19.03.2026
6 min read

EHDS, ePA, NIS2: Three regulations set to fundamentally transform digital healthcare by 2029 – and three regulations whose implementation will land squarely on the shoulders of one person in most hospitals: the CIO. Anyone who fails to orchestrate this triple burden strategically won’t just lose compliance – they’ll forfeit strategic influence over the next five years.

TL;DR

  • ePA: 40% in pilot operation; digitalization penalties begin in 2026. Hospitals that fail to digitize on schedule face deductions of up to 2% per billing case (DKI rapid survey, March 2026).
  • EHDS: Patient data must be exchangeable across the EU by 2029. The regulation entered into force in March 2025. HL7 FHIR becomes the mandatory interoperability standard.
  • NIS2: Reporting obligations have been in effect since December 2025. Hospitals and MedTech manufacturers with 50+ employees must report cyber incidents within 24 hours. No grace period applies.
  • Budget reality: KHZG funding is exhausted. The €4.3 billion in federal digitalization grants has already been allocated. What comes next must be financed from operational budgets.
  • The strategic CIO orchestrates – not reacts. Treating ePA, EHDS, and NIS2 as three separate projects guarantees failure. Real synergies lie in shared architectures.

Three Regulations, One Timeline

This simultaneity is no coincidence. Europe is accelerating its digital health transformation – and Germany must catch up. The Bertelsmann Foundation’s Digital Health Index ranks Germany 16th out of 17 OECD countries. These three regulations represent a deliberate effort to close that gap through binding mandates.

For the CIO of a mid-sized hospital (400-800 beds), this means: an IT budget that hasn’t grown, a team that hasn’t expanded – and three major regulatory construction sites, all due for completion before 2029. ePA pilots are already underway; EHDS demands interoperability standards; and NIS2 requires cybersecurity structures most hospitals simply don’t yet possess.

2026
ePA penalties + NIS2 registration
2027
AI Act high-risk requirements
2029
EHDS primary use phase

ePA: The Technical Foundation That Isn’t Yet Laid

The DKI rapid survey from March 2026 shows: 40% of hospitals are running ePA pilots; 90% have begun technical implementation. Yet 43% expect full hospital-wide deployment only from Q3 2026 onward. Meanwhile, digitalization penalties took effect in January: up to 2% per billing case if five mandatory digital services remain uncommissioned.

For the CIO, ePA isn’t a finished project – it’s the cornerstone upon which both EHDS and NIS2 are built. Whoever finalizes ePA integration into their hospital information system (KIS) today must tomorrow open those same interfaces for cross-border EHDS data exchange – and the day after, ensure those interfaces meet NIS2 security requirements. These three regulations aren’t parallel tracks. They’re layers of the same system.

EHDS: Interoperability Becomes Mandatory

The European Health Data Space (EHDS) requires patient data to be available in structured, interoperable formats. HL7 FHIR becomes the binding standard. By March 2029, patient summaries and electronic prescriptions must be accessible across borders. Medical imaging and discharge letters follow by 2031.

The strategic question for the CIO: Do I invest now in a KIS upgrade that supports only ePA – or in an FHIR-based architecture capable of serving both ePA and EHDS simultaneously? The short-term cheaper option (an ePA-only patch) becomes more expensive mid-term, requiring another overhaul in 2028. An FHIR-first strategy demands higher upfront investment – but avoids that second rebuild.

“The biggest challenge lies in technically and regulatorily integrating data from different sectors.” – Sebastian C. Semler, Managing Director, TMF e.V. (National Digital Health Symposium, 2025)

NIS2: Cybersecurity Becomes a Boardroom Responsibility

The NIS2 Implementation Act entered into force on 6 December 2025 – with no transition period. Hospitals and MedTech manufacturers with 50+ employees are classified as “essential entities.” The BSI registration deadline expired on 6 March 2026. Failure to register constitutes an immediate violation of current law.

Requirements are substantial: documented IT risk management – including supply chain assessments; mandatory reporting of cyber incidents within 24 hours; mandatory cybersecurity training for executive leadership; and a dedicated information system for affected patients. Fines for non-compliance reach up to €10 million.

For the CIO, this means cybersecurity is no longer a side project pursued alongside daily operations. It is now a board-level responsibility – with personal liability for executives. The February 2026 TI outage – triggered by a smoke alarm in Frankfurt that paralyzed the entire Telematics Infrastructure for eight hours – demonstrates a stark truth: Every new digital interface expands the attack surface.

The Orchestration Strategy: Synergies Over Silos

The strategic CIO treats ePA, EHDS, and NIS2 not as three independent projects – but as a single architecture program with three compliance layers. The synergies are significant:

Shared data layer: FHIR as a unified format serves both ePA connectivity and EHDS cross-border exchange. One format, two regulations.

Shared risk management: NIS2 mandates IT risk management. The AI Act (effective 2027) mandates AI-specific risk management. Both can be integrated into a single ISO 27001 framework – which also satisfies MDR requirements for connected medical devices.

Shared infrastructure: Secure connection to the Telematics Infrastructure (ePA), EHDS gateways, and NIS2 reporting systems can all be built atop the same network architecture. Building three separate infrastructures triples cost and complexity.

The KHZG provided €4.3 billion – but those funds are fully allocated. What comes next – EHDS compliance, NIS2 implementation, AI governance – must be funded from operational budgets. For the CIO, this is a powerful argument for orchestration: an integrated program isn’t just technically elegant – it’s 30-40% less expensive than three parallel standalone projects.

Frequently Asked Questions

What are the key deadlines for healthcare CIOs?

2026: ePA digitalization penalties + NIS2 registration (already due). 2027: AI Act high-risk requirements (August). 2029: EHDS primary use phase – EU-wide exchange of patient summaries. 2031: EHDS expansion to include medical imaging and discharge letters.

Can hospitals implement all three regulations within a single program?

Yes – and they should. FHIR as a common data format serves both ePA and EHDS simultaneously. An integrated risk management framework aligned with ISO 27001 covers NIS2, the AI Act, and MDR requirements. Infrastructure for TI connectivity, EHDS gateways, and incident reporting systems can be built jointly.

What happens in case of NIS2 non-compliance?

Fines of up to €10 million. Executive leadership bears personal liability for compliance. Cyber incidents must be reported within 24 hours. The NIS2 Implementation Act has applied without a transition period since 6 December 2025.

Where does Germany stand internationally?

16th out of 17 in the Bertelsmann Foundation’s Digital Health Index. According to Black Book Research, only 43% of German institutions are connected to the national Spine (EU average: 58%; Finland: 97%).

Header Image Source: Pexels / Tima Miroshnichenko (px:5726794)

Share this article:

Also available in

More Articles

23.07.2026

Orphaned Access: The Silent Cybersecurity Gap

Benedikt Langer

5 Min. Read Time Service accounts, API keys, and AI agents often outnumber human accounts. Many of these ...

Read Article
22.07.2026

Why Your Cloud Bill Never Gets Smaller

Bernhard Liebl

5 min read The cloud bill climbs month after month, even though no one deliberately orders more. Unused ...

Read Article
21.07.2026

The integration that dismantles the deal case.

Tobias Massow

3 min read The deal case promises value. The integration delivers friction. If Day-1 to Day-100 is treated ...

Read Article
21.07.2026

Which control remains after the agent rollout

Benedikt Langer

4 min read According to a Gartner press release (August 2025), around 40 percent of enterprise apps will ...

Read Article
21.07.2026

AI cloud commitments: Capex pace turns uncomfortable

Angelika Beierlein

5 Min. read time Hyperscalers continue to expand. Yet analysts and earnings calls point to a slower growth ...

Read Article
21.07.2026

Rigid RZ Contracts Meet the Flexible EnEfG

Bernhard Liebl

8 min read Anyone procuring capacity from 2027 will be negotiating against the current EnEfG (Energy ...

Read Article
A magazine by Evernine Media GmbH