Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Technical documentation readiness

Article 37 of the EHDS regulation requires a manufacturer to draw up technical documentation before an EHR system is placed on the market or put into service, and to keep it up to date. Article 37(2) says it must contain at least the elements of Annex III.

This page is not that documentation. It is a map of what FerroEHR can already supply for each element and what does not exist, so the gap is visible rather than discovered when someone needs the file.

Warning

No technical documentation has been drawn up, and no EU declaration of conformity exists. A “Shipped” row below means the material an element asks for is published and can be cited — not that the element has been written.

Regulation (EU) 2025/327 of the European Parliament and of the Council of 11 February 2025 on the European Health Data Space and amending Directive 2011/24/EU and Regulation (EU) 2024/2847 — OJ L series, 2025/327, 5.3.2025. Read on 2026-09-10; the regulation governs and the summaries here are this project’s paraphrase.

Annex III, element by element

1. A detailed description of the EHR system

#ElementStateMaterialNotes
1(a)Intended purpose, date and version.MissingThe version and release date are published per release; the intended purpose is a manufacturer’s statement that does not exist.
1(b)The categories of personal electronic health data it processes.Partialwhat existsThe storage model is documented and the pseudonymisation domains are separated, but a mapping onto the Annex I priority categories is not written.
1(c)How it interacts with hardware or software that is not part of it.Availablewhat exists
1(d)Versions of relevant software or firmware, and update requirements.Availablewhat exists
1(e)Every form in which it is placed on the market or put into service.Availablewhat exists
1(f)The hardware it is intended to run on.Partialwhat existsThe measured deployment classes state an environment envelope; a minimum hardware specification as such is not published.
1(g)The system architecture, and how the components integrate.Availablewhat exists
1(h)Technical specifications, variants, configurations.Availablewhat exists
1(i)A description of every change through the lifecycle.Availablewhat exists
1(j)Instructions for use and, where applicable, for installation.Availablewhat exists

2. The system in place to evaluate the EHR system’s performance

#ElementStateMaterialNotes
2Where applicable, how performance is evaluated.Availablewhat existsPerformance is measured by an independent instrument in open-loop, coordinated-omission-free runs, and the records are committed.

3. References to the common specifications used

#ElementStateMaterialNotes
3Common specifications under Article 36 against which conformity is declared.MissingThe implementing acts that set the common specifications have not been adopted. Nothing can reference them yet.

4. Verification and validation results

#ElementStateMaterialNotes
4Results and critical analyses of the tests demonstrating conformity.Partialwhat existsThe openEHR conformance record is complete and committed. It demonstrates conformity to the openEHR specifications, which is a different claim from conformity to Annex II; the European digital testing environment of Article 40 does not exist yet.

5. A copy of the information sheet

#ElementStateMaterialNotes
5The information sheet required by Article 38.MissingNo information sheet has been drawn up.

6. A copy of the EU declaration of conformity

#ElementStateMaterialNotes
6The declaration required by Article 39.MissingNo declaration exists, and none can be made before the common specifications are adopted and the manufacturer is identified.

Test evidence

Element 4 asks for the results of the verification and validation tests. What exists is the openEHR conformance record: an independent instrument’s runs against a composed deployment, with the results, verdicts and the statement committed under docs/conformance/ and published on the conformance pages.

Read what that record does and does not say. It demonstrates conformity to the openEHR specifications. Conformity to Annex II is a different claim against a different yardstick, and the European digital testing environment of Article 40 — whose results Article 37(2) also requires a reference to — does not exist yet.

Risk analysis

Annex III does not name a risk analysis as a separate element, but element 1 asks for a description of the system architecture and element 2 for the system in place to evaluate performance. The material FerroEHR publishes for both is the architecture chapter and the security chapter, with the pseudonymisation boundary and its data flows documented as they land.

Declaration of conformity

Article 39 requires an EU declaration of conformity stating that the essential requirements of Annex II are met, and Annex IV sets out what it contains. No declaration exists, and none can be drawn up yet: the common specifications of Article 36 have not been adopted, so there is nothing to declare conformity against, and the manufacturer of a given deployment has not been identified — see the open questions on the readiness page.

When those two are settled, the declaration is drawn up by the manufacturer of the deployment, not by this project on their behalf.