D7.4 Technical specifications for Health Data Access Bodies on the implementation of secure processing environments
Following the conclusion of the TEHDAS Joint Action, Deliverable 7.4 (D7.4) has established the foundational technical specifications for Secure Processing Environments (SPEs). Many Health Data Access Bodies (HDABs) across Europe are already utilizing these guidelines to prepare for the upcoming European Health Data Space (EHDS). The framework offers the necessary flexibility for each organization and member state to choose an implementation path that aligns with their specific national infrastructure.
What is TEHDAS D7.4?
TEHDAS D7.4 is the technical blueprint for the design and deployment of Secure Processing Environments (SPEs) under the EHDS framework. It provides a standardized approach and a common requirements matrix for information security and data governance when handling health data for secondary use. By placing risk management, data minimization, and privacy-by-design at its core, D7.4 ensures that health data remains strictly protected while still enabling secure scientific research and policy-making.
Do technology providers also need to comply with these specifications?
Yes. Third-party vendors and cloud service providers delivering infrastructure or software platforms to HDABs must align with the specific technical controls outlined in D7.4. These requirements cover critical areas such as absolute environment isolation, comprehensive auditing and logging, and restricted data export functionalities.
Because the HDAB ultimately retains legal and operational responsibility for assessing and managing risks related to outsourced services, it is highly recommended to integrate these TEHDAS D7.4 technical specifications directly into procurement criteria and vendor contracts.
More information: