Secondary use of health records is increasingly important for research, quality improvement, innovation, Artificial Intelligence development, statistics and policy planning. A 2026 analysis in npj Digital Medicine sets out a nine-step guideline for lawful reuse within Norwegian and European Union regulatory frameworks. It focuses on legal, ethical, security and technical requirements, with recommendations for transferability across the European Economic Area (EEA).

 

Norway’s Route Through Secondary Use
Secondary use of health records requires clear classification before data access begins. The guideline starts by requiring projects to record purpose, controller, processor, datasets, identifiability and relevant roles. It distinguishes personal data, special-category health, genetic or biometric data, pseudonymised data and truly anonymised data. Pseudonymised data remains personal data, while fully anonymised data falls outside GDPR when anonymisation is irreversible. Health records include electronic health data, electronic health records and patient journals, covering medical history, diagnoses, treatments, medications, allergies, vaccinations, radiology images, laboratory results and related clinical data.

 

Norway’s specialist healthcare structure creates a complex operational setting. Four regional health authorities operate distinct electronic health record systems, and national rules sit alongside binding EU law through the EEA Agreement. Data controller status usually rests with the healthcare institution, such as a public health trust, which carries legal responsibility for health records and compliance with data protection requirements. Patients retain statutory rights to access, correct and manage their records. Secondary-use pathways cover research, innovation or AI development, quality improvement, statistics and policy planning. Projects combining several purposes follow the same overall steps, while data linked to biological materials can bring additional regulatory regimes into scope.

 

Access, Security and Accountability
The EHDS creates a framework for secondary use involving health data access bodies (HDABs) and Secure Processing Environments (SPEs). HDABs act as national authorities that receive and assess secondary-use applications and issue data access permits. They do not replace national ethics committees, and ethical review remains a separate national process. Data permits follow any required ethical approvals. SPEs provide controlled technical environments where approved secondary-use processing takes place under defined safeguards.

 

Must Read: Regulators Set Conditions for Synthetic Health Data Sharing

 

Norway already uses sensitive data analysis platforms described as Secure Analysis Environments (SAEs), including HUNT Cloud at the Norwegian University of Science and Technology, Services for Sensitive Data at the University of Oslo and Secure Access to Research Data and E-infrastructure at the University of Bergen. These environments can function as specific laboratories or enclaves within future SPE infrastructure if they meet EHDS technical specifications. The mandatory EHDS SPE obligation applies later, while Norway continues to align policies for access, storage, sharing, ownership and accountability. Security controls include access control, logging, encryption, multifactor authentication, network segregation, key management and risk-based log review. Data agreements must define scope, purpose, duration, confidentiality, security, post-project return or secure destruction. External transfers require lawful mechanisms, protection assessments, documentation and mitigation.

 

Nine Steps for European Transferability
The nine-step workflow covers project classification, legal basis and consent, ethics and regulatory approval, data access and agreements, security and privacy, data minimisation and quality, analysis and AI development, compliance monitoring and auditing, then dissemination, close-out, retention and deletion. Most steps apply across research, quality improvement, statistics and policy planning. The AI step applies when secondary use involves algorithmic analysis or AI system development.

 

Legal basis and consent require careful handling because consent under Norway’s Health Research Act is not equivalent to consent under GDPR. Public bodies may rely on public-interest or official-authority tasks, research or statistics provisions, healthcare management or quality-improvement grounds, provided the required supplementary national legal basis exists. Confidentiality duties, consent or dispensation from consent and confidentiality must also be addressed. High-risk processing can require a Data Protection Impact Assessment, and Data Protection Officer consultation may be needed.

 

Transferability across the EU and EEA depends on functional equivalence rather than identical institutional structures. Other countries may distribute ethics approval, access authorisation, secure processing and compliance oversight across national access bodies, ethics committees, registry custodians, statistical offices or institutional secure environments. Patient and public trust remains central, with GDPR rights of access, rectification, erasure and objection continuing to apply to personal data processing, while EHDS adds transparency around access and opt-out rights for secondary use.


Secondary use of health records can support research, service improvement, policy planning, innovation and AI development only when legal, ethical, technical and organisational controls are coordinated across the full project lifecycle. The Norwegian pathway combines national health legislation with EU-level requirements, especially EHDS, GDPR and the AI Act. The nine-step workflow provides a structured route for classification, authorisation, secure processing, auditability, dissemination and close-out. Its broader value lies in helping institutions map equivalent responsibilities across EEA settings while preserving privacy, security, accountability and data-subject rights, rather than treating reuse as isolated extraction, analysis or one-off technical activity.

 

Source: npj Digital Medicine

Image Credit: iStock


References:

Pant D, Røst TB, Krüger H et al. (2026) Guideline for secondary use of health records within Norwegian and EU regulatory frameworks. npj Digit Med. https://doi.org/10.1038/s41746-026-02784-2




Latest Articles

secondary use health records, EHDS health data reuse, GDPR health data research, health data access body, secure processing environment, Norwegian health data law, health record AI development, European health data framework Nine-step guideline for lawful secondary use of health records aligns Norwegian and EU frameworks across GDPR, EHDS and AI Act for research and innovation.