Library
PubMed Central Open Access
research article
Professional
Open access

Smarter rules for digital health: How the digital omnibus can simplify without sacrificing patient rights

Source: PubMed Central Open Access, NCBI / U.S. National Library of Medicine

Digital HealthLast synced 7/8/2026Status: syncedPMID: 42404599 pmidDOI: 10.1177/20552076261452583

The European Commission’s Digital Omnibus proposal aims to simplify the European Union’s complex digital legislative framework, which includes the GDPR, Data Act, and AI Act. While streamlining regulatory compliance is an attractive objective for healthcare stakeholders, it must not compromise the foundational elements of patient rights, privacy, and data security. This policy-oriented perspective analyzes the proposed amendments and the subsequent European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) Joint Opinion 2/2026. Through a thematic and doctrinal analysis of these regulatory documents, this article examines four critical areas impacting digital health: (1) definitions of personal and pseudonymised data; (2) data processing for scientific research and AI; (3) the balance between data subject rights and administrative burdens; and (4) emergency data access and ePrivacy. We argue that data security is a prerequisite for trustworthy digital health systems, and regulatory simplification must not inadvertently expand the attack surface for health data. We conclude that while the Digital Omnibus offers necessary relief from compliance fatigue, true digital health governance requires a ‘security-by-design’ roadmap. Policymakers must adopt targeted derogations for health data that facilitate EHDS cross-border interoperability and AI innovation, without dismantling the foundational pseudonymisation and transparency safeguards upon which patient t

Abstract

The European Commission’s Digital Omnibus proposal aims to simplify the European Union’s complex digital legislative framework, which includes the GDPR, Data Act, and AI Act. While streamlining regulatory compliance is an attractive objective for healthcare stakeholders, it must not compromise the foundational elements of patient rights, privacy, and data security. This policy-oriented perspective analyzes the proposed amendments and the subsequent European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) Joint Opinion 2/2026. Through a thematic and doctrinal analysis of these regulatory documents, this article examines four critical areas impacting digital health: (1) definitions of personal and pseudonymised data; (2) data processing for scientific research and AI; (3) the balance between data subject rights and administrative burdens; and (4) emergency data access and ePrivacy. We argue that data security is a prerequisite for trustworthy digital health systems, and regulatory simplification must not inadvertently expand the attack surface for health data. We conclude that while the Digital Omnibus offers necessary relief from compliance fatigue, true digital health governance requires a ‘security-by-design’ roadmap. Policymakers must adopt targeted derogations for health data that facilitate EHDS cross-border interoperability and AI innovation, without dismantling the foundational pseudonymisation and transparency safeguards upon which patient trust relies.

Educational only
This information is for general education and is not medical advice. Always talk to a licensed U.S. clinician about your situation, medications, or treatment decisions.