Trust Is Not a Compliance Layer It Is Infrastructure

What health systems must build before EHDS can work at scale

As Europe moves from negotiating the European Health Data Space to implementing it, one question becomes unavoidable: what infrastructure — technical, organisational and human — must exist for people to trust it?

Ahead of the Health Data Forum Global Hybrid Summit in Bilbao, I explored this question with Markus Kalliola, Director of the Future Wellbeing Solutions programme at the Finnish Innovation Fund Sitra, and Krishna Singh, Data and AI Leader at AWS.

Markus and Krishna approach the challenge from different but complementary positions. Sitra has been actively involved in developing the European Health Data Space for several years, connecting policy with the practical conditions for implementation. Krishna works with health systems, national agencies, and European institutions to make health data discoverable, accessible, and secure at continental scale.

Their central message was remarkably aligned: trust cannot be treated as an abstract policy objective or a final compliance exercise. It must be designed into the operating infrastructure of our health systems.

Regulation is necessary, but it cannot carry trust alone

Europe has created an extensive regulatory architecture around health data and digital systems. GDPR, the EHDS Regulation, the AI Act, NIS2 and the Cyber Resilience Act collectively establish important rights, responsibilities and safeguards.

But, as Markus observed, regulation cannot solve every problem created by a rapidly changing technological environment.

Artificial intelligence is already transforming how data is accessed, interpreted and reused. Quantum technologies may introduce further opportunities and risks during the next decade. In this environment, trust must also be developed at the level of individual employees, organisational culture, software providers, health system leadership and citizens.

"I personally always start with regulation," Markus reflected, "but the more I think about it, the closer to the grassroots level I end up."

That movement — from legislation to everyday organisational behaviour — is where implementation begins.

Trust has technical building blocks

From an engineering perspective, Krishna described trust not merely as a principle but as a collection of concrete technological capabilities.

Identity federation helps establish whether someone is the person they claim to be. Encryption protects information at rest and in transit. Access controls determine who can use data and for what purpose. Audit trails make actions traceable. Data-residency arrangements clarify where sensitive information is held.

These are not peripheral technical details. They are part of the architecture through which policy becomes operational.

Yet technology alone is not enough. Krishna argued that organisations should begin with an honest assessment of their present capabilities. Before investing in a new platform or launching another transformation programme, leaders need to understand their current maturity, the destination they are trying to reach and the gaps between the two.

That assessment must cover people, processes and technology. If leadership does not own the mission, trust will not cascade into organisational practice or inform the technological decisions that follow.

Cybersecurity belongs in the boardroom

One of the strongest points of agreement concerned leadership responsibility.

Cybersecurity is still too often seen as the responsibility of the IT department or a specialised team working below executive level. NIS2 moves in the opposite direction by placing responsibility much closer to top management.

For Markus, this is decisive. When cybersecurity is not a leadership priority, it struggles to get the resources, attention, and authority it needs. Security teams are expected to keep systems running but are often noticed only when something goes wrong.

Krishna described the same problem from the perspective of healthcare organisations. Cybersecurity is commonly treated as reactive work. Resources arrive after an incident, when the immediate task should have been to develop resilience before the attack.

This matters because people often enter hospitals and other care settings when they are most vulnerable. Few categories of information could therefore require more protection — or carry greater consequences when trust is lost — than health data.

Resilience is inseparable from care

Cybersecurity in healthcare is not restricted to databases, applications or cloud environments. Hospitals depend on a complex mix of modern platforms, legacy systems, connected medical devices, and physical infrastructure.

Markus recalled asking a major European hospital about its principal cybersecurity vulnerability. The answer was not an advanced AI system or a research database. It was the elevators. If they stopped working, patients could not be moved, and the hospital itself could cease to function.

The example exposes a wider truth: in healthcare, digital resilience and continuity of care can no longer be separated.

Europe must therefore build specialised cybersecurity capacity that reflects the operational reality of health systems. Cloud technology can contribute to that resilience, but it is not the entire answer. Medical devices may remain in service for decades. Legacy systems cannot always be replaced quickly. Organisational readiness varies greatly between hospitals, regions and countries.

This is why resilience must be understood as a shared responsibility.

Europe needs shared fortresses rather than isolated ones

Cyber threats evolve too quickly for every hospital to build and defend its own technological fortress.

Krishna proposed a shared-responsibility model in which health systems benefit from common infrastructure, automated patching, threat intelligence and specialised capabilities that individual institutions may be unable to maintain independently.

Markus widened the same argument to Europe. Many countries lack sufficient healthcare-specific cybersecurity expertise. Building capacity separately in every hospital and Member State would be slow, expensive and likely to reproduce the same weaknesses.

Shared learning is therefore as important as shared infrastructure. When a major healthcare institution in one country suffers an attack, neighbouring countries often pay close attention because the risk suddenly feels close. But Europe should not have to wait for the next incident to exchange that learning.

The EHDS creates an opportunity to organise collaboration more systematically: sharing readiness approaches, maturity models, lessons from incidents and effective responses across borders.

Start by knowing where you are

Asked about the most common mistakes health system leaders might make, both guests returned to organisational maturity.

The temptation is to move immediately towards a new platform or visible infrastructure investment. But acting quickly without understanding the starting point can lead to poorly targeted spending and added complexity.

Health systems first need to ask: Where are we today? Where do we need to go? What capabilities are missing? What can we realistically change without disrupting care delivery?

This last question is especially important. A hospital's primary mission is to care for patients — not to implement the EHDS or run a cybersecurity programme. Implementation plans must therefore strengthen that mission rather than compete with it.

A practical maturity assessment, followed by a clear mandate from leadership, can establish an achievable route forward. This approach applies not only to cybersecurity but also to EHDS readiness, primary data use and trusted secondary use.

Europe should neither move too slowly nor invest in haste. It needs an informed pace, built around shared learning and a clear understanding of the value each investment is intended to create.

Continuing the conversation in Bilbao

This conversation offered only a preview of what Markus Kalliola, Krishna Singh and other international contributors will explore at the Health Data Forum Global Hybrid Summit in Bilbao on 24 and 25 September.

The Summit will bring together leaders from policy, health systems, research, clinical practice and technology around one practical question:

How do we make the European Health Data Space work in the real world?

Through plenary conversations, implementation-focused sessions, and collaborative working groups, we will examine trusted secondary use, genomics, imaging, interoperability, cybersecurity, resilient infrastructure, and responsible AI. The objective is not another declaration of ambition, but a clearer set of implementation priorities that health systems can act upon.

Trusted evidence, better AI, and improved health outcomes all depend on what we build now—and trust must be part of that infrastructure from the beginning.

The Health Data Forum Global Hybrid Summit takes place in Bilbao and online on 24–25 September 2026. Online participation is free.

Share