Your Patients’ Health Data Can Now Be Used to Train AI. Here’s What That Means.
Regulation (EU) 2025/327 has been in force since March 2025. Most patient-facing organisations have not read it.
Your Patients’ Health Data Can Now Be Used to Train AI. Here’s What That Means.
Regulation (EU) 2025/327 has been in force since March 2025. Most patient-facing organisations have not read it.

On 26 March 2025, a regulation came into force that changed the rules around one of the most sensitive categories of personal data in existence: health records.
Regulation (EU) 2025/327, which establishes the European Health Data Space (EHDS), creates a legal framework for accessing, sharing, and reusing electronic health data across the EU. It covers primary use, meaning direct patient care, and secondary use. That second category is where AI enters the picture.
Secondary use covers research, innovation, policymaking, and AI development. The EHDS makes it significantly easier, legally, for organisations to apply for access to EU patient health data for those purposes.
If you work in patient advocacy, run a healthcare NGO, or manage any organisation that touches health data, this regulation is already relevant to you. The prep window is narrowing.
What the EHDS Actually Does
The regulation works in two layers.
The first layer is about primary use. From March 2029, EU citizens will be able to access and share their electronic health records across all Member States through an infrastructure called MyHealth@EU. Patient summaries, prescriptions, and dispensation records will be available across borders.
The second layer matters more for AI. The EHDS establishes a framework for secondary use through Health Data Access Bodies (HDABs), one in each Member State. These bodies act as gatekeepers. Organisations that want to use patient health data for research or AI development apply to an HDAB for a data permit. If the permit is granted, they access the data through a secure processing environment. In most cases they work with anonymised data; they cannot simply download patient records.
The infrastructure for this secondary use, called HealthData@EU, is set to be operational by March 2029. Electronic health records, patient summaries, and prescription data form the first wave. Genomic data and other sensitive categories follow in March 2031.
This is not a future scenario. The regulation entered into force on 26 March 2025. Member States were required to appoint their National Digital Health Authority by June 2025. EHR vendors and healthcare providers face a certification deadline for interoperability and security compliance in January 2026. The clock is already running.
Where AI Fits Into This
AI developers, pharmaceutical companies, and research institutions stand to benefit significantly from the EHDS. Access to large, standardised pools of European health data, even in anonymised form, is extremely valuable for training clinical AI models, improving drug discovery pipelines, and conducting population health research.
The EU AI Act (Regulation 2024/1689) adds another layer on top. It classifies many AI systems used in clinical and patient-facing healthcare contexts as high-risk, which means they are subject to strict requirements on data governance, transparency, human oversight, and post-market monitoring. The core obligations for high-risk AI systems apply from August 2026.
The two regulations are designed to work together. The EHDS provides the data access framework. The AI Act sets the rules for what can be done with that data in an AI context. GDPR sits underneath both, with Article 9 providing heightened protections for health data specifically.
Any organisation processing health data for AI purposes must conduct a Data Protection Impact Assessment (DPIA) before that processing begins. A Data Protection Officer (DPO) is required for most organisations handling health data at scale. These are not new obligations; they existed under GDPR. But EHDS and the AI Act together make the compliance question more urgent and more layered.
The Opt-Out: Who Carries the Burden?
Patients have a right to opt out. Article 71 of the EHDS gives individuals the right to object to secondary use of their health data at any time, for any reason. The right is reversible. If someone opts out, their data cannot be shared with data users, even in anonymised form.
That is a meaningful protection. But it is an opt-out mechanism, not an opt-in. The default is that data is available for secondary use.
Most patients do not know this regulation exists. Most will not be proactively informed by their healthcare provider, because the regulation does not require that communication. The opt-out will be accessible, once national mechanisms are in place, but only if people know to look for it.
This is where patient advocacy organisations have a specific role. You have direct relationships with people who need to make an informed choice about whether their health data should be available for AI research. You are often better placed than anyone else to explain what secondary use means, what the opt-out covers, and how to exercise it.
A Practical Compliance Starting Point
This is not legal advice, and your specific obligations will depend on your organisation’s role and jurisdiction. But here is a practical framework to get you moving.
Map your role under EHDS first.
The regulation treats different organisations differently. Data holders (hospitals, clinics, any organisation holding electronic health records) have obligations to make data available to HDABs. Data users are the researchers and companies applying for permits. You may be neither, or both in different contexts. Starting with “what role do we play?” shapes everything that follows.
Check your DPO situation.
If you process health data at scale and you do not have a Data Protection Officer, that needs to be addressed before 2027. This applies under GDPR independently of EHDS, but EHDS enforcement will put the question under a brighter light.
Conduct a DPIA for any AI tools you use.
If your organisation uses AI in work that touches health data — clinical decision support, automated admin, patient-facing tools — you need a Data Protection Impact Assessment. Under GDPR and the EHDS framework, this is not optional. If a vendor you rely on has not conducted one, that is worth raising directly.
Tell your members or patients about the opt-out.
This is the most immediate, practical thing a patient advocacy organisation can do right now. Write a plain-language briefing. Explain what secondary use means in concrete terms. Explain that an opt-out exists, that it does not affect their care, and that it is reversible. Make it part of your regular member communications. The mechanism varies by Member State once national systems are in place, so update the briefing as your national authority publishes guidance.
Ask harder questions when you procure AI tools.
Standard procurement questions are not enough. Ask vendors where data is processed and stored, whether they meet GDPR and EHDS requirements, what their approach to de-identification is, and whether they have carried out a DPIA. Ask for a Data Processing Agreement. If a vendor cannot answer clearly, that is a signal.
Watch your national implementation.
The EHDS is a regulation, so it applies directly across all Member States. But the practical details, including how the opt-out mechanism works, are implemented nationally. Some countries are already moving. If your work spans multiple EU countries, you need to track this in each.
Plan for August 2026.
If you deploy or use high-risk AI systems in a healthcare context, the full set of EU AI Act obligations applies from August 2026. Conformity assessments, technical documentation, and human oversight requirements are all on the table. If you have not started scoping this, now is the time.
What This Is Not
EHDS is not an attack on patient privacy. Secondary use through Health Data Access Bodies, with permit requirements, secure processing environments, and anonymisation obligations, is significantly more controlled than much of what happens with health data in less regulated settings today.
The concern is not that the framework is irresponsible. The concern is the gap between the framework’s assumptions about patient awareness and the reality. The regulation assumes people will exercise meaningful choice. That only works if they know the choice exists.
Closing that gap is exactly the kind of work patient advocacy has always done.
Key Dates
26 March 2025 — EHDS entered into force.
June 2025 — Deadline for Member States to appoint National Digital Health Authorities.
January 2026 — EHR vendors and healthcare providers must certify systems for interoperability and security compliance.
26 March 2027 —Regulation formally applies. Governance and institutional obligations begin. Major operational provisions follow in 2029.
August 2026 — EU AI Act high-risk AI system obligations apply in full.
March 2029 — Secondary use provisions operational. HealthData@EU live for electronic health records and most data categories.
March 2031 — Genomic data and remaining categories available for secondary use.
Anjula Weeranayake is the founder of TekDruid (tekdruid.com), an IT consulting practice working with EU NGOs and patient advocacy organisations on GDPR, NIS2, and AI governance. www.tekdruid.com
메타데이터
- post_id
- be8d1dca8ea5
- slug
- your-patients-health-data-can-now-be-used-to-train-ai-here-s-what-that-means-be8d1dca8ea5
- url
- https://medium.com/@anjulaweeranayake/your-patients-health-data-can-now-be-used-to-train-ai-here-s-what-that-means-be8d1dca8ea5
- canonical_url
- https://medium.com/@anjulaweeranayake/your-patients-health-data-can-now-be-used-to-train-ai-here-s-what-that-means-be8d1dca8ea5
- author_url
- https://medium.com/@anjulaweeranayake
- status
- ok
- fetched_at
- 2026-06-16 19:09:56