Services · How do we get a data foundation we can trust?

OMOP for research, FHIR for exchange, regulation into the structure.

Health data sits in systems that describe the same thing in different ways. A standard alone does not solve the problem. What matters is how the harmonisation is documented and who maintains it.

When this becomes relevant

  • Several source systems have to be brought into one model for research or analytics.
  • OMOP has been chosen, but the conversion is a script that was run once and that nobody maintains.
  • The interfaces are scattered, and information does not move between systems in structured form.
  • The secondary use reform and EHDS bring requirements whose effect on the platform and the data models has not been assessed.
  • You are developing medical software, and the audit trail of the data has to be demonstrable.

The roles of the standards

OMOP

OMOP is a harmonised data model for research, analytics and secondary use. It is useful when several source systems are brought into one model. OMOP is an agreement about harmonisation, not a translator. The structure comes ready, but every mapping between a source system and a vocabulary is an interpretation that has to be documented and maintained. Vocabulary mappings need version control just as code does.

FHIR

FHIR is a standard for exchanging information and for application interfaces. It is needed when information has to move between systems in operational work. Earlier HL7 standards are still in use in many integrations, and new work is often built alongside them. One way to model structured clinical information is openEHR, and it suits some architectures.

Four contexts of use

Context of useWhat it requires of the data
ResearchSecondary use, OMOP harmonisation, cohort building, repeatability
Information-based managementShared definitions and metrics, situational picture, population-level analytics
Operational useExchange of information between systems, integrations, process automation
Clinical workDecision support and workflows that fit the work of the professional

Regulation is part of the structure

Regulation affects the architecture, the data flows, access rights, documentation and release practices. That is why it is taken along when the structure is designed. In the implementation it shows up as six things: data protection by design, role-based access control, audit trail and logging, controlled processing environments, documented ownership and use bound to the stated purpose.

The architecture is affected by GDPR, the Finnish Act on the Secondary Use of Health and Social Data, EHDS, the regulation of medical devices (MDR and IVDR) and the EU AI Act.

The Act on the Secondary Use of Health and Social Data changed on 1 May 2026

A permit for data held by several controllers can now be applied for from Findata or separately from each public controller. A wellbeing services county can therefore be both the authority that grants the permit and the party that compiles the dataset. The repeatability and the audit trail of the extraction are then the controller's own work. Pseudonymised data is still personal data for whoever holds the key.

EHDS in brief

EHDS, the European Health Data Space, is based on EU Regulation (EU) 2025/327. It affects both the primary use and the secondary use of health data. It is not one central database or a technical platform. The regulation entered into force in March 2025, and its obligations become applicable mainly between 2027 and 2031. The rules on secondary use start to apply mainly in March 2029. The effects reach data platforms, data models, access rights and the processes of secondary use. EHDS raises the level of the requirements, but it does not replace good architecture and clear ownership.

Evidence

We have evidence of technical support, architecture work and the strengthening of production readiness in OMOP-based and OMOP-related health data solutions. We have done this work in several environments. We will describe customer-specific details once the customer's permission is in place.

How to buy this

Health data work is bought in the same way as other data production: as a project or a continuous allocation. Choosing a standard or assessing the requirements of secondary use can also be a limited definition.