Home

Commission Implementing Decision 2019/1765 of 22 October 2019 providing the rules for the establishment, the management and the functioning of the network of national authorities responsible for eHealth, and repealing Implementing Decision 2011/890/EU (notified under document C(2019) 7460) (Text with EEA relevance)

Commission Implementing Decision 2019/1765 of 22 October 2019 providing the rules for the establishment, the management and the functioning of the network of national authorities responsible for eHealth, and repealing Implementing Decision 2011/890/EU (notified under document C(2019) 7460) (Text with EEA relevance)

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Directive 2011/24/EU of the European Parliament and of the Council of 9 March 2011 on the application of patients’ rights in cross-border healthcare(1), and in particular Article 14(3) thereof,

Whereas:

  1. Article 14 of Directive 2011/24/EU assigned the Union to support and facilitate cooperation and the exchange of information among Member States working within a voluntary network connecting national authorities responsible for eHealth (the ‘eHealth Network’) designated by the Member States.

  2. Commission Implementing Decision 2011/890/EU(2) provides rules for the establishment, the management and the functioning of the eHealth Network.

  3. That decision does not at the moment provide appropriate rules with regard to certain aspects necessary for the sufficiently transparent functioning of the eHealth Network, in particular, on the role of the eHealth Network and the Commission in relation to the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services, and the new requirements on data protection under Regulation (EU) 2016/679 of the European Parliament and of the Council (the ‘General Data Protection Regulation’)(3), and Regulation (EU) 2018/1725 of the European Parliament and of the Council(4).

  4. The transparent management of the eHealth Network should be ensured by laying down rules on becoming a member of the eHealth Network and withdrawing from it. Participation in the eHealth Network being voluntary, the Member States should be able to join at any time. For organisational purposes, the Member States wishing to participate should inform the Commission of this intention in advance.

  5. Electronic communication is a suitable means for rapid and reliable exchange of data between Member States participating in the eHealth Network. In this area, significant developments took place. In particular, in order to facilitate the interoperability of European eHealth systems, the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services was developed by those Member States participating in the eHealth Network which decided to advance their cooperation in this area with the support of the Commission, as an IT tool for the exchange of health data under the Connecting Europe Facility programme(5). These developments should be reflected in this Decision. Moreover, as stressed in the Commission Communication of 25 April 2018 on enabling the digital transformation of health and care in the Digital Single Market, empowering citizens and building a healthier society(6), the respective role of the participating Member States and of the Commission in relation to the functioning of the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services should be clarified.

  6. The role of the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services should be to facilitate the cross-border exchange of health data between the Member States participating in the eHealth Network as recognised in the 2017 Council Conclusions on Health in the Digital Society(7) such as patient data contained in ePrescriptions and Patient Summaries and eventually more comprehensive electronic health records, as well as to develop other use cases and health information domains.

  7. The eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services is composed of core services and generic services as provided for in Regulation (EU) No 283/2014 of the European Parliament of the Council(8). The core services are developed, deployed and maintained by the European Commission. Together with the generic services, they should enable and support trans-European connectivity. The generic services are developed, deployed and maintained by the National Contact Points for eHealth, designated by each Member State. The National Contact Points for eHealth, using the generic services, link the national infrastructure with the National Contact Points for eHealth from another Member State through the core service platforms.

  8. In order to improve cross-border exchange of health data and achieve technical, semantic, and organisational interoperability between national eHealth systems, the eHealth Network should in the context of eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services, play the leading role in the elaboration and coordination of the necessary common requirements and specifications.

  9. The eHealth Network is already carrying out several activities in e-health area, which are spelled out in its Multiannual Work Programme and are aimed mainly at providing guidance, sharing good practices or finding common ways of working together. Among these activities are, for instance: working to enable citizens to take an active role in the management of their own health data, including in the area of e-health, m-health and telemedicine, as well as patients’ access, use and share of their own health data and digital health literacy of patients. Other activities of the Network are related to the innovative use of health data, including Big Data, Artificial Intelligence, developing knowledge on healthcare policy, including the provision, in cooperation with the concerned parties at national and EU level, of guidance on health promotion, disease prevention and improved delivery of healthcare through better use of health data. The Network supports Member States to enable sharing and using health and medical data for public health and research. In line with Article 14(2)(c) of Directive 2011/24/EU, it also supports Member States in developing electronic identification means and authentication to facilitate transferability of data in cross-border healthcare, in particular as regards eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services, taking into account the eIDAS framework and other ongoing actions at Union level.

  10. The eHealth Network is also working on enhancing the continuity of care by improving the uptake of cross-border e-health services, developing new use cases and health information domains in addition to patient summary and e-prescriptions, as well as overcoming implementation challenges, related to interoperability, data protection, data security or e-skills for healthcare professionals. It also facilitates greater interoperability of the national information and communications technology systems and cross-border transferability of electronic health data in cross-border healthcare by providing guidance on which requirements and specifications should be used to achieve technical, semantic and organisational interoperability between national digital healthcare systems. The Network is working to foster stronger cooperation with regard to the development and sharing of good practices concerning national digital health strategies, with the view of building convergence for an e-health interoperable system.

  11. When preparing guidance concerning security aspects of data exchange, the eHealth Network should benefit from the expertise of the Network and Information Security (NIS) Cooperation Group established under Article 11 of Directive (EU) 2016/1148 of the European Parliament and of the Council(9), and the European Union Agency for Network and Information Security (ENISA).

  12. The eHealth Network is also promoting the exchange of views among its Members on national strategic challenges with regard to new technologies and data usages and it should promote discussions with other relevant Union fora (such as the Steering Group on Health Promotion, Disease Prevention and Management of Non-Communicable Diseases or Board of Member States for European Reference Networks) on priorities, strategic orientations and their implementation.

  13. On 6 February 2019, the Commission adopted a Recommendation on a European Electronic Health Record exchange format(10) (the ‘Commission Recommendation’). In order to support the take-up, further development and to facilitate the use of the European Electronic Health Record exchange format, the eHealth Network, working together with the Commission, stakeholders, clinicians, patients’ representatives, and the relevant authorities, is expected to develop guidance, further support the development and the monitoring of the electronic health records exchange format and support the Member States in ensuring the privacy and security of data exchange. In order to strengthen the interoperability, the Network developed investment guidelines(11), which recommend to take account of the standards and specifications referred to in the Commission Recommendation in particular for the purpose of procurement procedures.

  14. Since eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services is an important element of the Network’s functioning, the role of the eHealth Network in the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services and in other shared European eHealth services should be clarified in order to ensure transparent functioning of the Network.

  15. In order to ensure the effective exchange of health data among Member States, the eHealth Network should be able to work towards enabling Member States to such exchange. In particular, based on fulfilment of predefined requirements and tests provided by and of audits carried by the Commission and, if possible, other experts, the eHealth Network should have a possibility to agree on the organisational, semantic and technical readiness of candidate Member States to exchange validated comprehensive electronic health data for the adopted use cases through their respective National Contact Point for eHealth and their continued compliance in that respect.

  16. For an effective and transparent functioning of the Network, rules should be laid down on the adoption of the Rules of Procedure and multiannual work programme, as well as the creation of subgroups in order to ensure the effective functioning of the eHealth Network. The Rules of Procedure should specify the procedure for the decisions concerning the exchange of personal data through the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services, as described above.

  17. Interested Members of the eHealth Network may advance their cooperation in areas covered by the tasks of the Network. Such cooperation is Member State driven and voluntary in nature. This is the case for the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services and may also be the case for other shared European eHealth Services developed in the framework of the eHealth Network. Where Member States choose to advance their cooperation, they should agree on and commit to the rules of that cooperation.

  18. In order to further ensure the transparent functioning of the eHealth Network, its relation with the Commission should be set out, in particular in relation to the tasks of the eHealth Network and the Commission’s role in the cross-border exchange of health data through the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services.

  19. Processing of personal data of patients, representatives of Member States, experts and observers participating in the eHealth Network, which is done under the responsibility of the Member States or other public organisations or bodies in the Member States, should be carried out in accordance with the General Data Protection Regulation and Directive 2002/58/EC of the European Parliament and of the Council(12). Personal data of representatives of national authorities responsible for eHealth, other representatives of Member States, experts and observers participating in the eHealth Network shall be processed by the Commission in accordance with the Regulation (EU) 2018/1725. Processing of personal data for the purpose of managing and ensuring the security of the core services of the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services done under the responsibility of the Commission should comply with Regulation (EU) 2018/1725.

  20. The Member States, represented by the relevant National Authorities or other designated bodies, determine together the purpose and means of processing of personal data through the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services and are therefore controllers. The respective responsibilities between controllers should be defined in a separate arrangement. The Commission, as provider of technical and organisational solutions of the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services, processes encrypted patients’ personal data on behalf of the Member States between the national Contact Points for eHealth and is therefore a processor. According to Article 28 of the General Data Protection Regulation and Article 29 of the Regulation (EU) 2018/1725, the processing by a processor shall be governed by a contract or a legal act under Union or Member State law that is binding on the processor with regard to the controller and that specifies the processing. This Decision sets rules governing the processing by the Commission as a processor.

  21. In order to ensure equal access rights on the basis of the General Data Protection Regulation and Regulation (EU) 2018/1725, the Commission should be regarded as the controller of personal data relating to the management of access rights to the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services’ core services.

  22. In order to make reimbursement procedures transparent, rules on the expenses of participants in the activities of the eHealth Network should be set.

  23. Implementing Decision 2011/890/EU should therefore be repealed and replaced by this Decision for reasons of legal certainty and clarity.

  24. The measures provided for in this Decision are in accordance with the opinion of the Committee set up under Article 16 of Directive 2011/24/EU,

HAS ADOPTED THIS DECISION:

Article 1 Subject matter

This Decision provides the necessary rules for the establishment, the management and the functioning of the eHealth Network of national authorities responsible for eHealth, as provided for by Article 14 of Directive 2011/24/EU.

Article 2 Definitions

1.

For the purposes of this Decision:

  1. ‘eHealth Network’ means the voluntary network connecting national authorities responsible for eHealth designated by the Member States and pursuing the objectives laid down in Article 14 of Directive 2011/24/EU;

  2. ‘National Contact Points for eHealth’ means organisational and technical gateways for the provision of Cross-Border eHealth Information Services under the responsibility of the Member States;

  3. ‘Cross-Border eHealth Information Services’ means existing services that are processed via National Contact Points for eHealth and through a core service platform developed by the Commission for the purpose of cross-border healthcare;

  4. ‘eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services’ means the infrastructure that enables the provision of Cross-Border eHealth Information Services via National Contact Points for eHealth and the European core service platform. This infrastructure includes both generic services, as defined in Article 2(2)(e) of Regulation (EU) No 283/2014, developed by the Member States and a core service platform, as defined in Article 2(2)(d) therein, developed by the Commission;

  5. ‘other shared European eHealth Services’ means digital services that may be developed in the framework of the eHealth Network and shared between Member States;

  6. ‘governance model’ means a set of rules concerning the designation of bodies participating in decision-making processes concerning the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services or other shared European eHealth Services developed in the framework of the eHealth Network, as well as description of those processes.

2.

The definitions in points (1), (2), (7) and (8) of Article 4 of Regulation (EU) 2016/679 shall apply accordingly.

Article 3 Membership of the eHealth Network

1.

Members of the eHealth Network shall be Member States’ authorities responsible for eHealth, designated by those Member States participating in the eHealth Network.

2.

Member States wishing to participate in the eHealth Network shall notify the Commission in writing of:

  1. the decision to participate in the eHealth Network;

  2. the national authority responsible for eHealth which will become a Member of the eHealth Network, as well as the name of the representative and that of his/her alternate.

3.

Members shall notify the Commission in writing of the following:

  1. their decision to withdraw from the eHealth Network;

  2. any change in the information referred to in point (b) of paragraph 2.

4.

The Commission shall make available to the public the list of Members participating in the eHealth Network.

Article 4 Activities of the eHealth Network

1.

In pursuing the objective referred to in Article 14(2)(a) of Directive 2011/24/EU the eHealth Network may, in particular:

  1. facilitate greater interoperability of the national information and communications technology systems and cross-border transferability of electronic health data in cross-border healthcare;

  2. provide guidance to Member States, in cooperation with other competent supervisory authorities, in relation to sharing health data between Member States and empowering citizens to access and share their own health data;

  3. provide guidance to Member States and facilitate the exchange of good practices concerning the development of different digital health services, such as telemedicine, m-health, or new technologies in the area of big data and artificial intelligence, taking into consideration ongoing actions at EU level;

  4. provide guidance to Member States as regards supporting health promotion, disease prevention and improved delivery of healthcare through better use of health data and by improving digital skills of patients and healthcare professionals;

  5. provide guidance to Member States and facilitate voluntary exchange of best practices on the investments in digital infrastructure;

  6. provide guidance, in collaboration with other relevant bodies and stakeholders, to Member States on the necessary use cases for clinical interoperability and the tools for achieving it;

  7. provide guidance to the Members on security of the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services or other shared European eHealth Services developed in the framework of the eHealth Network, taking into account legislation and documents elaborated at Union level in particular in the area of security, as well as recommendations in the field of cybersecurity, working in close cooperation with the Network and Information Security Cooperation Group and with the European Union Agency for Network and Information Security and with national authorities, where relevant.

2.

In drawing up the guidelines on effective methods for enabling the use of medical information for public health and research referred to in Article 14(2)(b)(ii) of Directive 2011/24/EU, the eHealth Network shall take into account the guidelines adopted by and, where appropriate, consult with the European Data Protection Board. These guidelines may also address information exchanged through the eHealth Digital Service Infrastructure for Cross-Border eHealth Information Services or other shared European eHealth Services.

Article 5 Functioning of the eHealth Network

Article 6 Relation between the eHealth Network and the Commission

Article 7 Data protection

Article 8 Expenses

Article 9 Repeal

Article 10 Addressees

ANNEX