Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Project deliverable
Data sources: ZENODO
addClaim

Technical specification for Health Data Access Bodies on the implementation of secure processing environments

Authors: Lehväslaiho, Heikki; Lodenius, Helena; Barros, Beatriz; Berna, Alexandre; Bréchot, Lucas; Fekete-Molnar, Krisztina; Gütter, Zdenek; +10 Authors

Technical specification for Health Data Access Bodies on the implementation of secure processing environments

Abstract

This TEHDAS2 technical specification supports the implementation of the European Health Data Space (EHDS).This report presents the technical, functional, and security specifications of Secure Processing Environments (SPEs), a central component of the European Health Data Space (EHDS) as required under Article 73 of Regulation (EU) 2025/327. SPEs are designed to enable the safe secondary use of electronic health data while ensuring compliance with data protection, confidentiality, and information security obligations. Based on a thorough analysis, this report defines a structured set of minimum requirements for SPEs. It covers core capabilities needed to safeguard any sensitive data, as well as enabling requirements arising from the needs of scientific research principles. A generic SPE specification is developed that is flexible enough to fulfil current and future functional requirements. Functional and operational needs of two main SPE use cases identified to be needed by EHDS are shown to be derivable from this model. The report goes beyond the obligatory demands of EHDS to define minimal requirements of interoperability between compatible services that form an SPE-based federation that is required when data needs to be transferred between organisations. The SPE federation model is further expanded with a set of tentative practical implementation requirements for federated computing that is still an active research area. The primary purpose of this report is to support policy alignment, harmonised interpretation of legal obligations, and consistent high-level design choices across Member States. It does not aim to serve as a complete practical implementation manual or prescribe specific technologies or architectural solutions. Detailed implementation guidance, reference architectures, and operational playbooks will be developed in subsequent work, including implementing acts, pilot activities and follow-up guidance produced beyond TEHDAS2, for instance by the SPE Community of Practice subgroup. The present document should therefore be understood as a foundation for further specification, standardisation and implementation activities. Justification of the report focus on high-level functional requirements over technical ones is given in the appendices that cover existing solutions, pitfalls of too narrow approaches, and crucial interplay of SPEs with other services in the ecosystem. Attention is given to how various approaches and technical implementations affect the trade-offs between data security and usability, how they affect the health data users, and the responsibilities of actors accessing sensitive data. These specifications are intended to support Member States and stakeholders in the design and operation of SPEs and to inform the work of the European Commission in the preparation of the implementing act under Article 73(5) of the EHDS Regulation.

Powered by OpenAIRE graph
Found an issue? Give us feedback