recommendation on the Ethics of AI
1 source controls mapped|2 target controls covered
1%
UK AI Regulation Framework
1 source controls mapped|1 target controls covered
1%
Turkey KVKK
1 source controls mapped|1 target controls covered
1%
Texas Data Privacy and Security Act (TDPSA)
1 source controls mapped|1 target controls covered
1%
Taiwan PDPA
1 source controls mapped|2 target controls covered
1%
Peru DPL
1 source controls mapped|1 target controls covered
1%
GS1 Global Standards - Supply Chain Traceability and Data Security
1 source controls mapped|2 target controls covered
1%
Saudi Arabia PDPL
1 source controls mapped|3 target controls covered
1%
ISO/IEC 23894:2023
1 source controls mapped|2 target controls covered
1%
ISO/IEC 25012:2008 - Data Quality Model
1 source controls mapped|3 target controls covered
1%
WHO Global Strategy on Digital Health 2020-2025
1 source controls mapped|1 target controls covered
1%
RICS Rules of Conduct and Global Professional Standards
1 source controls mapped|1 target controls covered
1%
AICPA Privacy Management Framework (PMF)
1 source controls mapped|1 target controls covered
1%
GRI Standards
1 source controls mapped|1 target controls covered
1%
ISSB Standards
1 source controls mapped|1 target controls covered
1%
NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
1 source controls mapped|1 target controls covered
1%
W3C Verifiable Credentials (VC) Data Model 2.0
1 source controls mapped|1 target controls covered
1%
ISO/IEC 27007:2020
1 source controls mapped|1 target controls covered
1%
Science Based Targets Initiative (SBTi) - Net-Zero Standard
1 source controls mapped|2 target controls covered
1%
ISO/IEC 27031:2011
1 source controls mapped|1 target controls covered
1%
ISO/IEC 27011:2024
1 source controls mapped|2 target controls covered
1%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|3 target controls covered
1%
US Foreign Corrupt Practices Act (FCPA)
1 source controls mapped|1 target controls covered
1%
COBIT 2019
1 source controls mapped|1 target controls covered
1%
Connecticut Data Privacy Act (CTDPA)
1 source controls mapped|1 target controls covered
1%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|2 target controls covered
1%
ISO/IEC 27014:2020
1 source controls mapped|2 target controls covered
1%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|1 target controls covered
1%
ISO/IEC 29147:2018
1 source controls mapped|2 target controls covered
1%
ISO/IEC 29134:2023
1 source controls mapped|1 target controls covered
1%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
1%
ISO/IEC 30111:2019
1 source controls mapped|2 target controls covered
1%
ISO/IEC 27004:2016
1 source controls mapped|3 target controls covered
1%
Annex 11 to EU GMP - Computerised Systems
1 source controls mapped|3 target controls covered
1%
DFARS 252.204-7012 - Safeguarding Covered Defense Information
1 source controls mapped|1 target controls covered
1%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|1 target controls covered
1%
PCI DSS 4.0
1 source controls mapped|1 target controls covered
1%
ISO/IEC 27050-1:2019
1 source controls mapped|1 target controls covered
1%
FATF Recommendation 16 - Payment Transparency (Travel Rule)
1 source controls mapped|1 target controls covered
1%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|1 target controls covered
1%
GLBA
1 source controls mapped|1 target controls covered
1%
HKMA SPM
1 source controls mapped|1 target controls covered
1%
IATA Operational Safety Audit (IOSA) Standards Manual
1 source controls mapped|1 target controls covered
1%
IATF 16949:2016 - Quality Management System for Automotive Production
1 source controls mapped|2 target controls covered
1%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)
1 source controls mapped|1 target controls covered
1%
ITAR - International Traffic in Arms Regulations
1 source controls mapped|1 target controls covered
1%
ITU Radio Regulations and Space Security Standards
1 source controls mapped|1 target controls covered
1%
Monetary Authority of Singapore Technology Risk Management Guidelines
1 source controls mapped|1 target controls covered
1%
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
1 source controls mapped|1 target controls covered
1%
Notifiable Data Breaches Scheme (Australia)
1 source controls mapped|1 target controls covered
1%
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
1 source controls mapped|2 target controls covered
1%
OCC Heightened Standards (12 CFR Part 30, Appendix D)
1 source controls mapped|1 target controls covered
1%
Open Banking Security
1 source controls mapped|1 target controls covered
1%
OSFI B-13
1 source controls mapped|1 target controls covered
1%
OWASP Top 10:2025
1 source controls mapped|1 target controls covered
1%
Philippines Cybercrime Prevention Act (RA 10175)
1 source controls mapped|1 target controls covered
1%
PSD2 SCA
1 source controls mapped|1 target controls covered
1%
BSI IT-Grundschutz
1 source controls mapped|1 target controls covered
1%
Vermont Data Privacy and Online Surveillance Act
1 source controls mapped|1 target controls covered
1%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
1 source controls mapped|1 target controls covered
1%
AML/CTF Act 2006 (Australia)
1 source controls mapped|1 target controls covered
1%
US Consumer Product Safety Act (CPSC) Manufacturer and Importer Duties
1 source controls mapped|1 target controls covered
1%
Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
1 source controls mapped|1 target controls covered
1%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|2 target controls covered
1%
FDA 21 CFR Part 11
1 source controls mapped|1 target controls covered
1%
FIDO2 / WebAuthn
1 source controls mapped|2 target controls covered
1%
FISMA
1 source controls mapped|1 target controls covered
1%
Ghana Cybersecurity Act
1 source controls mapped|1 target controls covered
1%
HL7 FHIR Security Framework
1 source controls mapped|1 target controls covered
1%
ITU-T X.805 - Security Architecture for End-to-End Communications
1 source controls mapped|1 target controls covered
1%
MARS-E
1 source controls mapped|2 target controls covered
1%
OWASP Top 10 for LLM Applications 2025
1 source controls mapped|2 target controls covered
1%
Oman National Cybersecurity Framework
1 source controls mapped|1 target controls covered
1%
NIST SP 800-66
1 source controls mapped|1 target controls covered
1%

Coverage is not the same as your position

This page shows what Regulation on the European Health Data Space (EHDS) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is Regulation on the European Health Data Space (EHDS) and who does it apply to?

Regulation on the European Health Data Space (EHDS) is a compliance framework from European Union (and EEA) with 9 domains and 63 controls. The EU regulation creating the European Health Data Space: patients get free, immediate access to and portability of their priority health data (summaries, e-prescriptions, imaging, results, discharge reports) with cross-border exchange through MyHealth@EU; EHR systems must carry harmonised interoperability and logging components with CE-marked self-declared conformity; and health data holders make data available for research, innovation and policy through health data access bodies, data permits and secure processing environments, with an opt-out. In force 26 March 2025; applies in stages from 26 March 2027 to 2035. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Regulation on the European Health Data Space (EHDS) actually require?

Regulation on the European Health Data Space (EHDS) has 63 controls organised across 9 domains. The largest domains are EHR systems: requirements and economic operators – Regulation on the European Health Data Space (EHDS) (18 controls), Secondary use: health data access bodies and procedures – Regulation on the European Health Data Space (EHDS) (12 controls), Primary use: rights of natural persons and healthcare duties – Regulation on the European Health Data Space (EHDS) (11 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Regulation on the European Health Data Space (EHDS) do I already cover?

Regulation on the European Health Data Space (EHDS) maps to 172 other compliance frameworks. The top mapping partners are TEFCA - Trusted Exchange Framework and Common Agreement (5% coverage), NAIC Insurance Data Security Model Law (MDL-668) (5% coverage), MDS2 (Medical Device) (5% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Regulation on the European Health Data Space (EHDS)?

Start your Regulation on the European Health Data Space (EHDS) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Regulation on the European Health Data Space (EHDS) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 63 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 908 frameworks.

Get Started Free →

Free forever — no credit card required