INTERVIEW - 16 JUL 2024

WHAT IS THE EUROPEAN HEALTH DATA SPACE

The European Health Data Space (EHDS) is set to revolutionize how patients access healthcare and how data is used for research and AI training. This initiative will significantly impact everyone's lives, whether you’re a patient, researcher, entrepreneur, or policymaker.

The European digital health landscape is currently excited about a major new initiative. The European Health Data Space (EHDS) is set to revolutionize how patients access healthcare and how data is used for research and AI training. To get a deeper understanding of this groundbreaking change, we spoke with our project coordinator, Professor Stephen Gilbert from the TUD Dresden University of Technology in Germany. He leads the CYMEDSEC project and also coordinates another EU funded consortium project directly related to the European Health Data Space (a project called PATH). This makes him the ideal person to provide valuable insights.

 

Professor Gilbert, let’s start with an overview: what is the European Health Data Space (EHDS)?

The European Health Data Space (EHDS) is a significant legislative initiative from the European Union aimed at enhancing how health data is shared and used across member states. There are two main goals in EHDS. The first core idea is to put the citizen in control of the sharing of their own data for their own treatment, the so called ‘primary use’ of data. The second goal of the EHDS is to facilitate the secondary use of health data for broader purposes, including public health, research, and commercial use, like training artificial intelligence systems. The COVID-19 pandemic underscored the need for robust European data sharing frameworks to support public health. In the field of data sharing for primary and secondary use, there is a need to linking health data systems, infrastructures, frameworks and statutory bodies to oversee these wider uses are implemented and administrated responsibly and securely. The idea is that if you relocate from Italy to France, for example, your medical records should be accessible and usable by healthcare providers in your new country.

 

Is there any other new concept or idea introduced by EHDS?

One of the essential aspects of the EHDS is its broad definition of health data, which includes not only clinical data but also wellness information, such as data from fitness apps or wearable devices. This comprehensive view acknowledges that all data relevant to health, including lifestyle and wellness information, plays a role in long-term health outcomes.

 

It sounds like the EHDS has broad and ambitious goals. Are there any controversies and complexities surrounding this initiative?

Actually, it’s a kind of legislation which divides opinions and over which it’s possible that you get high levels of simultaneous enthusiasm, skepticism and, sometimes, opposition. Some of my views on the European Health Data Space may be somewhat on the controversial side. One aspect which is controversial is the way this actually looks as a law. Some people describe it as two laws formed together, kind of trying to grab too many things. Moreover, it’s extremely complex in its drafting and very difficult to read it, even if you are an expert. Then, another area of controversy is that there was a big rush for political, parliamentary procedural and European process reasons for getting this finished. Some compromises have been taken. Finally, unlike most European regulations, there’s an enormous degree of freedom for individual member states to adopt the law with different approaches in their own national legislation.

 

How does the EHDS interact with the General Data Protection Regulation (GDPR)?

As said before, each country will approach the European Health Data Space differently, based on their political and cultural perspectives on data sharing. Even under the existing GDPR, member states had varying interpretations, leading to different practices. One significant controversy is about whether individuals should automatically be included in data sharing (non-consent based sharing), whether they can choose not to be part of data sharing (opt-out) or if they only participate in data sharing f they make a postive choice to do so(opt-in). There was much debate about this in developmentof the EHDS, and largely an opt-out approach has been adopted. The EHDS does not replace GDPR, which is not changed by the new regulation. Instead, the new rules are on top of the GDPR, without replacing it. As member states have even more flexibility in the approaches taken under the EHDS than under GDPR, differing national approaches to data sharing will likely continue to differ.

 

What is the role of CYMEDSEC in such a complex initiative?

CYMEDSEC focuses on cybersecurity, particularly around the Internet of Medical Things (IoMT) and sensor technologies used in patients’ homes and hospitals. Our work is crucial because, while the EHDS lays out frameworks for legal data sharing, the actual security of the systems handling these data is paramount. Without secure systems, none of these legislative protections of data privacy matter if the data can be easily hacked or leaked. We, as CYMEDSEC partners, have recently published a paper exploring the interesction of these themes. It examines the severe consequences of an attack on the network infrastructure for a ‘Hospital at Home’ care pathway. Detailed research on those intersection points is one of the core tasks of the CYMEDSEC project.

 

So, data protection and privacy are the touchpoint between CYMEDSEC and EHDS. Are there any other issues in common?

Yes. There is also a bunch of mutual questions which are not entirely separable. One is: how are systems set up to be secure when patients are wearing devices/wearables? And second: how can we be sure that the data is going to the people who should be seeing the data? How is it correctly directed with the correct permissions from the citizens who are wearing the devices/wearables, and in a manner that it cannot be read, disrupted or changed?

 

Along with these synergies, are there any differences between CYMEDSEC and EHDS?

Since I have projects in both areas, it’s easier to examine the intersections between the European Health Data Space and cybersecurity concerns, like the risk of hacking or unauthorized access to data within systems designed for data handling. However, CYMEDSEC primary focus is on IoMT sensor technologies, especially those used in patients’ homes and, to some extent, in hospitals. So, we shouldn’t overstate our involvement by presenting CYMEDSEC as a project primarily focused on the European Health Data Space. Instead, it’s crucial to understand the intersection points, which is why we, in CYMEDSEC, have specific submodules – in the Work Package 5 – dedicated to exploring these overlaps.

 

Multidisciplinarity seems to be the key…

Absolutely. It’s important to recognize that research and projects like CYMEDSEC benefit greatly from a broad understanding of the legislative and regulatory environment they operate within. Our strength in CYMEDSEC comes from our diverse expertise in both cybersecurity and data privacy, and our ability to navigate these complex intersections. As the EHDS evolves, it’s critical that we continue to engage with these broader policy discussions to ensure our work remains relevant and impactful.

 

This interview is part of the #1 CYMEDSEC newsletter.

 

Image credits: Campaign Creators on Unsplash