Published July 7, 2026 | Version v1

An EHDS-Compliant Health Data Pipeline Combining LLM/MCP-Mediated Parameter Derivation with Privacy Enhancing Technologies

  • 1. Nodalpoint Systems
  • 2. ROR icon University of Patras
  • 3. NodalPoint Systems

Description

The European Health Data Space (EHDS), established by Regulation (EU) 2025/327, mandates support for secondary use of health data under a data permit regime while enforcing strict data minimisation and privacy obligations. Meeting these obligations requires careful architectural separation between primary care operations and secondary-use data pathways — a challenge that becomes particularly acute when synthetic data are used to ground secondary-use analytics without exposing individual records. This paper presents the secondary-use architecture of a National Health Registry (NHR) prototype developed under the EU-funded CONSENTIS project, which separates primary and secondary domains at the database and service layers, proposes an LLM/MCP-mediated calibration pipeline in which an internally hosted large language model derives synthetic population parameters through aggregate-only queries via a Model Context Protocol (MCP) server, and integrates Differential Privacy at the calibration boundary to provide formal, composable guarantees against residual inference risks. The result is a layered privacy-by design architecture combining structural domain separation, bounded aggregate access, and formal privacy guarantees — offering a replicable pattern for EHDS-compliant secondary use in national health registry systems.

Files

An EHDS-Compliant Health Data Pipeline.pdf

Files (366.4 kB)

Name Size Download all
md5:ab3c76ec9b39f4f4361089c9efff673c
366.4 kB Preview Download

Additional details

Funding

European Commission
CONSENTIS - IDENTITY AND CONSENT MANAGEMENT FOR EU DIGITAL AND DATA STRATEGIES 101168011