Privacy AI
Regulatory

Health data compliance, handled.

Tell us what you need. We'll tell you what it takes and how long, before you commit.

Contact us

Summary

Contact us
The regulation harmonizes regulations on a European scale, which is a major issue in terms of the health of populations across Europe on the one hand, and in terms of innovation on the other.

The regulation creates, in very concrete terms, for example:

• An infrastructure enabling the sharing of health data contained in medical records, respecting the rights of individuals, for cross-border care of people during their travels in Europe;

• An infrastructure, procedures for accessing harmonized and regulated data in member states, and catalogs of data available to facilitate the secondary reuse of health data that has been previously anonymized or pseudonymized.

The regulation strengthens and harmonizes, in addition to the GDPR, the rights of individuals concerning health data: the right of direct access to medical records, the right to object to the processing of health data, settings for access to this data, enhanced information, and facilitation of the exercise of rights for individuals, and rules for data localization.It also provides for a robust framework of European and national governance for digital health. It requires the creation, in each member state, of national authorities competent to support and control the proper application of the regulation. It strengthens European governance of digital health by replacing the eHealth network, co-chaired by France, with a committee of the EHDS with a comitology involving all stakeholders in the decisions (patients, health professionals, researchers, industrialists, institutional representatives, etc.).

The European Commission will establish the central infrastructure and services supporting the EHDS.In the medium term, the regulation also provides for the possibility of connection for countries and organizations based outside the EU, under conditions of guaranteed security and data protection.Its implementation will be spread over the next 2 to 6 years and will require adjustments to existing regulations in France, particularly concerning the reuse of health data (secondary use).

Contact us

FAQs

Our frequently questions

No items found.

Find out how iliomad can help your company.

[Map placeholder]
Only visible in production
38.709099
-39.182035
1.6
6d17042a3425c5b3
Your message has been received!
We'll get back to you as soon as possible.
Something went wrong, please try again.
Home

Discover our latest articles

View All Blog Posts
Illustration of the CNIL MR-001 framework applied to a clinical trial data compliance workflow in France, showing patient data flow and security controls
September 7, 2026
GDPR
Regulation
Guideline
Regulations & Guidelines

MR-001 CNIL: what clinical trial sponsors must know about French health data compliance

Understand MR-001 CNIL obligations for clinical trial sponsors in France, from Article 32 security requirements to breach notification and cross-border data transfers.

A clinical trial coordinator reviewing an informed consent form alongside a data governance checklist, representing ICF boilerplate review and open-access database disclosure compliance
September 4, 2026
Guideline
EU Privacy Law
Regulations & Guidelines
Clinical Trials
United-Kingdom

ICF Boilerplate and Open-Access Database Disclosures: What Clinical Trial Sponsors Must Know

Learn how US site ICF boilerplate on commercial products and open-access genetic databases affects sponsor data governance, Common Rule compliance and GDPR obligations.

Abstract digital network graphic representing data protection, clinical trial compliance and cybersecurity themes for the iliomad weekly digest
September 3, 2026
Regulations & Guidelines
GDPR
Data Breach & Cybersecurity
LLMS

iliomad Weekly Digest: DPO Conflicts, Bulk Data Rules, Healthcare Cyber Incidents and AI Transparency

This week: CNIL on DPO conflicts of interest, DOJ bulk data rule for life sciences, wave of healthcare ransomware attacks, Uber's €825m GDPR fine and AI disclosure demands.