Technical documentation readiness
Article 37 of the EHDS regulation requires a manufacturer to draw up technical documentation before an EHR system is placed on the market or put into service, and to keep it up to date. Article 37(2) says it must contain at least the elements of Annex III.
This page is not that documentation. It is a map of what FerroEHR can already supply for each element and what does not exist, so the gap is visible rather than discovered when someone needs the file.
Warning
No technical documentation has been drawn up, and no EU declaration of conformity exists. A “Shipped” row below means the material an element asks for is published and can be cited — not that the element has been written.
Regulation (EU) 2025/327 of the European Parliament and of the Council of 11 February 2025 on the European Health Data Space and amending Directive 2011/24/EU and Regulation (EU) 2024/2847 — OJ L series, 2025/327, 5.3.2025. Read on 2026-09-10; the regulation governs and the summaries here are this project’s paraphrase.
Annex III, element by element
1. A detailed description of the EHR system
| # | Element | State | Material | Notes |
|---|---|---|---|---|
| 1(a) | Intended purpose, date and version. | Missing | — | The version and release date are published per release; the intended purpose is a manufacturer’s statement that does not exist. |
| 1(b) | The categories of personal electronic health data it processes. | Partial | what exists | The storage model is documented and the pseudonymisation domains are separated, but a mapping onto the Annex I priority categories is not written. |
| 1(c) | How it interacts with hardware or software that is not part of it. | Available | what exists | — |
| 1(d) | Versions of relevant software or firmware, and update requirements. | Available | what exists | — |
| 1(e) | Every form in which it is placed on the market or put into service. | Available | what exists | — |
| 1(f) | The hardware it is intended to run on. | Partial | what exists | The measured deployment classes state an environment envelope; a minimum hardware specification as such is not published. |
| 1(g) | The system architecture, and how the components integrate. | Available | what exists | — |
| 1(h) | Technical specifications, variants, configurations. | Available | what exists | — |
| 1(i) | A description of every change through the lifecycle. | Available | what exists | — |
| 1(j) | Instructions for use and, where applicable, for installation. | Available | what exists | — |
2. The system in place to evaluate the EHR system’s performance
| # | Element | State | Material | Notes |
|---|---|---|---|---|
| 2 | Where applicable, how performance is evaluated. | Available | what exists | Performance is measured by an independent instrument in open-loop, coordinated-omission-free runs, and the records are committed. |
3. References to the common specifications used
| # | Element | State | Material | Notes |
|---|---|---|---|---|
| 3 | Common specifications under Article 36 against which conformity is declared. | Missing | — | The implementing acts that set the common specifications have not been adopted. Nothing can reference them yet. |
4. Verification and validation results
| # | Element | State | Material | Notes |
|---|---|---|---|---|
| 4 | Results and critical analyses of the tests demonstrating conformity. | Partial | what exists | The openEHR conformance record is complete and committed. It demonstrates conformity to the openEHR specifications, which is a different claim from conformity to Annex II; the European digital testing environment of Article 40 does not exist yet. |
5. A copy of the information sheet
| # | Element | State | Material | Notes |
|---|---|---|---|---|
| 5 | The information sheet required by Article 38. | Missing | — | No information sheet has been drawn up. |
6. A copy of the EU declaration of conformity
| # | Element | State | Material | Notes |
|---|---|---|---|---|
| 6 | The declaration required by Article 39. | Missing | — | No declaration exists, and none can be made before the common specifications are adopted and the manufacturer is identified. |
Test evidence
Element 4 asks for the results of the verification and validation tests. What
exists is the openEHR conformance record: an independent instrument’s runs
against a composed deployment, with the results, verdicts and the statement
committed under docs/conformance/ and published on the
conformance pages.
Read what that record does and does not say. It demonstrates conformity to the openEHR specifications. Conformity to Annex II is a different claim against a different yardstick, and the European digital testing environment of Article 40 — whose results Article 37(2) also requires a reference to — does not exist yet.
Risk analysis
Annex III does not name a risk analysis as a separate element, but element 1 asks for a description of the system architecture and element 2 for the system in place to evaluate performance. The material FerroEHR publishes for both is the architecture chapter and the security chapter, with the pseudonymisation boundary and its data flows documented as they land.
Declaration of conformity
Article 39 requires an EU declaration of conformity stating that the essential requirements of Annex II are met, and Annex IV sets out what it contains. No declaration exists, and none can be drawn up yet: the common specifications of Article 36 have not been adopted, so there is nothing to declare conformity against, and the manufacturer of a given deployment has not been identified — see the open questions on the readiness page.
When those two are settled, the declaration is drawn up by the manufacturer of the deployment, not by this project on their behalf.
Related
- EHDS readiness — status per Annex II requirement.
- Shared responsibility — which duties belong to the deployment.