Key data
| Regulation | Resolution of June 9, 2026, Joint Commission for Relations with the Court of Auditors |
|---|---|
| BOE Publication | October 6, 2026 |
| Entry into force | Not specified |
| Affected parties | Ministry of Health, autonomous communities, National Health System, IT providers and citizens |
| Category | Public Sector |
| Audited fiscal years | 2019, 2020 and 2021 |
| Related regulatory reference | Royal Decree 568/2024 (epidemiological surveillance) |
| Source | BOE-A-2026-20789 |
The information systems of the National Health System accumulate structural deficiencies detected during fiscal years 2019, 2020 and 2021. The Joint Commission for Relations with the Court of Auditors has approved, through a resolution published in the BOE on October 6, 2026, a set of mandates to the Government that will redefine how public healthcare technology is managed in Spain.
The resolution is not a norm for immediate compliance by private companies, but it does anticipate contractual changes, tenders and technical requirements that will directly affect IT providers, technology consultancies, healthcare product manufacturers and the autonomous administrations themselves.
What does this resolution establish?
The resolution approved by the Joint Commission includes a set of specific mandates to the Government, derived from the deficiencies detected in the audit. These are the main axes:
| Mandate | Detail |
|---|---|
| National reserve of medicines and healthcare products | Creation of a strategic stock for healthcare emergency situations |
| Integrated epidemiological surveillance system | Interoperable between the State, autonomous communities and private entities, in accordance with RD 568/2024 |
| HIV/AIDS system update | The current system is outdated since 2020; modernization is required |
| Strengthening respiratory disease surveillance | Improvement of monitoring and early warning systems |
| Reduction of technological outsourcing | Strengthen civil service IT personnel versus external contracting |
| Protection of sensitive health data | Strengthening guarantees on health data managed by third parties |
The regulatory framework of reference for the epidemiological surveillance system is Royal Decree 568/2024, which establishes interoperability requirements between administrations. The resolution urges that its application be effective and coordinated between the State and the seventeen autonomous communities.
Economic and operational impact
The resolution does not set specific amounts or allocated budgets, but its mandates have direct economic and operational consequences for several actors:
- IT providers in the public healthcare sector: The commitment to reduce technological outsourcing and strengthen civil service IT personnel can result in a contraction of outsourcing and system maintenance contracts. Companies currently providing externalized technology services to the NHS or autonomous communities must anticipate a review of their contracts in the next tender cycles.
- Manufacturers and distributors of medicines and healthcare products: The creation of a national strategic reserve implies new tenders and supply contracts with the State. It is a direct commercial opportunity for those operating in this segment.
- Healthcare data and digital health companies: The strengthening of sensitive health data protection and the requirement for interoperability raise the bar for technical and legal compliance for any company handling health data in public environments.
- Autonomous communities: They will have to adapt their information systems to comply with the interoperability requirements of RD 568/2024, which will generate investment in technology updates and possible autonomous tenders.
Who does it affect?
- Ministry of Health: It is the main recipient of the mandates. It will have to lead the development of the integrated epidemiological surveillance system and the creation of the national reserve.
- Autonomous communities: Required to integrate into the interoperable epidemiological surveillance system in accordance with RD 568/2024.
- IT providers and technology consultancies: Affected by the outsourcing reduction policy. Their current and future contracts with the NHS may be reviewed.
- Manufacturers and distributors of medicines and healthcare products: Potential beneficiaries of contracts derived from the national strategic reserve.
- Digital health and clinical data management companies: Must strengthen their healthcare data protection standards to maintain contracts with the public sector.
- Private entities with epidemiological surveillance functions: They will have to integrate into the interoperable system developed by the Ministry.
Practical example
A technology consultancy that currently manages externalized maintenance of the information systems of an autonomous healthcare department faces a specific scenario: the resolution explicitly urges strengthening civil service IT personnel and reducing dependence on external providers.
In practice, this means that in the next contract renewal cycle, the department could choose to internalize part of the currently outsourced services, reduce the contract scope, or require new clauses for knowledge transfer and healthcare data protection. The provider company must anticipate this negotiation and evaluate whether its value proposition can be reoriented towards higher specialization services—such as interoperability with the epidemiological surveillance system of RD 568/2024—that are more difficult to internalize in the short term.
On the other hand, a healthcare product manufacturer with large-scale supply capacity has an opportunity ahead: the creation of the national strategic reserve will require specific tenders. Preparing technical and regulatory compliance documentation in advance is key to accessing these contracts.
What should organizations do now?
- IT providers with contracts in the NHS or autonomous communities: Review current contracts and identify renewal clauses. Assess the risk of internalization by the public client and prepare a differentiated value proposition focused on high specialization services.
- Digital health companies: Audit the healthcare data protection systems they manage. The resolution anticipates a tightening of requirements; getting ahead reduces the risk of being excluded from future tenders.
- Manufacturers and distributors of medicines and healthcare products: Monitor tender calls from the Ministry of Health related to the national strategic reserve. Prepare technical and compliance documentation in advance.
- Private entities with epidemiological surveillance functions: Review the compatibility of their systems with the interoperability requirements of Royal Decree 568/2024 and plan necessary adaptations.
- Autonomous communities and their IT teams: Begin assessing the current state of their healthcare information systems against the required interoperability requirements, with special attention to the epidemiological surveillance system and the HIV/AIDS information system.
Frequently asked questions
What specific deficiencies did the Court of Auditors detect in NHS IT systems?
The audit of fiscal years 2019, 2020 and 2021 detected serious structural deficiencies in healthcare information systems. Among the most notable: the HIV/AIDS information system was outdated since 2020, respiratory disease surveillance was insufficient, there was excessive technological outsourcing, and there were deficiencies in sensitive health data protection. The lack of interoperability between State systems and those of autonomous communities was another critical point.
What is the national drug reserve that Congress demands?
The resolution urges the Government to create a strategic stock of medicines and healthcare products intended to address healthcare emergency situations. The resolution does not specify the volume, amount or specific timeline for its establishment, but its creation will involve new tenders and supply contracts with manufacturers and distributors in the sector.
What is the integrated epidemiological surveillance system and what regulation governs it?
It is an interoperable information system that must connect the State, the seventeen autonomous communities and private entities with epidemiological surveillance functions. Its development must be carried out in accordance with Royal Decree 568/2024, which establishes the applicable technical and interoperability requirements. The resolution requires the Ministry of Health to lead its effective implementation.
How does the resolution affect IT providers working with the public healthcare sector?
The resolution explicitly urges reducing technological outsourcing and strengthening civil service IT personnel. This can result in a review of outsourcing contracts in the next tender cycles. Providers must assess the risk of internalization by their public clients and reorient their value proposition towards high specialization services difficult to internalize, such as interoperability or cybersecurity of health data.
When does this resolution come into force and what are the timelines for compliance?
The resolution was approved on June 9, 2026 and published in the BOE on October 6, 2026. No specific entry into force date or compliance timelines for each mandate are specified. The mandates are directed at the Government and public administrations, so implementation timelines will depend on subsequent regulatory and budgetary development.
Official source
Consult complete regulation at official source
Notice: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://www.boe.es/diario_boe/txt.php?id=BOE-A-2026-20789