eIDAS 2 Industries

eIDAS 2 for Healthcare

What Providers, Insurers and Health Authorities Need to Know

Tamino BaumannUpdated August 24, 2026

Wallet acceptance deadlines, identifying patients and clinicians, and how it connects to the European Health Data Space and the digital EHIC.

Healthcare has two identity problems: patients need to prove who they are, and clinicians need to prove they are clinicians. eIDAS 2 requires healthcare organisations to accept the EUDI Wallet — public providers by the end of 2026, private ones a year later. With 2029, the European Health Data Space starts applying, and it will need an identity layer that eIDAS 2 provides. This guide explains the core eIDAS 2 obligations, how they intersect with the European Health Data Space, and how healthcare organisations can prepare for both.


What eIDAS 2 changes for healthcare

  1. Wallet acceptance, on two deadlines. Public hospitals, national health services and public insurers require wallet acceptance by the end of 2026. Private providers have until the end of 2027.
  2. Patients can be identified to a much higher standard. The identity credential in every certified EUDI wallet will be verified at the EU's strictest assurance level, which is what makes it the ideal authentication tool for remote access to health records.
  3. Clinicians can prove their professional status digitally. A doctor, nurse or pharmacist can present verifiable proof of who they are and what they are licensed to do — including to a system in another Member State.
  4. Coverage can be verified in seconds. A digital European Health Insurance Card in a patient's wallet confirms entitlement in seconds.

The timeline:

DateMilestoneRelevance for healthcare
20 May 2024eIDAS 2 enters into forceLegal framework for the wallet established
26 March 2025European Health Data Space enters into forceTransition period begins
End of 2026Member States must provide wallets — and public bodies must accept themThe deadline for public healthcare providers which are also public bodies
26 March 2027EHDS; deadline for the Commission's key implementing actsObligations are further defined.
End of 2027Acceptance deadline for private relying partiesThe deadline for private healthcare providers
March 2029Patient summaries, ePrescriptions and eDispensations mandatory EU-wideFirst data categories go live
March 2031Medical images, laboratory results and discharge reportsSecond data categories go live

The two deadlines

A public hospital, national health service, or public health insurer that qualifies as a public sector body must accept EUDI Wallets by the end of 2026, when they are expected to become available. Private clinics, private insurers, and commercial digital health providers have until the end of 2027.

These requirements apply only where the provider already uses an eID solution for authentication or is legally required to use strong user authentication.

Alongside the EUDI Wallet requirements, the European Health Data Space (EHDS) introduces additional obligations. As the EHDS takes effect, patients will gain the right to access and download their health records, correct them, transfer them to another provider, restrict professional access, and receive notifications when their data is accessed.

Exercising these rights requires providers to verify the identity of the person making the request. From 2029, patient summaries and ePrescriptions must also work across all Member States. This requires providers to verify that the professional requesting the information is an authorised clinician.

For both patient and clinician authentication, the EUDI Wallet offers a strong solution.


The roles healthcare organisations play

RoleWhat it meansObligation
Verifier (relying party)Identify patients; verify cliniciansMandatory, by end of 2026 or end of 2027
IssuerIssue professional attestations, coverage confirmations and insurance entitlements into walletsOptional
Wallet providerOffer a certified walletOptional

Who does what, concretely:

  • A hospital or provider group verifies patients and it verifies clinicians.
  • A health authority or professional body is the natural issuer of professional attestations — the credential that says this person is a licensed physician.
  • A health insurer is the issuer of coverage and EHIC attestations.
  • An EHR or hospital information system vendor builds verification into a product used by many providers, and carries its own EHDS conformity obligations from 2029.

National eHealth authorities can find more on the issuing side in the public sector guide.


Core healthcare use cases at a glance

Use caseWhat the EUDI Wallet enables
Patient identificationPatients identified for portals or record access
Clinician identityClinicians prove identity and professional status, including across borders
Cross-border care and the EHICCoverage confirmation
Portals and telemedicineWallet accepted for login to digital health services

Identifying patients

Giving patients remote access to health data should be both secure and easy. In practice, healthcare providers have faced a difficult trade-off: simple login methods may not adequately protect sensitive health data, while stronger authentication can create barriers for patients with limited digital skills.

The EUDI Wallet provides another option. Patients can prove their identity using a trusted credential issued by their Member State, without creating a new account or managing another password or hardware token for every provider.

The healthcare organisation receives reliable identity information, while the patient gets a simpler and more consistent way to access services.


Identifying clinicians

For a clinician to access a patient’s records, especially across borders, the system needs to know who they are, whether they are currently licensed, and their professional role or specialty. Today, that information is largely held in national systems, making it difficult for providers in another country to verify.

A professional attestation makes that information portable. A health authority or professional body issues a credential confirming the clinician’s identity and current professional status. The clinician presents it, and a provider in another Member State can verify it against the issuing authority and apply its own access rules, without a direct integration or manual qualification check.


Cross-border care and the digital EHIC

Around 242 million people in Europe hold a European Health Insurance Card. It is a plastic card that a provider abroad cannot verify in real time — so treatment happens, billing happens, and entitlement gets sorted out afterwards through a slow reimbursement process that absorbs a certain amount of error and fraud.

The Commission has worked through what this looks like with a wallet. A patient falls ill in another Member State and visits a clinic. Reception displays a QR code, the patient scans it with their wallet, the wallet checks the provider's identity and asks the patient to consent, and then transmits the insurance and identity data. The provider has verified entitlement before treatment rather than after it.

Issuing EHICs into wallets is not currently mandated by EU law — nor prohibited. However, some technical groundwork is done: the EU's DC4EU pilot built the EHIC attestation using the SD-JWT VC credential format, extending the existing issuance and verification processes with proper revocation support. A legislative proposal for a European Social Security Pass, which would digitalise EHICs and other social security entitlement documents, is expected as part of the Commission's Fair Labour Mobility Package.

For insurers, this is the clearest issuance opportunity in healthcare. For providers, it is the verification.


Portals, telemedicine and what EUDI wallet acceptance involves

The EUDI wallet acceptance requirement applies wherever a healthcare organisation already asks people to identify themselves electronically — patient portals, appointment booking, telemedicine platforms, digital therapeutics.

Four things are involved:

  • Register as a relying party with the national registrar, and declare which data each service will request. Wallets check requests against this registration.
  • Support the standard protocols and formats. Credentials are presented over OID4VP, in the mandated formats, principally SD-JWT VC.
  • Validate what comes back. Check the signature, check the credential is still valid, and check it belongs to the person presenting it.
  • Keep the alternatives. Patients who do not use a wallet must still be able to access care and their records.

Build vs buy: how to build a compliant solution

Whether acting as verifier, issuer, or both, a healthcare organisation faces the same decision as every other organisation in the ecosystem: how much of the solution to build, and how much to buy. The clinical and patient-facing applications — the portal, the EHR interface, the telemedicine platform — are where an organisation differentiates and will always be built in-house or with existing partners. The identity layer underneath — credential formats, exchange protocols, trust checks, key management, revocation — is standardised by definition and changes every time the EU specifications evolve. For that layer, there are three possible implementation paths:

  • Build apps, buy infrastructure (recommended) — build only the clinical and patient-facing applications and use a proven, standards-compliant provider for the identity layer. Fastest time to market, lowest regulatory and technical risk.
  • Build apps, own infrastructure — use open-source identity infrastructure to retain full control of the stack, while still avoiding implementing the credential formats, protocols, and trust validation from scratch.
  • Build everything in-house — implement and maintain the full stack internally, and keep it current as the specifications evolve. Viable only for organisations with a dedicated identity engineering team.

The walt.id solution

walt.id covers both of the first two paths. The walt.id Community Stack provides open-source issuer, verifier, and wallet infrastructure for organisations that want to own their stack; the walt.id Enterprise Stack is the enterprise grade offering on top of it — built on open-source technology used by more than +55.000 developers, governments, and businesses. For healthcare specifically:

  • Verifier — accept the EUDI Wallet to identify patients at portals, reception and telemedicine, and to verify clinician identity and professional status for record access, with trust, revocation and wallet-authenticity checks handled automatically and results passed to existing EHR and identity systems.
  • Issuer — issue professional attestations, coverage confirmations and entitlement credentials in all mandated formats (SD-JWT VC, ISO/IEC 18013-5, W3C VC), with revocation built into the issuance workflow.
  • Cross-border by default — the same verification works for patients and clinicians from every Member State, without country-by-country integration.

A role-by-role compliance breakdown is available in the eIDAS 2 Implementers Guide or reach out to our team to learn more.


Frequently asked questions

When do healthcare organisations have to accept the EUDI Wallet?

It depends on whether the organisation is public or private. Health is named in eIDAS 2 (Regulation (EU) 2024/1183) as a sector whose private organisations must accept the EUDI Wallet by the end of 2027. Public hospitals, national health services and public insurers which are public sector bodies and already offer eID solutions for logins today, must accept the wallet as soon as wallets are available which is towards the end of 2026.

Does the EUDI Wallet replace our national health ID system?

No. National systems such as Germany's GesundheitsID or Austria's ELGA continue to operate. The realistic picture is coexistence and progressive interoperability — the wallet as an EU-wide identity and credential layer alongside a national sectoral one, not a replacement for it.

How do clinicians prove they are clinicians?

Through a professional attestation — a credential issued by a health authority or professional body confirming that a named person holds a current licence in a named profession. Any system in any Member State can verify it against the issuing authority, which is what makes cross-border record access practical.

Can we verify insurance coverage from another Member State?

Yes. A digital European Health Insurance Card presented from a patient's wallet confirms entitlement at the point of care rather than through a reimbursement process afterwards. Issuing EHICs into wallets is currently neither mandated nor prohibited by EU law, and the technical work has been done — the EU's DC4EU pilot built the EHIC attestation using the SD-JWT VC format with revocation support.

Do we have to issue credentials, or only accept them?

It depends on the kind of organisation. eIDAS 2 requires acceptance, not issuance. Hospitals are almost purely verifiers. Health authorities and professional bodies are the natural issuers of professional attestations, and insurers of coverage credentials.


Build a compliant eIDAS 2 solution for healthcare

Identify patients and clinicians with the EUDI Wallet, verify coverage across borders, and issue professional and entitlement credentials — with trust, certificate, and revocation management handled for the organisation. EU trusted. Standard & regulatory compliant. Gov & enterprise proven.