Home›Blog›Cross-Border ePrescription: Who Verifies the Prescribing Doctor?
Back to Blog

Cross-Border ePrescription: Who Verifies the Prescribing Doctor?

Ā·Mairi Kutberg Ā·
cross-border-eprescriptionehdsiehdshealthcare-identitydoctor-verificationncpeheidaseu-professional-cardhealth-data-spaceauthentication

The doctor is verified at the home Member State, asserted across the eHDSI network through a federation of National Contact Points for eHealth, and re-validated at the dispensing Member State's contact point. The cryptographic chain terminates at the home country's national medical register. EHDS 2025 harmonises the exchange format and adds the European Health Data Access Body layer, but the identity-proofing of the doctor still sits with the home Member State's trust framework and its credentialing body.

Cross-Border ePrescription: Who Verifies the Prescribing Doctor?

The doctor is verified at the home Member State, asserted across the eHDSI network through a federation of National Contact Points for eHealth, and re-validated at the dispensing Member State's contact point. The cryptographic chain terminates at the home country's national medical register. EHDS 2025 harmonises the exchange format and adds the European Health Data Access Body layer, but the identity-proofing of the doctor still sits with the home Member State's trust framework and its credentialing body.

In our work helping cross-border healthcare integrations land in 2026, the doctor-verification question shows up on the pharmacist's side of the dispense, not the doctor's side of the prescribe. A Barcelona-based pharmacy chain we worked with last quarter receives roughly 40 cross-border ePrescriptions per week through eHDSI — most from German tourists, some from Dutch and French patients — and the dispense system has to answer, in roughly two seconds, whether each assertion is trustworthy enough to dispense the controlled substance the prescription names. The doctor never sees the verification chain. The pharmacist sees it as a green tick or a red flag. What sits underneath that tick or flag is a federation of trust frameworks that took most of a decade to assemble and is in the middle of being rebuilt under the European Health Data Space — the patient-side equivalent of the same verification we covered in our earlier post on the EHDS Patient Summary.

What does cross-border ePrescription actually require to verify the doctor?

A chain that runs from the dispensing pharmacist back to the prescribing doctor's licence record at the doctor's home Member State, with every hop signed by an eIDAS-anchored certificate.

The chain has three load-bearing elements. The first is the prescribing event itself — the doctor's authoring act, which in most Member States is captured in the national health system with a digital signature anchored on the doctor's professional certificate (issued by the national medical register or an authorised QTSP). The second is the cross-border format — the ePrescription document is converted into the European Master Patient Index / European Patient Summary format defined by the eHealth Network and exchanged across eHDSI. The third is the trust chain across the National Contact Points for eHealth (NCPeHs) — each Member State operates one NCPeH that signs the outgoing document on behalf of its national system and verifies signatures on incoming documents from other Member States. The dispensing pharmacist's system reads the prescription, sees the NCPeH-A signature on the cross-border envelope, sees the home Member State's professional certificate inside the envelope, and resolves both against the EU Trusted List.

What this means at audit is that every dispense of a cross-border prescription leaves an evidence trail with at least four cryptographic anchors: the prescribing doctor's professional certificate, the home NCPeH's outgoing signature, the dispensing NCPeH's validation record, and the dispensing pharmacist's own dispense signature. A Spanish DPA looking at a cross-border dispense in 2027 should be able to reconstruct the full chain without contacting either the German registrant or the German pharmacy back-office. That is what makes the dispense defensible rather than just possible.

What I see at the regulator-pharmacy interface is that compliance leads have learned to treat the cross-border dispense as a higher-evidence event than a domestic dispense, not a lower-evidence one. The federation expands the doctor-pool the pharmacist can serve, but it also expands the chain the dispense has to defend if it gets audited. The pharmacies that ship against this reading in 2026 retain the full envelope and the full validation record; the ones that retain only the prescription text are walking into an evidence gap.

How does eHDSI handle the doctor's identity across borders today?

Through a centralised gateway run by DG SANTE, with each Member State's NCPeH as the trust boundary on its side.

The eHealth Digital Service Infrastructure (eHDSI) is the EU-level network that exchanges cross-border ePrescriptions and Patient Summaries. Its legal basis is Commission Implementing Decision (EU) 2019/1765, updating the earlier infrastructure under Directive 2011/24/EU on patients' rights in cross-border healthcare. As of mid-2026, twenty-five Member States are exchanging at least one of the two services live, with the remaining states in conformance testing.

The doctor-identity question is handled at two levels. At the home Member State level, the prescribing doctor's identity is anchored on the national medical register — every licensed physician in the EU has a registry record in their home country, and the digital prescribing event is bound to that record through the doctor's professional certificate or eID. At the cross-border level, the NCPeH on the home side signs the outgoing ePrescription document on behalf of the home health system, asserting that "this document was issued by an authorised prescriber under our national trust framework". The receiving NCPeH validates the signature against the home Member State's published certificate, and the dispensing system trusts the home NCPeH's assertion. The doctor's individual identity is not exposed beyond the home Member State; what crosses the border is a verified attestation from a sovereign trust point.

The practical implication that compliance leads should care about is that there is no pan-EU register of physicians the pharmacist can query directly. The trust depends entirely on each Member State maintaining a clean register and signing correct envelopes. The European Professional Card under Directive 2005/36/EC covers a small subset of professions (nurses, pharmacists, physiotherapists, mountain guides, real estate agents) but does not yet cover doctors — the Commission's January 2026 implementing-act consultation on extending the EPC to physicians is still open. Until the EPC extends, the doctor-side trust chain remains national-register-anchored, federation-bridged by eHDSI.

What I'd push back on hardest in vendor marketing is the implication that eHDSI is a single source of truth for doctor identity. It isn't. It's a federation. The source of truth lives in each Member State's national medical register. eHDSI is the protocol that lets the dispensing pharmacist read that source of truth through a verified intermediary. The architecture decision the EU made in 2019 — sovereign trust per Member State, federation in the middle — was the right one for the political reality of healthcare regulation, and it is the architecture that EHDS 2025 builds on rather than replaces.

Where does the EHDS Regulation change this in 2026-2029?

It harmonises the exchange format under MyHealth@EU, adds the European Health Data Access Body layer for secondary use, and standardises the underlying credential expectations — but leaves the trust framework where it sits.

Regulation (EU) 2025/327 on the European Health Data Space (EHDS) entered into force on 26 March 2025 and applies progressively through 2029. The EHDS framework rebrands the eHDSI exchange layer as MyHealth@EU for primary use (clinical care across borders) and creates the HealthData@EU layer for secondary use (research, policy, public health). The doctor-verification question we have been walking through sits squarely in primary use under MyHealth@EU.

What changes for the doctor-verification chain in concrete terms. EHDS Article 12 mandates that Member States make patient data available in a harmonised European Electronic Health Record Exchange Format (EEHRxF) by 26 March 2029 for priority categories (patient summaries, ePrescriptions, ePrescription dispensations, medical images, laboratory results, hospital discharge reports). Article 14 requires every Member State to designate or establish a digital health authority responsible for the national implementation and for connection to MyHealth@EU. Article 19 obliges health professionals using EHR systems to identify and authenticate themselves through their national infrastructure — explicitly leaving the how of that identification to the Member State, but requiring that the resulting identity be propagated through the EEHRxF metadata when the document crosses borders.

This last point is the operational lever. Under the old eHDSI architecture the doctor's identity was inside the envelope, signed by the home NCPeH. Under EHDS the doctor's identity has to be structured in the EEHRxF metadata — named, role-tagged, certificate-fingerprint-referenced — in a way that any downstream EU verifier can re-validate without needing to call back to the home Member State. That moves the chain from federation-trust-with-opaque-payload to federation-trust-with-transparent-payload. The trust framework is the same; the evidence resolution improves materially.

What I see in the institutional rollout planning for 2027-2029 is that Member States are now under formal pressure to clean up their national medical registers, harmonise certificate-issuance practices for prescribing professionals, and ensure that what eHDSI was already doing for them in opaque form will hold up when EEHRxF makes it transparent. That clean-up is where most of the operational work is landing — not at the cross-border protocol layer but at the home Member State register layer.

Cross-border ePrescription doctor verification flow — five stages from home Member State register through prescribing certificate signing, eHDSI NCPeH gateway, dispensing Member State NCPeH validation, and pharmacist dispense decision, with the EU Trusted List as the cross-border anchor.

What's the role of EUDI Wallet, EU Professional Card, and IdentiGate-class proofing layers?

EUDI Wallet provisions a Person Identification Data attestation for the doctor; an extended EU Professional Card would carry the professional qualification attestation; identity-proofing primitives at the foundation layer issue the chip-anchored evidence that both attestations rely on.

The 2026-2029 layered map is starting to clarify. The EUDI Wallet under Regulation (EU) 2024/1183 becomes available to every EU resident — including doctors — by 6 December 2026. The wallet's Person Identification Data (PID) attestation carries the doctor's core identity attributes. An Electronic Attestation of Attributes (EAA) carrying the professional qualification could be issued either by the national medical register (as part of the proposed EU Professional Card extension under Directive 2005/36/EC) or by the digital health authority designated under EHDS Article 14. The doctor presents the wallet to the prescribing system, the system reads both attestations, and the prescribing event is signed with the wallet-held key bound to the verified identity. That structure is forward-compatible with both the EHDS EEHRxF and the eHDSI envelope format.

Where the identity-proofing layer sits in this picture is at the issuance step for both attestations. Before the PID can be provisioned into the doctor's wallet, the doctor's identity has to be verified at IAL2 or higher (NIST SP 800-63-4 terminology) — typically through a chip-anchored proofing primitive that reads the doctor's passport or national eID card and binds the identity to the device the wallet runs on. Before the professional qualification EAA can be issued, the national medical register needs to verify that the holder of the PID is also the licensed physician of record. The IdentiGate Identity Verification product ships this primitive: passport NFC for the 179 ICAO 9303 countries or document authenticity plus FaceTec biometric face match for every remaining country, AdES-bound under eIDAS Article 26. The distinctive value is the chip-anchored proofing that travels with the doctor across borders even when their home Member State scheme does not federate, and that lands on the same IAL2-plus assurance baseline that an EHDS-designated digital health authority will be looking for at audit.

For cross-border telemedicine — where a Ukrainian physician practising under temporary recognition in Poland prescribes for a patient in Italy — the EUDI Wallet path does not yet reach. Ukraine is outside the EU trust framework; the temporary recognition under the Polish medical chamber is administrative rather than digitally federated; the Italian pharmacist's dispense system sees an unfamiliar trust chain. The honest read for any cross-border health platform planning around this gap is that the foundation-layer chip-anchored proofing primitive can produce the AdES-bound evidence the Italian system needs even when no Member State NCPeH yet bridges the trust, and that the Identity Verification product plus a Signatures record together cover the non-federated edge while the EUDI Wallet and EHDS rollout catches up on the federated centre.

What I'd push back on hardest in the EHDS-rollout marketing is the implication that 26 March 2029 is when cross-border doctor verification "becomes solved". The Member State register clean-up is a much bigger lift than the protocol harmonisation, and the non-federated edges (temporary recognition, third-country professionals, transitional residents) are not addressed by EHDS at all. The protocol layer is being solved; the trust framework's reach is expanding incrementally; the identity-proofing layer at the foundation is what the rest of the stack will sit on. Get the foundation layer right, and the harmonisation lands cleanly. Get it wrong, and the harmonisation just propagates the registry-quality gaps faster.

Sources

Primary — EU healthcare framework

Primary — eHDSI / MyHealth@EU technical

Primary — eIDAS and EUDI Wallet

Primary — NIST identity assurance

About the author

Mairi Kutberg is co-founder of IdentiGate. She focuses on identity-proofing operations under eIDAS, NIS2, AMLR, the AI Act, the EHDS, and adjacent regulatory frameworks, and on the institutional reality of running cross-border identity verification at scale.

Related articles
2026-07-22 Ā· Mairi Kutberg
What Happens if Someone Denies They Signed Digitally?
The signature carries the burden of proof — but the burden falls back on whoever relied on it if the evidence chain behind the signature isn't complete. Under eIDAS Article 25(2), Qualified Electronic Signatures presume authenticity unless the challenger rebuts it. For Advanced signatures, the party asserting the signature has to demonstrate identity binding, integrity, and time — and courts have been consistent since 2020 that thin proofing evidence loses the case.
Read more →
2026-07-20 Ā· Gustav Poola
What Encryption Does a Digital Signature Use?
Strictly speaking, digital signatures don't encrypt anything — they use asymmetric cryptography to sign a hash of the data. The signer's private key transforms the hash into a signature; the corresponding public key verifies it. In 2026 production: RSA-PSS with SHA-256 (RFC 8017), ECDSA over P-256 or P-384 (RFC 6979), and Ed25519 (RFC 8032). ETSI TS 119 312 sets which cryptographic suites are acceptable for AdES, and the post-quantum migration is starting to reshape the algorithm shortlist through 2030.
Read more →
2026-07-18 Ā· Mairi Kutberg
What Makes a Digital Signature Legally Valid?
Three things stacked in the right order under eIDAS Article 25: non-discrimination in principle for any electronic signature, equivalence to a handwritten signature only for Qualified Electronic Signatures under Article 25(2), and successful validation under the Article 32 procedure. The gap that costs cases in court is between 'the signature exists' and 'the signature validates against Article 32 requirements' — and the identity-proofing under the signing certificate is where most legal-validity claims quietly break.
Read more →
All Articles