EHDS provides a legal framework for the secondary use of health data. Organisations still need an operational answer: how can that framework become a controlled, auditable process? The OpenEHDS PoC tests this in a limited scope and around a clearly defined use case.
- Why build a PoC
- The end-to-end process
- Hospital and researcher roles
- Secure Processing Environment
- Governance and compliance
- What we need to validate
A PoC should answer practical questions
The goal is not a polished demonstration detached from hospital reality. We want to test whether data from different health systems can be discovered, requested, prepared and analysed securely, interoperably and with a complete audit trail.
Twelve stages, one controlled process
The process begins with data holders and standardised metadata. A researcher discovers datasets and submits an application covering purpose, cohort, variables, duration and safeguards. After legal, ethical and data protection review, a permit defines the approved scope.
Extraction is orchestrated from approved sources. Data is pseudonymised or anonymised as required and made available inside a Secure Processing Environment. Researchers use analytical tools and AI/ML without unrestricted download. Only outputs passing disclosure control may leave the environment.
Metadata first, data only after a decision
A hospital publishes dataset descriptions, variables, provenance, quality and access conditions — not patient-level data. This lets researchers assess relevance before any sensitive processing begins. The PoC tests FHIR, DCAT-AP, controlled vocabularies and common data models.
Turning a data permit into technical rules
A permit should not remain a PDF stored in a repository. Its conditions should control extraction, permissions, environment lifetime, logging and export. This is where governance becomes executable infrastructure.
Secure analysis without unrestricted downloads
The SPE gives researchers access to approved data and tools, but not a file they can freely copy. Identity control, encryption, logging and monitoring operate throughout the session. Every result is reviewed for disclosure risk before release.
What should the PoC validate?
- Technical feasibilityCan the complete flow run in an environment close to real hospital systems?
- InteroperabilityCan standards reduce one-off integration work?
- GovernanceCan legal decisions become enforceable process rules?
- Secure environmentCan researchers work effectively without losing control over data?
- Operating modelWhich roles, skills and service times are required?
Why start with a PoC?
EHDS requires law, medicine, public administration and technology to work together. Architecture documents matter, but only a concrete case exposes dependencies, data-quality gaps, ambiguous responsibilities and real operational cost. We treat the PoC as a shared learning tool.
OpenEHDS, PoC for EHDS Secondary Use.
