Does stricter health data regulation mean less research?
Health data regulation exists to protect patients, and patients also benefit from research. Early evidence shows that stricter rules, as currently implemented, can shrink research instead of enabling it.
What the evidence shows
Finland was the first country to fully implement secondary-use rules for health data. In 2023, approved research permits fell an estimated 47% below projected levels. In the United States, registry studies under HIPAA recorded steep declines in patient follow-up and recruitment.
The mechanism is not the law alone; it is the culture the law creates. HIPAA’s architecture produced a compliance culture that systematically “errs on the side of caution”, with institutions placing blanket restrictions on data sharing that go well beyond what the law requires. After each breach, the dominant response is to tighten access controls further, which compounds the research access problem without addressing its structural causes.
The false trade-off
Protect patients or enable research: the choice only looks forced. The trade-off exists when consent is treated as an obstacle to route around, through de-identification, administrative authorisation, or blanket institutional permissions. Each workaround erodes protection, access, or both.
The European Health Data Space takes the administrative route for secondary use, moving much of it away from individual consent toward authorisation by Health Data Access Bodies. It may succeed, but the Finnish experience urges caution: moving decisions away from patients does not automatically produce more research.
The consent-based way out
There is a configuration where protection and research reinforce each other: data that is consented from the moment of collection. When each person holds their own record and grants explicit, revocable, purpose-specific access, researchers receive data that is research-grade because it is consented; nothing needs to be stripped, and no blanket institutional caution is needed, because the authorisation is individual and auditable.
Health Data Safe is built on this bet: a neutral Swiss non-profit foundation acts as Data Controller, so clinics and researchers inherit the consent, audit and compliance machinery instead of building it alone.
Related reading: GDPR, EHDS, nLPD explained and the women’s health data gap.