Data Protection

MiSalud@UE 2026: What Private Clinics and Hospitals Must Do to Comply

E
Equipo Editorial CambiosLegales
Sep 21, 2026 7 min 59 views

Key data

RegulationCommission Implementing Regulation (EU) 2026/2083 — CELEX:32026R2083
Publication21 September 2026
Entry into force18 September 2026
Affected partiesNational health systems, private healthcare entities, healthcare professionals and patients in the EU
CategoryData Protection / European Healthcare Regulation
Regulatory frameworkEuropean Health Data Space (EHDS) and GDPR
PlatformMiSalud@UE
Impact analysis reserved for subscribers
The detailed impact analysis of this regulation is available with the PRO and Business plans. Access the full content and receive personalized alerts.
From €9.99/month · Cancel anytime

Private healthcare entities operating in Spain and the EU have a new technical and legal obligation: to connect to the MiSalud@UE platform under the standards set by the Commission Implementing Regulation (EU) 2026/2083. The regulation, in force since 18 September 2026, develops the technical and operational specifications of the system within the European Health Data Space (EHDS).

This is not a regulation of intentions: it establishes concrete requirements for interoperability, authentication and processing of personal health data. Those who do not comply will not be able to participate in the European healthcare digital ecosystem and will be exposed to regulatory risks under the GDPR.

What does this regulation establish?

Regulation 2026/2083 develops the technical and operational framework of MiSalud@UE, the European platform that enables the sharing of healthcare data of citizens between Member States. These are the pillars it establishes:

AreaWhat the Regulation requires
InteroperabilityNational and private systems must comply with common technical standards so that healthcare data is readable and usable in any EU Member State
Data securityDefines specific security standards for the processing and transmission of personal health data
AuthenticationEstablishes authentication requirements for healthcare professionals accessing data through the platform
Data protectionData processing must comply with the GDPR and European healthcare sectoral regulations
Digital infrastructureNational health systems must adapt their infrastructures to connect to the common MiSalud@UE platform
Private entitiesPrivate healthcare entities operating in the European digital ecosystem are subject to the same technical provisions

The legal framework of reference is the European Health Data Space (EHDS), which seeks to enable a Spanish citizen to receive medical care in Germany, France or any other Member State with access to their medical history in a secure and interoperable manner.

Economic and operational impact

The impact is not only regulatory: it is a mandatory technology investment. Entities that have not yet begun adapting their digital systems must consider the following operational costs:

  • Technical audit of current systems: assessment of whether the existing infrastructure meets the interoperability standards required by MiSalud@UE.
  • Adaptation or replacement of clinical software: electronic medical record (EMR) systems must be capable of exporting and importing data in the standardized formats defined by the regulation.
  • Implementation of authentication systems: healthcare professionals will need approved digital identification mechanisms to access patient data from other countries.
  • Review of GDPR compliance: the processing of health data—a category specially protected under the GDPR—requires updating records of processing activities, impact assessments (DPIA) and contracts with data processors.
  • Staff training: doctors, nurses and administrative staff must be familiar with the new procedures for accessing and using cross-border data.

The risk of inaction is not just operational. A private healthcare entity that processes health data without complying with GDPR standards may face fines of up to 4% of its annual global turnover under the general GDPR regime, regardless of the specific consequences arising from non-compliance with the EHDS.

Who does it affect?

  • National health systems of all EU Member States, including the Spanish National Health System (SNS).
  • Private hospitals and clinics operating in the European digital ecosystem or serving patients from other EU countries.
  • Healthcare software providers (EMR, clinical ERP) that will need to update their products to comply with interoperability standards.
  • Healthcare professionals (doctors, nurses, pharmacists) who access patient data through cross-border digital platforms.
  • Patients residing in the EU, whose health data may be consulted in any Member State.
  • Data Protection Officers (DPO) of healthcare entities, who must review and update health data processing policies.
  • Health insurance companies with cross-border digital operations within the EU.

Practical example

A Spanish private clinic with its own electronic medical record regularly serves European patients (German tourists, French residents, etc.). Until now, access to their medical history at source was impossible or depended on the patient providing paper documentation.

With MiSalud@UE in force, the doctor at that clinic will be able—if the patient authorizes it—to consult the patient's relevant health data in their country of origin through the common platform. To do this, the clinic must:

  1. Verify that its EMR software is compatible with the interoperability standards of the regulation.
  2. Implement the authentication system for professionals required by MiSalud@UE.
  3. Update its privacy policy and record of processing activities to include the cross-border flow of health data.
  4. Conduct a Data Protection Impact Assessment (DPIA) if it does not already have one updated for this type of processing.

If the clinic does not adapt its infrastructure, it will be excluded from the MiSalud@UE ecosystem and will not be able to offer this level of care to European patients, losing competitiveness against centers that do comply.

Do you need to track this and other regulations?

Check the full details on CambiosLegales

What should companies do now?

  1. Audit current digital infrastructure: identify whether electronic medical record systems and data flows comply with the interoperability standards required by Regulation 2026/2083.
  2. Review GDPR compliance for health data: health data is a special category under the GDPR. Update the record of processing activities, information clauses and contracts with data processors.
  3. Conduct or update the Data Protection Impact Assessment (DPIA): mandatory for large-scale health data processing or with cross-border transfers.
  4. Contact your clinical software provider: require confirmation that the system will be compatible with MiSalud@UE and request an adaptation roadmap.
  5. Implement authentication systems for professionals: ensure that healthcare staff have approved digital identification mechanisms to operate on the platform.
  6. Train your team: both healthcare and administrative staff in the new procedures for accessing and using cross-border data.
  7. Consult with the DPO or specialized legal advisor: to verify that all adaptations comply with the GDPR and European healthcare sectoral regulations.

Frequently asked questions

What is MiSalud@UE and what is it for?

MiSalud@UE is the European digital platform that enables the sharing of healthcare data of citizens between EU Member States. Its objective is to enable a healthcare professional in any EU country to consult the relevant health data of a patient, with their authorization, regardless of where it was generated. Regulation 2026/2083 establishes the technical and operational specifications that systems connected to this platform must comply with.

Are private clinics required to comply with Regulation 2026/2083?

Yes. The regulation expressly affects private healthcare entities operating in the European digital ecosystem. It is not limited to public national health systems. Any private clinic, hospital or healthcare center that processes health data in digital format and may interact with patients from other Member States is subject to its technical provisions.

When did the MiSalud@UE Regulation enter into force?

Commission Implementing Regulation (EU) 2026/2083 entered into force on 18 September 2026, three days before its official publication, which took place on 21 September 2026. Affected entities must begin their adaptation process immediately.

What is the relationship between MiSalud@UE and the GDPR?

Regulation 2026/2083 expressly requires that the processing of personal health data complies with the GDPR and European healthcare sectoral regulations. Health data is a specially protected category under the GDPR (Article 9). Entities that do not comply with the regulation's standards may be exposed to sanctions under the GDPR regime, which provides for fines of up to 4% of annual global turnover for the most serious infringements.

What is the European Health Data Space (EHDS)?

The European Health Data Space (EHDS) is the European regulatory framework that establishes the conditions for the use, access and exchange of healthcare data in the EU. MiSalud@UE is the technical platform that materializes this space. Regulation 2026/2083 develops the specific interoperability, security and authentication specifications that systems connected to the EHDS must comply with.

Official source

Consult full regulation at official source

Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=CELEX:32026R2083



Share:
E
Equipo Editorial CambiosLegales

El equipo editorial de CambiosLegales analiza diariamente los cambios normativos que afectan a empresas y autónomos en España, ofreciendo análisis pro...

Comments

No comments yet. Be the first to comment!

Leave a comment
Activate alerts