top of page

Nelson Advisors: Harmonising Cross Border Digital Identity in European Healthcare and MyHealth@EU Architecture

Writer: Nelson Advisors
Nelson Advisors
7 minutes ago
13 min read
Nelson Advisors: Harmonising Cross Border Digital Identity in European Healthcare and MyHealth@EU Architecture
Nelson Advisors: Harmonising Cross Border Digital Identity in European Healthcare and MyHealth@EU Architecture

Harmonising Cross Border Digital Identity in European Healthcare: Analysis of Commission Implementing Regulation (EU) 2026/2099 and the MyHealth@EU Architecture


The cross border delivery of healthcare within the European Union has historically been constrained by administrative fragmentation, incompatible patient identification methodologies, and the absence of mutually recognised digital trust frameworks across Member States. Although the free movement of persons represents a foundational pillar of Union law, an individual's medical data has largely remained confined within national or regional digital silos. In situations involving emergency treatment abroad or planned cross-border interventions, clinicians frequently operate in data vacuums, increasing the risk of adverse medical events, redundant diagnostic testing and substantial clinical overhead.


To resolve these structural vulnerabilities, the European Commission has established a binding legal and architectural bridge connecting the European Health Data Space (EHDS) with the revised European Digital Identity Framework (eIDAS 2.0). Promulgated as Commission Implementing Regulation (EU) 2026/2099 on 21 September 2026 and published in the Official Journal of the European Union on 22 September 2026, this regulatory instrument establishes an interoperable, cross-border identification and authentication mechanism governing patients, healthcare professionals, and healthcare organizations across the MyHealth@EU infrastructure. The resulting framework establishes a phased transition toward high-assurance, wallet-mediated identity exchanges operating between 2027 and 2032, fundamentally converting European Digital Identity (EUDI) Wallets into specialised sectoral tools for healthcare interoperability.


Regulatory Genesis and the eIDAS–EHDS Convergence


The legal foundation of Regulation (EU) 2026/2099 rests upon primary legislation enacted under Regulation (EU) 2025/327, which instituted the European Health Data Space to govern the primary use of electronic health data for direct patient care alongside secondary reuse for scientific research, health policymaking, and innovation. Regulation (EU) 2025/327 entered into force on 26 March 2025, mandating under Article 23 the deployment of MyHealth@EU as the central interoperability platform connecting national digital health ecosystems through designated National Contact Points for Digital Health (NCPeH).


Article 16(2) of Regulation (EU) 2025/327 specifically empowered the European Commission to formulate implementing acts establishing common technical parameters and verification procedures to authenticate all parties participating in cross-border exchanges. Regulation (EU) 2026/2099 fulfills this mandate by directly linking the operational mechanics of MyHealth@EU to the horizontal digital identity provisions established under eIDAS 2.0 (Regulation (EU) 2024/1183), which entered into force on 20 May 2024.


This legal alignment resolves a critical shortcoming of the original eIDAS framework (Regulation (EU) No 910/2014), which maintained voluntary participation models for national electronic identification schemes and lacked harmonised mechanisms for exchanging specialised, sector-specific professional credentials. By embedding eIDAS 2.0 obligations directly into the operational fabric of MyHealth@EU, the European Commission prevents the fragmentation of digital health into proprietary, incompatible identity silos. Instead, health authorities are required to rely on standardized European identity containers—specifically notified national eIDs and certified EUDI Wallets—guaranteeing reciprocal legal validity and uniform technical rigor across all twenty-seven Member States.


Structurally, the regulatory framework operates through a clear institutional hierarchy. The broad governance and primary-use data exchange rights are established under Regulation (EU) 2025/327, while Implementing Regulation (EU) 2026/2099 defines the precise technical mechanics for cross-border identity matching and role authorization. Beneath these legal acts sit the horizontal trust rails of eIDAS 2.0, which provide the underlying cryptographic protocols, assurance levels, and wallet container architectures, and the secure communication network of MyHealth@EU, which routes standardised health records between national gateways.


Technical Architecture and Patient Identity Verification


The verification model defined by Regulation (EU) 2026/2099 establishes dual pathways for patient-related workflows, encompassing both direct point-of-care patient presentations and remote, patient-initiated electronic record requests across national borders.


A central challenge historically impeding cross-border clinical data retrieval has been the lack of a unified European health record identifier. Member States utilise divergent national identifiers to register patients, ranging from civil registration codes and fiscal identifiers to dedicated social security or health insurance numbers. Article 3 of Regulation (EU) 2026/2099 resolves this by requiring every Member State to establish a designated set of "healthcare attributes" utilized within its domestic system to verify a person's identity in connection with their electronic health records for cross-border exchange. Member States must determine these attributes and formally notify them to the European Commission by 26 March 2028 for validation and public dissemination.


When a patient seeks medical assistance in a foreign Member State, the treating provider must first identify the patient by capturing these standardized healthcare attributes. Beginning 26 March 2029, under Article 3(3) and Article 5(2), the competent authority in the patient's Member State of affiliation is legally obligated to issue these attributes upon request directly to the individual's EUDI Wallet in the form of Electronic Attestations of Attributes (EAAs) or Qualified Electronic Attestations of Attributes (QEAAs). Consequently, healthcare providers across the Union are required to accept attribute attestations presented via the wallet container, whether the encounter occurs in person at a clinic or remotely via an online digital service.


The technological mechanism underpinning this interaction relies on standardised, privacy-preserving exchange protocols defined within the eIDAS Architecture Reference Framework (ARF). The wallet interaction utilizes presentation standards such as OpenID for Verifiable Presentations (OpenID4VP), facilitating credential exchange via proximity optical scanning (QR codes), near-field communication (NFC), or direct web handshakes. The credential presentation incorporates selective disclosure mechanisms, supported by formats such as Selective Disclosure JSON Web Tokens (SD-JWT) and ISO/IEC 18013-5 verifiable credentials.


Selective disclosure allows a patient to reveal only the specific healthcare attributes and person identification data (PID) required by the foreign clinic to query their medical records, without exposing extraneous personal details such as complete residential histories or civil status. This technical design enforces the data minimization requirements of Article 5(1)(c) of the General Data Protection Regulation (GDPR). Once captured, the foreign provider transmits these attributes to their national NCPeH gateway, which initiates an authenticated query across MyHealth@EU to the patient's domestic NCPeH to retrieve the corresponding clinical files.


Professional and Institutional Trust Architecture


Cross-border access to special category health data requires symmetrical authentication safeguards for clinical practitioners. A foreign digital health gateway cannot permit data queries based merely on unverified user accounts; it must verify the practitioner's active license, clinical role, and institutional affiliation to ensure that clinical records are accessed solely on a need-to-know basis.


Article 6 of Regulation (EU) 2026/2099 establishes that each Member State must designate authorized entities responsible for identifying, authenticating, and validating the authorizations of healthcare professionals and healthcare providers before any cross-border health data exchange is requested. Prior to dispatching an exchange request through MyHealth@EU, the designated authority in the country where care is delivered must verify that the practitioner possesses valid standing.


To enable end to end verification, Article 7 mandates that the requesting National Contact Point for Digital Health transmit standardised professional and organizational metadata directly to the responding National Contact Point. The Annex to Regulation (EU) 2026/2099 sets out the mandatory technical data fields required for this transmission, standardising the identity profile of both individual clinicians and the healthcare institutions on whose behalf they operate.


Data Identifier

Subject Entity

Technical Scope and Regulatory Definition

family_name

Health Professional

The official surname(s) of the requesting practitioner.

given_name

Health Professional

First name(s) and any registered middle names of the practitioner.

country_code

Professional & Provider

ISO 3166-1 alpha-2 code of the Member State issuing the credential.

hp_identifier

Health Professional

Unique national identifier assigned by the competent licensing body.

issuing_authority_name

Professional & Provider

Official designation of the registry validating the credential.

hp_professional_role

Health Professional

Standardized clinical specialization governing role-based access.

healthcare_provider_identifier

Professional & Provider

Unique system identifier of the treatment facility or organization.

healthcare_provider_name

Healthcare Provider

Full legal commercial or institutional title of the medical facility.

healthcare_provider_address

Healthcare Provider

Legally registered physical and administrative address of the facility.


In addition to individual practitioner verification, cross-border care delivery frequently involves legal representation, such as parents acting on behalf of minor children or appointed legal guardians acting for incapacitated adults. Article 4(4) mandates that whenever an individual acts in a representative capacity, the healthcare provider must authenticate the representative and verify their legal mandate before requesting data.


To avoid the administrative friction of manually translating and verifying foreign court orders or birth certificates, the framework permits healthcare providers and foreign contact points to rely directly on electronic mandate attestations issued by authentic sources within the patient's Member State of affiliation. By integrating digital representation mandates managed through the eIDAS 2.0 wallet infrastructure, legal custodians can assert proxy rights electronically across borders, ensuring that vulnerable individuals receive immediate care without legal ambiguity.


Phased Implementation Roadmap and Assurance Escalation


The technological overhaul required to connect national health directories, regional hospital networks, and public health contact points to a unified identity fabric necessitates a realistic compliance runway. Consequently, the European Commission structured Regulation (EU) 2026/2099 around a phased implementation schedule spanning from March 2027 to March 2032, tied to escalating Levels of Assurance (LoA).


Under eIDAS rules (Regulation (EU) No 910/2014, Article 8), electronic identification means are categorized under three distinct assurance thresholds: Low, Substantial, and High. A Level of Assurance Substantial requires robust identity verification and multi-factor authentication, though it permits software-based cryptographic tokens. Conversely, a Level of Assurance High demands the highest degree of technical security against identity theft and unauthorised alteration, requiring hardware-backed key storage (such as certified Secure Elements, smart cards, or qualified hardware tokens) coupled with biometric or strong cryptographic possession controls.


The phased rollout established by Regulation (EU) 2026/2099 reflects a structured transition path. The general application of the regulation begins on 26 March 2027, from which date electronic identification for online patient requests and authentication for healthcare professionals must meet at least LoA Substantial. Exactly one year later, on 26 March 2028, Member States must complete and notify their standardised national healthcare attribute schemas to the European Commission.


A major operational milestone arrives on 26 March 2029, when Member States must begin issuing healthcare attributes as electronic attestations to citizens' EUDI Wallets, and healthcare providers must accept these credentials at the point of care. This deadline directly synchronizes with the primary use mandate under Regulation (EU) 2025/327, which makes cross-border exchanges of Patient Summaries and electronic prescriptions/dispensations compulsory across all Member States on that same date.


Following the 2029 baseline, the framework mandates an escalation to maximum technical security,

applying an asynchronous schedule for patients and clinicians. On 26 March 2030, all electronic identification means utilized by natural persons accessing MyHealth@EU online must strictly fulfill LoA High. However, healthcare professional authentication is granted an extended transition window, remaining permitted at LoA Substantial until 26 March 2032, after which LoA High becomes mandatory.


This two-year asymmetry between patient and practitioner assurance requirements addresses significant institutional and technological realities. Patient identification will scale rapidly through consumer smartphones that integrate hardware-isolated security environments (e.g., embedded SIMs, secure enclaves) certified to LoA High under eIDAS 2.0 consumer wallet deployments.


In contrast, professional authentication across the European healthcare sector is distributed across thousands of autonomous hospital information systems, specialized ambulatory suites, community pharmacies, and regional health trusts. Transitioning entire clinical workforces to hardware-backed tokens or high-assurance smart identity cards requires comprehensive re-engineering of internal hospital Identity and Access Management (IAM) systems, directory services, and hardware terminal interfaces. Imposing an immediate LoA High threshold on medical practitioners would have risked excluding broad segments of the clinical community from accessing vital foreign medical summaries, thereby compromising emergency patient care.


Milestone Date

Legal Basis

Implementation Target and Compliance Requirement

Mandatory Assurance Threshold

26 March 2027

Article 9(1)

General date of application; baseline cross-border identity exchanges become active across MyHealth@EU.

Minimum LoA Substantial


26 March 2028

Article 3(2)

Member States formally notify national healthcare attribute schemas to the Commission for publication.

Administrative notification

26 March 2029

Articles 3(3), 5(2)

Mandatory issuance of healthcare attributes to EUDI Wallets and mandatory acceptance by healthcare providers.

Minimum LoA Substantial


26 March 2030

Article 4(3)

Escalation of electronic identification means for natural persons accessing health records online.

Mandatory LoA High


26 March 2032

Article 6(3)

Escalation of electronic authentication means for healthcare professionals accessing cross-border records.

Mandatory LoA High



Where a Member State deploys an electronic identification mechanism that has not been formally notified to the Commission under eIDAS 2.0, Regulation (EU) 2026/2099 requires that its compliance with the high assurance level be verified by an accredited Conformity Assessment Body (CAB) in accordance with Regulation (EC) No 765/2008. This ensures that regional or private healthcare authentication tokens undergo rigorous third-party auditing before being recognised across the MyHealth@EU mesh.


Data Governance, Clinical Safety and Interoperability Infrastructure


The convergence of digital identity with electronic health records operates under strict data governance parameters dictated by the sensitive nature of clinical data under Article 9 of the GDPR. Implementing Regulation (EU) 2026/2099 functions as an access control and traceability mechanism to enforce the substantive rights granted to patients under Regulation (EU) 2025/327.


Under Article 9 of the EHDS Regulation, patients possess the statutory right to receive transparent information regarding who has accessed their electronic health data. The inclusion of mandatory technical parameters, such as hp_identifier, hp_professional_role, and healthcare_provider_identifier—within every cross-border query creates a tamper evident audit record. When a foreign physician queries a patient's domestic EHR via MyHealth@EU, the domestic system captures this metadata, enabling the patient to review via their digital health portal exactly which clinician, at which medical facility, inspected their medical summary and for what explicit clinical purpose.


Furthermore, the identity framework interfaces with national opt-out and access restriction policies. Article 10 of Regulation (EU) 2025/327 permits Member States to provide patients with a legal right to opt out of the primary-use data exchange system, provided the exercise of that right remains fully reversible.


When an individual exercises their opt-out right or restricts access to specific sensitive categories within their record (such as behavioral health data or sexual health history), the identity query engine enforces these boundaries automatically. Foreign clinicians querying the system are denied access to the restricted files, and the technical protocol prevents the practitioner from being alerted to the existence or content of the masked information, protecting patient autonomy and preventing institutional bias. In critical life-or-death scenarios, the system accommodates break-glass emergency protocols to protect the vital interests of the patient, but every emergency override is permanently logged and surfaced to the patient upon review.


Beyond authentication, clinical safety relies on syntactic and semantic interoperability. The authenticated identity token functions as an access key, opening a secure transaction tunnel across which health data is exchanged using the European Electronic Health Record Exchange Format (EEHRxF). The EEHRxF standardizes health data structures across priority domains, including Patient Summaries, ePrescriptions, Laboratory Reports, Medical Imaging, and Hospital Discharge Reports.


The syntactic layer utilizes Health Level Seven Fast Healthcare Interoperability Resources (HL7 FHIR), packaging clinical observations into structured JSON or XML bundles. The semantic layer relies on internationally standardized clinical terminologies, such as SNOMED CT for clinical concepts, LOINC for diagnostic and laboratory observations, and the European Medicines Agency's Product Management Service (EMA PMS) for medicinal products and dosage forms. When an e-prescription is transmitted across borders, this semantic harmonisation ensures that a pharmacist in one Member State can interpret and dispense the correct equivalent active substance prescribed in another, regardless of differences in commercial brand names.


Operational validation of this combined identity and health data framework was demonstrated through the European Commission's large-scale pilot initiatives funded by the Digital Europe Programme. The flagship POTENTIAL consortium, which concluded its two-year pilot cycle in autumn 2025, involved more than 140 public and private entities across nineteen Member States and Ukraine. Over more than 1,300 tests and 249 live cross-border transactions, POTENTIAL validated the operational integration of the EUDI Wallet with e-prescription workflows.


In practical trials, patients successfully presented cryptographic e-prescription tokens from their wallets to foreign pharmacies, where dispensing systems parsed the credentials, retrieved the prescription data, and registered the dispensation back to the home country's registry.


However, the pilot also exposed operational friction. Interoperability proved fragile when national OpenNCP connectors ran disparate software versions or utilized non-standardized attribute mapping rules, leading to dropped connections. Furthermore, existing hospital information systems and community pharmacy applications demonstrated an inability to process verifiable presentations natively, indicating that Member States must construct dedicated middleware gateways to translate wallet handshakes into legacy hospital protocols.


Strategic Implications and Industry Readiness


The enactment of Regulation (EU) 2026/2099 transforms digital identity from a back-office IT consideration into a critical compliance priority for healthcare providers, software developers, and national administrations.


For healthcare organizations and hospital administrators, clinical admissions and check-in workflows must be re-engineered. Facilities must install point-of-care readers capable of interacting with EUDI Wallets via NFC and QR scanning, while ensuring that registration staff are trained to manage wallet-based identity verification.


On an enterprise level, hospital CIOs must audit and modernize internal Identity and Access Management (IAM) systems. Clinical directories must be updated to ensure that every practitioner is assigned an accredited professional identifier mapped to standardized clinical roles matching the Annex specifications of Regulation (EU) 2026/2099. Failure to establish these technical integrations will functionally disconnect hospitals from MyHealth@EU, preventing clinicians from accessing foreign medical histories and creating liability risks during emergency treatment of cross-border patients.


For manufacturers, importers, and distributors of Electronic Health Record (EHR) systems, the regulatory landscape imposes strict market-entry criteria. Under Chapter III of Regulation (EU) 2025/327, EHR systems must undergo mandatory conformity assessment procedures and obtain a CE mark confirming compliance with European interoperability and security standards before being placed on the Union market.

Software architectures must natively support the identity data fields mandated by Regulation (EU) 2026/2099, ensure compatibility with the EEHRxF data formats, and incorporate automated audit logging mechanisms. Non-compliant software platforms face exclusion from public procurement tenders, and severe regulatory breaches carry financial penalties under the EHDS framework of up to €20 million or 4% of total worldwide annual turnover.


For national digital health authorities, the primary focus shifts to establishing national authentic sources. Between 2027 and 2028, health ministries must harmonize regional professional registers into unified authoritative lookup directories. This task is complex in decentralized healthcare administrations, such as those in Spain, Italy, and Germany, where professional licensure and health record indexing are governed by regional authorities or autonomous medical chambers. Central governments must build national attribute aggregation backends to ensure that when a citizen requests their healthcare attributes via an EUDI Wallet in 2029, the competent authority can issue a cryptographically validated attestation without administrative failure.


The adoption of Commission Implementing Regulation (EU) 2026/2099 establishes a legally binding, high-assurance digital identity layer across the European Health Data Space. By anchoring cross-border medical data exchange to eIDAS 2.0 and the European Digital Identity Wallet, the European Union has resolved the long-standing challenge of patient and provider identification across borders. Through a calibrated, phased implementation extending from 2027 to 2032, the Union is dismantling national data silos and deploying an interoperable trust infrastructure that ensures personal health data moves securely alongside the citizen throughout the European internal market.


Nelson Advisors > European Healthcare Technology Investment Banking


Nelson Advisors specialise in Mergers and Acquisitions for European HealthTech, MedTech, Digital Health, Healthcare IT, Healthcare AI companies in the Lower to Mid Market ranging from $25M to $250M EV. www.nelsonadvisors.co.uk


Healthcare.Digital is the Google News approved HealthTech and MedTech Thought Leadership platform for Nelson Advisors, positioning them as a specialised authority on European Healthcare Technology M&A and strategic corporate development. https://www.healthcare.digital 


Nelson Advisors publish Europe's Leading Healthcare Technology Investment Banking Newsletter every week, join 5000+ HealthTech and MedTech subscribers today! https://lnkd.in/e5hTp_xb 


Healthcare.Digital serves as a research platform for Nelson Advisors’ perspectives on deals, valuations and structural shifts reshaping Global Digital Health, MedTech, Healthcare AI and Health IT. https://www.healthcare.digital 


Nelson Advisors is one of Europe's leading mergers and acquisitions advisory firms, exclusively dedicated to the dynamic and rapidly evolving healthcare technology sector. With a deep understanding of market dynamics and technological advancements, they empower innovative HealthTech companies and strategic investors to navigate complex transactions and achieve their growth ambitions. www.nelsonadvisors.co.uk



Nelson Advisors LLP


Hale House, 76-78 Portland Place, Marylebone, London, W1B 1NT




Meet Nelson Advisors @ Events in 2026


Digital Health Rewired > March 2026 > Birmingham, UK  


NHS ConfedExpo  > June 2026 > Manchester, UK 


HLTH Europe > June 2026, Amsterdam, Netherlands


HIMSS AI in Healthcare > July 2026, New York, USA


Bits & Pretzels > September 2026, Munich, Germany  


HealthInvestor Healthcare Summit > September 2026, London, UK 


World Health Summit 2026 > October 2026, Berlin, Germany


HLTH USA 2026 > October 2026, USA


Global Health Exhibition 2026 > October 2026, Riyadh, Saudi Arabia


Web Summit 2026 > November 2026, Lisbon, Portugal  


MEDICA 2026 > November 2026, Düsseldorf, Germany


Leaders in Health Summit 2026 > November 2026, London, UK 


Venture Capital World Summit > December 2026, Toronto, Canada


Meet Nelson Advisors @ Events in 2027


Digital Health Rewired > March 2027 > Birmingham, UK


Barclays Health Elevate > March 2027, London, UK 


NHS ConfedExpo  > June 2027 > Manchester, UK 


HLTH Europe > June 2027, Amsterdam, Netherlands


Nelson Advisors specialise in Mergers and Acquisitions for European HealthTech, MedTech, Digital Health, Healthcare IT, Healthcare AI companies in the Lower to Mid Market ranging from $25M to $250M EV. www.nelsonadvisors.co.uk
Nelson Advisors specialise in Mergers and Acquisitions for European HealthTech, MedTech, Digital Health, Healthcare IT, Healthcare AI companies in the Lower to Mid Market ranging from $25M to $250M EV. www.nelsonadvisors.co.uk

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page