Does stricter health data regulation mean less research?
Health data regulation exists to protect patients, and patients also benefit from research. Early evidence shows that stricter rules, as currently implemented, can shrink research instead of enabling it.
What the evidence shows
Finland was the first European country to adopt a dedicated law on the secondary use of health and social data, in force since May 2019, with a single permit authority, Findata. In 2023, new data permits for registry-based research were an estimated 47% below the number expected from the pre-2020 trend. In the United States, a cardiac registry saw consent to follow-up fall from 96% to 34% after the HIPAA Privacy Rule took effect, and other studies reported recruitment drops of a similar scale.
The mechanism is not the law alone; it is the culture the law creates. HIPAA’s architecture produced a compliance culture marked by what the Institute of Medicine called “overly conservative interpretations” of the Privacy Rule, with institutions imposing restrictions on data sharing that go beyond what the rule requires. After each breach, the dominant response is to tighten access controls further, which compounds the research access problem without addressing its structural causes.
The false trade-off
Protect patients or enable research: the choice only looks forced. The trade-off exists when consent is treated as an obstacle to route around, through de-identification, administrative authorisation, or blanket institutional permissions. Each workaround erodes protection, access, or both.
The European Health Data Space takes the administrative route for secondary use, moving much of it away from individual consent toward authorisation by Health Data Access Bodies, with an opt-out right for individuals in place of a consent. It may succeed, but the Finnish experience urges caution: moving decisions away from patients does not automatically produce more research.
The consent-based way out
There is a configuration where protection and research reinforce each other: data that is consented from the moment of collection. When each person holds their own record and grants explicit, revocable, purpose-specific access, researchers receive data that is research-grade because it is consented; nothing needs to be stripped, and no blanket institutional caution is needed, because the authorisation is individual and auditable.
Health Data Safe is built on this bet: a neutral Swiss non-profit foundation acts as Data Controller, so clinics and researchers inherit the consent, audit and compliance machinery instead of building it alone.
Related reading: GDPR, EHDS, nLPD explained and the women’s health data gap.
Sources
- Finland, Act on the Secondary Use of Health and Social Data (552/2019), in force 1 May 2019. Finlex
- Brück O, Sanmark E, Ponkilainen V, et al. (2024). European health regulations reduce registry-based research. Health Research Policy and Systems 22: 135. doi:10.1186/s12961-024-01228-1
- Armstrong D, Kline-Rogers E, Jani SM, et al. (2005). Potential impact of the HIPAA privacy rule on data collection in a registry of patients with acute coronary syndrome. Archives of Internal Medicine 165(10): 1125–1129. doi:10.1001/archinte.165.10.1125
- Nass SJ, Levit LA, Gostin LO (eds), Institute of Medicine (2009). Beyond the HIPAA Privacy Rule: Enhancing Privacy, Improving Health Through Research, chapter 5. National Academies Press. ncbi.nlm.nih.gov
- Regulation (EU) 2025/327 on the European Health Data Space, Articles 53, 55, 68 and 71. EUR-Lex, English and French.