Digital repository of Slovenian research organisations

Show document
A+ | A- | Help | SLO | ENG

Title:AI act compliance within the MyHealth@EU framework : tutorial
Authors:ID Simjanoska Misheva, Monika (Author)
ID Shahpaski, Dragan (Author)
ID Dobreva, Jovana (Author)
ID Gams, Matjaž, Institut "Jožef Stefan" (Author), et al.
Files:URL URL - Source URL, visit https://www.jmir.org/2025/1/e81184/
 
.pdf PDF - Presentation file, download (691,23 KB)
MD5: 8F2C2082FA325A693D8D3CB3006B41E1
 
Language:English
Typology:1.01 - Original Scientific Article
Organization:Logo IJS - Jožef Stefan Institute
Abstract:The integration of artificial intelligence (AI) into clinical workflows is advancing even before full compliance with the European Union Cross-Border eHealth Network (MyHealth@EU) framework is achieved. While AI-based clinical decision support systems are automatically classified as high risk under the European Union’s AI Act, cross-border health data exchange must also satisfy MyHealth@EU interoperability requirements. This creates a dual-compliance challenge: vertical safety and ethics controls mandated by the AI Act and horizontal semantic transport requirements enforced through Open National Contact Point (OpenNCP) gateways, many of which are still maturing toward production readiness. This paper provides a practical, phase-oriented tutorial that enables developers and providers to embed AI Act safeguards before approaching MyHealth@EU interoperability tests. The goal is to show how AI-specific metadata can be included in the Health Level Seven International Clinical Document Architecture and Fast Healthcare Interoperability Resources messages without disrupting standard structures, ensuring both compliance and trustworthiness in AI-assisted clinical decisions. We systematically analyzed Regulation (EU) 2024/1689 (AI Act) and the OpenNCP technical specifications, extracting a harmonized set of overlapping obligations. The AI Act provisions on transparency, provenance, and robustness are mapped directly onto MyHealth@EU workflows, identifying the points where outgoing messages must record AI involvement, log provenance, and trigger validation. To operationalize this mapping, we propose a minimal extension set, covering AI contribution status, rationale, risk classification, and Annex IV documentation links, together with a phase-based compliance checklist that aligns AI Act controls with MyHealth@EU conformance steps. A simulated International Patient Summary transmission demonstrates how Clinical Document Architecture/Fast Healthcare Interoperability Resources extensions can annotate AI involvement, how OpenNCP processes such enriched payloads, and how clinicians in another member state view the result with backward compatibility preserved. We expand on security considerations (eg, Open Worldwide Application Security Project generative AI risks such as prompt injection and adversarial inputs), continuous postmarket risk assessment, monitoring, and alignment with MyHealth@EU’s incident aggregation system. Limitations reflect the immaturity of current infrastructures and regulations, with real-world validation pending the rollout of key dependencies. AI-enabled clinical software succeeds only when AI Act safeguards and MyHealth@EU interoperability rules are engineered together from day 0. This tutorial provides developers with a forward-looking blueprint that reduces duplication of effort, streamlines conformance testing, and embeds compliance early. While the concept is still in its early phases of practice, it represents a necessary and worthwhile direction for ensuring that future AI-enabled clinical systems can meet both European Union regulatory requirements from day 1. Risks such as prompt injection and adversarial inputs), continuous postmarket risk assessment, monitoring, and alignment with MyHealth@EU’s incident aggregation system. Limitations reflect the immaturity of current infrastructures and regulations, with real-world validation pending the rollout of key dependencies.
Keywords:e-health, epidemiological modeling
Geographic coverage:Evropa;
Publication status:Published
Publication version:Version of Record
Publication date:10.11.2025
Publisher:JMIR Publications
Year of publishing:2025
Number of pages:str. 1-17
Numbering:Vol. 27, [article no.] e81184
Source:ZDA
PID:20.500.12556/DiRROS-25021 New window
UDC:004.8
ISSN on article:1438-8871
DOI:10.2196/81184 New window
COBISS.SI-ID:263792387 New window
Copyright:© Monika Simjanoska Misheva, Dragan Shahpaski, Jovana Dobreva, Djansel Bukovec, Blagojche Gjorgjioski, Marjan Nikolov, Dalibor Frtunikj, Petre Lameski, Azir Aliu, Kostadin Mishev, Matjaž Gams.
Note:Nasl. z nasl. zaslona; Soavtor iz Slovenije: Matjaž Gams; Opis vira z dne 7. 1. 2026;
Publication date in DiRROS:07.01.2026
Views:170
Downloads:101
Metadata:XML DC-XML DC-RDF
:
Copy citation
  
Share:Bookmark and Share


Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Record is a part of a journal

Title:Journal of medical internet research
Shortened title:JMIR, J. med. internet res.
Publisher:s. n.
ISSN:1438-8871
COBISS.SI-ID:2406629 New window

Document is financed by a project

Funder:EC - European Commission
Project number:101159214
Name:Bridging Research Institutions to Catalyze Generative AI Adoption by the Health Sector in the Widening Countries
Acronym:ChatMED

Licences

License:CC BY 4.0, Creative Commons Attribution 4.0 International
Link:http://creativecommons.org/licenses/by/4.0/
Description:This is the standard Creative Commons license that gives others maximum freedom to do what they want with the work as long as they credit the author.
Licensing start date:10.11.2025
Applies to:VoR

Secondary language

Language:Slovenian
Title:AI act compliance within the MyHealth@EU framework: tutorial
Keywords:e-zdravje, elektronsko zdravstvo


Back