Law / European Union

European Health Data Space Regulation, Serious-Incident Reporting by Manufacturers of EHR Systems

Regulation (EU) 2025/327, Art. 44(7)

A vulnerability and incident reporting rule binding public and private bodies.

Private right of action
Yes
Obligation class
Reporting

As of .

What it requires

  • This duty takes effect on for EHR systems intended by the manufacturer to process the priority categories of personal electronic health data in Article 14(1), points (a), (b) and (c), and on for those intended to process points (d), (e) and (f): Article 105 applies the Regulation from but applies Articles 25 to 27, which govern placing an EHR system on the market, from those later dates, and the Article 44(7) report concerns a system placed on the market under them.
  • It reaches you if you are the manufacturer of an EHR system placed on the market or put into service. Report any serious incident (Article 2, point (r)) involving the EHR system to the market surveillance authorities of the Member States where the serious incident occurred and of the Member States where the system is placed on the market or put into service, and include a description of the corrective action you have taken or envisage (Article 44(7)).
  • Make the report immediately after you have established a causal link between the EHR system and the serious incident or the reasonable likelihood of such a link and, in any event, not later than three days after you become aware of the serious incident (Article 44(7)).
  • Make the report without prejudice to any incident notification that Directive (EU) 2022/2555 requires of you (Article 44(7)).

Who enforces it

Enforcement body

The market surveillance authority or authorities that each Member State designates under Article 43(2), which apply Regulation (EU) 2019/1020 to EHR systems (Article 43(1)) and are empowered to take the market surveillance measures in Article 16 of that Regulation (Article 43(2)); for medical devices, in vitro diagnostic medical devices and high-risk AI systems that claim interoperability, the authorities named in Article 43(7).

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 44(7) of Regulation (EU) 2025/327 requires manufacturers of EHR systems placed on the market or put into service to report any serious incident involving an EHR system to the market surveillance authorities of the Member States where the serious incident occurred and of the Member States where the EHR systems are placed on the market or put into service. The report must also include a description of the corrective action taken or envisaged by the manufacturer.

Article 44(7) sets the time for the report at immediately after the manufacturer has established a causal link between the EHR system and the serious incident or the reasonable likelihood of such a link and, in any event, not later than three days after the manufacturer becomes aware of the serious incident. The report is made without prejudice to incident notification requirements under Directive (EU) 2022/2555.

Article 44(7) lets Member States provide for users of EHR systems to report such incidents.

Article 2, point (r), defines a serious incident as any malfunction or deterioration in the characteristics or performance of an EHR system made available on the market that directly or indirectly leads, might have led or might lead to the death of a natural person or serious harm to a natural person's health, serious prejudice to a natural person's rights, or serious disruption of the management and operation of critical infrastructure in the health sector.

Article 44(10) lets the market surveillance authorities, in the event of incidents putting at risk patient safety or information security, take immediate action and require the manufacturer, its authorized representative and other economic operators to take immediate corrective action.

Article 2, point (k), defines an EHR system as any system whereby the software, or a combination of the hardware and the software of that system, allows personal electronic health data that belong to the priority categories to be stored, intermediated, exported, imported, converted, edited or viewed, and intended by the manufacturer to be used by healthcare providers when providing patient care or by patients when accessing their electronic health data.

Article 105 applies Regulation (EU) 2025/327 from . Article 105 applies Articles 25, 26 and 27 from to EHR systems intended by the manufacturer to process the priority categories of personal electronic health data in Article 14(1), points (a), (b) and (c), and from to those intended to process points (d), (e) and (f).

Article 43(2) requires each Member State to designate the market surveillance authority or authorities responsible for the implementation of Chapter III. Article 99 requires Member States to lay down the rules on penalties applicable to infringements of Regulation (EU) 2025/327, which must be effective, proportionate and dissuasive.

Article 100 gives any natural or legal person that has suffered material or non-material damage as a result of an infringement the right to receive compensation in accordance with Union and national law.

When LexLint raises it

When your app profile says your app distributes a software product or ships a mobile app.

Back to the example  ·  Lint your app