Key data
| Regulation | Commission Implementing Regulation (EU) 2026/2099, of 21 September 2026 |
|---|---|
| Publication | 22 September 2026 |
| Entry into force | Not specified in the published text |
| Affected parties | Patients, healthcare professionals, hospitals, clinics and health administrations in the EU |
| Category | European Regulation |
| Reference framework | European Health Data Space (EHDS), eIDAS Regulation, GDPR |
| Official source | OJ:L_202602099 — EUR-Lex |
Spanish health centers—both public and private—face mandatory technological adaptation. The Commission Implementing Regulation (EU) 2026/2099, published on 22 September 2026, establishes the technical mechanism that will allow citizens, professionals and health centers to authenticate digitally to exchange medical records between EU countries.
This is not a recommendation: it is the technical standard that national systems must comply with to connect to the European Health Data Space (EHDS). Regional governments and the Ministry of Health are the first obligated parties, but private centers that want to operate in this environment will also need to adapt.
What does this regulation establish?
The regulation defines the interoperable technical mechanism that enables cross-border exchange of electronic health data in the EU. In practical terms, it establishes three pillars:
| Pillar | What it regulates | Who it applies to |
|---|---|---|
| Technical standards and interoperability | Protocols and requirements that national systems must meet to connect to the EHDS | Health administrations, hospital information systems |
| Authentication and credentials | Robust authentication protocols in accordance with eIDAS for professionals and centers | Healthcare professionals, hospitals, clinics |
| Data protection | Enhanced authentication requirements aligned with the GDPR | All actors handling cross-border health data |
The regulation affects three types of system users: natural persons (patients), healthcare professionals and healthcare providers (hospitals, clinics, health centers). Each will need an identification and authentication mechanism recognized at European level to access or share health data in another Member State.
The regulation is based on the eIDAS Regulation framework and the GDPR, strengthening authentication as a guarantee of data protection in cross-border environments.
Economic and operational impact
The regulation does not set specific investment amounts or penalties in the published text. However, the operational and economic consequences are clear:
- Investment in technological adaptation: Health information systems in regional governments and the Ministry of Health will need to update their infrastructures to comply with new technical standards and authentication protocols.
- European credentials for professionals: Healthcare professionals will need to obtain credentials recognized at European level, which involves registration processes, verification and possibly specific training.
- Cost of non-compliance: Centers that do not meet technical requirements will be excluded from cross-border data exchange, which limits care for European patients and may represent a competitive disadvantage for private clinics with international ambitions.
- Impact on private clinics: Although the direct obligation falls on public administrations, private centers that want to integrate into the EHDS will need to adopt the same technical standards.
Who does it affect?
- Regional governments: Must adapt their health information systems to the new EHDS technical standards and interoperability.
- Ministry of Health: Coordination and implementation at national level of the identification and authentication mechanism.
- Public and private hospitals: Will need to update their digital infrastructures to connect to the European system.
- Clinics and health centers: Any healthcare provider that wants to exchange data with other EU countries must comply with technical requirements.
- Healthcare professionals (doctors, nurses, pharmacists...): Must obtain authentication credentials recognized at European level.
- Patients: Benefit from access to their health data in any Member State, but must also have recognized digital identification mechanisms.
- Technology providers in the health sector: Healthcare software companies (HIS, EHR) that will need to update their solutions to comply with new protocols.
Practical example
A private hospital in Barcelona treats a German patient in the emergency department. To access his medical record stored in Germany, the responsible doctor needs to authenticate with credentials recognized at European level in accordance with the eIDAS Regulation. If the hospital has not adapted its information system to the new interoperable authentication mechanism of the EHDS, access is impossible: the doctor cannot consult allergies, previous medication or relevant medical history.
This same scenario applies in reverse: a Spanish doctor working in another EU country needs his European credentials to access the system. Without technical adaptation, the professional is excluded from information exchange, with the resulting clinical risk and loss of competitiveness for the center.
What should companies do now?
- Audit current digital infrastructure: Review whether health information systems (HIS, EHR, electronic medical record) are compatible with EHDS technical standards and authentication protocols required by eIDAS.
- Identify the technology gap: Determine what adaptations are necessary to comply with the regulation's interoperability and robust authentication requirements.
- Contact technology providers: Require healthcare software providers to provide a concrete roadmap for adaptation to Regulation (EU) 2026/2099.
- Plan the acquisition of European credentials: Initiate the process for healthcare professionals at the center to obtain authentication credentials recognized at European level.
- Review data protection policy: Ensure that cross-border health data exchange processes comply with the GDPR with the enhanced authentication required by the regulation.
- Follow Ministry of Health instructions: Regional governments will receive specific implementation guidelines. Stay informed of national adaptation timelines and requirements.
Frequently asked questions
What is the European Health Data Space (EHDS) and why does it affect my clinic?
The EHDS is the European framework that enables secure exchange of electronic health data between EU countries. Regulation (EU) 2026/2099 establishes the technical mechanism for identification and authentication that all actors—patients, professionals and centers—must use to connect to this system. If your clinic treats patients from other EU countries or your professionals work abroad, you will need to adapt to be able to exchange medical records.
When does Regulation (EU) 2026/2099 enter into force?
The regulation was published on 22 September 2026, but the entry into force date is not specified in the published text to date. It is essential to consult the full text on EUR-Lex and follow communications from the Ministry of Health to learn about national implementation timelines.
What credentials do healthcare professionals need to operate in the EHDS?
The regulation requires healthcare professionals to have authentication credentials recognized at European level, in accordance with the eIDAS Regulation. This means their digital identification systems must comply with robust authentication protocols defined in Regulation (EU) 2026/2099. The specific process for obtaining these credentials will depend on instructions issued by national health authorities.
Does this regulation affect only public hospitals or also private clinics?
It affects all healthcare providers: public hospitals, private clinics and health centers. Although the obligation to adapt national systems falls mainly on regional governments and the Ministry of Health, any private center that wants to exchange health data with other EU countries must comply with the same EHDS technical standards and interoperability.
What is the relationship between this regulation and the GDPR and eIDAS?
Regulation (EU) 2026/2099 strengthens data protection by requiring robust authentication in accordance with the GDPR for any cross-border health data exchange. It relies on the eIDAS Regulation to define digital identification standards recognized throughout the EU. In practice, the authentication systems that health centers implement must be compatible with both regulatory frameworks.
Official source
Consult complete regulation in official source
Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=OJ:L_202602099