Cloud, AI, and platform technologies open up new possibilities for hospitals. But with every technology decision comes a strategic question: how much control does a hospital retain over its data, IT operations, and future technology decisions? This is precisely what digital sovereignty for the healthcare sector is about. It does not mean forgoing cloud or international technology providers. It means knowing dependencies, consciously assessing them, and keeping them manageable.
This question has occupied me long before cloud and AI began to dominate discussions in healthcare. From my time in strategic hospital procurement, I know it from a different context.
When investing in medical technology, large equipment, or infrastructure, what mattered was not only what a solution delivers on the day of purchase.
At least equally important was: What dependencies are we entering into for the next five or ten years? How will service and costs develop? What expansion options remain? And what alternatives do we have if our requirements change?
Today we are talking about cloud platforms, hospital information systems (HIS), data spaces, and AI. However, the logic of a sound investment decision has remained the same.
For me, digital sovereignty therefore describes above all the ability of a clinic to retain control over its data, IT operations, and key technology decisions. Digital independence, however, is not the goal, because no hospital can or must develop and operate all of its technology itself. What is crucial instead is to retain realistic alternatives for action, even within digital ecosystems.
Digital sovereignty is more than the question of which country a server is located in. For hospitals, it can be broken down into four levels.
Data sovereignty: Who is allowed to access health data? Where is it processed? Who controls cryptographic keys? And can data be exported completely and in a reusable format?
Operational sovereignty: Which external services are critical to care delivery? How quickly can systems be restored? What options exist for emergency operations and recovery if a service fails?
Technological sovereignty: How interchangeable are applications and platform services? Open interfaces, standardized data models, and interoperability can prevent data and processes from being permanently locked into proprietary systems.
Decision-making sovereignty: Does the hospital remain able to choose between realistic alternatives when providers, technologies, costs, or regulatory requirements change?
In particular, the last level connects digital sovereignty with the responsibility for care. Because IT is today a prerequisite for a hospital to be able to fulfil its medical mission.
The decisive question is therefore not: public cloud or private cloud? Instead, it is: What level of control do we need for which data and which process?
A publicly accessible information service has different requirements than a core clinical system or a platform processing particularly sensitive health data. A hybrid cloud, for example, can combine different operating models and makes it possible to assign workloads according to their criticality. Critical data and applications can be operated where particularly high requirements for control and sovereignty exist. Other workloads can specifically leverage the scalability and speed of innovation offered by public cloud services.
What is interesting is that the European discussion is increasingly following this risk-based approach as well. The European Commission proposed the Cloud and AI Development Act (CADA) in June 2026. The EU-wide Sovereignty Framework envisaged therein distinguishes four levels of sovereignty—from processing and storage within the EU to far-reaching control over providers and software supply chains.¹
For hospitals, an important principle can be derived from this: sovereignty must match criticality. Maximum sovereignty for every individual workload is neither necessary nor economically viable. What matters is an architecture that enables different options and does not preclude their later adaptation.
One important insight from strategic hospital procurement has stayed with me to this day: The quality of an investment decision often only becomes apparent years after the procurement.
With a large medical device, dependencies are relatively visible. Maintenance contracts, spare parts supply, software updates, and expansion options can be evaluated in advance.
With digital platforms, dependencies often arise where they are initially barely noticeable: in proprietary interfaces and data formats, licensing models, platform services, or operational processes. When these components are closely interlinked, the efforts and costs of a later migration are amplified.
That is why, for me, a simple question should be asked at the very start of every strategic technology decision:
How do we get out again?
Can data be exported completely and in a usable format? Can applications and workloads be transferred to another provider? What support is contractually provided for a migration? How long would a switch take—and can hospital operations continue without restriction in the meantime?
Portability and a robust exit strategy are therefore not questions for the end of a contract. They are criteria for the original investment decision. The EU Data Act also focuses on switching options, portability, and interoperability for cloud and data processing services.²
This applies equally to the further development of HIS. When data remains available through open interfaces and standardized models independently of individual applications, clinics can more easily integrate new services, AI applications, or platforms. A vendor-independent health data platform such as synedra AIM can create a technological foundation for this without permanently binding the data to individual applications.
Technology alone does not create digital sovereignty. Hospitals must also define who assesses dependencies, who decides on the necessary level of sovereignty, and when these decisions are to be reviewed again.
For major technology decisions, management, CIO, procurement, information security, and data protection teams should therefore work together to find answers to key questions:
Why these questions are relevant is also illustrated by the current discussion surrounding the US case Trump v. Slaughter. While the ruling itself does not affect European data protection law and does not invalidate the EU-US Data Privacy Framework, it does show how political and legal frameworks can change even when the technology in use remains unchanged.³
For decision-makers in hospitals, this is precisely the relevant message: An architecture should not only function under today's conditions, but it should also preserve options for action, even if those conditions change tomorrow.
Clinics must modernize their IT while simultaneously keeping an eye on economic viability, security, and patient care. The German hospital reform is adding to this pressure to act: According to the Krankenhaus-Barometer 2025 published by the German Hospital Institute, two-thirds of hospitals reported losses in 2024; around 90 percent reported limited planning certainty in connection with the reform.⁴
Especially under such conditions, technology decisions must be sustainable in the long term.
Digital sovereignty for the healthcare sector therefore does not mean avoiding dependencies entirely. It means knowing them, assessing them, and keeping them manageable.
For CIOs and hospital management, this raises three questions that, in my view, should be answered for every major technology decision:
If the answer to that is yes, genuine investment protection is created. Because digital sovereignty is not demonstrated by which technology a hospital uses today. It is demonstrated by which options remain open to it tomorrow.
Digital sovereignty for the healthcare sector describes the ability of hospitals and other stakeholders to retain control over their data, IT operations, and key technology decisions. What matters is not to avoid dependencies entirely, but to know them, assess them, and keep them manageable.
Hospitals depend on constantly available digital systems for patient care and process particularly sensitive health data. Digital sovereignty helps them to use cloud, AI, and platform technologies while remaining capable of acting in the long term—even when providers, technologies, or regulatory frameworks change.
Digital independence aims to reduce dependencies on individual providers or technologies as much as possible. Digital sovereignty goes beyond this: a hospital can use external cloud and platform services and still act sovereignly, provided that dependencies remain transparent and manageable and realistic alternatives exist.
No. The required level of sovereignty should be determined by the criticality of data, applications, and processes. A publicly accessible information service has different requirements than a core clinical system with sensitive health data. Hybrid cloud models can combine different operating models and assign workloads according to their requirements.
Vendor lock-in can be limited in particular through open interfaces, standardised data models, interoperable systems, and portable data and workloads. Equally important are contractual provisions for changing providers. What matters is not avoiding every dependency, but knowing its implications and switching costs and keeping them manageable.
Digital sovereignty is also reflected in whether a hospital can actually switch a provider or a technology. An exit strategy should therefore already take into account during procurement which data and workloads can be transferred, in which formats they are available, what support the provider must offer, and how hospital operations will be ensured during a migration.
1 European Commission: Cloud and AI Development Act (CADA), proposal of 3 June 2026. The proposed EU Sovereignty Framework provides for four risk-based sovereignty levels for cloud and AI.
2 European Commission: Data Act / Interoperability of data processing services. The Data Act addresses in particular switching options, portability, and interoperability between data processing services.
3 See classification on Trump v. Slaughter and the EU-US Data Privacy Framework; the Framework continues to apply. The case illustrates possible changes in political and regulatory conditions.
4 German Hospital Institute (DKI): Hospital Barometer 2025, published by the German Hospital Association (DKG), December 2025.