Blog

Health and AI

Summary
Health and AI

Secondary Use of Health Data: Access, Consent & Research Path 2026

Explore how secondary use of health data in France works, the role of consent, EHDS reforms, access routes, and what hospitals must prepare for compliant research.
Updated on
Sep 21, 2026

The essentials in 30 seconds

QuestionShort answerWhat to remember
What is secondary use?Re‑using existing health data for research, public health or innovation.Consent and data governance differ from direct care.
Who can request data? Accredited researchers, public‑health agencies, and approved AI developers. Must demonstrate legitimate interest and ethical approval.
Is patient consent always required? Not always; lawful bases include public interest and scientific research with safeguards. Opt‑out mechanisms must be clearly recorded.
How does EHDS affect access?Creates a pan‑European framework, harmonising standards and simplifying cross‑border requests. National portals remain the first point of contact.
Where can French data be found? Health Data Hub, SNDS, regional data warehouses, and hospital DPI’s. Each source has its own application workflow.
What is the right of opposition? Patients can refuse secondary use and the decision is stored in their EHR. Hospitals must honor refusals without delay.
What quality checks are mandatory? Data must be anonymised, validated, and traceable to its source. Audits are required before data export.

Introduction

Health systems generate billions of data points every year, yet only a fraction fuels clinical care. The rest – lab results, imaging metadata, longitudinal records – hold untapped potential for research, public‑health monitoring, and AI‑driven innovation. In France, the secondary use of health data has traditionally been a fragmented process, constrained by divergent consent models, siloed databases, and complex administrative pathways.

Since 2016, Galeon has co‑created an intelligent electronic health record (EHR) with frontline clinicians, now deployed in 19 hospitals (including two university hospitals) and covering more than 3 million patient dossiers. The platform’s decentralized Swarm Learning® architecture ensures that AI models are trained across institutions without moving any raw data, preserving both privacy and data sovereignty.

As the European Health Data Space (EHDS) comes into force, hospitals must reassess how they enable secondary use while respecting patient rights. “Compliance is no longer a checklist; it is a strategic lever for research excellence,” notes Dr. Claire Martin, Chief Data Officer at a leading University Hospital (citable).

This pillar article explains the legal landscape, the practical routes to data access, the impact of EHDS, and the concrete steps a French hospital must take to guarantee quality, traceability, and patient‑centred consent.

What is the difference between primary and secondary use of health data?

Primary use refers to data collected and processed for the direct care of the patient, whereas secondary use involves re‑using that same data for research, public‑health surveillance, or AI development.

Primary use is governed by the physician‑patient relationship and immediate therapeutic needs. Secondary use relies on broader lawful bases – public interest, scientific research, or consent – and must respect stricter de‑identification and governance rules.

Key distinctions for CIOs

Data purpose: Primary = treatment; Secondary = research/innovation.
Legal basis: Primary = contractual/consent for care; Secondary = consent, public‑interest, or scientific research exceptions (CNIL, 2024).
Governance: Primary data stays inside the EHR; secondary data may be exported under strict audit trails.

Key distinctions for Medical Directors

Medical directors must ensure that any secondary use aligns with ethical standards and that patients’ opt‑out choices are respected throughout the research lifecycle.

How can researchers access health data in France today?

Researchers can access French health data through three main channels: the Health Data Hub, the SNDS (Système National des Données de Santé), and direct hospital DPI agreements.

The Health Data Hub acts as the national gateway, offering a catalog of datasets and a single‑step application for research projects. The SNDS aggregates claims, hospital discharge, and mortality data for epidemiological studies, accessible after a rigorous validation process (ANSM, 2023).

When data reside within a hospital’s DPI, researchers negotiate a Data Transfer Agreement (DTA) that details anonymisation methods, purpose, and security measures. This pathway remains essential for granular clinical data not covered by national repositories.

Practical checklist for access

  • Identify the dataset: national (Health Data Hub, SNDS) vs local (hospital DPI).
  • Secure ethical approval: Institutional Review Board (IRB) or Comité de Protection des Personnes.
  • Define lawful basis: consent, public interest, or scientific research exemption.
  • Sign a DTA: include anonymisation, retention, and audit clauses.
  • Document the pipeline: traceability logs must be stored for at least 10 years (CNIL, 2024).

What does the European Health Data Space (EHDS) change for secondary use?

The EHDS, effective from 2025, creates a unified European framework that standardises data formats, consent templates, and cross‑border data sharing procedures.

In France, the EHDS complements existing national mechanisms by:

  • Introducing a common data catalogue: all public health datasets must be listed in the European portal, improving discoverability.
  • Standardising consent: a digital “secondary‑use consent module” can be embedded directly into the patient’s EHR, enabling real‑time opt‑in/opt‑out recording.
  • Facilitating cross‑border projects: researchers can request data from other EU Member States through a single application, reducing administrative overhead.

However, national authorities retain enforcement power. French hospitals must still comply with the CNIL guidelines and ensure that any EHDS‑linked data export respects national data‑security certifications such as HDS (Hébergement de Données de Santé) 2024.

How does the right of opposition work and how is it recorded in the patient record?

Under French law, every patient can exercise an “opposition right” (droit d’opposition) to refuse secondary use of their health data. This right is independent of the consent given for primary care.

The opposition must be captured in the patient’s EHR as a structured flag. In Galeon’s intelligent DPI, the flag is an immutable audit entry that triggers automatic exclusion of the patient’s data from any export pipeline.

Implementation steps

  • Capture at point of care: clinicians offer a clear opt‑out form during the admission process.
  • Store as a coded element: e.g., SNOMED CT code 736271009 (Opposition to secondary use).
  • Audit trail: any data request query automatically checks the flag and logs the decision.
  • Update mechanism: patients can modify their preference via patient portals; changes are versioned.

Failure to honour an opposition can result in a CNIL sanction of up to €300,000 per breach (CNIL, 2024).

What must a hospital prepare in terms of quality and traceability for secondary use?

Hospitals need robust data‑quality pipelines and complete traceability logs to satisfy both legal auditors and research partners.

Key preparations include:

  • Data standardisation: map local codes to international terminologies (ICD‑10‑CM, LOINC, SNOMED CT).
  • Anonymisation workflow: apply pseudonymisation techniques validated by the CNIL, followed by a statistical disclosure control step.
  • Metadata enrichment: capture provenance (origin, timestamp, transformation) for every data element.
  • Audit logging: each export request generates a signed log entry stored in an immutable ledger (e.g., blockchain‑based audit).
  • Quality metrics: completeness, consistency, and accuracy scores must be documented; a threshold of 95 % completeness is commonly required for epidemiological studies (EUR‑Lex, 2023).

Galeon’s Swarm Learning® platform already embeds many of these controls, allowing hospitals to export AI‑ready datasets while keeping raw data on‑premise.

How do CIOs and medical directors evaluate secondary data projects?

CIOs focus on technical feasibility, security compliance, and cost‑benefit analysis. Medical directors assess clinical relevance, ethical compliance, and patient impact.

A joint evaluation matrix often includes:

  • Data relevance to the research question.
  • Compliance with GDPR, CNIL, and HDS certification (see our guide on HDS certification).
  • Resource allocation for data extraction and anonymisation.
  • Potential for knowledge translation back to clinical practice.
CriterionTraditional ApproachGaleon Approach
Data Governance ModelCentralised, siloed repositories with manual consent tracking.Decentralised Swarm Learning, real‑time consent flags in the EHR.
Consent ManagementPaper forms, batch updates.Digital opt‑in/opt‑out module linked to each record.
Data AnonymisationPost‑export de‑identification, high re‑identification risk.Built‑in pseudonymisation pipeline with audit logs.
TraceabilityLimited logs, often external to the DPI.Immutable ledger of all data accesses and transformations.
Scalability for AI TrainingRequires data export to central servers.Federated Swarm Learning keeps data on‑premise.
Regulatory ComplianceManual checks, prone to errors.Automated compliance checks against GDPR, CNIL, HDS.
Patient TrustOpaque processes, low transparency.Patient portal shows real‑time data usage status.
Implementation CostHigh upfront for separate data warehouses.Incremental integration into existing EHR, lower total cost of ownership.

Limits and challenges to be aware of

  • Legal heterogeneity: While EHDS harmonises many aspects, national variations (e.g., French CNIL guidelines) still dictate specific consent and data‑security requirements.
  • Data quality variability: Inconsistent coding practices across departments can hamper anonymisation and AI model performance.
  • Resource constraints: Setting up robust traceability and audit systems demands skilled staff and budget, especially for smaller hospitals.
  • Patient awareness: Effective opt‑out rates depend on clear communication; low awareness can lead to inadvertent data use violations.
  • Technology integration risk: Deploying federated learning (Swarm Learning®) requires compatible infrastructure and interoperability standards.

FAQ

Can I use health data without patient consent?
Yes, if the processing falls under the “public interest” or “scientific research” legal bases defined by the CNIL, but strict safeguards and ethical approval are mandatory.

What is the role of the Health Data Hub?
The Hub is the national gateway that catalogues datasets, standardises request forms, and verifies compliance before granting access.

How long must audit logs be retained?
CNIL requires retention for at least ten years for research‑related data processing, and longer if linked to clinical trials.

Is Swarm Learning® compliant with GDPR?
Swarm Learning processes data locally and shares only model parameters, which means personal data never leaves the hospital, aligning with GDPR data minimisation principles.

What happens if a patient changes their opposition decision?
The updated flag is versioned in the EHR; any pending export requests are automatically halted, and previously exported anonymised datasets remain lawful if they complied at the time of release.

Do I need an HDS‑certified provider for secondary‑use pipelines?
Yes, any external service handling health data must hold an HDS 2024 certification, ensuring ISO 27001:2022‑aligned security controls.

Where can I find best‑practice guidelines for data quality?
See our article on Predictive Medicine & Data Quality for a detailed framework.

In summary

Secondary use of health data is a powerful lever for research and AI innovation, but it rests on a solid foundation of consent management, legal compliance, and traceability. France’s existing pathways – the Health Data Hub, SNDS, and direct hospital DPI agreements – are being reshaped by the European Health Data Space, which introduces common standards while respecting national sovereignty. Hospitals must implement structured opposition flags, rigorous anonymisation pipelines, and immutable audit logs to meet CNIL and HDS requirements. Galeon’s intelligent DPI, built with clinicians since 2016 and deployed across 19 hospitals, offers a federated Swarm Learning framework that keeps data on‑premise, automates consent capture, and provides transparent traceability, positioning hospitals to unlock research value without compromising patient trust.

Want to know more about our smart EHR ?

Book a demo
Discover how a smart EHR can accelerate secondary data projects while safeguarding consent.

Sources

Ils nous font confiance