An EHDS-Compliant Health Data Pipeline Combining LLM/MCP-Mediated Parameter Derivation with Privacy Enhancing Technologies
Authors/Creators
Description
The European Health Data Space (EHDS), established by Regulation (EU) 2025/327, mandates support for secondary use of health data under a data permit regime while enforcing strict data minimisation and privacy obligations. Meeting these obligations requires careful architectural separation between primary care operations and secondary-use data pathways — a challenge that becomes particularly acute when synthetic data are used to ground secondary-use analytics without exposing individual records. This paper presents the secondary-use architecture of a National Health Registry (NHR) prototype developed under the EU-funded CONSENTIS project, which separates primary and secondary domains at the database and service layers, proposes an LLM/MCP-mediated calibration pipeline in which an internally hosted large language model derives synthetic population parameters through aggregate-only queries via a Model Context Protocol (MCP) server, and integrates Differential Privacy at the calibration boundary to provide formal, composable guarantees against residual inference risks. The result is a layered privacy-by design architecture combining structural domain separation, bounded aggregate access, and formal privacy guarantees — offering a replicable pattern for EHDS-compliant secondary use in national health registry systems.
Files
An EHDS-Compliant Health Data Pipeline.pdf
Files
(366.4 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:ab3c76ec9b39f4f4361089c9efff673c
|
366.4 kB | Preview Download |