Article 44
Handling of risks posed by EHR systems and of serious incidents
In short: defines the responsibilities of the surveillance authority when it comes to risks to persons.
- Where a market surveillance authority of one Member State has reason to believe that an EHR system poses a risk to the health,
safety or rights of natural persons or to the protection of personal data, that market surveillance authority shall carry out an
evaluation in relation to the EHR system concerned covering all relevant requirements laid down in this Regulation. The manufacturer,
the manufacturer's authorised representative and all other relevant economic operators shall cooperate as necessary with the market
surveillance authority for that purpose and take all appropriate measures to ensure that the EHR system concerned no longer
poses that risk when placed on the market or to recall or withdraw the EHR system from the market within a reasonable period.
- Where the market surveillance authorities of a Member State consider that the non-compliance of the EHR system is not limited to
their national territory, they shall inform the Commission and the other Member States' market surveillance authorities of
the results of the evaluation referred to in paragraph 1 of this Article and of the corrective action which they have required
the economic operator to take pursuant to Article 16(2) of Regulation (EU) 2019/1020.
- Where a market surveillance authority finds that an EHR system has caused harm to the health or safety of natural persons
or to certain aspects of public interest protection, the manufacturer shall immediately provide information and documentation,
as applicable, to the affected natural person or user and, where applicable, other third parties affected by that harm,
without prejudice to data protection rules.
- The economic operator concerned referred to in paragraph 1 shall ensure that corrective action is taken in respect of
all the EHR systems concerned that it has placed on the market throughout the Union.
- The market surveillance authority shall without undue delay inform the Commission and the market surveillance authorities,
or, if applicable, the supervisory authorities under Regulation (EU) 2016/679 [GDPR], of other Member States of the corrective action
referred to in paragraph 2. That information shall include all available details, in particular the data necessary for the
identification of the EHR system concerned, the origin and the supply chain of the EHR system, the nature of the risk involved
and the nature and duration of the national measures taken.
- Where a finding of a market surveillance authority, or a serious incident it is informed of, concerns personal data protection,
that market surveillance authority shall without undue delay inform the relevant supervisory authorities under Regulation (EU) 2016/679 [GDPR]
and cooperate with them.
- Manufacturers of EHR systems placed on the market or put into service shall report any serious incident involving an EHR system to
the market surveillance authorities of the Member States where such serious incident occurred and of the Member States where such EHR
systems are placed on the market or put into service. That reporting shall also include a description of the corrective action taken
or envisaged by the manufacturer. Member States may provide for users of EHR systems placed on the market or put into service to be
able to report such incidents.
The reporting required pursuant to the first subparagraph of this paragraph shall be carried out, without prejudice to incident
notification requirements under Directive (EU) 2022/2555 [Cybersecurity], immediately after the manufacturer has established a causal link
between the EHR system and the serious incident or the reasonable likelihood of such a link and, in any event, not later than
three days after the manufacturer becomes aware of the serious incident involving the EHR system.
- The market surveillance authorities referred to in paragraph 7 shall inform the other market surveillance authorities, without delay,
of the serious incident and the corrective action taken or envisaged by the manufacturer or required of it to minimise the risk of
recurrence of the serious incident.
- Where its tasks are not performed by the digital health authority, the market surveillance authority shall cooperate with the
digital health authority. The market surveillance authority shall inform the digital health authority of any serious incidents,
of EHR systems presenting a risk, including risks related to interoperability, security and patient safety, of any corrective
action and of any recall or withdrawal of such EHR systems.
- In the event of incidents putting at risk patient safety or information security, the market surveillance authorities may take
immediate action and require the manufacturer of the EHR system concerned, its authorised representative and other economic operators,
if applicable, to take immediate corrective action.
Discussion
Feedback
Please e-mail
ehds@ringholm.com should the information on this page be incorrect or incomplete; we welcome your suggestions to improve its content.
About Ringholm bv
Ringholm bv is a group of European experts in the field of messaging standards and systems integration in healthcare IT.
We provide the industry's most advanced training courses and consulting on healthcare information exchange standards.