AdAdvertisement
← Back to News

The Data Act puts device data in the hands of hospitals

J

By João L. Carapinha

September 16, 2026

Big data analysis
Data Act access by design

On 12 September 2026, the last major product-side obligation of the EU Data Act took effect: the Data Act access by design rule. New connected products and related services placed on the Union market after that date must be designed so that users can reach the data those products generate by default, easily, securely, free of charge, in a structured machine-readable format, and, where relevant and technically feasible, directly.

That obligation sits in Article 3(1) of Regulation (EU) 2023/2854. Two days later, Digital Inside translated the change into hospital terms. The persistent problem in health digitalisation, it argued, is less about whether records interoperate than about who controls the data a device produces once it is inside the hospital. From 12 September the answer is no longer “ask the manufacturer and wait.” For new equipment, the architecture itself must let the user, including a hospital that owns or leases the device, retrieve the relevant data.

Vendor lock-in does not disappear. Hardware, clinical-system integration, certification, maintenance contracts and proprietary algorithms still bind buyers. What changes is that data control stops being a secondary clause. For CIOs and purchasing departments, the ability to extract device data and use it outside the original vendor stack now sits alongside price, uptime and cybersecurity as a first-order specification.

Why 12 September 2026 matters

The Data Act did not come into force on 12 September 2026. That happened on 11 January 2024. Most user rights already applied from 12 September 2025: access on request (Article 4), sharing with a third party chosen by the user (Article 5), and pre-contract information about data types, volumes, storage and retrieval (Article 3(2) and 3(3)).

What began on 12 September 2026 is different in kind. Article 50 states that the Article 3(1) obligation applies to connected products and related services placed on the market after that date. The law moves from a request-and-respond model to a design model. The product must carry the access path in its architecture: an interface, an application, an API, on-device retrieval, or another adequate technical mechanism.

Date What became binding Meaning for hospitals
11 January 2024 Entry into force The Regulation exists in the Official Journal. Design work for 2026 products should already have started.
12 September 2025 General application: Articles 4 and 5 access on request, pre-contract transparency, B2B FRAND sharing, public-sector exceptional-need access, cloud switching Hospitals could already demand usage data from existing connected devices and instruct the data holder to send it to a third party. Access still depended on the holder’s process.
12 September 2026 Article 3(1) access by design for products and related services placed on the market after this date New connected equipment must embed default, usable access. Procurement specifications can require native export, not a promised extract.
12 September 2027 Unfair-terms rules extend to certain long-running pre-2025 contracts Older maintenance and data-use contracts that lock hospitals into one-sided terms become easier to challenge.

Products already on the market before 12 September 2026 do not have to be redesigned for direct access. They remain under the 2025 access-on-request regime. That distinction is the most important procurement filter for the next buying cycle: is this unit a pre-deadline installed base, or a post-deadline product whose architecture must already contain the access path?

The 12-day window

The twelve days around the deadline were quiet as a go-live event and loud as an interpretation event. No Commission press conference marked the date; it had been written into Article 50 back in December 2023. What moved in the window was trade press, national regulators and technology media turning a two-year-old legal sentence into a hospital buying problem.

The date arrived without fanfare, and that is part of the point. Access by design was not a surprise. Manufacturers of connected medical devices have had the date in Article 50 since December 2023 and a 20-month design runway after general application in September 2025. Hospitals that treat 12 September as the start of a conversation are late. Hospitals that treat it as the start of specification language in tenders are on time.

Why this matters for hospitals

Hospitals have spent a decade buying connected equipment that improved bedside function and then trapped the resulting data. Remote-monitoring platforms, smart infusion, cardiac telemetry, connected IVDs and wearable programmes all generate operational and clinical signal. When that signal lives only in the manufacturer’s cloud, the hospital cannot run its own utilisation analytics, feed a multi-vendor command centre, switch maintenance providers without losing history, or reuse the data for quality, research or AI development under its own governance.

Access by design does not solve clinical interoperability on its own. HL7 FHIR, IHE profiles, the European EHR exchange format and, from 2027, the European Health Data Space address record-level health data. The Data Act addresses a prior layer: the device and the related service as sources. Without that layer, EHDS secondary use and hospital-level AI remain dependent on whatever the vendor chooses to expose.

Once access is a design obligation rather than a contractual concession, the hospital can put it in the specification, score it in the tender, and treat its absence in a post-12 September product as non-compliance rather than a commercial disagreement.

There is a cost to note. Adding interfaces, export paths or authentication layers to a certified medical device can be a substantial change under the Medical Devices Regulation or the In Vitro Diagnostic Regulation, and a substantial change can reopen conformity assessment. Manufacturers that waited until 2026 to redesign face both a Data Act problem and an MDR timeline problem. Hospitals should expect some vendors to argue that “technically not feasible” includes “not feasible without a new CE cycle.” That argument should be tested, not accepted at face value, especially for devices whose connectivity already implies retrievable data.

Security and safety are real constraints, not a loophole. Articles 4 and 5 allow access to be restricted where it would undermine security requirements laid down in Union or national law and produce a serious adverse effect on the health, safety or security of people. A manufacturer that invokes this should identify the legal security requirement, the serious-adverse-effect pathway, and the alternative access mode that still meets Article 4. A blanket “cybersecurity, therefore no export” position is not what the Regulation provides.

Devices most exposed

Category Typical product data Why a hospital wants it outside the vendor stack
Smart infusion and medication-delivery pumps Usage cycles, alarm logs, occlusion events, firmware state, connectivity health Independent maintenance, fleet utilisation, medication-safety analytics across brands
Implantable and wearable cardiac devices Telemetry, battery, lead and sensor status, episode logs Multi-vendor clinic workflows, second-opinion platforms, research cohorts
Connected IVDs and point-of-care analysers Run logs, QC, instrument status, result-transmission records Laboratory middleware not owned by the analyser vendor, capacity planning
Remote-monitoring platforms and related apps Device-side measurements, adherence, connectivity, service events Avoiding a second patient app, feeding the hospital EHR and command centre
Imaging and theatre equipment with IoT telemetry Uptime, tube and detector usage, error codes, environmental sensors Independent service, predictive maintenance, multi-site asset management
Ward monitors, ventilators, anaesthesia workstations Operational status, alarm floods, configuration drift, consumable use Unified alarm management, biomedical engineering dashboards

What does not change on 12 September

  • Installed-base devices placed on the market before 12 September 2026 do not have to be retrofitted for direct access. Hospitals still hold Article 4 rights against those data holders.
  • Trade secrets are not abolished. They must generally still be shared under agreed technical and organisational measures; withholding is exceptional and must be substantiated.
  • Patients do not lose GDPR rights, and hospitals do not gain a new GDPR basis.
  • A third party receiving data may not use it to clone the connected product.
  • Related-service lock-in can survive if the service is what makes the device clinically usable and no alternative service can consume the newly available data.
  • Enforcement remains national. There is no single EU Data Act inspectorate walking into hospitals this week.

Bottom line

12 September 2026 matters because it is the date the Data Act stops being only a right to ask and becomes, for new connected equipment, a duty to design. Digital Inside’s contribution, two days later, was to name the hospital consequence in one sentence: the data a device produces after it enters a hospital is no longer a vendor courtesy.

Hospitals that act on that sentence will put data-control language into tenders this autumn, test one extract per strategic vendor, and treat “not in our ecosystem” as a scored defect rather than a fact of life. Hospitals that wait will keep buying post-deadline products as if the architecture obligation did not exist, and will discover the gap only when they try to feed a third-party maintenance tool, a command centre or an AI service with data they already paid to generate.

Sources

  • Regulation (EU) 2023/2854 of 13 December 2023 (Data Act), Articles 2, 3, 4, 5 and 50, and Recital 14.
  • European Commission, “Data Act explained,” digital-strategy.ec.europa.eu (current as of 16 September 2026).
  • Bundesnetzagentur, Data Act background pages on data access and data use (updated through 16 September 2026).
  • Legal analyses on medical and health devices: Taylor Wessing, CMS, White & Case, Bech-Bruun, and Pure Clinical’s FAQ discussion of IoT medical devices.

Let Google know we are your trusted source.

Add our editorial as a preferred source in your search results.

Trust this Source