27–29 Oct 2026
Santiago Compostela
Europe/Madrid timezone

An Integrated Medical Imaging Archive and Secure Processing Environment

28 Oct 2026, 16:25
15m
Santiago Compostela

Santiago Compostela

Facultad de Química Santiago de Compostela Aula Magna
Presentation (15' + 5' for questions) Trusted Research Environments Parallel track - III

Speaker

Ignacio Blanquer Espert (Universitat Politècnica de València)

Description

Here is an improved version of your text with polished grammar, enhanced flow, corrected capitalization, and consistent professional style:

The Data Governance Act defines a Secure Processing Environment (SPE) as “the physical or virtual environment and organisational means to ensure compliance with Union law, such as Regulation (EU) 2016/679, in particular with regard to data subjects’ rights, intellectual property rights, and commercial and statistical confidentiality, integrity and accessibility, as well as with applicable national law, and to allow the entity providing the secure processing environment to determine and supervise all data processing actions, including the display, storage, download and export of data and the calculation of derivative data through computational algorithms.”

Under the European Health Data Space (EHDS) framework, an SPE must incorporate specific safeguards. These include restricting access to authorized persons designated in the relevant data permit; minimizing the risk of unauthorized reading, copying, modification, or removal of electronic health data; ensuring data users can access only the specific data covered by their permit; maintaining identifiable access logs for the duration necessary to verify and audit all processing operations; and continuously monitoring security measures to mitigate potential threats.

According to the TEHDAS2 Technical Specifications, the main features of an SPE encompass stringent technical, functional, and security capabilities mandated for Health Data Access Bodies (HDABs). These include robust identity and access management with multi-factor authentication, end-to-end encryption for data both at rest and in transit, and comprehensive logging and auditing tools to track all user activities. Furthermore, SPEs enforce strict limitations on data export, allowing only aggregated, anonymized, or non-sensitive research results to leave the environment following rigorous compliance reviews to prevent the re-identification of subjects. Architecturally, these specifications differentiate between standalone environments and an interoperable target ecosystem that supports federated computing across organizations and EU Member States, enabling researchers, innovators, and policymakers to leverage distributed health data repositories safely while complying fully with GDPR and EHDS mandates.

IMASPE (Integrated Medical Archive and Secure Processing Environment) is a secure platform designed to manage medical imaging datasets, enabling them to be efficiently organized, published, accessed, and processed via virtual research environments and federated platforms. Built on top of Kubernetes, IMASPE delivers a comprehensive suite of services: managing authentication and permits via external identity providers, ingesting data, structuring files into distinct datasets, publishing associated metadata, exposing secure endpoints for federated search and processing, and providing access through secure graphical virtual environments that guarantee data sovereignty and non-repudiable access logs. IMASPE serves as a key component of the European Cancer Imaging Infrastructure.

Authors

Ignacio Blanquer Espert (Universitat Politècnica de València) Dr Adrei Stefan Alic Dadu (Universitat Politècnica de València) Dr Damià Segrelles Quilis (Universitat Politècnica de València) Mr David Arce Grilo (Universitat Politècnica de València) Mr Pablo Montoliu Rico (Universitat Politècnica de València) Mr Pau Lozano Lloret (Universitat Politècnica de València)

Presentation materials

There are no materials yet.