.png)
Germany has taken its most significant step yet toward a connected digital health system. The GeDIG Act, short for the Act on Data and Digital Innovation in Healthcare (Gesetz zu Daten und digitaler Innovation im Gesundheitswesen), transforms the electronic patient record from a storage tool into the central hub of German healthcare. For the first time, it also opens a formal path for wearable data to be integrated into that infrastructure.
For digital health companies, health insurers, and platforms operating in the German market, GeDIG is not a distant policy development. It defines new compliance requirements, creates new market opportunities, and establishes the technical and regulatory conditions under which wearable data can be used in clinical and insurance contexts. Understanding what it actually says matters.
The GeDIG Act was approved by the German government as part of a broader effort to bring healthcare into the digital era. It builds on earlier reforms, including the Digital Healthcare Act (DVG) and the Digital Supply Act (DiGA framework), but goes significantly further in scope.
Where previous legislation focused on enabling individual digital tools, GeDIG is about connectivity: making the electronic patient record (ePA) the platform through which all digital health interactions are coordinated. The Act is part of Germany's Digitalisation Strategy for Health and Care 2026, which sets out a vision of a health system where data, digital services, and AI are embedded in everyday care delivery rather than bolted on as optional extras.
The broader financial commitment behind this vision is substantial. The government's Transformation Fund is designed to provide up to 50 billion euros over ten years, from 2026 to 2035, to support hospital modernisation, digital infrastructure, and interoperable health platforms.
The electronic patient record has existed in Germany since 2021, but uptake and functionality have been limited. GeDIG changes that fundamentally.
Under the new Act, the ePA is no longer conceived as a passive repository for medical documents. It becomes the digital entry point to the healthcare system, intended to support patients and clinicians throughout the entire care journey. Planned additions include:
The goal is a single digital environment from which patients can access care, receive advice, track their health records, and communicate with providers, without navigating multiple disconnected systems.
Healthcare providers are now required to use software compatible with the ePA. Non-compliance can affect billing eligibility, which gives the interoperability requirement real teeth.
The most significant development for wearable technology companies and health insurers is a specific provision that allows health insurance companies to use data from the ePA alongside data from wearable devices, such as smartwatches, to identify health risks in their members.
This is not unconditional. The provision requires explicit consent from the insured individual before any wearable data can be accessed or processed. But within that consent framework, the scope is meaningful: insurers can combine passive biometric data from wearable devices with medical record data and billing data to build a more complete picture of a member's health status.
The practical implications are significant:
What this requires, on the technical side, is a consent architecture that is genuinely robust, a data pipeline that meets GDPR Article 9 standards for special category health data, and wearable data that is normalized and reliable enough to be clinically and actuarially meaningful.
Artificial intelligence is one of the most prominent themes of GeDIG. The Act formalises AI's role in German healthcare in several ways.
The Health Research Data Center (Forschungsdatenzentrum Gesundheit, FDZ) is expected to support at least 300 research projects by the end of 2026, and the platform is being expanded to become AI-ready, allowing data to be used for training, testing, and validating AI models at scale.
Within the ePA itself, AI-supported processing of medical findings will allow clinical documents to be analysed, summarised, and made searchable. This is designed to reduce the administrative burden on clinicians and make relevant information more accessible at the point of care.
The government's position is that AI should move beyond supporting treatment into preventing disease before it occurs. Prevention reminders, personalised health information, and risk identification tools are all part of the ePA's expanded role under GeDIG.
GeDIG gives health insurers significantly expanded scope to build digital health capabilities. The Act allows insurer apps to incorporate:
For insurers that have been building wearable-based wellness programs without a clear regulatory foundation, GeDIG provides that foundation. It also raises the bar: informal data sharing arrangements are no longer sufficient. The consent, data quality, and compliance requirements attached to the wearable data provision mean that insurers need infrastructure capable of meeting those standards at scale.
For DiGA developers and digital health platforms operating in Germany, GeDIG introduces new obligations and new opportunities in parallel.
Mandatory success measurement for DiGA products (AbEM) requires continuous reporting of clinical outcomes to the Federal Institute for Drugs and Medical Devices (BfArM), with results published publicly. This raises the evidence standard for digital health applications and increases the operational reporting burden.
Software that interacts with the ePA must meet the interoperability standards required for ePA compatibility. For products not already built to those standards, this requires investment in integration work.
The formalisation of wearable data as a legitimate source for health record enrichment and insurer risk programs opens a market that has previously operated in a regulatory grey area. Products that can reliably connect wearable data to ePA infrastructure, with appropriate consent management and GDPR compliance, are now in a position to serve a formally recognised need.
GeDIG's vision depends on infrastructure that most organisations are not starting with. Making wearable data useful in an ePA or insurer context requires more than a device connection. It requires:
Building this infrastructure from scratch is a significant undertaking. The organizations that can move quickly under GeDIG are those that are already working on a foundation that meets these requirements.
At Thryve, we build the wearable data infrastructure that digital health organizations operating in the German market need to act on GeDIG's provisions. Our platform is designed for exactly the combination of requirements the Act creates: normalized data across hundreds of devices, GDPR-compliant data flows with EU data residency, and consent management built in at the infrastructure level.
With our wearable API, you get:
If your organization is building digital health products for the German market and wants to understand how GeDIG affects your data infrastructure requirements, book a demo with Thryve!
Friedrich Lämmel is CEO of Thryve, the plug & play API to access and understand 24/7 health data from wearables and medical trackers. Prior to Thryve, he built eCommerce platforms with billions of turnover and worked and lived in several countries in Europe and beyond.