The Netherlands Is Making Electronic Health-Data Exchange Mandatory
The Dutch Wegiz is a framework for turning selected exchanges of health information from optional digitisation projects into mandatory, standardised and potentially certified processes.
The Wet elektronische gegevensuitwisseling in de zorg, known as the Wegiz, entered into force on 1 July 2023. It allows the government to designate particular exchanges between healthcare providers that must occur electronically and to impose requirements for interoperable exchange.
The Act does not make every health-data flow electronic on its first day. Specific obligations are activated through secondary measures and a multi-year agenda. That staged model makes implementation a portfolio of defined exchanges rather than one national “health data” project.
Designation turns a workflow into a regulated exchange
A designated exchange identifies the data and care context to which the requirement applies. The law can require healthcare providers to exchange that information through electronic infrastructure. Further rules can prescribe functional, technical and organisational methods.
The first compliance task is therefore to map care workflows to designated exchanges. A hospital should not ask only whether it has an electronic record system. It should know how a medication transfer, referral or other specified process moves from the sending professional to the receiving professional and where manual re-entry remains.
That map should include systems, interfaces, organisations, professional roles and patient-facing environments. An exchange can be electronic at both ends and still depend on a fax, PDF or copy-and-paste in the middle.
Interoperability is semantic as well as technical
The Wegiz supports mandatory use of standards and requires attention to interfaces based on open and, where possible, international standards. Connectivity alone is not enough. The receiver must understand the meaning, context and status of the information.
For each data element, implementation teams need shared definitions, codes, units, identifiers and rules for corrections. They also need to know whether the information is a current clinical statement, a historical observation or an unverified patient report.
API conformance can test structure and transport, but clinical safety also depends on how software presents the information and how professionals resolve conflicts. Interoperability testing should therefore include realistic end-to-end scenarios, not only sample messages accepted by a gateway.
Certification changes the supplier relationship
The Act enables requirements for information-technology products, services and healthcare information systems, including mandatory certification for relevant parts of a designated exchange. The aim is to support interoperable operation and improve substitutability in the market.
Healthcare organisations should identify which compliance evidence belongs to the vendor and which belongs to local deployment. A certified product can still be configured poorly, connected to an unsupported version or used in a workflow that bypasses the standard exchange.
Contracts should address maintenance of certification, version changes, vulnerability management, interface stability, test support, migration and the handling of non-conformity. A certificate at purchase should not become an excuse to stop monitoring the service.
Privacy law still governs the decision to share
The Wegiz changes the form and standards of designated exchanges; it does not create a universal permission to disclose health data. The Act expressly distinguishes an obligation to exchange electronically from the legal basis and professional rules that determine whether information should be exchanged in a particular case.
Access control, patient information, confidentiality, purpose limitation and logging remain central. A technically interoperable exchange can increase both clinical benefit and the scale of an error. Identity matching and authorisation must therefore be tested as seriously as message format.
Build evidence by exchange
For every designated exchange, a provider should maintain:
- scope and participating care processes;
- the applicable standard and implementation version;
- sending, receiving and intermediary systems;
- identity, authorisation and logging controls;
- product certificates and local configuration evidence;
- end-to-end test results and clinical-safety issues; and
- downtime, correction and fallback procedures.
The Wegiz makes interoperability a continuing operational duty. Its success will not be measured by how many systems claim to support a standard, but by whether authorised professionals receive accurate, usable information at the point of care—and whether the organisation can prove how that happened.
Official sources
- Dutch legislation database: Wegiz as in force from 1 July 2023
- Dutch government: technical information and commencement history for the Wegiz
Continue the series
- Also in the Netherlands: The Dutch Digital Government Act Regulates How Citizens Log In
- European National Cyber & Digital Law Series index
This article provides general information and is not legal advice.



